* [PATCH 7.2 000/438] 7.2.8-rc1 review
@ 2026-09-23 14:00 Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 001/438] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test Greg Kroah-Hartman
` (449 more replies)
0 siblings, 450 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, linux-kernel, torvalds, akpm, linux,
shuah, patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
This is the start of the stable review cycle for the 7.2.8 release.
There are 438 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Fri, 25 Sep 2026 14:05:46 +0000.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.8-rc1.gz
or in the git tree and branch at:
git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
and the diffstat can be found below.
thanks,
greg k-h
-------------
Pseudo-Shortlog of commits:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Linux 7.2.8-rc1
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: fix partial normalized name responses
Mario Limonciello <mario.limonciello@amd.com>
drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only
Vadim Nikitushkin <bub4z0r@gmail.com>
drm/ttm: fix swapped-out resources never leaving their bulk_move range
Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
ntsync: reject wait ioctls with zero owner
Mario Limonciello <mario.limonciello@amd.com>
drm/amdgpu: Fix GPU PCIe link capability reporting
chong li <chongli2@amd.com>
drm/amdgpu: reduce early full GPU access during SR-IOV init
Arun Easi <aeasi@cisco.com>
scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU
Karan Tilak Kumar <kartilak@cisco.com>
scsi: fnic: Bump up version number
Karan Tilak Kumar <kartilak@cisco.com>
scsi: fnic: Make debug logging protocol independent
Qi Zheng <qi.zheng@linux.dev>
fs: fix missed removal of super_fs_objects_eligible()
Usama Arif <usama.arif@linux.dev>
fs/super: skip non-memcg-aware nr_cached_objects in memcg slab shrink
Frank Sorenson <sorenson@redhat.com>
smb: client: fix missing iov bounds check in parse_posix_sids()
Frank Sorenson <sorenson@redhat.com>
smb: client: fix missing lower-bound check on DFS referral string offsets
Frank Sorenson <sorenson@redhat.com>
smb: client: fix server->total_read for compound encrypted PDUs
Frank Sorenson <sorenson@redhat.com>
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
Frank Sorenson <sorenson@redhat.com>
smb: client: fix potential OOB read in smb3_enum_snapshots()
Frank Sorenson <sorenson@redhat.com>
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
Frank Sorenson <sorenson@redhat.com>
smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
Paulo Alcantara <pc@manguebit.org>
smb: client: fix fattr leaking on wsl_to_fattr() failure
Paulo Alcantara <pc@manguebit.org>
smb: client: fix unaligned access in WSL reparse point parser
Paulo Alcantara <pc@manguebit.org>
smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
Frank Sorenson <sorenson@redhat.com>
smb: client: reject short Next offsets in parse_server_interfaces()
Joseph Qi <joseph.qi@linux.alibaba.com>
smb: client: fix use-after-free of iface in cifs_try_adding_channels()
Paulo Alcantara <pc@manguebit.org>
smb: client: fix rlist race and missing initialization
April Cardenas <april.cardenas@canonical.com>
smb/client: send lease break ACKs thru correct session for multiuser mounts
Paulo Alcantara <pc@manguebit.org>
smb: client: cancel reconnect work in clean_demultiplex_info()
Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1
David Francis <David.Francis@amd.com>
drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc
David Francis <David.Francis@amd.com>
drm/amdkfd: Avoid integer underflow in EOP ring size calculation.
Mario Limonciello <mario.limonciello@amd.com>
drm/amdgpu: Skip KFD mapping clear before initialization
Mike Lothian <mike@fireburn.co.uk>
drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments
Chengjun Yao <Chengjun.Yao@amd.com>
drm/amdgpu: fix rmmio iounmap skipped on device removal
Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
drm/sched: Fix virtual runtime race
Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
drm/msm: RCU-free the scheduler-containing ring and VM objects
Guangshuo Li <lgs201920130244@gmail.com>
drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure
Saim Shujah <saimzst@gmail.com>
drm/msm/dpu: clear pending peripheral flush state
Guangshuo Li <lgs201920130244@gmail.com>
drm/msm/adreno: fix autosuspend cleanup during teardown
Sophie D <patches@scd31.com>
drm/gud: Ignore damage clips in full update mode
Sajal Gupta <sajal2005gupta@gmail.com>
drm/gud: fix out-of-bounds write in gud_plane_atomic_check()
Devin Wittmayer <lucid_duck@justthetip.ca>
wifi: mac80211: refuse to make a monitor active when it has no queue
Ivan Pustogarov <ivan@ipust.net>
wifi: mac80211: avoid out-of-bounds read for empty PREQ elements
Rik van Riel <riel@surriel.com>
wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver
Zhao Li <enderaoelyther@gmail.com>
wifi: mwifiex: validate action frame fixed fields
Linmao Li <lilinmao@kylinos.cn>
wifi: mwifiex: prevent authentication frame length truncation
Pengpeng Hou <pengpeng@iscas.ac.cn>
wifi: mwifiex: validate scan response extents
Doruk Tan Ozturk <doruk@0sec.ai>
wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length
Shengzhuo Wei <me@cherr.cc>
wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
Shengzhuo Wei <me@cherr.cc>
wifi: p54: validate curve data length in the calibration curve converters
Tianchu Chen <flynnnchen@tencent.com>
wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext()
Ali Ahmet Memis <ali@iusegentoo.com>
wifi: wilc1000: fix out-of-bounds read in P2P public action frames
Runyu Xiao <runyu.xiao@seu.edu.cn>
wifi: wlcore: release runtime PM ref on regdomain config failure
Fan Wu <fanwu01@zju.edu.cn>
wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown
Tianchu Chen <flynnnchen@tencent.com>
wifi: rsi: fix heap OOB write on key removal
Daehyeon Ko <4ncienth@gmail.com>
wifi: libipw: reject TKIP frames without a full MIC
Jiangshan Yi <yijiangshan@kylinos.cn>
wifi: libertas_tf: fix UAF in lbtf_free_adapter()
Stanislaw Gruszka <stf_xl@wp.pl>
wifi: iwlegacy: fix broadcast stations deallocation
Jiangshan Yi <yijiangshan@kylinos.cn>
wifi: brcmsmac: fix UAF in brcms_free_timer()
Wentao Liang <vulab@iscas.ac.cn>
watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start()
Wentao Liang <vulab@iscas.ac.cn>
watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init()
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: rzv2h: Avoid division by zero
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: rtd119x: Avoid division by zero
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: msc313e: Propagate error code in resume()
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: msc313e: Fix premature reset during timeout update
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: digicolor: Avoid division by zero
Li Jun <lijun01@kylinos.cn>
watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
hwmon: (cgbc-hwmon) Add missing sensors
Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
hwmon: (cgbc-hwmon) Fix current sensors ID lookup
Guangshuo Li <lgs201920130244@gmail.com>
hwmon: (w83793) release probe data through kref
Guangshuo Li <lgs201920130244@gmail.com>
hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
Yibo Tan <lhfff@tju.edu.cn>
hwmon: (pwm-fan) Stop RPM timer before freeing tach data
Sanman Pradhan <psanman@juniper.net>
hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
Sanman Pradhan <psanman@juniper.net>
hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
Nuno Sá <nuno.sa@analog.com>
hwmon: (pmbus/core) increase number of phases and add new mask
Muhammad Bilal <meatuni001@gmail.com>
hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Input: zero ff_effect before compat copy in input_ff_effect_from_user
Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
Raphaël Larocque <rlarocque@disroot.org>
Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
Hans de Goede <johannes.goede@oss.qualcomm.com>
Input: soc_button_array - check btns_desc->package.count
Hans de Goede <johannes.goede@oss.qualcomm.com>
Input: soc_button_array - fix MS Surface Pro 11 probe failure
Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
Chris Sommers <chris.sommers@icloud.com>
Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
Runyu Xiao <runyu.xiao@seu.edu.cn>
Input: hp_sdc - shut down kicker timer on module exit
Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Input: evdev - zero absinfo before partial copy in EVIOCSABS
Linkai Gong <gonglinkai@kylinos.cn>
Input: cyttsp5 - clamp the HID report size before memcpy
Alexei Turtanov <9alexei9@gmail.com>
Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
Alvin Šipraga <alvin.sipraga@analog.com>
Input: adp5588-keys - cache GPIO state before registering the gpiochip
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning failure
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Clear ITAPDLY on tuning failure
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Reset command and data lines on failed tuning
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Move tuning_loop to local variable
Xu Rao <raoxu@uniontech.com>
mmc: spi: reset bytes_xfered before retrying CRC failures
Runyu Xiao <runyu.xiao@seu.edu.cn>
mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt
Felix Gu <ustc.gu@gmail.com>
mmc: sdio_uart: fix xmit_fifo leak when the port table is full
Myeonghun Pak <mhun512@gmail.com>
mmc: sdhci-of-aspeed: Remove children before releasing SDC resources
Florian Maillard <florian.maillard@mailoo.org>
mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260
Fan Wu <fanwu01@zju.edu.cn>
mmc: mxcmmc: cancel data work and watchdog on remove
Fan Wu <fanwu01@zju.edu.cn>
mmc: mmci: Fix use-after-free in busy-timeout work
Fan Wu <fanwu01@zju.edu.cn>
mmc: hsq: Fix use-after-free in retry work
Zhu Ling <zhuling0805@qq.com>
mmc: core: Fix OF node reference leak on card add failure
Fan Wu <fanwu01@zju.edu.cn>
mmc: core: Cancel SDIO IRQ work before freeing host
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
power: sequencing: fix NULL-pointer dereference in pwrseq_device_register()
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new()
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
power: sequencing: don't call .post_enable() if pwrseq_unit_enable() failed
Christian Göttsche <cgzones@googlemail.com>
selinux: always fill AVC decision in avc_has_perm_noaudit()
Karl Mehltretter <kmehltretter@gmail.com>
selinux: recheck intermediate backing files on mprotect()
Karl Mehltretter <kmehltretter@gmail.com>
selinux: preserve user SID across nested backing files
Shuhei Takeshita <jyohuku.alterego@gmail.com>
IB/hfi1: Fix the PIO_CRED credit-return mmap
Shuhei Takeshita <jyohuku.alterego@gmail.com>
IB/hfi1: Resolve the credit-return buffer through the send context's node
Shuangpeng Bai <shuangpeng.kernel@gmail.com>
IB/mlx4: Fix use-after-free on pkey sysfs registration failure
Guangshuo Li <lgs201920130244@gmail.com>
i2c: imx: disable autosuspend on remove
Shengzhuo Wei <me@cherr.cc>
i2c: imx: release DMA channels on probe error
Liu Zhenlong <dragonliu2018@gmail.com>
i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
Linkai Gong <gonglinkai@kylinos.cn>
i2c: atr: fix dangling adapter pointer on add failure
Shengzhuo Wei <me@cherr.cc>
i2c: at91: release DMA channels on remove and probe error
fangqiurong <fangqiurong@kylinos.cn>
sched_ext: Close the pre-enable ops error claim window
Wanwu Li <liwanwu@kylinos.cn>
sched_ext: Fix NULL sched deref in kfunc sub-sched error paths
Jarkko Sakkinen <jarkko@kernel.org>
KEYS: trusted: Fix tpm2_load_cmd() boundary check
Maoyi Xie <maoyixie.tju@gmail.com>
keys: translate request_key_auth pid for the reading procfs instance
Cen Zhang <cenzhang@linux.microsoft.com>
KEYS: encrypted: fix integer overflow of datablob_len
Wenjie Qi <qiwenjie@xiaomi.com>
mm: filemap: retain mapped dropbehind folios
Lorenzo Stoakes (ARM) <ljs@kernel.org>
mm/vma: correctly unaccount on mmap_prepare() failure
Jiayuan Chen <jiayuan.chen@linux.dev>
mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem
Lorenzo Stoakes (ARM) <ljs@kernel.org>
mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP
Shakeel Butt <shakeel.butt@linux.dev>
mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio()
Lorenzo Stoakes (ARM) <ljs@kernel.org>
mm/huge_memory: bypass THP tuneables for huge pfnmap mappings
Nhat Pham <nphamcs@gmail.com>
mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count
Yifei Gao <gyf161023@gmail.com>
memstick: ms_block: destroy io_queue workqueue on removal
Shakeel Butt <shakeel.butt@linux.dev>
memcg: avoid charging the root memcg from obj_cgroup_charge_pages()
Théo Lebrun <theo.lebrun@bootlin.com>
mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
Alexey Klimov <alexey.klimov@linaro.org>
soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node
Zhiling Zou <zhilinz@nebusec.ai>
xfrm: save input state data before secpath resets
Siwei Zhang <fourdizhang@tencent.com>
xfrm: use hlist_del_init_rcu for state_cache and state_cache_input
Chengfeng Ye <nicoyip.dev@gmail.com>
xfrm: serialize state GC with device state flush
Alberto Carboneri <acarboneri@drivesec.com>
scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()
Mark Amirkan <markdamirkan@gmail.com>
net/packet: avoid truncating TPACKET_V3 private size
Mark Amirkan <markdamirkan@gmail.com>
net/packet: clear RX owner on VNET header error
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: hhf: cap hh_flows_limit at change time
Xuanqiang Luo <luoxuanqiang@kylinos.cn>
net/sched: act_api: release tail references on DELACTION failure
Guanglei Zhu <zhugl3@xiaopeng.com>
net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value
Guanglei Zhu <zhugl3@xiaopeng.com>
net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain
Guanglei Zhu <zhugl3@xiaopeng.com>
net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()
Ahmed Naseef <naseefkm@gmail.com>
net: phy: mediatek: do not report link and per-speed LED rules together
Mark Amirkan <markdamirkan@gmail.com>
net: lan743x: fix RX checksum use-after-free
Gris Ge <cnfourt@gmail.com>
net: ip_tunnel: initialize `options_len` before referencing options
Zhiling Zou <zhilinz@nebusec.ai>
ipv6: xfrm: use full sockets in local error paths
David Hu <xuehaohu@google.com>
dma-buf: Split sgl by largest page-aligned chunk
David Hu <xuehaohu@google.com>
dma-buf: Fix silent overflow for phys vec to sgt
Christian König <christian.koenig@amd.com>
dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3
Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
Christian Lugnberg <christian.lugnberg@soundtrack.io>
dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
Christian Lugnberg <christian.lugnberg@soundtrack.io>
dmaengine: sun6i: fix non-atomic read of DMA position registers
Abdurrahman Hussain <abdurrahman@nexthop.ai>
gpiolib: of: don't mark hog nodes OF_POPULATED before a chip is found
Michail Tatas <michail.tatas@gmail.com>
gpiolib: Put fwnode reference on failure
Guanghui Yang <3497809730@qq.com>
btrfs: clear free space tree creation state on rebuild failure
Anand Jain <asj@kernel.org>
btrfs: derive f_fsid with dev_t only when temp_fsid is active
Filipe Manana <fdmanana@suse.com>
btrfs: fix creation of compressed inline extents that don't save space
Hongling Zeng <zenghongling@kylinos.cn>
btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
Radek Podgorny <radek@podgorny.cz>
Bluetooth: keep dst_type with dst when reusing an LE connection
Chengfeng Ye <nicoyip.dev@gmail.com>
Bluetooth: hci_sync: Serialize local codec list cleanup
Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Bluetooth: hci_codec: validate vendor codec count length
Aamir Ahmed <elb12345@hotmail.co.uk>
Bluetooth: eir: validate service data length before reading UUID
Nicolas Thibert <nithibert@gmail.com>
Bluetooth: btusb: fix NXP IW610 composite device handling
Mark Rutland <mark.rutland@arm.com>
arm64: percpu: Fix LSE operations on {8,16}-bit types
Mark Rutland <mark.rutland@arm.com>
arm64: percpu: Fix this_cpu_and() mask generation
Mark Rutland <mark.rutland@arm.com>
arm64: percpu: Fix this_cpu_write() casting
Dinh Nguyen <dinguyen@kernel.org>
arm64: dts: socfpga: change access permission from 755 to 644
Koichiro Den <den@valinux.co.jp>
arm64: dts: renesas: r8a779f0: Set UFS lane count
Bradley Morgan <include@grrlz.net>
arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
Thomas Huth <thuth@redhat.com>
kselftest/arm64: Fix size of thread_data values for pthread_join()
Wyatt Feng <wf.kernel.dev@gmail.com>
net: xfrm: reject unrepresentable espintcp transport headers
Jeff Layton <jlayton@kernel.org>
nfsd: fix handling of NFSEXP_PNFS in the netlink codepath
Zhiling Zou <zhilinz@nebusec.ai>
openvswitch: avoid reallocating confirmed conntrack labels
Jeffin Philip <jeffinphilip14@gmail.com>
RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
Quanye Yang <quanyeyang@proton.me>
RDMA/ucma: Serialize join and leave on copy_to_user failure
Hao-Qun Huang <alvinhuang0603@gmail.com>
spi: virtio: Use the per-transfer bits per word
Itai Handler <itai.handler@gmail.com>
spi: spi-zynqmp-gqspi: stop the controller on shutdown
Frieder Schrempf <frieder.schrempf@kontron.de>
spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes
Ian Luites <ian@luites.com>
soundwire: dmi-quirks: Disable ghost Realtek on Asus GX651AX
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
swiotlb: use the adjusted address for the highmem page lookup
Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
tcp: exclude old ACKs from tcp fast path
Chang S. Bae <chang.seok.bae@intel.com>
x86/microcode/intel: Reject problematic loading on Granite Rapids systems
Chang S. Bae <chang.seok.bae@intel.com>
x86/build/64: Prevent native builds from generating EGPR use
Lyude Paul <lyude@redhat.com>
drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP
Lyude Paul <lyude@redhat.com>
drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr
Lyude Paul <lyude@redhat.com>
drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini()
Lyude Paul <lyude@redhat.com>
Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware"
Chunfeng Song <springbreeze@stu.pku.edu.cn>
rust: net: phy: fix off-by-one bit positions in device status accessors
Thomas Gleixner <tglx@kernel.org>
signal: Prevent exec() race
Aohan Mei <henrymei@tencent.com>
rds: ib: use rds_conn_drop() on protocol version mismatch
Thomas Gleixner <tglx@kernel.org>
posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context
Richard Zhu <hongxing.zhu@nxp.com>
PCI: imx6: Move clock enable after core reset assertion
Seunguk Shin <seunguk.shin@arm.com>
fs/dax: check zero or empty entry before converting xarray entry
Hyunwoo Kim <imv4bel@gmail.com>
exec: Cleanup POSIX timers right after de_thread()
Wentao Liang <vulab@iscas.ac.cn>
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
Wentao Liang <vulab@iscas.ac.cn>
ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
Niklas Cassel <cassel@kernel.org>
ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
Michal Koutný <mkoutny@suse.com>
cgroup: Avoid iteration of dying tasks with zero refcount
Jiangshan Yi <yijiangshan@kylinos.cn>
ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type
Yuho Choi <oss.patchbox@gmail.com>
ALSA: virtio: reset device before deleting virtqueues
Xiang Mei <xmei5@asu.edu>
ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity
Takashi Iwai <tiwai@suse.de>
ALSA: core: Fix potential UAF after asynchronous card release
David Howells <dhowells@redhat.com>
9p: Fix v9fs_issue_write() to update i_size and remote_i_size
Jeremy Nyberg <slickstretch3.0@gmail.com>
Input: xpad - fix PDP Marvel Xbox 360 controller
Roberts Kursitis <roberts.kursitis@azeron.eu>
Input: xpad - add support for Azeron devices
Erich Sartison <byt.es@mailbox.org>
Input: xpad - add support for Victrix Pro BFG Controller
Li Jun <lijun01@kylinos.cn>
watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog
James Seo <james@equiv.tech>
hwmon: (hp-wmi-sensors) Improve raw WMI string handling
Cong Nguyen <congnt264@gmail.com>
hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler
hpp.iscas <hppiscas@163.com>
Input: eeti_ts - publish the OF module alias
Matthew Schwartz <matthew.schwartz@linux.dev>
x86/fred: Reconstruct the #GP context for rejected INT instructions
Andrea Righi <arighi@nvidia.com>
sched/core: Avoid false migration warning for proxy donors
Vinay Belgaumkar <vinay.belgaumkar@intel.com>
perf: Fix null pointer access in is_include_guest_event()
Filipe Manana <fdmanana@suse.com>
btrfs: check if there is space for chunk item when validating sys chunk array
Filipe Manana <fdmanana@suse.com>
btrfs: abort transaction on failure to update inode for hole punching and reflinking
Francis Marlou Pacaro <pacaro.francis.marlou.n@gmail.com>
drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates
Dmitriy Chumachenko <Dmitry.Chumachenko@cyberprotect.ru>
drm/amdgpu: check ras and obj before dereference
Eric Dumazet <edumazet@google.com>
net: skbuff: do not leave stale header offsets after pskb_carve()
Dmitriy Okunev <dokunevdmitriy@gmail.com>
net: mvpp2: prevent buffer overflow in page_pool allocation
James Clark <jjc@jclark.com>
net: macb: fix ordering around PTP timestamp read
Jinke Han <jinkehan@didiglobal.com>
x86/kprobes: Fix crash when probing CS CALL instructions
Daniel Zahka <daniel.zahka@gmail.com>
net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: stmmac: preserve real_num_tx_queues on mqprio setup failure
Eric Dumazet <edumazet@google.com>
net: prevent torn reads in netdev_tc_txq
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: stmmac: propagate FPE preemption-class mapping errors
Linus Walleij <linusw@kernel.org>
net: ethernet: cortina: Ack RX overrun interrupt correctly
Eric Dumazet <edumazet@google.com>
net: lock the socket in sock_gettstamp()
Jakub Kicinski <kuba@kernel.org>
eth: fbnic: ring the doorbell if a burst ends in a drop
Yige Jiang <yigejiang86@gmail.com>
net: netsec: fix device_node reference leak on phy_np
Farhad Alemi <farhad.alemi@berkeley.edu>
net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: pass net_device_path_ctx to dev_fill_forward_path()
Pablo Neira Ayuso <pablo@netfilter.org>
net: pass dst via net_device_path in dev_fill_forward_path()
Pablo Neira Ayuso <pablo@netfilter.org>
net: do not advance stack index from dev_fwd_path()
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: codel: bound the dropping loop per dequeue call
Vijendar Mukunda <Vijendar.Mukunda@amd.com>
ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID
Vijendar Mukunda <Vijendar.Mukunda@amd.com>
ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver
Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints()
Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
ASoC: sdw_utils: tidyup .count_sidecar
Vijendar Mukunda <Vijendar.Mukunda@amd.com>
ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers
Richard Fitzgerald <rf@opensource.cirrus.com>
ASoC: cs-amp-lib: Prevent NULL pointer if efi variable is zero length
HyeongJun An <sammiee5311@gmail.com>
ASoC: hdmi-codec: Report a change when the channel status moves
Sasha Levin <sashal@kernel.org>
ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments
Daniel Linjama <daniel@dev.linjama.com>
btrfs: handle lack of space when cleaning up verity items
Raag Jadav <raag.jadav@intel.com>
drm/xe/i2c: Disable IRQ on unbind
Peter Zijlstra <peterz@infradead.org>
futex: Also allocate private hash on vfork()
Nemesa Garg <nemesa.garg@intel.com>
Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable"
Shivaprasad G Bhat <sbhat@linux.ibm.com>
powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
Amit Machhiwal <amachhiw@linux.ibm.com>
KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure
Amit Machhiwal <amachhiw@linux.ibm.com>
KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
Eric Dumazet <edumazet@google.com>
netlink: do not free nlk->groups while lockless readers can use it
Nikolay Aleksandrov <razor@blackwall.org>
net: bridge: vlan: fix bugs caused by switchdev deletion errors
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: stmmac: do not overwrite phc_index when no PTP clock is registered
Eric Dumazet <edumazet@google.com>
drop_monitor: fix out-of-bounds write in reset_per_cpu_data()
Eric Dumazet <edumazet@google.com>
drop_monitor: use raw_cpu_ptr() in tracepoint probes
Eric Dumazet <edumazet@google.com>
drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown
Eric Dumazet <edumazet@google.com>
drop_monitor: synchronize tracepoint unregistration on error path
Eric Dumazet <edumazet@google.com>
pppoatm: ensure a writable skb header and linear data
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: stmmac: fix TSO header length truncation
Kuniyuki Iwashima <kuniyu@google.com>
af_unix: Unify scc_index when finalising SCC in __unix_walk_scc().
Juan Perdomo <jcperdomo100@gmail.com>
Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
Sai Teja Aluvala <aluvala.sai.teja@intel.com>
Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
Tzung-Bi Shih <tzungbi@kernel.org>
Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown
Chris Lu <chris.lu@mediatek.com>
Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access
Chris Lu <chris.lu@mediatek.com>
Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events
Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync
Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()
Ibrahim Abdelkader <iabdelka@qti.qualcomm.com>
Bluetooth: hci_qca: Do not write to the serial port after it is closed
Radek Podgorny <radek@podgorny.cz>
Bluetooth: put the peer's on-air address on air when we cannot resolve
Weiming Shi <bestswngs@gmail.com>
Bluetooth: coredump: Quiesce dump work on unregister
Chandrashekar Devegowda <chandrashekar.devegowda@intel.com>
Bluetooth: btintel_pcie: validate TX skb length in send_sync
ThangNN99 <ngocthang2710.1999@gmail.com>
Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
Baineng Shou <shoubaineng@gmail.com>
dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: keep compound responses on query info errors
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: fix partial file information responses
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: return buffer overflow for partial filesystem info
Eric Dumazet <edumazet@google.com>
tcp: do not let tcp_rmem be set below 4096
Kuniyuki Iwashima <kuniyu@google.com>
tcp: Don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().
Nikolay Aleksandrov <razor@blackwall.org>
net: bridge: mst: move switchdev call outside rcu
Karl Mehltretter <kmehltretter@gmail.com>
wifi: brcmfmac: fix lost 802.1x TX completion wakeup
Hohyun Sim <tlaghgus0425@korea.ac.kr>
net: fddi: skfp: fix NULL deref when setting the MAC address while down
Dong Chenchen <dongchenchen2@huawei.com>
ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
Kuniyuki Iwashima <kuniyu@google.com>
sysctl: Check range in proc_dointvec_ms_jiffies_minmax
Nicolai Buchwitz <nb@tipi-net.de>
net: bcmgenet: restore the hardware filters on open
Daniel Golle <daniel@makrotopia.org>
net: dsa: mxl862xx: disable the stats poll on teardown
Andrea Mayer <andrea.mayer@uniroma2.it>
seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL
Filipe Manana <fdmanana@suse.com>
btrfs: tree-checker: print dev extent offset in error message
Nicolas Escande <nico.escande@gmail.com>
wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()
Slavin Liu <bolin.liu@seu.edu.cn>
ALSA: hda: trace PCM open only after assigning a stream
Karl Mehltretter <kmehltretter@gmail.com>
drm/vc4: Use managed KMS polling to fix UAF on unbind
Shuicheng Lin <shuicheng.lin@intel.com>
drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory
Shuicheng Lin <shuicheng.lin@intel.com>
drm/xe/shrinker: Return the freed page count through a parameter
Shuicheng Lin <shuicheng.lin@intel.com>
drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy
Ilia Levi <ilia.levi@intel.com>
drm/xe/mmio_gem: use write-back mapping for dummy page
Ilia Levi <ilia.levi@intel.com>
drm/xe/mmio_gem: forbid VMA split
Zihan Xi <zihanx@nebusec.ai>
wifi: virt_wifi: don't transfer operstate before register
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: follow SMB2 session expiration semantics
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: extend procfs server statistics
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: fix malformed procfs status output
Xiang Mei <xmei5@asu.edu>
ALSA: 6fire: fix OOB write from device-reported iso length
Takashi Iwai <tiwai@suse.de>
ALSA: usb: 6fire: Avoid embedded URBs
Runyu Xiao <runyu.xiao@seu.edu.cn>
gpio: virtuser: skip free_irq when no IRQ is installed
Ulises Mendez Martinez <umendez@google.com>
objtool: Validate disassembler headers in libopcodes probe
Karl Mehltretter <kmehltretter@gmail.com>
Input: trackpoint - fix the inertia attribute name in the ABI document
Gabor Juhos <j4g8y7@gmail.com>
spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register
Richard Fitzgerald <rf@opensource.cirrus.com>
ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params
Richard Fitzgerald <rf@opensource.cirrus.com>
ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map
Richard Fitzgerald <rf@opensource.cirrus.com>
ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask
William Bright <william.bright@imd-tec.com>
drm/msm/dp: fix link bandwidth check when wide bus is enabled
Jesse Casco <jesse.casco@gmail.com>
drm/msm/dp: skip PUSH_IDLE when the link was never enabled
Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
ALSA: pcm: set timer->private_data before registering the PCM timer
AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting
AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow
Namjae Jeon <linkinjeon@kernel.org>
ntfs: ignore interrupted inode reads as corruption
Namjae Jeon <linkinjeon@kernel.org>
ntfs: propagate folio errors
Namjae Jeon <linkinjeon@kernel.org>
ntfs: protect runlist updates with the runlist lock
Namjae Jeon <linkinjeon@kernel.org>
ntfs: account for MFT records added during allocation
Namjae Jeon <linkinjeon@kernel.org>
ntfs: repack $MFT/$ATTRIBUTE LIST
Namjae Jeon <linkinjeon@kernel.org>
ntfs: use dynamic MFT tail reservation
Takashi Iwai <tiwai@suse.de>
ALSA: bcd2000: Fix race between rawmidi and disconnect
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Skip default parms when resumed in neightbl_dump_info().
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Don't render blackhole_netdev via RTM_GETNEIGHTBL.
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Add missing RCU annotation for neightbl_dump_info().
Karl Mehltretter <kmehltretter@gmail.com>
keys: fix lost wakeup when reaping a dead key type
Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
smb: client: validate absolute native symlink targets before NT fixups
Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
Catalin Marinas <catalin.marinas@arm.com>
arm64: mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentation
Breno Leitao <leitao@debian.org>
arm64: hibernate: clone only the linear map that exists at runtime
Shouping Wang <allen.wang@hj-micro.com>
perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: flowtable: hold reference on ct until flow is released
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: nf_nat: unregister and release hooks on error
Fernando Fernandez Mancera <fmancera@suse.de>
netfilter: nf_tables: fix device name and prefix match in hook lookup
Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
netfilter: nft_nat: fully initialise new_addr in netmap setup
Karl Mehltretter <kmehltretter@gmail.com>
dma-buf: Make DMABUF_DEBUG default to y on DEBUG_KERNEL kernels
Karl Mehltretter <kmehltretter@gmail.com>
drm/msm/adreno: Fix the skip_gpu parameter description
Karl Mehltretter <kmehltretter@gmail.com>
drm/msm: Fix the separate_gpu_kms parameter description
David Laight <david.laight.linux@gmail.com>
x86/div64: Fix addition of large constants in mul_u64_add_u64_div_u64()
Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
RDMA/siw: Bound fragmented header copies by the remaining length
Leon Romanovsky <leon@kernel.org>
RDMA/efa: Keep EQ resources alive while IRQ is registered
Leon Romanovsky <leon@kernel.org>
RDMA/efa: Keep admin queues alive while IRQ is registered
Alex Bereza <alex@bereza.email>
dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
Sascha Hauer <s.hauer@pengutronix.de>
dmaengine: pxa: fix double counting of the hw descriptors
Alex Bereza <alex@bereza.email>
dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
Karl Mehltretter <kmehltretter@gmail.com>
scsi: qla2xxx: Fix the ql2xfc2target parameter description
Karl Mehltretter <kmehltretter@gmail.com>
scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions
Meijing Zhao <zhaomeijing@lixiang.com>
mm: memblock: show all region flags in debugfs
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: set up the TX info early to fix failure paths
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: mesh: release the channel if start fails
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: mesh: reset the CSA state when leaving
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: add HE 6 GHz capability in the scan elems len
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't access the TSF of a down interface
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't RCU-dereference the mesh CSA settings we just set
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't allow link changes when iface is down
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: require a peer station for TDLS setup confirm
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't allow injecting frames wider than the chanctx
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211_hwsim: don't hand frames to mac80211 while stopping
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: get the wiphy out of a dying network namespace
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: unlist vifs when their netdev is unregistered
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: undo netns switch if renaming the wiphy fails
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: restore netns_immutable on failures
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: only operate on TDLS peers in the TDLS code
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: reset the LED state when ifup fails
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: reset state when starting AP fails
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: abort chanswitch when leaving a mesh
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: suppress chanctx warning for debugfs reset
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't offload TC setup on AP_VLAN interfaces
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't warn when an IBSS has no channel to scan
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't start a ROC while scanning
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: fix NAN regulatory enforcement
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: ibss: ref BSS entry for joined event
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: don't filter by BSS type when removing stale entries
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: only group hidden BSSes with beacon entries
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: don't free driver-owned scan requests
Shivank Garg <shivankg@amd.com>
dmaengine: wait for RCU readers before releasing dma_device
Shivank Garg <shivankg@amd.com>
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
Shivank Garg <shivankg@amd.com>
dmaengine: Fix device kref underflow in dma_chan_put()
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
dma-mapping: don't trace the DMA address when the allocation fails
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
dma-coherent: report a failed reserved memory assignment
Orgad Shaneh <orgads@gmail.com>
MIPS: Octeon: apply USB FDT fixups also when USB is modular
Julian Braha <julianbraha@gmail.com>
mips: econet: fix unmet dependencies for ECONET
Bard Liao <yung-chuan.liao@linux.intel.com>
soundwire: cadence_master: wait and cancel cdns->work before clock stop
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: check IP header size in cfg80211_classify8021d()
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: don't get the radio mask for netdev-less wdevs
Carolina Jubran <cjubran@nvidia.com>
IB/IPoIB: Avoid restoring OPER_UP after multicast flush
Shmulik Cohen <anuk909@gmail.com>
wifi: libipw: reject too-short association responses
Shmulik Cohen <anuk909@gmail.com>
wifi: libipw: reject too-short beacon and probe responses
Bogdan Nicolae <bogdan.nicolae@gmail.com>
wifi: brcmfmac: cyw: pass PMKID to firmware if present
Peng Hao <flyingpenghao@gmail.com>
wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path
Mariano Baragiola <mbaragiola@linux.com>
wifi: virt_wifi: free skb when disconnected
Lachlan Hodges <lachlan.hodges@morsemicro.com>
wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic
Ruoyu Wang <ruoyuw560@gmail.com>
dmaengine: sprd: Fix runtime PM reference leak in probe
Troy Mitchell <troy.mitchell@linux.spacemit.com>
dmaengine: mmp_pdma: fix wrong extended DRCMR base for SpacemiT K3
Quanye Yang <quanyeyang@proton.me>
RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
Jacob Moroni <jmoroni@google.com>
RDMA/irdma: Enforce local fence for IB_WR_REG_MR
Cheng Xu <chengyou@linux.alibaba.com>
RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables
Li RongQing <lirongqing@baidu.com>
RDMA/mad: Fix receive buffer leak when PKey enforcement fails
Li RongQing <lirongqing@baidu.com>
RDMA/uverbs: Fix potential leak of resources->collection in flow_resources_alloc()
Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
RDMA/bnxt_re: Avoid exposing umdbr to userspace
Ryan Mehri <ryan.mehri1@gmail.com>
RDMA/rtrs: guard against null kobj name
Linkai Gong <gonglinkai@kylinos.cn>
RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
IB/isert: wait for deferred control PDU completions before releasing the connection
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
IB/iser: reject a remote invalidation of an unregistered direction
Ovidiu Panait <ovidiu.panait.rb@renesas.com>
arm64: dts: renesas: r9a09g087: Switch GBETH TX queue scheduling to WRR
Ovidiu Panait <ovidiu.panait.rb@renesas.com>
arm64: dts: renesas: r9a09g077: Switch GBETH TX queue scheduling to WRR
Ovidiu Panait <ovidiu.panait.rb@renesas.com>
arm64: dts: renesas: r9a09g047: Switch GBETH TX queue scheduling to WRR
Ovidiu Panait <ovidiu.panait.rb@renesas.com>
arm64: dts: renesas: r9a09g056: Switch GBETH TX queue scheduling to WRR
Ovidiu Panait <ovidiu.panait.rb@renesas.com>
arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR
Biju Das <biju.das.jz@bp.renesas.com>
power: sequencing: Fix build issue with COMPILE_TEST
Or Har-Toov <ohartoov@nvidia.com>
RDMA/uverbs: Fix mmap_lock/disassociation_lock circular dependency
Krystian Kaniewski <krystianmkaniewski@gmail.com>
RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
Or Har-Toov <ohartoov@nvidia.com>
RDMA/mlx5: Remove warn on missing representor in query_port_speed
Michael Bommarito <michael.bommarito@gmail.com>
RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds
Weiming Shi <bestswngs@gmail.com>
RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths
Xixin Liu <liuxixin@kylinos.cn>
clk: scpi: register scpi-cpufreq once and clear on failure
Xixin Liu <liuxixin@kylinos.cn>
clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
Xixin Liu <liuxixin@kylinos.cn>
firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
Cen Zhang (Microsoft Security FORGE Labs) <blbllhy@gmail.com>
xfrm: hold net_device reference under RCU in bundle creation
Gang Yan <yangang@kylinos.cn>
RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
Norbert Szetei <norbert@doyensec.com>
RDMA/rxe: validate access flags before swapping the MR's PD
Guoqing Jiang <guoqing.jiang@linux.dev>
RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
Pengpeng Hou <pengpeng@iscas.ac.cn>
ARM: socfpga: select the PL310 erratum 753970 workaround
Lucas Tanure <tanure@linux.com>
arm64: dts: amlogic: t7: fix the pin groups of the vsync PWM
Lucas Tanure <tanure@linux.com>
arm64: dts: amlogic: t7: khadas-vim4: add the PWM-driven supplies
Lucas Tanure <tanure@linux.com>
arm64: dts: amlogic: t7: fix the pin groups of two PWM outputs
Lucas Tanure <tanure@linux.com>
arm64: dts: amlogic: t7: khadas-vim4: allow the SD card to be power cycled
Lucas Tanure <tanure@linux.com>
arm64: dts: amlogic: t7: use the real UART pclk
Maher Azzouzi <maherazz04@gmail.com>
esp: downgrade zerocopy managed frags before mutating skb frags
Eric Dumazet <edumazet@google.com>
xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()
Kyle Zeng <kylebot@openai.com>
xfrm: fix compat ALLOCSPI request use-after-free
Henry Martin <bsdhenrymartin@gmail.com>
xfrm: iptfs: fix runt reassembly panic from short inner tot_len
Aleksandr Nogikh <nogikh@google.com>
xfrm: add missing RCU read lock in xfrm_send_migrate_state()
Roshan Kumar <roshaen09@gmail.com>
xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()
Jens Axboe <axboe@kernel.dk>
sunvdc: fix -EIO issue due to lack of retries
Günther Noack <gnoack@google.com>
selftests/landlock: Add audit test for whiteout object creation
Günther Noack <gnoack@google.com>
selftests/landlock: Add tests for whiteout object creation
Günther Noack <gnoack@google.com>
selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
-------------
Diffstat:
.../ABI/testing/sysfs-devices-platform-trackpoint | 2 +-
.../arch/arm64/memory-tagging-extension.rst | 5 +-
Documentation/hwmon/cgbc-hwmon.rst | 42 +-
Documentation/netlink/specs/rt-neigh.yaml | 3 +
Documentation/networking/ip-sysctl.rst | 4 +-
Makefile | 4 +-
arch/arm/mach-socfpga/Kconfig | 2 +-
.../boot/dts/altera/socfpga_stratix10_socdk.dtsi | 0
.../dts/altera/socfpga_stratix10_socdk_emmc.dts | 0
.../boot/dts/amlogic/amlogic-t7-a311d2-an400.dts | 2 +-
.../dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts | 113 +++-
arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi | 44 +-
arch/arm64/boot/dts/renesas/r8a779f0.dtsi | 1 +
arch/arm64/boot/dts/renesas/r9a09g047.dtsi | 10 +
arch/arm64/boot/dts/renesas/r9a09g056.dtsi | 10 +
arch/arm64/boot/dts/renesas/r9a09g057.dtsi | 10 +
arch/arm64/boot/dts/renesas/r9a09g077.dtsi | 27 +
arch/arm64/boot/dts/renesas/r9a09g087.dtsi | 27 +
arch/arm64/include/asm/percpu.h | 20 +-
arch/arm64/kernel/hibernate-asm.S | 2 +
arch/arm64/kernel/hibernate.c | 4 +-
arch/arm64/kernel/mte.c | 2 +-
arch/mips/Kconfig | 4 +-
arch/mips/cavium-octeon/octeon-platform.c | 4 +-
arch/powerpc/kernel/iommu.c | 2 +-
arch/powerpc/kvm/book3s_hv_nested.c | 2 +
arch/powerpc/kvm/book3s_hv_uvmem.c | 5 +-
arch/x86/Kconfig.cpu | 11 +
arch/x86/Makefile | 5 +
arch/x86/entry/entry_fred.c | 11 +-
arch/x86/include/asm/div64.h | 2 +-
arch/x86/include/asm/text-patching.h | 4 +-
arch/x86/kernel/alternative.c | 6 +-
arch/x86/kernel/cpu/microcode/intel.c | 26 +
arch/x86/kernel/kprobes/core.c | 5 +-
drivers/ata/libahci.c | 15 +-
drivers/ata/libahci_platform.c | 2 +-
drivers/block/sunvdc.c | 9 +-
drivers/bluetooth/btintel_pcie.c | 8 +-
drivers/bluetooth/btmtk.c | 7 +-
drivers/bluetooth/btmtksdio.c | 24 +-
drivers/bluetooth/btmtkuart.c | 20 +-
drivers/bluetooth/btusb.c | 17 +
drivers/bluetooth/hci_qca.c | 14 +-
drivers/clk/clk-scpi.c | 8 +-
drivers/dma-buf/Kconfig | 2 +-
drivers/dma-buf/dma-buf-mapping.c | 31 +-
drivers/dma-buf/dma-fence.c | 14 +-
drivers/dma/dmaengine.c | 10 +-
drivers/dma/mmp_pdma.c | 5 +-
drivers/dma/pxa_dma.c | 3 +-
drivers/dma/sprd-dma.c | 3 +-
drivers/dma/sun6i-dma.c | 9 +-
drivers/dma/ti/k3-udma-glue.c | 5 +-
drivers/dma/xilinx/xilinx_dma.c | 26 +-
drivers/firmware/arm_scpi.c | 4 +-
drivers/gpio/gpio-virtuser.c | 3 +-
drivers/gpio/gpiolib-of.c | 6 +-
drivers/gpio/gpiolib-shared.c | 9 +-
drivers/gpu/drm/amd/amdgpu/amdgpu.h | 3 +
drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c | 2 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_device.c | 145 ++--
drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c | 43 +-
drivers/gpu/drm/amd/amdgpu/mxgpu_ai.c | 7 +-
drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c | 2 +-
.../gpu/drm/amd/amdkfd/kfd_device_queue_manager.c | 7 +-
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v10.c | 2 +-
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v11.c | 2 +-
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12.c | 61 +-
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c | 70 +-
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v9.c | 6 +-
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_vi.c | 5 +-
.../drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c | 13 +-
drivers/gpu/drm/drm_atomic_uapi.c | 13 +-
drivers/gpu/drm/gud/gud_pipe.c | 7 +-
drivers/gpu/drm/i915/display/intel_cursor.c | 15 +-
drivers/gpu/drm/i915/display/skl_universal_plane.c | 15 +-
drivers/gpu/drm/msm/adreno/adreno_device.c | 2 +-
drivers/gpu/drm/msm/adreno/adreno_gpu.c | 2 +
drivers/gpu/drm/msm/disp/dpu1/dpu_hw_ctl.c | 1 +
drivers/gpu/drm/msm/dp/dp_display.c | 21 +-
drivers/gpu/drm/msm/dsi/dsi_host.c | 36 +-
drivers/gpu/drm/msm/hdmi/hdmi_phy.c | 8 +-
drivers/gpu/drm/msm/msm_drv.c | 2 +-
drivers/gpu/drm/msm/msm_gem.h | 3 +
drivers/gpu/drm/msm/msm_gem_vma.c | 2 +-
drivers/gpu/drm/msm/msm_ringbuffer.c | 2 +-
drivers/gpu/drm/msm/msm_ringbuffer.h | 1 +
.../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/fbsr.c | 2 +-
.../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c | 8 +-
.../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c | 8 +-
.../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c | 3 +-
.../drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/gsp.h | 8 +
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h | 2 +-
drivers/gpu/drm/scheduler/sched_entity.c | 8 +-
drivers/gpu/drm/scheduler/sched_rq.c | 20 +-
drivers/gpu/drm/ttm/ttm_bo.c | 2 +-
drivers/gpu/drm/vc4/vc4_kms.c | 2 +-
drivers/gpu/drm/xe/xe_i2c.c | 3 +
drivers/gpu/drm/xe/xe_mmio_gem.c | 33 +-
drivers/gpu/drm/xe/xe_mmio_gem.h | 2 +-
drivers/gpu/drm/xe/xe_shrinker.c | 124 ++--
drivers/hwmon/cgbc-hwmon.c | 129 ++--
drivers/hwmon/gpio-fan.c | 4 +-
drivers/hwmon/hp-wmi-sensors.c | 32 +-
drivers/hwmon/pmbus/pmbus.h | 3 +-
drivers/hwmon/pmbus/tps53679.c | 11 +-
drivers/hwmon/pwm-fan.c | 13 +-
drivers/hwmon/w83791d.c | 1 +
drivers/hwmon/w83793.c | 4 +-
drivers/i2c/busses/i2c-at91-core.c | 3 +
drivers/i2c/busses/i2c-at91-master.c | 12 +-
drivers/i2c/busses/i2c-at91.h | 1 +
drivers/i2c/busses/i2c-imx.c | 3 +
drivers/i2c/busses/i2c-qcom-cci.c | 20 +-
drivers/i2c/i2c-atr.c | 1 +
drivers/infiniband/core/iwpm_util.c | 9 +-
drivers/infiniband/core/mad.c | 3 +-
drivers/infiniband/core/rdma_core.c | 1 -
drivers/infiniband/core/ucma.c | 7 +-
drivers/infiniband/core/uverbs_flow.c | 1 +
drivers/infiniband/core/uverbs_main.c | 25 +-
drivers/infiniband/core/verbs.c | 12 +-
drivers/infiniband/hw/bnxt_re/main.c | 10 +-
drivers/infiniband/hw/bnxt_re/uapi.c | 6 +-
drivers/infiniband/hw/efa/efa_com.c | 7 +-
drivers/infiniband/hw/efa/efa_com.h | 1 +
drivers/infiniband/hw/efa/efa_main.c | 35 +-
drivers/infiniband/hw/erdma/erdma_main.c | 4 +-
drivers/infiniband/hw/erdma/erdma_verbs.c | 18 +-
drivers/infiniband/hw/hfi1/file_ops.c | 23 +-
drivers/infiniband/hw/irdma/verbs.c | 2 +-
drivers/infiniband/hw/mlx4/sysfs.c | 4 +
drivers/infiniband/hw/mlx5/main.c | 7 +-
drivers/infiniband/sw/rxe/rxe_mcast.c | 50 +-
drivers/infiniband/sw/rxe/rxe_mr.c | 3 +-
drivers/infiniband/sw/rxe/rxe_odp.c | 16 +-
drivers/infiniband/sw/rxe/rxe_verbs.c | 13 +-
drivers/infiniband/sw/siw/siw_cm.c | 7 +-
drivers/infiniband/sw/siw/siw_qp_rx.c | 2 +-
drivers/infiniband/ulp/ipoib/ipoib.h | 7 +
drivers/infiniband/ulp/ipoib/ipoib_ib.c | 12 +-
drivers/infiniband/ulp/ipoib/ipoib_multicast.c | 16 +-
drivers/infiniband/ulp/iser/iser_initiator.c | 16 +-
drivers/infiniband/ulp/isert/ib_isert.c | 22 +
drivers/infiniband/ulp/isert/ib_isert.h | 2 +
drivers/infiniband/ulp/rtrs/rtrs-clt-trace.h | 2 +-
drivers/infiniband/ulp/rtrs/rtrs-clt.c | 8 +
drivers/infiniband/ulp/rtrs/rtrs-clt.h | 2 +
drivers/infiniband/ulp/rtrs/rtrs-srv-trace.h | 2 +-
drivers/input/evdev.c | 2 +
drivers/input/input-compat.c | 2 +
drivers/input/joystick/xpad.c | 10 +-
drivers/input/keyboard/adp5588-keys.c | 12 +-
drivers/input/keyboard/atkbd.c | 8 +
drivers/input/misc/soc_button_array.c | 16 +-
drivers/input/mouse/synaptics.c | 8 +
drivers/input/rmi4/rmi_driver.c | 13 +
drivers/input/rmi4/rmi_smbus.c | 10 +-
drivers/input/serio/hp_sdc.c | 2 +-
drivers/input/serio/i8042-acpipnpio.h | 7 +
drivers/input/touchscreen/cyttsp5.c | 1 +
drivers/input/touchscreen/eeti_ts.c | 1 +
drivers/memstick/core/ms_block.c | 2 +
drivers/misc/ntsync.c | 3 +
drivers/mmc/core/bus.c | 2 +-
drivers/mmc/core/host.c | 1 +
drivers/mmc/core/sdio_uart.c | 3 +
drivers/mmc/host/mmc_hsq.c | 8 +-
drivers/mmc/host/mmc_spi.c | 1 +
drivers/mmc/host/mmci.c | 3 +
drivers/mmc/host/mxcmmc.c | 4 +
drivers/mmc/host/rtsx_pci_sdmmc.c | 5 +
drivers/mmc/host/sdhci-of-aspeed.c | 5 +-
drivers/mmc/host/sdhci_am654.c | 43 +-
drivers/mmc/host/sh_mmcif.c | 3 +-
drivers/net/dsa/mxl862xx/mxl862xx.c | 23 +-
drivers/net/ethernet/airoha/airoha_ppe.c | 17 +-
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 19 +-
drivers/net/ethernet/cadence/macb_ptp.c | 9 +
drivers/net/ethernet/cortina/gemini.c | 2 +-
drivers/net/ethernet/intel/igc/igc_tsn.c | 6 +-
drivers/net/ethernet/intel/ixgbe/ixgbe_main.c | 7 +-
drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 3 +-
drivers/net/ethernet/mediatek/mtk_ppe_offload.c | 17 +-
drivers/net/ethernet/mellanox/mlx5/core/en_main.c | 2 +-
drivers/net/ethernet/meta/fbnic/fbnic_txrx.c | 42 +-
drivers/net/ethernet/meta/fbnic/fbnic_txrx.h | 9 +-
drivers/net/ethernet/microchip/lan743x_main.c | 2 +-
drivers/net/ethernet/sfc/falcon/tx.c | 8 +-
drivers/net/ethernet/sfc/siena/tx.c | 8 +-
drivers/net/ethernet/socionext/netsec.c | 2 +
drivers/net/ethernet/stmicro/stmmac/hwif.h | 2 +-
.../net/ethernet/stmicro/stmmac/stmmac_ethtool.c | 2 -
drivers/net/ethernet/stmicro/stmmac/stmmac_fpe.c | 14 +-
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 6 +-
drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c | 99 ++-
drivers/net/fddi/skfp/skfddi.c | 3 +-
drivers/net/phy/mediatek/mtk-phy-lib.c | 27 +-
drivers/net/wireless/ath/ath11k/mac.c | 25 +-
drivers/net/wireless/ath/wcn36xx/dxe.c | 2 +-
.../wireless/broadcom/brcm80211/brcmfmac/core.c | 2 +
.../broadcom/brcm80211/brcmfmac/cyw/core.c | 5 +-
.../broadcom/brcm80211/brcmsmac/mac80211_if.c | 4 +
.../wireless/intel/ipw2x00/libipw_crypto_tkip.c | 12 +-
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 6 +
drivers/net/wireless/intel/iwlegacy/common.c | 2 +-
drivers/net/wireless/intersil/p54/eeprom.c | 22 +-
drivers/net/wireless/marvell/libertas_tf/main.c | 2 +-
drivers/net/wireless/marvell/mwifiex/cfg80211.c | 12 +-
drivers/net/wireless/marvell/mwifiex/pcie.c | 2 +-
drivers/net/wireless/marvell/mwifiex/scan.c | 54 +-
drivers/net/wireless/marvell/mwifiex/util.c | 10 +-
drivers/net/wireless/microchip/wilc1000/cfg80211.c | 14 +
drivers/net/wireless/microchip/wilc1000/wlan.c | 9 +
drivers/net/wireless/rsi/rsi_91x_mgmt.c | 2 -
drivers/net/wireless/ti/wlcore/main.c | 4 +-
drivers/net/wireless/virtual/mac80211_hwsim_main.c | 39 +-
drivers/net/wireless/virtual/virt_wifi.c | 4 +-
drivers/net/wwan/mhi_wwan_mbim.c | 28 +-
drivers/net/wwan/t7xx/t7xx_netdev.c | 4 +
drivers/pci/controller/dwc/pci-imx6.c | 12 +-
drivers/perf/arm-cmn.c | 10 +-
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c | 4 +-
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h | 3 +
drivers/phy/renesas/phy-rcar-gen3-usb2.c | 310 +++++++--
drivers/power/sequencing/Kconfig | 3 +-
drivers/power/sequencing/core.c | 11 +-
drivers/scsi/fnic/fdls_disc.c | 726 +++++++++++----------
drivers/scsi/fnic/fip.c | 117 ++--
drivers/scsi/fnic/fip.h | 2 +-
drivers/scsi/fnic/fnic.h | 68 +-
drivers/scsi/fnic/fnic_fcs.c | 126 ++--
drivers/scsi/fnic/fnic_isr.c | 41 +-
drivers/scsi/fnic/fnic_main.c | 89 ++-
drivers/scsi/fnic/fnic_scsi.c | 210 +++---
drivers/scsi/pm8001/pm8001_init.c | 6 +-
drivers/scsi/qla2xxx/qla_os.c | 2 +-
drivers/scsi/scsi.c | 24 +-
drivers/soc/samsung/exynos-pmu.c | 7 +-
drivers/soundwire/cadence_master.c | 7 +
drivers/soundwire/dmi-quirks.c | 7 +
drivers/spi/spi-fsl-qspi.c | 5 +-
drivers/spi/spi-qpic-snand.c | 4 -
drivers/spi/spi-virtio.c | 2 +-
drivers/spi/spi-zynqmp-gqspi.c | 34 +
drivers/watchdog/da9062_wdt.c | 4 +-
drivers/watchdog/da9063_wdt.c | 4 +-
drivers/watchdog/digicolor_wdt.c | 13 +-
drivers/watchdog/msc313e_wdt.c | 16 +-
drivers/watchdog/rtd119x_wdt.c | 7 +-
drivers/watchdog/rzv2h_wdt.c | 7 +-
drivers/watchdog/sp5100_tco.c | 6 +-
drivers/watchdog/starfive-wdt.c | 2 +-
fs/9p/vfs_addr.c | 28 +-
fs/btrfs/dev-replace.c | 1 +
fs/btrfs/disk-io.c | 4 +
fs/btrfs/file.c | 4 +-
fs/btrfs/free-space-tree.c | 14 +-
fs/btrfs/inode.c | 18 +-
fs/btrfs/super.c | 8 +-
fs/btrfs/tree-checker.c | 2 +-
fs/btrfs/verity.c | 18 +-
fs/dax.c | 9 +-
fs/exec.c | 29 +-
fs/nfsd/export.c | 3 +-
fs/ntfs/attrib.c | 259 ++++++--
fs/ntfs/attrib.h | 9 +
fs/ntfs/attrlist.c | 224 ++++++-
fs/ntfs/attrlist.h | 2 +
fs/ntfs/compress.c | 2 +-
fs/ntfs/file.c | 3 +-
fs/ntfs/inode.c | 35 +-
fs/ntfs/mft.c | 445 ++++++++++---
fs/ntfs/mft.h | 2 +-
fs/ntfs/namei.c | 2 +-
fs/ntfs/super.c | 12 +-
fs/ntfs/volume.h | 12 +-
fs/smb/client/cifssmb.c | 2 +-
fs/smb/client/connect.c | 9 +
fs/smb/client/file.c | 4 +-
fs/smb/client/misc.c | 12 +-
fs/smb/client/reparse.c | 58 +-
fs/smb/client/reparse.h | 7 +-
fs/smb/client/sess.c | 104 +--
fs/smb/client/smb2inode.c | 11 +
fs/smb/client/smb2ops.c | 51 +-
fs/smb/client/smb2pdu.c | 13 +-
fs/smb/client/trace.h | 1 +
fs/smb/server/connection.c | 84 ++-
fs/smb/server/connection.h | 3 +
fs/smb/server/mgmt/user_session.c | 199 ++++--
fs/smb/server/mgmt/user_session.h | 8 +-
fs/smb/server/misc.h | 7 +-
fs/smb/server/proc.c | 159 ++++-
fs/smb/server/server.c | 9 +-
fs/smb/server/smb2pdu.c | 126 ++--
fs/smb/server/smb2pdu.h | 3 +-
fs/smb/server/smb_common.h | 2 +-
fs/smb/server/stats.h | 58 +-
fs/smb/server/vfs_cache.c | 26 +-
fs/smb/server/vfs_cache.h | 1 +
fs/super.c | 1 +
include/keys/request_key_auth-type.h | 2 +-
include/linux/dma-fence.h | 6 +
include/linux/ieee80211-mesh.h | 4 +-
include/linux/netdevice.h | 13 +-
include/net/bluetooth/coredump.h | 2 +
include/net/codel.h | 5 +
include/net/codel_impl.h | 16 +-
include/net/mac80211.h | 5 +-
include/net/sock.h | 2 +
include/rdma/uverbs_types.h | 2 -
include/sound/soc.h | 3 +-
include/sound/soc_sdw_utils.h | 31 +-
include/trace/events/dma.h | 2 +-
include/uapi/rdma/bnxt_re-abi.h | 2 +-
kernel/cgroup/cgroup.c | 7 +-
kernel/dma/coherent.c | 3 +-
kernel/dma/swiotlb.c | 4 +-
kernel/events/core.c | 4 +
kernel/exit.c | 11 +-
kernel/fork.c | 4 +-
kernel/sched/core.c | 9 +-
kernel/sched/ext/ext.c | 27 +-
kernel/sched/ext/idle.c | 11 +-
kernel/signal.c | 117 +++-
kernel/time/jiffies.c | 2 +-
kernel/time/posix-cpu-timers.c | 40 +-
mm/filemap.c | 2 +-
mm/huge_memory.c | 86 ++-
mm/memblock.c | 18 +-
mm/memcontrol.c | 2 +-
mm/mlock.c | 2 +-
mm/mremap.c | 9 +-
mm/shrinker.c | 2 +
mm/swapfile.c | 2 +-
mm/vma.c | 6 +-
net/atm/pppoatm.c | 42 +-
net/bluetooth/coredump.c | 65 +-
net/bluetooth/eir.c | 10 +-
net/bluetooth/hci_codec.c | 36 +-
net/bluetooth/hci_conn.c | 21 +
net/bluetooth/hci_core.c | 18 +-
net/bluetooth/hci_sync.c | 2 +
net/bluetooth/iso.c | 53 +-
net/bluetooth/rfcomm/sock.c | 13 +-
net/bridge/br_mst.c | 20 +-
net/bridge/br_vlan.c | 31 +-
net/core/dev.c | 110 +++-
net/core/drop_monitor.c | 18 +-
net/core/neighbour.c | 35 +-
net/core/skbuff.c | 32 +-
net/core/sock.c | 16 +-
net/ipv4/esp4.c | 6 +
net/ipv4/icmp.c | 17 +-
net/ipv4/ip_tunnel_core.c | 16 +-
net/ipv4/sysctl_net_ipv4.c | 4 +-
net/ipv4/tcp_input.c | 3 +-
net/ipv4/tcp_ulp.c | 4 +
net/ipv6/esp6.c | 6 +
net/ipv6/seg6_local.c | 3 +
net/ipv6/tcp_ipv6.c | 3 +-
net/ipv6/xfrm6_output.c | 10 +-
net/mac80211/cfg.c | 18 +-
net/mac80211/debugfs.c | 2 +-
net/mac80211/debugfs_netdev.c | 9 +
net/mac80211/ieee80211_i.h | 2 +-
net/mac80211/iface.c | 39 +-
net/mac80211/main.c | 4 +
net/mac80211/mesh.c | 34 +-
net/mac80211/offchannel.c | 7 +
net/mac80211/pm.c | 8 +-
net/mac80211/scan.c | 2 +-
net/mac80211/tdls.c | 40 +-
net/mac80211/tx.c | 107 +--
net/netfilter/nf_flow_table_core.c | 12 +-
net/netfilter/nf_flow_table_path.c | 7 +-
net/netfilter/nf_nat_core.c | 46 +-
net/netfilter/nf_tables_api.c | 22 +-
net/netfilter/nft_nat.c | 2 +-
net/netlink/af_netlink.c | 42 +-
net/netlink/diag.c | 18 +-
net/openvswitch/conntrack.c | 2 +-
net/packet/af_packet.c | 4 +-
net/packet/internal.h | 2 +-
net/psp/psp_sock.c | 4 +
net/rds/ib_cm.c | 2 +-
net/sched/act_api.c | 11 +-
net/sched/sch_hhf.c | 9 +-
net/sched/sch_mqprio.c | 4 +-
net/sched/sch_mqprio_lib.c | 7 +-
net/sched/sch_taprio.c | 26 +-
net/unix/garbage.c | 17 +-
net/wireless/core.c | 150 +++--
net/wireless/core.h | 16 +-
net/wireless/ibss.c | 38 +-
net/wireless/rdev-ops.h | 3 +
net/wireless/reg.c | 2 +-
net/wireless/scan.c | 43 +-
net/wireless/util.c | 38 +-
net/xfrm/espintcp.c | 6 +-
net/xfrm/xfrm_input.c | 22 +-
net/xfrm/xfrm_iptfs.c | 12 +-
net/xfrm/xfrm_policy.c | 20 +-
net/xfrm/xfrm_state.c | 9 +-
net/xfrm/xfrm_user.c | 18 +-
rust/kernel/net/phy.rs | 38 +-
scripts/generate_rust_target.rs | 5 +
security/keys/encrypted-keys/encrypted.c | 20 +-
security/keys/gc.c | 4 +-
security/keys/request_key_auth.c | 12 +-
security/keys/trusted-keys/trusted_tpm2.c | 12 +-
security/selinux/avc.c | 5 +-
security/selinux/hooks.c | 158 ++++-
security/selinux/include/objsec.h | 10 +-
sound/core/init.c | 3 +-
sound/core/pcm_timer.c | 7 +-
sound/hda/common/controller.c | 2 +-
sound/soc/amd/acp/acp-sdw-legacy-mach.c | 16 +-
sound/soc/amd/acp/acp-sdw-sof-mach.c | 21 +-
sound/soc/codecs/cs-amp-lib.c | 2 +
sound/soc/codecs/hdmi-codec.c | 6 +-
sound/soc/codecs/rt712-sdca-dmic.c | 14 +-
sound/soc/intel/boards/sof_sdw.c | 2 +-
sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c | 4 +-
sound/soc/sdw_utils/soc_sdw_utils.c | 9 +-
sound/soc/soc-pcm.c | 18 +-
sound/soc/ux500/ux500_msp_i2s.h | 4 +-
sound/usb/6fire/comm.c | 42 +-
sound/usb/6fire/comm.h | 2 +-
sound/usb/6fire/midi.c | 43 +-
sound/usb/6fire/midi.h | 2 +-
sound/usb/6fire/pcm.c | 138 ++--
sound/usb/6fire/pcm.h | 5 +-
sound/usb/bcd2000/bcd2000.c | 33 +-
sound/usb/card.h | 1 +
sound/usb/endpoint.c | 12 +-
sound/virtio/virtio_card.c | 4 +-
tools/objtool/Makefile | 8 +-
.../selftests/arm64/mte/check_gcr_el1_cswitch.c | 2 +-
tools/testing/selftests/landlock/fs_test.c | 197 +++++-
442 files changed, 6831 insertions(+), 2723 deletions(-)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 001/438] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 002/438] selftests/landlock: Add tests for whiteout object creation Greg Kroah-Hartman
` (448 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack,
Mickaël Salaün, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Günther Noack <gnoack@google.com>
[ Upstream commit 173b1bd8730825e1f6862dbd07856e7d68447a41 ]
By passing a (0, 0) device number, the audit test for
LANDLOCK_ACCESS_FS_MAKE_CHAR was accidentally creating a whiteout object
rather than a char device. In preparation to treating whiteout objects
differently, use an actual character device instead.
Signed-off-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260813093157.1436894-2-gnoack@google.com
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 86e08aa6e0a7e..e82b56a74c5f5 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -7436,7 +7436,7 @@ TEST_F(audit_layout1, make_char)
enforce_fs(_metadata, ACCESS_ALL, NULL);
- EXPECT_EQ(-1, mknod(file1_s1d3, S_IFCHR | 0644, 0));
+ EXPECT_EQ(-1, mknod(file1_s1d3, S_IFCHR | 0644, makedev(7, 0)));
EXPECT_EQ(EACCES, errno);
EXPECT_EQ(0, matches_log_fs(_metadata, self->audit_fd, "fs\\.make_char",
dir_s1d3));
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 002/438] selftests/landlock: Add tests for whiteout object creation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 001/438] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 003/438] selftests/landlock: Add audit test " Greg Kroah-Hartman
` (447 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack,
Mickaël Salaün, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Günther Noack <gnoack@google.com>
[ Upstream commit ee890889b30b22f9a21636061def7a04e4f89380 ]
Add tests to check that whiteout object creation is guarded by
LANDLOCK_ACCESS_FS_MAKE_REG, in the cases where these are created from
userspace:
* Conventional creation with mknod()
* Linking or renaming an existing whiteout object
* renameat2() with RENAME_WHITEOUT,
which creates a new whiteout object in the source location
* renameat2() with RENAME_EXCHANGE,
with one of the renamed objects being a whiteout object
Signed-off-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260813093157.1436894-4-gnoack@google.com
[mic: Update commit message as requested]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 176 +++++++++++++++++++++
1 file changed, 176 insertions(+)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index e82b56a74c5f5..871a5b819b989 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -2247,6 +2247,170 @@ TEST_F_FORK(layout1, rename_file)
RENAME_EXCHANGE));
}
+TEST_F_FORK(layout1, rename_whiteout_denied)
+{
+ /* The affected file is a FIFO. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+
+ /* Deny MAKE_REG, but allow MAKE_FIFO. */
+ enforce_fs(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, NULL);
+
+ /*
+ * Try to rename a file with RENAME_WHITEOUT.
+ * file1_s3d3 is in dir_s3d2 (tmpfs), so it supports RENAME_WHITEOUT.
+ * Denied, because whiteout creation is guarded with MAKE_REG.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+ EXPECT_EQ(EACCES, errno);
+}
+
+static bool is_whiteout(const char *const path)
+{
+ struct stat st;
+
+ if (stat(path, &st) == -1)
+ return false;
+
+ return S_ISCHR(st.st_mode) && st.st_rdev == makedev(0, 0);
+}
+
+static bool is_fifo(const char *const path)
+{
+ struct stat st;
+
+ return stat(path, &st) == 0 && S_ISFIFO(st.st_mode);
+}
+
+TEST_F_FORK(layout1, rename_whiteout_allowed)
+{
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The affected file is a FIFO. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+
+ /* Allow MAKE_REG below dir_s3d3. */
+ enforce_fs(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, rules);
+
+ /*
+ * Rename a file with RENAME_WHITEOUT within the same directory.
+ * Allowed, because MAKE_REG is granted for the whiteout object which
+ * gets created in the source location.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+
+ /* A whiteout object took the place of the moved FIFO. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(TMP_DIR "/s3d1/s3d2/s3d3/f2"));
+}
+
+TEST_F_FORK(layout1, rename_whiteout_reparenting)
+{
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d2,
+ .access = LANDLOCK_ACCESS_FS_REFER,
+ },
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The moved files are FIFOs. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+ ASSERT_EQ(0, unlink(file1_s3d4));
+ ASSERT_EQ(0, mknod(file1_s3d4, S_IFIFO | 0600, 0));
+
+ /* Allow REFER below dir_s3d2, but MAKE_REG only below dir_s3d3. */
+ enforce_fs(_metadata,
+ LANDLOCK_ACCESS_FS_MAKE_REG | LANDLOCK_ACCESS_FS_REFER,
+ rules);
+
+ /*
+ * The whiteout object is created in the source directory: Moving the
+ * FIFO out of dir_s3d4 is denied because MAKE_REG is not granted
+ * there, even though it is granted in the destination directory
+ * dir_s3d3.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d4, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+ EXPECT_EQ(EACCES, errno);
+
+ /*
+ * Moving the FIFO out of dir_s3d3 is allowed, because MAKE_REG is
+ * granted there for the created whiteout object.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d4/f2", RENAME_WHITEOUT));
+
+ /* A whiteout object took the place of the moved FIFO. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(TMP_DIR "/s3d1/s3d2/s3d4/f2"));
+}
+
+TEST_F_FORK(layout1, rename_whiteout_exchange)
+{
+ const char *const whiteout_s3d3 = TMP_DIR "/s3d1/s3d2/s3d3/f2";
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d2,
+ .access = LANDLOCK_ACCESS_FS_REFER,
+ },
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The exchanged files are FIFOs and an existing whiteout object. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+ ASSERT_EQ(0, mknod(whiteout_s3d3, S_IFCHR | 0600, makedev(0, 0)));
+ ASSERT_EQ(0, unlink(file1_s3d4));
+ ASSERT_EQ(0, mknod(file1_s3d4, S_IFIFO | 0600, 0));
+
+ /* Allow REFER below dir_s3d2, but MAKE_REG only below dir_s3d3. */
+ enforce_fs(_metadata,
+ LANDLOCK_ACCESS_FS_MAKE_REG | LANDLOCK_ACCESS_FS_REFER,
+ rules);
+
+ /*
+ * With RENAME_EXCHANGE, the whiteout object moves into the source
+ * directory of the rename: Exchanging the FIFO in dir_s3d4 with the
+ * whiteout object is denied because MAKE_REG is not granted in
+ * dir_s3d4, even though it is granted in the whiteout object's own
+ * directory dir_s3d3.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d4, AT_FDCWD, whiteout_s3d3,
+ RENAME_EXCHANGE));
+ EXPECT_EQ(EACCES, errno);
+
+ /*
+ * Exchanging the FIFO in dir_s3d3 with the whiteout object is
+ * allowed, because MAKE_REG is granted in the directory into which
+ * the whiteout object moves.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD, whiteout_s3d3,
+ RENAME_EXCHANGE));
+
+ /* The FIFO and the whiteout object swapped places. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(whiteout_s3d3));
+}
+
TEST_F_FORK(layout1, rename_dir)
{
const struct rule rules[] = {
@@ -3270,6 +3434,18 @@ TEST_F_FORK(layout1, make_char)
makedev(1, 3));
}
+TEST_F_FORK(layout1, make_whiteout)
+{
+ /*
+ * Creates a whiteout object (creation guarded by MAKE_REG).
+ *
+ * Contrary to the other character devices, this does not require
+ * CAP_MKNOD, cf. vfs_mknod().
+ */
+ test_make_file(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, S_IFCHR,
+ makedev(0, 0));
+}
+
TEST_F_FORK(layout1, make_block)
{
/* Creates a /dev/loop0 device. */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 003/438] selftests/landlock: Add audit test for whiteout object creation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 001/438] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 002/438] selftests/landlock: Add tests for whiteout object creation Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 004/438] sunvdc: fix -EIO issue due to lack of retries Greg Kroah-Hartman
` (446 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack,
Mickaël Salaün, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Günther Noack <gnoack@google.com>
[ Upstream commit 8c46c6acbebe0d8544fd1b55e5ddf36828d7b9ea ]
Add audit_layout1.make_whiteout: This test looks similar to
audit_layout1.make_char, but creates a whiteout object through mknod().
Since whiteout object creation is now guarded with
LANDLOCK_ACCESS_FS_MAKE_REG rather than LANDLOCK_ACCESS_FS_MAKE_CHAR, it
also needs to log the matching denial to audit.
Signed-off-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260813093157.1436894-5-gnoack@google.com
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 871a5b819b989..a9130ed70af5c 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -7622,6 +7622,25 @@ TEST_F(audit_layout1, make_char)
EXPECT_EQ(1, records.domain);
}
+TEST_F(audit_layout1, make_whiteout)
+{
+ struct audit_records records;
+
+ EXPECT_EQ(0, unlink(file1_s1d3));
+
+ enforce_fs(_metadata, ACCESS_ALL, NULL);
+
+ /* Whiteout creation is denied and logged as fs.make_reg. */
+ EXPECT_EQ(-1, mknod(file1_s1d3, S_IFCHR | 0644, makedev(0, 0)));
+ EXPECT_EQ(EACCES, errno);
+ EXPECT_EQ(0, matches_log_fs(_metadata, self->audit_fd, "fs\\.make_reg",
+ dir_s1d3));
+
+ EXPECT_EQ(0, audit_count_records(self->audit_fd, &records));
+ EXPECT_EQ(0, records.access);
+ EXPECT_EQ(1, records.domain);
+}
+
TEST_F(audit_layout1, make_dir)
{
struct audit_records records;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 004/438] sunvdc: fix -EIO issue due to lack of retries
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (2 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 003/438] selftests/landlock: Add audit test " Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 005/438] xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() Greg Kroah-Hartman
` (445 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Paul Adrian Glaubitz,
Stian Halseth, Jens Axboe, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Axboe <axboe@kernel.dk>
[ Upstream commit 5067d4ba713961d8ccea1e06cd4c453793f3121e ]
John reports that since commit:
a11f6ca9aef9 ("sunvdc: Do not spin in an infinite loop when vio_ldc_send() returns EAGAIN")
users of Linux inside Solaris ldom see occasional -EIO errors because
the request send loop now times out. The current loop does 10 retries,
and inside vio_ldc_send() a further 1000 1usec retries are done as well.
Even with 10.5 msec of busy loop retries that's apparently not enough to
always succeed.
Rather than introduce continued busy looping, requeue the request and
have the delayed queue kicking retry the request after another 10ms.
This obviously isn't ideal, but there's seemingly no way to wait for
this type of event. And if 10ms of busy looping was not enough to make
progress, then presumably this is an edge condition and we just need to
guarantee to make forward progress at some later point in time. That's
more suitably done through letting the CPU tend to other work, rather
than sitting in a tight loop retrying.
[stian: rebased on top of the cookie-unmap fix, without which every
requeued attempt leaks LDC map table entries; tested on an
UltraSPARC T4 LDOM where the vdc_tx_trigger failure condition was
reproduced and absorbed by the requeue with no I/O error]
Reported-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Link: https://lore.kernel.org/all/20251006100226.4246-2-glaubitz@physik.fu-berlin.de/
Link: https://lore.kernel.org/all/418310b3-2b77-4534-b2fd-27dcc11e333c@kernel.dk/
Signed-off-by: Stian Halseth <stian@itx.no>
Link: https://patch.msgid.link/20260901173947.3292110-3-stian@itx.no
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/block/sunvdc.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/block/sunvdc.c b/drivers/block/sunvdc.c
index 24ad56536ed60..2be8231dcd5b4 100644
--- a/drivers/block/sunvdc.c
+++ b/drivers/block/sunvdc.c
@@ -556,6 +556,7 @@ static blk_status_t vdc_queue_rq(struct blk_mq_hw_ctx *hctx,
struct vdc_port *port = hctx->queue->queuedata;
struct vio_dring_state *dr;
unsigned long flags;
+ int ret;
dr = &port->vio.drings[VIO_DRIVER_TX_RING];
@@ -577,7 +578,13 @@ static blk_status_t vdc_queue_rq(struct blk_mq_hw_ctx *hctx,
return BLK_STS_DEV_RESOURCE;
}
- if (__send_request(bd->rq) < 0) {
+ ret = __send_request(bd->rq);
+ if (ret == -EAGAIN) {
+ spin_unlock_irqrestore(&port->vio.lock, flags);
+ /* already spun for 10msec, defer 10msec and retry */
+ blk_mq_delay_kick_requeue_list(hctx->queue, 10);
+ return BLK_STS_DEV_RESOURCE;
+ } else if (ret < 0) {
spin_unlock_irqrestore(&port->vio.lock, flags);
return BLK_STS_IOERR;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 005/438] xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (3 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 004/438] sunvdc: fix -EIO issue due to lack of retries Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 006/438] xfrm: add missing RCU read lock in xfrm_send_migrate_state() Greg Kroah-Hartman
` (444 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Roshan Kumar, Steffen Klassert,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Roshan Kumar <roshaen09@gmail.com>
[ Upstream commit d042487dc118e494db2e2c1382310255c90ff544 ]
iptfs_skb_reset_frag_walk() advances to the fragment containing @offset
with an unbounded loop:
while (offset >= walk->past + walk->frags[walk->fragi].len)
walk->past += walk->frags[walk->fragi++].len;
walk->fragi is advanced and walk->frags[walk->fragi] is dereferenced
without ever checking fragi against walk->nr_frags. When the requested
offset is at or beyond the total length spanned by the walk's fragments,
fragi runs past nr_frags and off the end of the fixed-size on-stack
frags[MAX_SKB_FRAGS + 1] array, reading out-of-bounds stack memory.
The two callers behave differently: iptfs_skb_add_frags() already guards
against this with
if (!walk->nr_frags ||
offset >= walk->total + walk->initial_offset)
return len;
but iptfs_skb_can_add_frags() has no such guard and calls
iptfs_skb_reset_frag_walk() unconditionally, so it performs the
out-of-range walk. Its own "fragi < walk->nr_frags" bound check runs only
afterwards, too late to prevent the read.
This is reachable from the receive path: a crafted IP-TFS (AGGFRAG)
payload delivered to an IPTFS SA drives iptfs_reassem_cont() ->
iptfs_skb_can_add_frags() with an offset past the fragment total, e.g.:
BUG: KASAN: stack-out-of-bounds in iptfs_skb_reset_frag_walk+0x235/0x250
Read of size 4 at addr ffff888008ad7210 by task repro/345
iptfs_skb_reset_frag_walk+0x235/0x250 net/xfrm/xfrm_iptfs.c:392
iptfs_skb_can_add_frags+0x155/0x310 net/xfrm/xfrm_iptfs.c:420
iptfs_reassem_cont+0xcf8/0x1140 net/xfrm/xfrm_iptfs.c:902
iptfs_input_ordered+0x552/0x670 net/xfrm/xfrm_iptfs.c:1280
iptfs_input+0x3d6/0xde0 net/xfrm/xfrm_iptfs.c:1741
xfrm_input+0x282f/0x6140 net/xfrm/xfrm_input.c:700
xfrm4_esp_rcv+0x93/0x120 net/ipv4/xfrm4_protocol.c:104
ip_rcv+0x278/0x2d0 net/ipv4/ip_input.c:612
Give iptfs_skb_can_add_frags() the same up-front guard that
iptfs_skb_add_frags() already has, so the walk is never entered with an
out-of-range offset. When it triggers, the caller falls back to the
existing linearize-and-copy path, which is safe.
Fixes: 5f2b6a909574 ("xfrm: iptfs: add skb-fragment sharing code")
Reported-by: Roshan Kumar <roshaen09@gmail.com>
Signed-off-by: Roshan Kumar <roshaen09@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_iptfs.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/net/xfrm/xfrm_iptfs.c b/net/xfrm/xfrm_iptfs.c
index 597aedeac26eb..2ce15c472cc4d 100644
--- a/net/xfrm/xfrm_iptfs.c
+++ b/net/xfrm/xfrm_iptfs.c
@@ -416,6 +416,14 @@ static bool iptfs_skb_can_add_frags(const struct sk_buff *skb,
if (skb_has_frag_list(skb) || skb->pp_recycle != walk->pp_recycle)
return false;
+ /* Reject an @offset that is at or beyond the end of the walk's data
+ * before calling iptfs_skb_reset_frag_walk(), whose fragment-advance
+ * loop is otherwise unbounded and would index past walk->frags[].
+ * This mirrors the guard already present in iptfs_skb_add_frags().
+ */
+ if (!walk->nr_frags || offset >= walk->total + walk->initial_offset)
+ return false;
+
/* Make offset relative to current frag after setting that */
offset = iptfs_skb_reset_frag_walk(walk, offset);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 006/438] xfrm: add missing RCU read lock in xfrm_send_migrate_state()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (4 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 005/438] xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 007/438] xfrm: iptfs: fix runt reassembly panic from short inner tot_len Greg Kroah-Hartman
` (443 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+c0e99a1aa85a286d7a3b,
Aleksandr Nogikh, Steffen Klassert, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aleksandr Nogikh <nogikh@google.com>
[ Upstream commit 42d100f5232f39b8ea7b00a7c2482325c7f032a4 ]
xfrm_nlmsg_multicast() requires the RCU read lock to be held because it
safely dereferences the net->xfrm.nlsk pointer using rcu_dereference().
When it is called from xfrm_send_migrate_state(), the RCU read lock is not
held, which triggers a suspicious RCU usage warning:
WARNING: suspicious RCU usage
net/xfrm/xfrm_user.c:1630 suspicious rcu_dereference_check() usage!
Call Trace:
lockdep_rcu_suspicious+0x13f/0x1d0 kernel/locking/lockdep.c:6876
xfrm_nlmsg_multicast+0x1d8/0x1f0 net/xfrm/xfrm_user.c:1630
xfrm_send_migrate_state+0x870/0xae0 net/xfrm/xfrm_user.c:3340
xfrm_do_migrate_state+0x1749/0x1e90 net/xfrm/xfrm_user.c:3507
xfrm_user_rcv_msg+0x7a8/0xf30 net/xfrm/xfrm_user.c:3907
Fix this by wrapping the xfrm_nlmsg_multicast() call in
xfrm_send_migrate_state() with rcu_read_lock() and rcu_read_unlock().
Fixes: a9d155ea9b44 ("xfrm: add XFRM_MSG_MIGRATE_STATE for single SA migration")
Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot
Reported-by: syzbot+c0e99a1aa85a286d7a3b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c0e99a1aa85a286d7a3b
Link: https://syzkaller.appspot.com/ai_job?id=8977f559-3a7e-4bb5-b4d6-1196956260b6
Signed-off-by: Aleksandr Nogikh <nogikh@google.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_user.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 6266a92cf3020..980dbeb5a57de 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -3337,7 +3337,11 @@ static int xfrm_send_migrate_state(struct net *net,
return err;
}
- return xfrm_nlmsg_multicast(net, skb, 0, XFRMNLGRP_MIGRATE);
+ rcu_read_lock();
+ err = xfrm_nlmsg_multicast(net, skb, 0, XFRMNLGRP_MIGRATE);
+ rcu_read_unlock();
+
+ return err;
}
static int xfrm_do_migrate_state(struct sk_buff *skb, struct nlmsghdr *nlh,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 007/438] xfrm: iptfs: fix runt reassembly panic from short inner tot_len
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (5 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 006/438] xfrm: add missing RCU read lock in xfrm_send_migrate_state() Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 008/438] xfrm: fix compat ALLOCSPI request use-after-free Greg Kroah-Hartman
` (442 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Henry Martin, Steffen Klassert,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Henry Martin <bsdhenrymartin@gmail.com>
[ Upstream commit dc33262be1fe43d0eb0b84fb58c6ed42e2f64a8c ]
When the start of an inner packet is split across two outer packets
such that fewer than 4 bytes land at the end of the first one,
__input_process_payload() saves those bytes as a runt and skips the
iplen/iphlen validation performed for in-place packets. When the
continuation packet arrives, iptfs_reassem_cont() only requires the
declared inner length to be >= sizeof(ra_runt) (6) before allocating
the reassembly skb with that attacker-controlled length.
However, __iptfs_iphlen() always returns the fixed minimum IP header
size (20 for IPv4, 40 for IPv6), so for an inner IPv4 tot_len in
[6, 19] the header-completion copy writes past the declared packet
length, and the subsequent "ipremain -= copylen" underflows to ~4GB,
leaving the payload copy length bounded only by blkoff (up to 64KB).
At runtime the skb_put() tailroom check turns this into
skb_over_panic(), i.e. an unprivileged kernel panic (DoS), reachable
locally via userns+netns IPTFS SAs and remotely against IPTFS VPN
gateways when the decrypted outer skb is linear (e.g. AF_PACKET taps,
tun/tap delivery).
Align the runt path with the normal path by requiring the declared
inner length to cover at least the IP header size. This also subsumes
the previous >= sizeof(ra_runt) check, since the minimum IP header
is always larger than the runt buffer.
This issue was found by the autokbug dynamic kernel fuzzer at
Tencent Yunding Lab.
Fixes: 075694765446 ("xfrm: iptfs: handle received fragmented inner packets")
Reported-by: Henry Martin <bsdhenrymartin@gmail.com>
Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_iptfs.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/xfrm/xfrm_iptfs.c b/net/xfrm/xfrm_iptfs.c
index 2ce15c472cc4d..6920940a35b49 100644
--- a/net/xfrm/xfrm_iptfs.c
+++ b/net/xfrm/xfrm_iptfs.c
@@ -828,8 +828,8 @@ static u32 iptfs_reassem_cont(struct xfrm_iptfs_data *xtfs, u64 seq,
* allocate an in progress skb
*/
ipremain = __iptfs_iplen(xtfs->ra_runt);
- if (ipremain < sizeof(xtfs->ra_runt)) {
- /* length has to be at least runtsize large */
+ if (ipremain < __iptfs_iphlen(xtfs->ra_runt)) {
+ /* length has to be at least the IP header size */
XFRM_INC_STATS(xs_net(xtfs->x),
LINUX_MIB_XFRMINIPTFSERROR);
goto abandon;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 008/438] xfrm: fix compat ALLOCSPI request use-after-free
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (6 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 007/438] xfrm: iptfs: fix runt reassembly panic from short inner tot_len Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 009/438] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() Greg Kroah-Hartman
` (441 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kyle Zeng, David Lee,
Steffen Klassert, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kyle Zeng <kylebot@openai.com>
[ Upstream commit d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320 ]
xfrm_state_netlink() builds the ALLOCSPI response with
dump_one_state(), which already calls alloc_compat() with the response
skb and header.
xfrm_alloc_userspi() then calls alloc_compat() again, but passes the
original request skb and its header. For a compat request, the
translator therefore interprets the 228-byte compat xfrm_userspi_info
as the 232-byte native layout and reads four bytes past the declared
payload. It also publishes the translated child through the request's
frag_list.
A multicast clone of the request shares skb_shared_info and can observe
that child. xfrm_user_rcv_msg() frees it after the request handler
returns, racing a compat receiver which may still be copying from it and
resulting in a use-after-free.
Remove the redundant conversion. The response keeps its correct compat
translation from dump_one_state(), and no child is attached to the
inbound request.
Fixes: 5f3eea6b7e8f ("xfrm/compat: Attach xfrm dumps to 64=>32 bit translator")
Assisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber
Signed-off-by: Kyle Zeng <kylebot@openai.com>
Co-developed-by: David Lee <david.lee@trailofbits.com>
Signed-off-by: David Lee <david.lee@trailofbits.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_user.c | 12 ------------
1 file changed, 12 deletions(-)
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 980dbeb5a57de..a2587c7e796b4 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -1877,7 +1877,6 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
struct net *net = sock_net(skb->sk);
struct xfrm_state *x;
struct xfrm_userspi_info *p;
- struct xfrm_translator *xtr;
struct sk_buff *resp_skb;
xfrm_address_t *daddr;
int family;
@@ -1943,17 +1942,6 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
goto out;
}
- xtr = xfrm_get_translator();
- if (xtr) {
- err = xtr->alloc_compat(skb, nlmsg_hdr(skb));
-
- xfrm_put_translator(xtr);
- if (err) {
- kfree_skb(resp_skb);
- goto out;
- }
- }
-
err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid);
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 009/438] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (7 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 008/438] xfrm: fix compat ALLOCSPI request use-after-free Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 010/438] esp: downgrade zerocopy managed frags before mutating skb frags Greg Kroah-Hartman
` (440 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot, Eric Dumazet,
Steffen Klassert, Liu Jian, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit d2f5082f9e84653fa1a9e8aebaaff23e688f5e19 ]
syzbot reported a suspicious RCU usage warning in ip6_pkt_drop():
WARNING: suspicious RCU usage in ip6_pkt_drop
include/net/addrconf.h:389 suspicious rcu_dereference_check() usage!
Call Trace:
__in6_dev_get_safely include/net/addrconf.h:389 [inline]
ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620
ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651
xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806
process_one_work kernel/workqueue.c:3322 [inline]
process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405
worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486
When commit 4f4920669d21 ("xfrm: Reinject transport-mode packets through
workqueue") converted xfrm_trans_reinject from a tasklet to a workqueue,
the reinjection loop ceased running in softirq context. Workqueue workers
run in process context where local_bh_disable() does not enter an RCU
read-side critical section under CONFIG_PREEMPT_RCU.
Because finish callbacks (such as ip6_rcv_finish) expect to run under an
RCU read lock (performing route lookups, l3mdev lookups, and accessing
RCU-protected data structures), invoking them in workqueue context without
rcu_read_lock() triggers RCU lockdep warnings.
Furthermore, packets queued to the workqueue via xfrm_trans_queue_net()
may carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref).
Additionally, on netdevice unregistration, dst_dev_put() replaces dst->dev
with blackhole_netdev, so dst entries do not keep skb->dev alive while
queued in the workqueue.
Fix these issues by:
1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the
caller's RCU section to ensure dst is reference-counted before queuing.
2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue
deferral so skb->dev remains valid during finish() callback processing.
3. Acquiring rcu_read_lock() around the finish callback invocation loop in
xfrm_trans_reinject().
Fixes: 4f4920669d21 ("xfrm: Reinject transport-mode packets through workqueue")
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Steffen Klassert <steffen.klassert@secunet.com>
Cc: Liu Jian <liujian56@huawei.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_input.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/net/xfrm/xfrm_input.c b/net/xfrm/xfrm_input.c
index eecab337bd0a7..8f6109eada7ea 100644
--- a/net/xfrm/xfrm_input.c
+++ b/net/xfrm/xfrm_input.c
@@ -800,12 +800,17 @@ static void xfrm_trans_reinject(struct work_struct *work)
spin_unlock_bh(&trans->queue_lock);
local_bh_disable();
+ rcu_read_lock();
while ((skb = __skb_dequeue(&queue))) {
struct net *net = XFRM_TRANS_SKB_CB(skb)->net;
+ struct net_device *dev = skb->dev;
XFRM_TRANS_SKB_CB(skb)->finish(net, NULL, skb);
+ if (dev)
+ dev_put(dev);
put_net(net);
}
+ rcu_read_unlock();
local_bh_enable();
}
@@ -821,12 +826,18 @@ int xfrm_trans_queue_net(struct net *net, struct sk_buff *skb,
if (skb_queue_len(&trans->queue) >= READ_ONCE(net_hotdata.max_backlog))
return -ENOBUFS;
+ if (skb_dst(skb) && !skb_dst_force(skb))
+ return -EHOSTUNREACH;
+
BUILD_BUG_ON(sizeof(struct xfrm_trans_cb) > sizeof(skb->cb));
hold_net = maybe_get_net(net);
if (!hold_net)
return -ENODEV;
+ if (skb->dev)
+ dev_hold(skb->dev);
+
XFRM_TRANS_SKB_CB(skb)->finish = finish;
XFRM_TRANS_SKB_CB(skb)->net = hold_net;
spin_lock_bh(&trans->queue_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 010/438] esp: downgrade zerocopy managed frags before mutating skb frags
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (8 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 009/438] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 011/438] arm64: dts: amlogic: t7: use the real UART pclk Greg Kroah-Hartman
` (439 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maher Azzouzi, Steffen Klassert,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maher Azzouzi <maherazz04@gmail.com>
[ Upstream commit f89416eb3db151170a6f3c6dfc5239d26cdce4d2 ]
On the out-of-place output path (esp->inplace == false) ESP rewrites the
skb frag array: esp_output_head() appends a trailer frag and
esp_output_tail() replaces the frags with a destination page, both
referenced with get_page().
When the skb carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS) the
payload frags are owned by the ubuf and must not be referenced or
unreferenced individually, but ESP mutates the frag array without ever
downgrading the skb. This breaks the managed-frag invariant two ways:
- esp_ssg_unref() walks the source scatterlist and drops a page
reference for every frag, including the ubuf-owned payload frags,
pushing their refcount below the GUP pin bias while the pages are
still pinned, i.e. a use-after-free of the zerocopy pages;
- esp_output_tail() installs its destination page as frag 0 with
get_page() but leaves SKBFL_MANAGED_FRAG_REFS set, so
skb_release_data() takes the skip_unref branch and never drops that
reference, leaking the x->xfrag page at packet rate.
Fix this the way every other frag-mutating site does (__ip_append_data(),
__ip6_append_data(), tcp_sendmsg_locked()) and call
skb_zcopy_downgrade_managed() before ESP touches the frag array: it takes
a real reference on each existing frag and clears SKBFL_MANAGED_FRAG_REFS,
so the per-frag unref in esp_ssg_unref() and the frag release in
skb_release_data() are both balanced and no mixed-ownership frag array is
left behind.
Fixes: 753f1ca4e1e5 ("net: introduce managed frags infrastructure")
Signed-off-by: Maher Azzouzi <maherazz04@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/esp4.c | 6 ++++++
net/ipv6/esp6.c | 6 ++++++
2 files changed, 12 insertions(+)
diff --git a/net/ipv4/esp4.c b/net/ipv4/esp4.c
index dfc81ee969ae0..faa48f5b97395 100644
--- a/net/ipv4/esp4.c
+++ b/net/ipv4/esp4.c
@@ -441,6 +441,12 @@ int esp_output_head(struct xfrm_state *x, struct sk_buff *skb, struct esp_info *
esp->inplace = false;
+ /* Take real page refs and clear SKBFL_MANAGED_FRAG_REFS before
+ * we mutate the frag array, so the per-frag unref stays balanced
+ * for zerocopy managed frags (see __ip_append_data()).
+ */
+ skb_zcopy_downgrade_managed(skb);
+
allocsize = ALIGN(tailen, L1_CACHE_BYTES);
spin_lock_bh(&x->lock);
diff --git a/net/ipv6/esp6.c b/net/ipv6/esp6.c
index 296b57926abb9..a3a3857eed98a 100644
--- a/net/ipv6/esp6.c
+++ b/net/ipv6/esp6.c
@@ -470,6 +470,12 @@ int esp6_output_head(struct xfrm_state *x, struct sk_buff *skb, struct esp_info
esp->inplace = false;
+ /* Take real page refs and clear SKBFL_MANAGED_FRAG_REFS before
+ * we mutate the frag array, so the per-frag unref stays balanced
+ * for zerocopy managed frags (see __ip_append_data()).
+ */
+ skb_zcopy_downgrade_managed(skb);
+
allocsize = ALIGN(tailen, L1_CACHE_BYTES);
spin_lock_bh(&x->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 011/438] arm64: dts: amlogic: t7: use the real UART pclk
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (9 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 010/438] esp: downgrade zerocopy managed frags before mutating skb frags Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 012/438] arm64: dts: amlogic: t7: khadas-vim4: allow the SD card to be power cycled Greg Kroah-Hartman
` (438 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lucas Tanure, Neil Armstrong,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lucas Tanure <tanure@linux.com>
[ Upstream commit 882de800bf583dd15969836088789edbf035a944 ]
uart_a listed the 24MHz crystal for all three of its clocks because the
T7 clock controller driver did not exist when these boards were added.
That leaves the real UART bus clock without a user, so the kernel
turns it off when it disables unused clocks at the end of boot, and
the board hangs.
Update the board DTS files to point uart_a's pclk to CLKID_SYS_UART_A
instead of the dummy crystal clock.
Fixes: 4fef056588f5 ("arm64: dts: amlogic-t7-a311d2-khadas-vim4: add initial device-tree")
Fixes: 6f048cc7a635 ("arm64: dts: add board AN400")
Signed-off-by: Lucas Tanure <tanure@linux.com>
Assisted-by: Claude:claude-fable-5
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260823115335.102219-2-tanure@linux.com
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-an400.dts | 2 +-
arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-an400.dts b/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-an400.dts
index cab2ee9ea0d31..ca7536f772ff1 100644
--- a/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-an400.dts
+++ b/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-an400.dts
@@ -33,7 +33,7 @@ xtal: xtal-clk {
};
&uart_a {
- clocks = <&xtal>, <&xtal>, <&xtal>;
+ clocks = <&xtal>, <&clkc_periphs CLKID_SYS_UART_A>, <&xtal>;
clock-names = "xtal", "pclk", "baud";
status = "okay";
};
diff --git a/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts b/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts
index c41525a34b721..75d81ad6830df 100644
--- a/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts
+++ b/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts
@@ -266,6 +266,6 @@ &sd_emmc_c {
&uart_a {
status = "okay";
- clocks = <&xtal>, <&xtal>, <&xtal>;
+ clocks = <&xtal>, <&clkc_periphs CLKID_SYS_UART_A>, <&xtal>;
clock-names = "xtal", "pclk", "baud";
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 012/438] arm64: dts: amlogic: t7: khadas-vim4: allow the SD card to be power cycled
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (10 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 011/438] arm64: dts: amlogic: t7: use the real UART pclk Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 013/438] arm64: dts: amlogic: t7: fix the pin groups of two PWM outputs Greg Kroah-Hartman
` (437 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lucas Tanure, Neil Armstrong,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lucas Tanure <tanure@linux.com>
[ Upstream commit c793a084ab3088744516aef437b4239d0d98623f ]
SD cards start at 3.3V and switch to 1.8V to reach UHS-I speeds. Some
cards refuse that switch, and the SD specification says the only way
to recover is to power the card off and start again.
SD_3V3 is marked regulator-always-on, so the supply never goes off,
the card stays stuck half way through the switch, and the MMC core
retries forever:
mmc1: error -95 whilst initialising SD card
Drop regulator-always-on. regulator-boot-on still turns the supply on
at boot, and a card that refuses the switch now falls back to high
speed instead of failing to initialise.
Fixes: 8c45bf9ae4ef ("arm64: dts: amlogic: t7: khadas-vim4: Add power regulators")
Signed-off-by: Lucas Tanure <tanure@linux.com>
Assisted-by: Claude:claude-fable-5
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260823115335.102219-3-tanure@linux.com
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts | 1 -
1 file changed, 1 deletion(-)
diff --git a/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts b/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts
index 75d81ad6830df..c94afaaf8826e 100644
--- a/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts
+++ b/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts
@@ -71,7 +71,6 @@ sd_3v3: regulator-sdcard-3v3 {
vin-supply = <&vddao_3v3>;
gpio = <&gpio GPIOD_11 GPIO_ACTIVE_LOW>;
regulator-boot-on;
- regulator-always-on;
};
sdio_pwrseq: sdio-pwrseq {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 013/438] arm64: dts: amlogic: t7: fix the pin groups of two PWM outputs
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (11 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 012/438] arm64: dts: amlogic: t7: khadas-vim4: allow the SD card to be power cycled Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 014/438] arm64: dts: amlogic: t7: khadas-vim4: add the PWM-driven supplies Greg Kroah-Hartman
` (436 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lucas Tanure, Neil Armstrong,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lucas Tanure <tanure@linux.com>
[ Upstream commit ae7be5c58a819259e5eb98a3abfa60842478f2ae ]
Two of the PWM outputs can each appear on more than one pin, but the
description named a single group that does not exist, so anything using
it refused to start.
Name the real groups instead, one entry per pin, the same way the other
multi-pin PWM output is already described.
Fixes: 2a2a7b9701a7 ("arm64: dts: amlogic: t7: Add PWM pinctrl nodes")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Lucas Tanure <tanure@linux.com>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260829094758.23248-3-tanure@linux.com
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi | 32 ++++++++++++++++++---
1 file changed, 28 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi b/arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi
index cc371fcd18967..66605b200b708 100644
--- a/arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi
+++ b/arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi
@@ -458,9 +458,25 @@ mux {
};
};
- pwm_ao_g_pins: pwm-ao-g {
+ pwm_ao_g_d11_pins: pwm-ao-g-d11 {
mux {
- groups = "pwm_ao_g";
+ groups = "pwm_ao_g_d11";
+ function = "pwm_ao_g";
+ bias-disable;
+ };
+ };
+
+ pwm_ao_g_d7_pins: pwm-ao-g-d7 {
+ mux {
+ groups = "pwm_ao_g_d7";
+ function = "pwm_ao_g";
+ bias-disable;
+ };
+ };
+
+ pwm_ao_g_e_pins: pwm-ao-g-e {
+ mux {
+ groups = "pwm_ao_g_e";
function = "pwm_ao_g";
bias-disable;
};
@@ -474,9 +490,17 @@ mux {
};
};
- pwm_ao_h_pins: pwm-ao-h {
+ pwm_ao_h_d5_pins: pwm-ao-h-d5 {
+ mux {
+ groups = "pwm_ao_h_d5";
+ function = "pwm_ao_h";
+ bias-disable;
+ };
+ };
+
+ pwm_ao_h_d10_pins: pwm-ao-h-d10 {
mux {
- groups = "pwm_ao_h";
+ groups = "pwm_ao_h_d10";
function = "pwm_ao_h";
bias-disable;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 014/438] arm64: dts: amlogic: t7: khadas-vim4: add the PWM-driven supplies
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (12 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 013/438] arm64: dts: amlogic: t7: fix the pin groups of two PWM outputs Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 015/438] arm64: dts: amlogic: t7: fix the pin groups of the vsync PWM Greg Kroah-Hartman
` (435 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lucas Tanure, Neil Armstrong,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lucas Tanure <tanure@linux.com>
[ Upstream commit 1e5a53bd16ac501e68463e84023d1bff543cc696 ]
The board powers its two CPU clusters, the GPU, the NPU, the memory and
the always-on domain from regulators steered by PWM outputs. None of
them were described, so Linux treated those outputs as unused and
switched them off part way through boot. The supplies then drifted away
from the levels the bootloader had set, which showed up as random hangs
and memory corruption.
Describe each supply so it has an owner and is left alone.
The voltage ranges are read off the feedback networks on the board
schematic. VDDNPU is deliberately not the range in Amlogic's own
device tree: this board fits a different feedback resistor, which
puts it about 40mV higher at both ends.
Fixes: 8c45bf9ae4ef ("arm64: dts: amlogic: t7: khadas-vim4: Add power regulators")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Lucas Tanure <tanure@linux.com>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260829094758.23248-4-tanure@linux.com
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../amlogic/amlogic-t7-a311d2-khadas-vim4.dts | 110 +++++++++++++++++-
1 file changed, 109 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts b/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts
index c94afaaf8826e..77abfd555ec5b 100644
--- a/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts
+++ b/arch/arm64/boot/dts/amlogic/amlogic-t7-a311d2-khadas-vim4.dts
@@ -104,6 +104,66 @@ vcc5v0_usb: regulator-vcc-usb {
enable-active-high;
};
+ vdd_ddr: regulator-vddddr {
+ /*
+ * SY8003ADFC Regulator.
+ */
+ compatible = "pwm-regulator";
+ regulator-name = "VDDDDR";
+ regulator-min-microvolt = <690000>;
+ regulator-max-microvolt = <890000>;
+ pwm-supply = <&dc_in>;
+ pwms = <&pwm_ao_gh 0 1500 0>;
+ pwm-dutycycle-range = <100 0>;
+ regulator-boot-on;
+ regulator-always-on;
+ };
+
+ vdd_ee: regulator-vddee {
+ /*
+ * MP8756GD Regulator.
+ */
+ compatible = "pwm-regulator";
+ regulator-name = "VDDEE";
+ regulator-min-microvolt = <700000>;
+ regulator-max-microvolt = <922000>;
+ pwm-supply = <&dc_in>;
+ pwms = <&pwm_ao_ab 0 1500 0>;
+ pwm-dutycycle-range = <100 0>;
+ regulator-boot-on;
+ regulator-always-on;
+ };
+
+ vdd_gpu: regulator-vddgpu {
+ /*
+ * SY8003ADFC Regulator.
+ */
+ compatible = "pwm-regulator";
+ regulator-name = "VDDGPU";
+ regulator-min-microvolt = <700000>;
+ regulator-max-microvolt = <922000>;
+ pwm-supply = <&dc_in>;
+ pwms = <&pwm_ao_ef 0 1500 0>;
+ pwm-dutycycle-range = <100 0>;
+ regulator-boot-on;
+ regulator-always-on;
+ };
+
+ vdd_npu: regulator-vddnpu {
+ /*
+ * SY8003ADFC Regulator.
+ */
+ compatible = "pwm-regulator";
+ regulator-name = "VDDNPU";
+ regulator-min-microvolt = <733000>;
+ regulator-max-microvolt = <933000>;
+ pwm-supply = <&dc_in>;
+ pwms = <&pwm_ao_ef 1 1500 0>;
+ pwm-dutycycle-range = <100 0>;
+ regulator-boot-on;
+ regulator-always-on;
+ };
+
vddao_1v8: regulator-vddao-1v8 {
compatible = "regulator-fixed";
regulator-name = "VDDAO_1V8";
@@ -122,6 +182,36 @@ vddao_3v3: regulator-vddao-3v3 {
regulator-always-on;
};
+ vddcpu_a: regulator-vddcpu-a {
+ /*
+ * MP8756GD Regulator.
+ */
+ compatible = "pwm-regulator";
+ regulator-name = "VDDCPU_A";
+ regulator-min-microvolt = <689000>;
+ regulator-max-microvolt = <1049000>;
+ pwm-supply = <&dc_in>;
+ pwms = <&pwm_ao_cd 1 1500 0>;
+ pwm-dutycycle-range = <100 0>;
+ regulator-boot-on;
+ regulator-always-on;
+ };
+
+ vddcpu_b: regulator-vddcpu-b {
+ /*
+ * MP8756GD Regulator.
+ */
+ compatible = "pwm-regulator";
+ regulator-name = "VDDCPU_B";
+ regulator-min-microvolt = <689000>;
+ regulator-max-microvolt = <1049000>;
+ pwm-supply = <&dc_in>;
+ pwms = <&pwm_ao_ab 1 1500 0>;
+ pwm-dutycycle-range = <100 0>;
+ regulator-boot-on;
+ regulator-always-on;
+ };
+
vddio_1v8: regulator-vddio-1v8 {
compatible = "regulator-fixed";
regulator-name = "VDDIO_1V8";
@@ -172,9 +262,27 @@ &pwm_ab {
pinctrl-names = "default";
};
+&pwm_ao_ab {
+ status = "okay";
+ pinctrl-0 = <&pwm_ao_a_pins>, <&pwm_ao_b_pins>;
+ pinctrl-names = "default";
+};
+
&pwm_ao_cd {
status = "okay";
- pinctrl-0 = <&pwm_ao_c_d_pins>;
+ pinctrl-0 = <&pwm_ao_c_d_pins>, <&pwm_ao_d_pins>;
+ pinctrl-names = "default";
+};
+
+&pwm_ao_ef {
+ status = "okay";
+ pinctrl-0 = <&pwm_ao_e_pins>, <&pwm_ao_f_pins>;
+ pinctrl-names = "default";
+};
+
+&pwm_ao_gh {
+ status = "okay";
+ pinctrl-0 = <&pwm_ao_g_e_pins>;
pinctrl-names = "default";
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 015/438] arm64: dts: amlogic: t7: fix the pin groups of the vsync PWM
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (13 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 014/438] arm64: dts: amlogic: t7: khadas-vim4: add the PWM-driven supplies Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 016/438] ARM: socfpga: select the PL310 erratum 753970 workaround Greg Kroah-Hartman
` (434 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lucas Tanure, Neil Armstrong,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lucas Tanure <tanure@linux.com>
[ Upstream commit 406292fd75f95aa3010fec95b5beb5a8b7e3ba3a ]
The vsync PWM output can appear on either of two pins, but the
description named a single group that does not exist, so anything using
it would refuse to start.
Name the real groups instead, one entry per pin. No board describes this
output yet, so nothing changes today.
Fixes: 2a2a7b9701a7 ("arm64: dts: amlogic: t7: Add PWM pinctrl nodes")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Lucas Tanure <tanure@linux.com>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260829094758.23248-5-tanure@linux.com
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi b/arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi
index 66605b200b708..1711e24cce17b 100644
--- a/arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi
+++ b/arch/arm64/boot/dts/amlogic/amlogic-t7.dtsi
@@ -546,9 +546,17 @@ mux {
};
};
- pwm_vs_pins: pwm-vs {
+ pwm_vs_y_pins: pwm-vs-y {
mux {
- groups = "pwm_vs";
+ groups = "pwm_vs_y";
+ function = "pwm_vs";
+ bias-disable;
+ };
+ };
+
+ pwm_vs_h_pins: pwm-vs-h {
+ mux {
+ groups = "pwm_vs_h";
function = "pwm_vs";
bias-disable;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 016/438] ARM: socfpga: select the PL310 erratum 753970 workaround
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (14 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 015/438] arm64: dts: amlogic: t7: fix the pin groups of the vsync PWM Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 017/438] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept Greg Kroah-Hartman
` (433 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Dinh Nguyen,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit cfc1e9a543e3589ba200795b6e7fd8ef4314efdf ]
ARCH_INTEL_SOCFPGA selects CACHE_L2X0 and several PL310 erratum
workarounds. The 753970 workaround is still conditioned on PL310, but that
Kconfig symbol no longer exists, so this one selection is always disabled.
Select PL310_ERRATA_753970 directly, consistently with the other PL310
workarounds required by the platform.
Fixes: fbc125afdc50 ("ARM: socfpga: Turn on ARM errata for L2 cache")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Dinh Nguyen <dinguyen@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mach-socfpga/Kconfig | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm/mach-socfpga/Kconfig b/arch/arm/mach-socfpga/Kconfig
index eb72c240c2486..528c5c1368c37 100644
--- a/arch/arm/mach-socfpga/Kconfig
+++ b/arch/arm/mach-socfpga/Kconfig
@@ -16,7 +16,7 @@ menuconfig ARCH_INTEL_SOCFPGA
select ARM_ERRATA_775420
select PL310_ERRATA_588369
select PL310_ERRATA_727915
- select PL310_ERRATA_753970 if PL310
+ select PL310_ERRATA_753970
select PL310_ERRATA_769419
select RESET_CONTROLLER
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 017/438] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (15 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 016/438] ARM: socfpga: select the PL310 erratum 753970 workaround Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 018/438] RDMA/rxe: validate access flags before swapping the MRs PD Greg Kroah-Hartman
` (432 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Guoqing Jiang,
Bernard Metzler, Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guoqing Jiang <guoqing.jiang@linux.dev>
[ Upstream commit 32cd87f54dd1070020e664ccb0312a9f0fea79b4 ]
We need to clear cep before release state_lock as siw_qp_llp_close and
siw_qp_modify->siw_qp_llp_close did.
Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock
is released before the error path cleanup. A concurrent ibv_modify_qp()
transitioning the QP to ERROR can race in this window:
siw_accept() ibv_modify_qp(ERROR)
---------------------- ----------------------
siw_qp_modify() fails
up_write(&qp->state_lock)
down_write(&qp->state_lock)
nextstate_from_idle():
if (qp->cep)
siw_cep_put(qp->cep) <- frees cep
qp->cep = NULL
goto error
cep->qp = NULL <- UAF
Clear qp->cep and drop the association reference taken by siw_cep_get(),
all under the write lock held from the initial down_write(&qp->state_lock).
Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free
the cep before siw_accept() is done with it.
Fixes: 6c52fdc244b5 ("rdma/siw: connection management")
Reported-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Link: https://lore.kernel.org/linux-rdma/d6fbe475-a5c2-f975-99b0-a0bd6b6d10e8@linux.dev/T/#m5876c1ff2de8686a9a1173b8f1aa0ff5363a785c
Signed-off-by: Guoqing Jiang <guoqing.jiang@linux.dev>
Link: https://patch.msgid.link/20260827125553.12831-1-guoqing.jiang@linux.dev
Acked-by: Bernard Metzler <bernard.metzler@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_cm.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/sw/siw/siw_cm.c b/drivers/infiniband/sw/siw/siw_cm.c
index 0245b25e72718..ed49818793dde 100644
--- a/drivers/infiniband/sw/siw/siw_cm.c
+++ b/drivers/infiniband/sw/siw/siw_cm.c
@@ -1719,9 +1719,12 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
SIW_QP_ATTR_STATE | SIW_QP_ATTR_LLP_HANDLE |
SIW_QP_ATTR_ORD | SIW_QP_ATTR_IRD |
SIW_QP_ATTR_MPA);
+ if (rv) {
+ qp->cep = NULL;
+ siw_cep_put(cep);
+ goto error_unlock;
+ }
up_write(&qp->state_lock);
- if (rv)
- goto error;
siw_dbg_cep(cep, "[QP %u]: send mpa reply, %d byte pdata\n",
qp_id(qp), params->private_data_len);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 018/438] RDMA/rxe: validate access flags before swapping the MRs PD
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (16 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 017/438] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 019/438] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access Greg Kroah-Hartman
` (431 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Norbert Szetei, Zhu Yanjun,
Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
[ Upstream commit ae36a5b609ae79f4de966328b78d2584be9719a4 ]
rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then
validates the IB_MR_REREG_ACCESS argument:
if (flags & IB_MR_REREG_PD) {
rxe_put(old_pd);
rxe_get(pd);
mr->ibmr.pd = ibpd;
}
if (flags & IB_MR_REREG_ACCESS) {
if (access & ~RXE_ACCESS_SUPPORTED_MR)
return ERR_PTR(-EOPNOTSUPP);
mr->access = access;
}
Both flags pass the entry check because RXE_MR_REREG_SUPPORTED is
IB_MR_REREG_PD | IB_MR_REREG_ACCESS, so a caller can reach the access
check with mr->ibmr.pd already reassigned.
mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the
success path: ib_uverbs_rereg_mr() jumps to put_new_uobj on a driver error
without undoing the reassignment, so mr->pd == new_pd while the usecnts
still charge the MR to orig_pd. ib_dereg_mr_user() then decrements
new_pd, whose count can reach zero while a memory window still references
it; uverbs_free_pd() frees the PD on that count alone and rxe_mw_cleanup()
writes to freed memory:
BUG: KASAN: slab-use-after-free in __rxe_put+0x31/0xa0
Write of size 4 at addr ffff8881301dd690 by task rxe_poc/591
__rxe_put+0x31/0xa0
rxe_mw_cleanup+0x42/0x200
__rxe_cleanup+0x115/0x370
rxe_dealloc_mw+0x4c/0x80
Allocated by task 591:
ib_uverbs_alloc_pd+0x258/0x540
Freed by task 591:
ib_dealloc_pd_user+0x174/0x210
uverbs_free_pd+0x8d/0xc0
ib_uverbs_dealloc_pd+0x18e/0x1d0
Validate the access flags before mutating any state so the callback either
applies every requested change or none.
Fixes: 544c7f62cf32 ("RDMA/rxe: Implement rereg_user_mr")
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Link: https://patch.msgid.link/46E1D5C0-24BE-4D01-BDB3-634FE09B22C5@doyensec.com
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_verbs.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_verbs.c b/drivers/infiniband/sw/rxe/rxe_verbs.c
index 1ec130fee8ea7..f8c29fc5961d7 100644
--- a/drivers/infiniband/sw/rxe/rxe_verbs.c
+++ b/drivers/infiniband/sw/rxe/rxe_verbs.c
@@ -1327,19 +1327,20 @@ static struct ib_mr *rxe_rereg_user_mr(struct ib_mr *ibmr, int flags,
if (err)
return ERR_PTR(err);
+ if ((flags & IB_MR_REREG_ACCESS) &&
+ (access & ~RXE_ACCESS_SUPPORTED_MR)) {
+ rxe_err_mr(mr, "access = %#x not supported\n", access);
+ return ERR_PTR(-EOPNOTSUPP);
+ }
+
if (flags & IB_MR_REREG_PD) {
rxe_put(old_pd);
rxe_get(pd);
mr->ibmr.pd = ibpd;
}
- if (flags & IB_MR_REREG_ACCESS) {
- if (access & ~RXE_ACCESS_SUPPORTED_MR) {
- rxe_err_mr(mr, "access = %#x not supported\n", access);
- return ERR_PTR(-EOPNOTSUPP);
- }
+ if (flags & IB_MR_REREG_ACCESS)
mr->access = access;
- }
return NULL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 019/438] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (17 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 018/438] RDMA/rxe: validate access flags before swapping the MRs PD Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 020/438] xfrm: hold net_device reference under RCU in bundle creation Greg Kroah-Hartman
` (430 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gang Yan, Zhu Yanjun, Shukai Ni,
Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gang Yan <yangang@kylinos.cn>
[ Upstream commit d10e2a08799e858d3e71ea4169bcd018f216d444 ]
mr_check_range() validates that [iova, iova+length) falls within the
registered MR range using wraparound-prone arithmetic:
if (iova < mr->ibmr.iova ||
iova + length > mr->ibmr.iova + mr->ibmr.length)
A remote peer can craft an RDMA-Write/Read RETH so that iova + length
wraps to 0 (e.g. iova=0xfffffffffffffff8, length=8), bypassing the
check. rxe_mr_iova_to_index() then computes a huge index (int idx, only
guarded by WARN_ON) and rxe_mr_copy_xarray() dereferences
mr->page_info[huge], causing an out-of-bounds read/write and a kernel
oops that is triggerable by an unauthenticated remote peer.
Rewrite the check in overflow-safe form; the first two clauses guarantee
that the subsequent subtractions do not underflow:
if (iova < mr->ibmr.iova ||
length > mr->ibmr.length ||
iova - mr->ibmr.iova > mr->ibmr.length - length)
With the fix, mr_check_range() returns -EINVAL for the crafted iova and
the responder reports REMOTE_ACCESS_ERROR instead of triggering the OOB.
Fixes: 8700e3e7c485 ("Soft RoCE driver")
Signed-off-by: Gang Yan <yangang@kylinos.cn>
Link: https://patch.msgid.link/20260814093740.292954-1-gang.yan@linux.dev
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Reviewed-by: Shukai Ni <shukai.ni@kuleuven.be>
Tested-by: Shukai Ni <shukai.ni@kuleuven.be>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_mr.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_mr.c b/drivers/infiniband/sw/rxe/rxe_mr.c
index 875eceb55fdfa..71d9ea4772890 100644
--- a/drivers/infiniband/sw/rxe/rxe_mr.c
+++ b/drivers/infiniband/sw/rxe/rxe_mr.c
@@ -33,7 +33,8 @@ int mr_check_range(struct rxe_mr *mr, u64 iova, size_t length)
case IB_MR_TYPE_USER:
case IB_MR_TYPE_MEM_REG:
if (iova < mr->ibmr.iova ||
- iova + length > mr->ibmr.iova + mr->ibmr.length) {
+ length > mr->ibmr.length ||
+ iova - mr->ibmr.iova > mr->ibmr.length - length) {
rxe_dbg_mr(mr, "iova/length out of range\n");
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 020/438] xfrm: hold net_device reference under RCU in bundle creation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (18 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 019/438] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 021/438] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS Greg Kroah-Hartman
` (429 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Steffen Klassert,
Xiang Mei (Microsoft), AutonomousCodeSecurity,
Cen Zhang (Microsoft Security FORGE Labs), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cen Zhang (Microsoft Security FORGE Labs) <blbllhy@gmail.com>
[ Upstream commit 9fa903b24b1f46b4ff5443bcd4aca23e5c57f9c1 ]
xfrm_bundle_create() and xfrm_create_dummy_bundle() read dst->dev into
a local pointer without taking a device reference, then pass it to
xfrm_fill_dst(). A concurrent RTM_DELLINK replaces dst->dev via
dst_dev_put() and frees the old net_device, causing a use-after-free
when xfrm6_fill_dst() later dereferences the stale dev pointer.
BUG: KASAN: slab-use-after-free in xfrm6_fill_dst+0x82c/0x860
(net/ipv6/xfrm6_policy.c:86 netdev_hold())
Read of size 8 at addr ffff8880142fe588 by task exploit/153
Call Trace:
xfrm6_fill_dst+0x82c/0x860
xfrm_resolve_and_create_bundle+0x21d4/0x2bd0
xfrm_lookup_with_ifid+0x485/0x1640
ip6_dst_lookup_flow+0x19b/0x1e0
udpv6_sendmsg+0x1443/0x2dd0
Fix this by reading dst->dev via dst_dev_rcu() and keeping the RCU
read-side critical section active until xfrm_fill_dst() has taken the
required device references.
Fixes: 25ee3286dcbc ("[IPSEC]: Merge common code into xfrm_bundle_create")
Fixes: a0073fe18e71 ("xfrm: Add a state resolution packet queue")
Suggested-by: Steffen Klassert <steffen.klassert@secunet.com>
Reported-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
Link: https://lore.kernel.org/all/20260820200245.44312-1-blbllhy@gmail.com/
Cc: AutonomousCodeSecurity@microsoft.com
Assisted-by: GitHub-Copilot:claude-opus-4.6
Signed-off-by: Cen Zhang (Microsoft Security FORGE Labs) <blbllhy@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_policy.c | 20 +++++++++++++++-----
1 file changed, 15 insertions(+), 5 deletions(-)
diff --git a/net/xfrm/xfrm_policy.c b/net/xfrm/xfrm_policy.c
index 932a313b9460a..513c9f2283347 100644
--- a/net/xfrm/xfrm_policy.c
+++ b/net/xfrm/xfrm_policy.c
@@ -2770,9 +2770,12 @@ static struct dst_entry *xfrm_bundle_create(struct xfrm_policy *policy,
xdst0->path = dst;
err = -ENODEV;
- dev = dst->dev;
- if (!dev)
+ rcu_read_lock();
+ dev = dst_dev_rcu(dst);
+ if (!dev) {
+ rcu_read_unlock();
goto free_dst;
+ }
xfrm_init_path(xdst0, dst, nfheader_len);
xfrm_init_pmtu(bundle, nx);
@@ -2780,8 +2783,10 @@ static struct dst_entry *xfrm_bundle_create(struct xfrm_policy *policy,
for (xdst_prev = xdst0; xdst_prev != (struct xfrm_dst *)dst;
xdst_prev = (struct xfrm_dst *) xfrm_dst_child(&xdst_prev->u.dst)) {
err = xfrm_fill_dst(xdst_prev, dev, fl);
- if (err)
+ if (err) {
+ rcu_read_unlock();
goto free_dst;
+ }
xdst_prev->u.dst.header_len = header_len;
xdst_prev->u.dst.trailer_len = trailer_len;
@@ -2789,6 +2794,7 @@ static struct dst_entry *xfrm_bundle_create(struct xfrm_policy *policy,
trailer_len -= xdst_prev->u.dst.xfrm->props.trailer_len;
}
+ rcu_read_unlock();
return &xdst0->u.dst;
put_states:
@@ -3058,11 +3064,15 @@ static struct xfrm_dst *xfrm_create_dummy_bundle(struct net *net,
xfrm_init_path((struct xfrm_dst *)dst1, dst, 0);
err = -ENODEV;
- dev = dst->dev;
- if (!dev)
+ rcu_read_lock();
+ dev = dst_dev_rcu(dst);
+ if (!dev) {
+ rcu_read_unlock();
goto free_dst;
+ }
err = xfrm_fill_dst(xdst, dev, fl);
+ rcu_read_unlock();
if (err)
goto free_dst;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 021/438] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (19 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 020/438] xfrm: hold net_device reference under RCU in bundle creation Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 022/438] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate Greg Kroah-Hartman
` (428 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xixin Liu, Sudeep Holla, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xixin Liu <liuxixin@kylinos.cn>
[ Upstream commit 32471d84a487c7fd74532bc96be56f8028cf4a3f ]
scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted
any larger value from the SCP firmware. The shared-memory reply only holds
MAX_DVFS_OPPS entries in buf.opps[]; a bigger count over-reads that array
and then sizes the allocated OPP table incorrectly (garbage OPPs / OOB).
The missing upper bound dates back to the original SCPI DVFS support.
Reject zero and out-of-range counts in one check and return -EINVAL.
Fixes: 8cb7cf56c9fe ("firmware: add support for ARM System Control and Power Interface(SCPI) protocol")
Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
Link: https://patch.msgid.link/022802f0b38f.v2.1785200642.git.liuxixin@kylinos.cn
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scpi.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/firmware/arm_scpi.c b/drivers/firmware/arm_scpi.c
index 2acad5fa5a286..6eeb0ad9b0085 100644
--- a/drivers/firmware/arm_scpi.c
+++ b/drivers/firmware/arm_scpi.c
@@ -631,8 +631,8 @@ static struct scpi_dvfs_info *scpi_dvfs_get_info(u8 domain)
if (ret)
return ERR_PTR(ret);
- if (!buf.opp_count)
- return ERR_PTR(-ENOENT);
+ if (!buf.opp_count || buf.opp_count > MAX_DVFS_OPPS)
+ return ERR_PTR(-EINVAL);
info = kmalloc_obj(*info);
if (!info)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 022/438] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (20 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 021/438] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 023/438] clk: scpi: register scpi-cpufreq once and clear on failure Greg Kroah-Hartman
` (427 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xixin Liu, Sudeep Holla, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xixin Liu <liuxixin@kylinos.cn>
[ Upstream commit 70f4b78d560e592cbf3325b162424737d032fc1d ]
dvfs_get_idx() may return an out-of-range index if the SCP firmware is
buggy or returns a stale value. Only negative indexes were rejected, so a
large index walked past info->opps and could treat garbage as a clock rate
(KASAN OOB / wrong frequency to consumers). The missing upper bound dates
back to the original SCPI clock driver.
Treat indexes >= opp count as invalid and return 0, same as idx < 0.
Fixes: cd52c2a4b5c4 ("clk: add support for clocks provided by SCP(System Control Processor)")
Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
Link: https://patch.msgid.link/04f9ab766e07.v2.1785200642.git.liuxixin@kylinos.cn
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/clk-scpi.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/clk/clk-scpi.c b/drivers/clk/clk-scpi.c
index 24cee7c9fda6c..3c33a9e3c6909 100644
--- a/drivers/clk/clk-scpi.c
+++ b/drivers/clk/clk-scpi.c
@@ -85,7 +85,7 @@ static unsigned long scpi_dvfs_recalc_rate(struct clk_hw *hw,
int idx = clk->scpi_ops->dvfs_get_idx(clk->id);
const struct scpi_opp *opp;
- if (idx < 0)
+ if (idx < 0 || idx >= clk->info->count)
return 0;
opp = clk->info->opps + idx;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 023/438] clk: scpi: register scpi-cpufreq once and clear on failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (21 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 022/438] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 024/438] RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Greg Kroah-Hartman
` (426 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xixin Liu, Sudeep Holla, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xixin Liu <liuxixin@kylinos.cn>
[ Upstream commit ab06cf8152dace327cd873188e4a036c4e0b5944 ]
scpi_clocks_probe() walks clock children and, for each DVFS provider, calls
platform_device_register_simple("scpi-cpufreq", -1, ...). Two related bugs:
Since all DVFS providers register the fixed scpi-cpufreq device using
PLATFORM_DEVID_NONE, a second registration fails with -EEXIST and
overwrites the pointer to the successfully registered device. The first
device can then no longer be unregistered.
Register the virtual device only once. If registration fails, reset the
pointer to NULL so a subsequent DVFS provider can retry and the global
pointer only represents a successfully registered device.
Fixes: 9490f01e2471 ("clk: scpi: add support for cpufreq virtual device")
Fixes: 67bcc2c5f1da ("clk: scpi: don't add cpufreq device if the scpi dvfs node is disabled")
Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
Link: https://patch.msgid.link/fd1b9199a9c3.v2.1785200642.git.liuxixin@kylinos.cn
(sudeep.holla: reworded the commit message to improve readability)
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/clk-scpi.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/clk/clk-scpi.c b/drivers/clk/clk-scpi.c
index 3c33a9e3c6909..e1891351c221a 100644
--- a/drivers/clk/clk-scpi.c
+++ b/drivers/clk/clk-scpi.c
@@ -284,10 +284,14 @@ static int scpi_clocks_probe(struct platform_device *pdev)
if (match->data != &scpi_dvfs_ops)
continue;
/* Add the virtual cpufreq device if it's DVFS clock provider */
+ if (cpufreq_dev)
+ continue;
cpufreq_dev = platform_device_register_simple("scpi-cpufreq",
-1, NULL, 0);
- if (IS_ERR(cpufreq_dev))
+ if (IS_ERR(cpufreq_dev)) {
pr_warn("unable to register cpufreq device");
+ cpufreq_dev = NULL;
+ }
}
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 024/438] RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (22 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 023/438] clk: scpi: register scpi-cpufreq once and clear on failure Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 025/438] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds Greg Kroah-Hartman
` (425 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Zhu Yanjun,
Hongqiang Luo, Xinyu Ma, Zhanbo Ye, Shaomin Chen, Rui Ding,
Miao Zhao, Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit 769001ce838d907ecaa95f1d0a4e8fc86f761f9f ]
Commit 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO
pages") dropped the access permission test from rxe_check_pagefault()
and left only HMM_PFN_VALID. A page faulted in read-only, for example
a page-cache folio behind a PROT_READ file mapping, then satisfies the
check and ODP write operations (RDMA WRITE, RDMA READ response, SEND
payload, atomics) modify it through kmap without ever breaking CoW.
An unprivileged user can register an ODP MR over such a mapping and
have incoming RDMA traffic overwrite the page cache of a file it only
holds O_RDONLY, including /etc/passwd or setuid binaries. This is the
same primitive class as Dirty COW and CVE-2022-2590.
mlx5 has the missing invariant: its ODP path sets the device write bit
only for pfns that carry HMM_PFN_WRITE. Restore it in rxe by requiring
HMM_PFN_WRITE in rxe_check_pagefault() for every operation except
RXE_PAGEFAULT_RDONLY. A write to a non-writable VMA now fails the one
fault attempt with -EPERM from hmm_vma_fault() instead of re-faulting
forever. For a writable VMA the fault breaks CoW and the write lands
in the private page.
Keep pmem flushes on the read-only check. arch_wb_cache_pmem() never
modifies memory, and the FLUSH access bits do not make the umem
writable, so classifying flushes as writes would make every flush
against a flush-only MR fail.
Fixes: 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO pages")
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Link: https://patch.msgid.link/20260726111533.1037819-1-bestswngs@gmail.com
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Tested-by: Hongqiang Luo <wanbafv@gmail.com>
Tested-by: Xinyu Ma <mmmxny@gmail.com>
Tested-by: Zhanbo Ye <cainyzb@gmail.com>
Reported-by: Weiming Shi <bestswngs@gmail.com>
Reported-by: Shaomin Chen <eeesssooo020@gmail.com>
Reported-by: Rui Ding <threonine42@gmail.com>
Reported-by: Miao Zhao <muel@nova.gal>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_odp.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_odp.c b/drivers/infiniband/sw/rxe/rxe_odp.c
index 1b1c4a0c71100..0f24a55c06371 100644
--- a/drivers/infiniband/sw/rxe/rxe_odp.c
+++ b/drivers/infiniband/sw/rxe/rxe_odp.c
@@ -125,19 +125,23 @@ int rxe_odp_mr_init_user(struct rxe_dev *rxe, u64 start, u64 length,
}
static inline bool rxe_check_pagefault(struct ib_umem_odp *umem_odp, u64 iova,
- int length)
+ int length, bool write)
{
bool need_fault = false;
+ u64 access = HMM_PFN_VALID;
u64 addr;
int idx;
+ if (write)
+ access |= HMM_PFN_WRITE;
+
addr = iova & (~(BIT(umem_odp->page_shift) - 1));
/* Skim through all pages that are to be accessed. */
while (addr < iova + length) {
idx = (addr - ib_umem_start(umem_odp)) >> umem_odp->page_shift;
- if (!(umem_odp->map.pfn_list[idx] & HMM_PFN_VALID)) {
+ if ((umem_odp->map.pfn_list[idx] & access) != access) {
need_fault = true;
break;
}
@@ -160,6 +164,7 @@ static unsigned long rxe_odp_iova_to_page_offset(struct ib_umem_odp *umem_odp, u
static int rxe_odp_map_range_and_lock(struct rxe_mr *mr, u64 iova, int length, u32 flags)
{
struct ib_umem_odp *umem_odp = to_ib_umem_odp(mr->umem);
+ bool write = !(flags & RXE_PAGEFAULT_RDONLY);
bool need_fault;
int err;
@@ -168,7 +173,7 @@ static int rxe_odp_map_range_and_lock(struct rxe_mr *mr, u64 iova, int length, u
mutex_lock(&umem_odp->umem_mutex);
- need_fault = rxe_check_pagefault(umem_odp, iova, length);
+ need_fault = rxe_check_pagefault(umem_odp, iova, length, write);
if (need_fault) {
mutex_unlock(&umem_odp->umem_mutex);
@@ -178,7 +183,7 @@ static int rxe_odp_map_range_and_lock(struct rxe_mr *mr, u64 iova, int length, u
if (err < 0)
return err;
- need_fault = rxe_check_pagefault(umem_odp, iova, length);
+ need_fault = rxe_check_pagefault(umem_odp, iova, length, write);
if (need_fault) {
mutex_unlock(&umem_odp->umem_mutex);
return -EFAULT;
@@ -340,8 +345,9 @@ int rxe_odp_flush_pmem_iova(struct rxe_mr *mr, u64 iova,
int err;
u8 *va;
+ /* A flush never modifies memory; read-only access suffices. */
err = rxe_odp_map_range_and_lock(mr, iova, length,
- RXE_PAGEFAULT_DEFAULT);
+ RXE_PAGEFAULT_RDONLY);
if (err)
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 025/438] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (23 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 024/438] RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 026/438] RDMA/mlx5: Remove warn on missing representor in query_port_speed Greg Kroah-Hartman
` (424 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Zhu Yanjun,
Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit 1caceeb2d74bbe88223aea55eb8626b4c5f076fd ]
rxe_get_mcg() publishes a newly allocated multicast group in
rxe->mcg_tree before programming the backing Ethernet multicast address
with rxe_mcast_add(), which runs outside mcg_lock. A local userspace
RDMA client reaches this path with ATTACH_MCAST on a UD QP; if
rxe_mcast_add() then returns an error (for example -ENODEV when the
backing netdev has been removed, or a propagated dev_mc_add() error),
the unwind frees the published group without removing it from the tree.
A later lookup of the same MGID dereferences the freed struct rxe_mcg
from __rxe_lookup_mcg().
Fix this by keeping the new mcg private until rxe_mcast_add() succeeds.
Split the tree publication into __rxe_publish_mcg(), call rxe_mcast_add()
before taking the tree reference, and free the still-private mcg on
failure. Because the group is never visible in mcg_tree until the
multicast address is programmed, no concurrent caller can look it up or
attach a QP to a group that is about to be torn down, so the error path
needs no conditional unwind. If another caller publishes the same MGID
while the address is being programmed, the post-add re-check under
mcg_lock finds the winner; this caller then drops its private object and
balances its own rxe_mcast_add() with rxe_mcast_del() before returning
the winner.
Reproduced by forcing the rxe_mcast_add() error return under KASAN:
without the change the next attach to the same MGID reports a
slab-use-after-free in __rxe_lookup_mcg(); with it the forced failure
returns cleanly. A no-injection attach/detach regression, including a
two-QP shared join/leave and re-attach, stays KASAN- and leak-clean.
Fixes: a926a903b7dc ("RDMA/rxe: Do not call dev_mc_add/del() under a spinlock")
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Link: https://patch.msgid.link/20260617022728.2770116-1-michael.bommarito@gmail.com
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_mcast.c | 50 +++++++++++++++++++--------
1 file changed, 36 insertions(+), 14 deletions(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_mcast.c b/drivers/infiniband/sw/rxe/rxe_mcast.c
index acd03bd87794e..5ca9211ab33bc 100644
--- a/drivers/infiniband/sw/rxe/rxe_mcast.c
+++ b/drivers/infiniband/sw/rxe/rxe_mcast.c
@@ -175,7 +175,9 @@ struct rxe_mcg *rxe_lookup_mcg(struct rxe_dev *rxe, union ib_gid *mgid)
* @mgid: multicast address as a gid
* @mcg: new mcg object
*
- * Context: caller should hold rxe->mcg lock
+ * Initializes the mcg fields. The mcg is private and not yet visible in
+ * mcg_tree, so this may run without rxe->mcg_lock; __rxe_publish_mcg()
+ * makes it visible under the lock once it is ready.
*/
static void __rxe_init_mcg(struct rxe_dev *rxe, union ib_gid *mgid,
struct rxe_mcg *mcg)
@@ -184,13 +186,22 @@ static void __rxe_init_mcg(struct rxe_dev *rxe, union ib_gid *mgid,
memcpy(&mcg->mgid, mgid, sizeof(mcg->mgid));
INIT_LIST_HEAD(&mcg->qp_list);
mcg->rxe = rxe;
+}
- /* caller holds a ref on mcg but that will be
- * dropped when mcg goes out of scope. We need to take a ref
- * on the pointer that will be saved in the red-black tree
- * by __rxe_insert_mcg and used to lookup mcg from mgid later.
- * Inserting mcg makes it visible to outside so this should
- * be done last after the object is ready.
+/**
+ * __rxe_publish_mcg - make a fully initialized mcg visible in mcg_tree
+ * @mcg: the mcg object
+ *
+ * Context: caller must hold rxe->mcg_lock and a reference on mcg
+ */
+static void __rxe_publish_mcg(struct rxe_mcg *mcg)
+{
+ /* caller holds a ref on mcg but that will be dropped when mcg goes
+ * out of scope. We need to take a ref on the pointer that will be
+ * saved in the red-black tree by __rxe_insert_mcg and used to lookup
+ * mcg from mgid later. Inserting mcg makes it visible to outside so
+ * this is done last after the object is ready and the multicast
+ * address has been programmed.
*/
kref_get(&mcg->ref_cnt);
__rxe_insert_mcg(mcg);
@@ -228,26 +239,37 @@ static struct rxe_mcg *rxe_get_mcg(struct rxe_dev *rxe, union ib_gid *mgid)
err = -ENOMEM;
goto err_dec;
}
+ __rxe_init_mcg(rxe, mgid, mcg);
+
+ /* program the multicast address while mcg is still private, before
+ * it is inserted into mcg_tree. dev_mc_add() may sleep so this must
+ * run outside mcg_lock. On failure mcg was never published, so a
+ * plain free is correct and the tree is untouched.
+ */
+ err = rxe_mcast_add(rxe, mgid);
+ if (err) {
+ kfree(mcg);
+ goto err_dec;
+ }
spin_lock_bh(&rxe->mcg_lock);
- /* re-check to see if someone else just added it */
+ /* re-check to see if someone else just added it while we were adding
+ * the multicast address; if so use theirs and drop ours
+ */
tmp = __rxe_lookup_mcg(rxe, mgid);
if (tmp) {
spin_unlock_bh(&rxe->mcg_lock);
+ rxe_mcast_del(rxe, mgid);
atomic_dec(&rxe->mcg_num);
kfree(mcg);
return tmp;
}
- __rxe_init_mcg(rxe, mgid, mcg);
+ __rxe_publish_mcg(mcg);
spin_unlock_bh(&rxe->mcg_lock);
- /* add mcast address outside of lock */
- err = rxe_mcast_add(rxe, mgid);
- if (!err)
- return mcg;
+ return mcg;
- kfree(mcg);
err_dec:
atomic_dec(&rxe->mcg_num);
return ERR_PTR(err);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 026/438] RDMA/mlx5: Remove warn on missing representor in query_port_speed
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (24 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 025/438] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 027/438] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Greg Kroah-Hartman
` (423 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Or Har-Toov, Shay Drory,
Edward Srouji, Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Or Har-Toov <ohartoov@nvidia.com>
[ Upstream commit 2be77295316c2dff0a33c0dc3a65abdab4ccf796 ]
The representor ib_device's phys_port_cnt is set to the total vport
count when the uplink vport rep loads. Individual port[i].rep entries
are populated only as each VF/SF vport rep registers. A NULL .rep for
a given port index is therefore expected while VF reps are still
loading or haven't been enabled yet.
Tools like ibstat and ibv_devinfo iterate over all ports of all RDMA
devices. Some ports may not have an eswitch representor, causing
repeated dmesg warnings when these tools run without a device argument.
This causes dmesg to be flooded with this message on every ibstat
invocation.
Remove the warning and return -ENODEV when no representor exists for
the queried port.
Fixes: aaecff5e13cd ("RDMA/mlx5: Implement query_port_speed callback")
Signed-off-by: Or Har-Toov <ohartoov@nvidia.com>
Reviewed-by: Shay Drory <shayd@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260811-remove-warn-on-miss-rep-v1-1-eccf399bc6af@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/mlx5/main.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/hw/mlx5/main.c b/drivers/infiniband/hw/mlx5/main.c
index c283a902ea7e4..05985395fca00 100644
--- a/drivers/infiniband/hw/mlx5/main.c
+++ b/drivers/infiniband/hw/mlx5/main.c
@@ -1684,11 +1684,8 @@ static int mlx5_ib_query_port_speed_rep(struct mlx5_ib_dev *dev, u32 port_num,
struct mlx5_core_dev *mdev;
u16 op_mod;
- if (!dev->port[port_num - 1].rep) {
- mlx5_ib_warn(dev, "Representor doesn't exist for port %u\n",
- port_num);
- return -EINVAL;
- }
+ if (!dev->port[port_num - 1].rep)
+ return -ENODEV;
rep = dev->port[port_num - 1].rep;
mdev = mlx5_eswitch_get_core_dev(rep->esw);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 027/438] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (25 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 026/438] RDMA/mlx5: Remove warn on missing representor in query_port_speed Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 028/438] RDMA/uverbs: Fix mmap_lock/disassociation_lock circular dependency Greg Kroah-Hartman
` (422 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+5fe14f2ff4ccbace9a26,
Krystian Kaniewski, Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Krystian Kaniewski <krystianmkaniewski@gmail.com>
[ Upstream commit ef9fbe1b93f3b617b96e86d5cd76b3fa44514cb5 ]
ib_device_get_netdev() intentionally returns a referenced net_device even
when it is unregistering, so matching and cleanup callers can still find
the association. The reference keeps struct net_device allocated, but does
not guarantee that the device remains operational.
ib_get_eth_speed() uses the returned device operationally by invoking its
ethtool callback. Although that call is made under RTNL, the function does
not verify the registration state first. An asynchronous RDMA port query
can therefore call into a netdev after NETDEV_UNREGISTER and ndo_uninit
have completed.
Check for NETREG_REGISTERED while holding RTNL and return -ENODEV for a
device which is being unregistered. Keeping RTNL across the check and the
ethtool operation prevents unregister from starting between them.
Keep the speed fallback and warning under RTNL as well, so the warning can
safely read netdev->name. Drop the netdev reference before releasing RTNL
once all accesses to the device are complete.
Fixes: d41861942fc5 ("IB/core: Add generic function to extract IB speed from netdev")
Reported-by: syzbot+5fe14f2ff4ccbace9a26@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=5fe14f2ff4ccbace9a26
Signed-off-by: Krystian Kaniewski <krystianmkaniewski@gmail.com>
Link: https://patch.msgid.link/20260812081708.32468-1-krystianmkaniewski@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/verbs.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c
index f8b219bd308bd..5447d39fa89dd 100644
--- a/drivers/infiniband/core/verbs.c
+++ b/drivers/infiniband/core/verbs.c
@@ -2056,11 +2056,13 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_num, u16 *speed, u8 *width)
return -ENODEV;
rtnl_lock();
- rc = __ethtool_get_link_ksettings(netdev, &lksettings);
- rtnl_unlock();
-
- dev_put(netdev);
+ if (READ_ONCE(netdev->reg_state) != NETREG_REGISTERED) {
+ dev_put(netdev);
+ rtnl_unlock();
+ return -ENODEV;
+ }
+ rc = __ethtool_get_link_ksettings(netdev, &lksettings);
if (!rc && lksettings.base.speed != (u32)SPEED_UNKNOWN) {
netdev_speed = lksettings.base.speed;
} else {
@@ -2069,6 +2071,8 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_num, u16 *speed, u8 *width)
pr_warn("%s speed is unknown, defaulting to %u\n",
netdev->name, netdev_speed);
}
+ dev_put(netdev);
+ rtnl_unlock();
ib_get_width_and_speed(netdev_speed, lksettings.lanes,
speed, width);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 028/438] RDMA/uverbs: Fix mmap_lock/disassociation_lock circular dependency
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (26 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 027/438] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 029/438] power: sequencing: Fix build issue with COMPILE_TEST Greg Kroah-Hartman
` (421 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Or Har-Toov, Leon Romanovsky,
Edward Srouji, Junxian Huang, Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Or Har-Toov <ohartoov@nvidia.com>
[ Upstream commit a44a3f175eaee7e5aeb6a8fed381c4a0d5f49236 ]
Commit 51976c6cd786 ("RDMA/core: Provide rdma_user_mmap_disassociate()
to disassociate mmap pages") introduced disassociation_lock to protect
new mmap registrations against uverbs_user_mmap_disassociate(), but
created an ABBA deadlock:
Thread A (mmap / fork):
mmap_lock -> disassociation_lock
Thread B (disassociate):
disassociation_lock -> mmap_lock
Fix by removing disassociation_lock entirely and using the pre-existing
hw_destroy_rwsem instead. hw_destroy_rwsem already provides the same
protection: rdma_umap_open() and ib_uverbs_mmap() both use
down_read_trylock() before registering a new VMA, so holding hw_destroy_rwsem
in uverbs_user_mmap_disassociate() is sufficient to block new registrations.
trylock is used in both mmap paths (not blocking down_read) because
mmap_lock is already held on entry, and uverbs_user_mmap_disassociate()
acquires mmap_lock internally — a blocking read would recreate the same
deadlock.
The only caller that was not taking hw_destroy_rwsem for write was
rdma_user_mmap_disassociate(). Fix it to take the rwsem per-ufile while
iterating under lists_mutex. This is safe because ib_uverbs_close()
releases hw_destroy_rwsem entirely before acquiring lists_mutex, so the
two locks are never held simultaneously.
lockdep warning:
[ 776.654252] ======================================================
[ 776.655214] WARNING: possible circular locking dependency detected
[ 776.656167] 6.18.0for-upstream_debug_94e244d9ccab #1 Not tainted
[ 776.657114] ------------------------------------------------------
[ 776.658087] devlink/14824 is trying to acquire lock:
[ 776.658879] ffff88811170c800 (&mm->mmap_lock){++++}-{4:4}, at: uverbs_user_mmap_disassociate+0x168/0x780 [ib_uverbs]
[ 776.660479]
[ 776.660479] but task is already holding lock:
[ 776.661460] ffff888142d92b08 (&file->disassociation_lock){+.+.}-{4:4}, at: uverbs_user_mmap_disassociate+0x39/0x780 [ib_uverbs]
[ 776.663177]
[ 776.663177] which lock already depends on the new lock.
[ 776.663177]
[ 776.664525]
[ 776.664525] the existing dependency chain (in reverse order) is:
[ 776.665724]
[ 776.665724] -> #2 (&file->disassociation_lock){+.+.}-{4:4}:
[ 776.666887] __mutex_lock+0x16d/0x2330
[ 776.667633] rdma_umap_open+0x129/0x280 [ib_uverbs]
[ 776.668489] dup_mmap+0xa40/0x1790
[ 776.669170] copy_process+0x5dd2/0x6170
[ 776.669933] kernel_clone+0xb6/0x610
[ 776.670636] __do_sys_clone+0xb5/0xf0
[ 776.671354] do_syscall_64+0x70/0x12e0
[ 776.672083] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 776.672940]
[ 776.672940] -> #1 (&mm->mmap_lock/1){+.+.}-{4:4}:
[ 776.673985] down_write_nested+0x90/0x1e0
[ 776.674751] dup_mmap+0x201/0x1790
[ 776.675448] copy_process+0x5dd2/0x6170
[ 776.676180] kernel_clone+0xb6/0x610
[ 776.676904] __do_sys_clone+0xb5/0xf0
[ 776.677615] do_syscall_64+0x70/0x12e0
[ 776.678351] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 776.679239]
[ 776.679239] -> #0 (&mm->mmap_lock){++++}-{4:4}:
[ 776.680253] __lock_acquire+0x18c6/0x2ec0
[ 776.681018] lock_acquire+0x10e/0x2e0
[ 776.681742] down_read+0x95/0x430
[ 776.682395] uverbs_user_mmap_disassociate+0x168/0x780 [ib_uverbs]
[ 776.683436] uverbs_destroy_ufile_hw+0x1ae/0x270 [ib_uverbs]
[ 776.684416] ib_uverbs_remove_one+0x22b/0x420 [ib_uverbs]
[ 776.685371] remove_client_context+0xa6/0xf0 [ib_core]
[ 776.686342] disable_device+0x12b/0x240 [ib_core]
[ 776.687249] __ib_unregister_device+0x269/0x460 [ib_core]
[ 776.688233] ib_unregister_device+0x21/0x30 [ib_core]
[ 776.689140] mlx5r_remove+0xd0/0x170 [mlx5_ib]
[ 776.689999] device_release_driver_internal+0x3b2/0x560
[ 776.694876] bus_remove_device+0x1f5/0x3e0
[ 776.695638] device_del+0x3b9/0x990
[ 776.696329] mlx5_detach_device+0x17e/0x350 [mlx5_core]
[ 776.697429] mlx5_unload_one_devl_locked+0x3f/0xb0 [mlx5_core]
[ 776.698578] mlx5_devlink_reload_down+0x1f9/0x550 [mlx5_core]
[ 776.699712] devlink_reload+0x13e/0x680
[ 776.700456] devlink_nl_reload_doit+0xc29/0x1160
[ 776.701293] genl_family_rcv_msg_doit+0x1c9/0x2a0
[ 776.702135] genl_rcv_msg+0x3f0/0x6b0
[ 776.702854] netlink_rcv_skb+0x11d/0x370
[ 776.703605] genl_rcv+0x24/0x40
[ 776.704236] netlink_unicast+0x5b4/0x970
[ 776.704984] netlink_sendmsg+0x730/0xbf0
[ 776.705748] __sock_sendmsg+0xc5/0x190
[ 776.706461] __sys_sendto+0x201/0x2f0
[ 776.707188] __x64_sys_sendto+0xdc/0x1b0
[ 776.707931] do_syscall_64+0x70/0x12e0
[ 776.708643] entry_SYSCALL_64_after_hwframe+0x4b/0x53
[ 776.709546]
[ 776.709546] other info that might help us debug this:
[ 776.709546]
[ 776.710910] Chain exists of:
[ 776.710910] &mm->mmap_lock --> &mm->mmap_lock/1 --> &file->disassociation_lock
[ 776.710910]
[ 776.712805] Possible unsafe locking scenario:
[ 776.712805]
[ 776.713828] CPU0 CPU1
[ 776.714589] ---- ----
[ 776.715347] lock(&file->disassociation_lock);
[ 776.716097] lock(&mm->mmap_lock/1);
[ 776.717067] lock(&file->disassociation_lock);
[ 776.718199] rlock(&mm->mmap_lock);
[ 776.718857]
[ 776.718857] *** DEADLOCK ***
Fixes: 51976c6cd786 ("RDMA/core: Provide rdma_user_mmap_disassociate() to disassociate mmap pages")
Signed-off-by: Or Har-Toov <ohartoov@nvidia.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260811-fix-mmap-lockdep-v1-1-1151b41063b4@nvidia.com
Acked-by: Junxian Huang <huangjunxian6@hisilicon.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/rdma_core.c | 1 -
drivers/infiniband/core/uverbs_main.c | 25 +++++++++++--------------
include/rdma/uverbs_types.h | 2 --
3 files changed, 11 insertions(+), 17 deletions(-)
diff --git a/drivers/infiniband/core/rdma_core.c b/drivers/infiniband/core/rdma_core.c
index fd5651c003aed..a7cbe643e33c6 100644
--- a/drivers/infiniband/core/rdma_core.c
+++ b/drivers/infiniband/core/rdma_core.c
@@ -69,7 +69,6 @@ void ib_uverbs_release_file(struct kref *ref)
if (file->disassociate_page)
__free_pages(file->disassociate_page, 0);
- mutex_destroy(&file->disassociation_lock);
mutex_destroy(&file->umap_lock);
mutex_destroy(&file->ucontext_lock);
kfree(file);
diff --git a/drivers/infiniband/core/uverbs_main.c b/drivers/infiniband/core/uverbs_main.c
index 0d88b2ee68ffa..2a046c888dfab 100644
--- a/drivers/infiniband/core/uverbs_main.c
+++ b/drivers/infiniband/core/uverbs_main.c
@@ -644,12 +644,15 @@ static int ib_uverbs_mmap(struct file *filp, struct vm_area_struct *vma)
goto out;
}
- mutex_lock(&file->disassociation_lock);
+ if (!down_read_trylock(&file->hw_destroy_rwsem)) {
+ ret = -EIO;
+ goto out;
+ }
vma->vm_ops = &rdma_umap_ops;
ret = ucontext->device->ops.mmap(ucontext, vma);
- mutex_unlock(&file->disassociation_lock);
+ up_read(&file->hw_destroy_rwsem);
out:
srcu_read_unlock(&file->device->disassociate_srcu, srcu_key);
return ret;
@@ -671,7 +674,6 @@ static void rdma_umap_open(struct vm_area_struct *vma)
/* We are racing with disassociation */
if (!down_read_trylock(&ufile->hw_destroy_rwsem))
goto out_zap;
- mutex_lock(&ufile->disassociation_lock);
/*
* Disassociation already completed, the VMA should already be zapped.
@@ -684,12 +686,10 @@ static void rdma_umap_open(struct vm_area_struct *vma)
goto out_unlock;
rdma_umap_priv_init(priv, vma, opriv->entry);
- mutex_unlock(&ufile->disassociation_lock);
up_read(&ufile->hw_destroy_rwsem);
return;
out_unlock:
- mutex_unlock(&ufile->disassociation_lock);
up_read(&ufile->hw_destroy_rwsem);
out_zap:
/*
@@ -773,7 +773,7 @@ void uverbs_user_mmap_disassociate(struct ib_uverbs_file *ufile)
{
struct rdma_umap_priv *priv, *next_priv;
- mutex_lock(&ufile->disassociation_lock);
+ lockdep_assert_held_write(&ufile->hw_destroy_rwsem);
while (1) {
struct mm_struct *mm = NULL;
@@ -799,10 +799,8 @@ void uverbs_user_mmap_disassociate(struct ib_uverbs_file *ufile)
break;
}
mutex_unlock(&ufile->umap_lock);
- if (!mm) {
- mutex_unlock(&ufile->disassociation_lock);
+ if (!mm)
return;
- }
/*
* The umap_lock is nested under mmap_lock since it used within
@@ -832,8 +830,6 @@ void uverbs_user_mmap_disassociate(struct ib_uverbs_file *ufile)
mmap_read_unlock(mm);
mmput(mm);
}
-
- mutex_unlock(&ufile->disassociation_lock);
}
/**
@@ -851,8 +847,11 @@ void rdma_user_mmap_disassociate(struct ib_device *device)
mutex_lock(&uverbs_dev->lists_mutex);
list_for_each_entry(ufile, &uverbs_dev->uverbs_file_list, list) {
- if (ufile->ucontext)
+ if (ufile->ucontext) {
+ down_write(&ufile->hw_destroy_rwsem);
uverbs_user_mmap_disassociate(ufile);
+ up_write(&ufile->hw_destroy_rwsem);
+ }
}
mutex_unlock(&uverbs_dev->lists_mutex);
}
@@ -927,8 +926,6 @@ static int ib_uverbs_open(struct inode *inode, struct file *filp)
mutex_init(&file->umap_lock);
INIT_LIST_HEAD(&file->umaps);
- mutex_init(&file->disassociation_lock);
-
filp->private_data = file;
list_add_tail(&file->list, &dev->uverbs_file_list);
mutex_unlock(&dev->lists_mutex);
diff --git a/include/rdma/uverbs_types.h b/include/rdma/uverbs_types.h
index 5a07f9a6dcd1f..6f3622892c0cc 100644
--- a/include/rdma/uverbs_types.h
+++ b/include/rdma/uverbs_types.h
@@ -180,8 +180,6 @@ struct ib_uverbs_file {
struct page *disassociate_page;
struct xarray idr;
-
- struct mutex disassociation_lock;
};
extern const struct uverbs_obj_type_class uverbs_idr_class;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 029/438] power: sequencing: Fix build issue with COMPILE_TEST
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (27 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 028/438] RDMA/uverbs: Fix mmap_lock/disassociation_lock circular dependency Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 030/438] arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR Greg Kroah-Hartman
` (420 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Biju Das, Bartosz Golaszewski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Biju Das <biju.das.jz@bp.renesas.com>
[ Upstream commit 3b54dbd119805361695cb50ca6a875f4c7518b74 ]
The POWER_SEQUENCING_TH1520_GPU driver depends on
(ARCH_THEAD && AUXILIARY_BUS) || COMPILE_TEST. This means when
COMPILE_TEST=y and ARCH_THEAD is not set, the driver can still be
built even though it requires AUXILIARY_BUS, which may not be
selected in that configuration, leading to a build failure.
Fix this by dropping AUXILIARY_BUS from the dependency and instead
selecting it directly, so the dependency is satisfied regardless of
whether COMPILE_TEST or ARCH_THEAD is enabled.
Fixes: 1a7312b93ab0 ("power: sequencing: extend build coverage with COMPILE_TEST=y")
Signed-off-by: Biju Das <biju.das.jz@bp.renesas.com>
Link: https://patch.msgid.link/20260826122742.153643-3-biju.das.jz@bp.renesas.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/power/sequencing/Kconfig | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/power/sequencing/Kconfig b/drivers/power/sequencing/Kconfig
index 1c5f5820f5b76..226c62704d9bb 100644
--- a/drivers/power/sequencing/Kconfig
+++ b/drivers/power/sequencing/Kconfig
@@ -29,7 +29,8 @@ config POWER_SEQUENCING_QCOM_WCN
config POWER_SEQUENCING_TH1520_GPU
tristate "T-HEAD TH1520 GPU power sequencing driver"
- depends on (ARCH_THEAD && AUXILIARY_BUS) || COMPILE_TEST
+ depends on ARCH_THEAD || COMPILE_TEST
+ select AUXILIARY_BUS
help
Say Y here to enable the power sequencing driver for the TH1520 SoC
GPU. This driver handles the complex clock and reset sequence
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 030/438] arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (28 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 029/438] power: sequencing: Fix build issue with COMPILE_TEST Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 031/438] arm64: dts: renesas: r9a09g056: " Greg Kroah-Hartman
` (419 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ovidiu Panait, Geert Uytterhoeven,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
[ Upstream commit 33da68f61d25ef8411489d06514ff627c1f88152 ]
The GBETH ethernet nodes don't specify a TX scheduling policy, so stmmac
falls back to Strict Priority. In this configuration the queue with the
highest priority gets all the traffic, starving the others under load.
Under sustained UDP TX load with multiple data streams, this starvation
triggers spurious adapter resets due to TX queue timeouts:
iperf3 -c <ip> -i0 -t60 --bind-dev end0 -u -b0 -P4
end0: NETDEV WATCHDOG: CPU: 1: transmit queue 1 timed out 5228 ms
end0: Reset adapter.
Investigation shows that only the highest priority queue is advancing
while the others stall for more than 5 seconds, causing a netdev watchdog
reset.
Switch the TX scheduling policy to Weighted-Round-Robin (WRR) so that
traffic is processed across all queues, eliminating the stalls.
Fixes: 050ee38d0002 ("arm64: dts: renesas: r9a09g057: Add GBETH nodes")
Signed-off-by: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260722085353.136986-2-ovidiu.panait.rb@renesas.com
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/renesas/r9a09g057.dtsi | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/arch/arm64/boot/dts/renesas/r9a09g057.dtsi b/arch/arm64/boot/dts/renesas/r9a09g057.dtsi
index 1e94366bb7eee..99d197f309d00 100644
--- a/arch/arm64/boot/dts/renesas/r9a09g057.dtsi
+++ b/arch/arm64/boot/dts/renesas/r9a09g057.dtsi
@@ -1559,23 +1559,28 @@ queue3 {
mtl_tx_setup0: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
@@ -1660,23 +1665,28 @@ queue3 {
mtl_tx_setup1: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 031/438] arm64: dts: renesas: r9a09g056: Switch GBETH TX queue scheduling to WRR
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (29 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 030/438] arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 032/438] arm64: dts: renesas: r9a09g047: " Greg Kroah-Hartman
` (418 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ovidiu Panait, Geert Uytterhoeven,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
[ Upstream commit 66fcbdbeca0118b8aeac218b33fa18c394513543 ]
The GBETH ethernet nodes don't specify a TX scheduling policy, so stmmac
falls back to Strict Priority. In this configuration the queue with the
highest priority gets all the traffic, starving the others under load.
Under sustained UDP TX load with multiple data streams, this starvation
triggers spurious adapter resets due to TX queue timeouts:
iperf3 -c <ip> -i0 -t60 --bind-dev end0 -u -b0 -P4
end0: NETDEV WATCHDOG: CPU: 1: transmit queue 1 timed out 5228 ms
end0: Reset adapter.
Investigation shows that only the highest priority queue is advancing
while the others stall for more than 5 seconds, causing a netdev watchdog
reset.
Switch the TX scheduling policy to Weighted-Round-Robin (WRR) so that
traffic is processed across all queues, eliminating the stalls.
Fixes: c8c8a57c5b40 ("arm64: dts: renesas: r9a09g056: Add GBETH nodes")
Signed-off-by: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260722085353.136986-3-ovidiu.panait.rb@renesas.com
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/renesas/r9a09g056.dtsi | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/arch/arm64/boot/dts/renesas/r9a09g056.dtsi b/arch/arm64/boot/dts/renesas/r9a09g056.dtsi
index 5a3a6f72029a2..6e1444b80a28f 100644
--- a/arch/arm64/boot/dts/renesas/r9a09g056.dtsi
+++ b/arch/arm64/boot/dts/renesas/r9a09g056.dtsi
@@ -1569,23 +1569,28 @@ queue3 {
mtl_tx_setup0: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
@@ -1670,23 +1675,28 @@ queue3 {
mtl_tx_setup1: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 032/438] arm64: dts: renesas: r9a09g047: Switch GBETH TX queue scheduling to WRR
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (30 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 031/438] arm64: dts: renesas: r9a09g056: " Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 033/438] arm64: dts: renesas: r9a09g077: " Greg Kroah-Hartman
` (417 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ovidiu Panait, Geert Uytterhoeven,
Tommaso Merciai, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
[ Upstream commit 63016c3a91f2c458ca75869c8c782e899591f22d ]
The GBETH ethernet nodes don't specify a TX scheduling policy, so stmmac
falls back to Strict Priority. In this configuration the queue with the
highest priority gets all the traffic, starving the others under load.
Under sustained UDP TX load with multiple data streams, this starvation
triggers spurious adapter resets due to TX queue timeouts:
iperf3 -c <ip> -i0 -t60 --bind-dev end0 -u -b0 -P4
end0: NETDEV WATCHDOG: CPU: 1: transmit queue 1 timed out 5228 ms
end0: Reset adapter.
Investigation shows that only the highest priority queue is advancing
while the others stall for more than 5 seconds, causing a netdev watchdog
reset.
Switch the TX scheduling policy to Weighted-Round-Robin (WRR) so that
traffic is processed across all queues, eliminating the stalls.
Fixes: 41ffbb1c42d3 ("arm64: dts: renesas: r9a09g047: Add GBETH nodes")
Signed-off-by: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Tested-by: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
Link: https://patch.msgid.link/20260722085353.136986-4-ovidiu.panait.rb@renesas.com
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/renesas/r9a09g047.dtsi | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/arch/arm64/boot/dts/renesas/r9a09g047.dtsi b/arch/arm64/boot/dts/renesas/r9a09g047.dtsi
index b6193c1583706..4de93fceb605a 100644
--- a/arch/arm64/boot/dts/renesas/r9a09g047.dtsi
+++ b/arch/arm64/boot/dts/renesas/r9a09g047.dtsi
@@ -1394,23 +1394,28 @@ queue3 {
mtl_tx_setup0: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
@@ -1494,23 +1499,28 @@ queue3 {
mtl_tx_setup1: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 033/438] arm64: dts: renesas: r9a09g077: Switch GBETH TX queue scheduling to WRR
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (31 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 032/438] arm64: dts: renesas: r9a09g047: " Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 034/438] arm64: dts: renesas: r9a09g087: " Greg Kroah-Hartman
` (416 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ovidiu Panait, Geert Uytterhoeven,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
[ Upstream commit f9d9a1913c09366bf7b967d39575e06cb80128dc ]
The GBETH ethernet nodes don't specify a TX scheduling policy, so stmmac
falls back to Strict Priority. In this configuration the queue with the
highest priority gets all the traffic, starving the others under load.
Under sustained UDP TX load with multiple data streams, this starvation
triggers spurious adapter resets due to TX queue timeouts:
iperf3 -c <ip> -i0 -t60 --bind-dev end0 -u -b0 -P4
end0: NETDEV WATCHDOG: CPU: 1: transmit queue 1 timed out 5228 ms
end0: Reset adapter.
Investigation shows that only the highest priority queue is advancing
while the others stall for more than 5 seconds, causing a netdev watchdog
reset.
Switch the TX scheduling policy to Weighted-Round-Robin (WRR) so that
traffic is processed across all queues, eliminating the stalls.
Fixes: 394c1e24a4cf ("arm64: dts: renesas: r9a09g077: Add GMAC nodes")
Signed-off-by: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260722085353.136986-5-ovidiu.panait.rb@renesas.com
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/renesas/r9a09g077.dtsi | 27 ++++++++++++++++++++++
1 file changed, 27 insertions(+)
diff --git a/arch/arm64/boot/dts/renesas/r9a09g077.dtsi b/arch/arm64/boot/dts/renesas/r9a09g077.dtsi
index 40494159831d8..bac39390ead74 100644
--- a/arch/arm64/boot/dts/renesas/r9a09g077.dtsi
+++ b/arch/arm64/boot/dts/renesas/r9a09g077.dtsi
@@ -642,36 +642,45 @@ queue7 {
mtl_tx_setup0: tx-queues-config {
snps,tx-queues-to-use = <8>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
};
queue1 {
+ snps,weight = <0x11>;
snps,dcb-algorithm;
};
queue2 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
};
queue3 {
+ snps,weight = <0x13>;
snps,dcb-algorithm;
};
queue4 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
};
queue5 {
+ snps,weight = <0x15>;
snps,dcb-algorithm;
};
queue6 {
+ snps,weight = <0x16>;
snps,dcb-algorithm;
};
queue7 {
+ snps,weight = <0x17>;
snps,dcb-algorithm;
};
};
@@ -788,36 +797,45 @@ queue7 {
mtl_tx_setup1: tx-queues-config {
snps,tx-queues-to-use = <8>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
};
queue1 {
+ snps,weight = <0x11>;
snps,dcb-algorithm;
};
queue2 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
};
queue3 {
+ snps,weight = <0x13>;
snps,dcb-algorithm;
};
queue4 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
};
queue5 {
+ snps,weight = <0x15>;
snps,dcb-algorithm;
};
queue6 {
+ snps,weight = <0x16>;
snps,dcb-algorithm;
};
queue7 {
+ snps,weight = <0x17>;
snps,dcb-algorithm;
};
};
@@ -934,36 +952,45 @@ queue7 {
mtl_tx_setup2: tx-queues-config {
snps,tx-queues-to-use = <8>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
};
queue1 {
+ snps,weight = <0x11>;
snps,dcb-algorithm;
};
queue2 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
};
queue3 {
+ snps,weight = <0x13>;
snps,dcb-algorithm;
};
queue4 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
};
queue5 {
+ snps,weight = <0x15>;
snps,dcb-algorithm;
};
queue6 {
+ snps,weight = <0x16>;
snps,dcb-algorithm;
};
queue7 {
+ snps,weight = <0x17>;
snps,dcb-algorithm;
};
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 034/438] arm64: dts: renesas: r9a09g087: Switch GBETH TX queue scheduling to WRR
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (32 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 033/438] arm64: dts: renesas: r9a09g077: " Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 035/438] IB/iser: reject a remote invalidation of an unregistered direction Greg Kroah-Hartman
` (415 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ovidiu Panait, Geert Uytterhoeven,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
[ Upstream commit 2ac7bad110be6ebe478d6bd57821f7f5259a1f54 ]
The GBETH ethernet nodes don't specify a TX scheduling policy, so stmmac
falls back to Strict Priority. In this configuration the queue with the
highest priority gets all the traffic, starving the others under load.
Under sustained UDP TX load with multiple data streams, this starvation
triggers spurious adapter resets due to TX queue timeouts:
iperf3 -c <ip> -i0 -t60 --bind-dev end0 -u -b0 -P4
end0: NETDEV WATCHDOG: CPU: 1: transmit queue 1 timed out 5228 ms
end0: Reset adapter.
Investigation shows that only the highest priority queue is advancing
while the others stall for more than 5 seconds, causing a netdev watchdog
reset.
Switch the TX scheduling policy to Weighted-Round-Robin (WRR) so that
traffic is processed across all queues, eliminating the stalls.
Fixes: c4698a34993b ("arm64: dts: renesas: r9a09g087: Add GMAC nodes")
Signed-off-by: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260722085353.136986-6-ovidiu.panait.rb@renesas.com
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/renesas/r9a09g087.dtsi | 27 ++++++++++++++++++++++
1 file changed, 27 insertions(+)
diff --git a/arch/arm64/boot/dts/renesas/r9a09g087.dtsi b/arch/arm64/boot/dts/renesas/r9a09g087.dtsi
index e8d4f76949ccb..03b976d93e105 100644
--- a/arch/arm64/boot/dts/renesas/r9a09g087.dtsi
+++ b/arch/arm64/boot/dts/renesas/r9a09g087.dtsi
@@ -643,36 +643,45 @@ queue7 {
mtl_tx_setup0: tx-queues-config {
snps,tx-queues-to-use = <8>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
};
queue1 {
+ snps,weight = <0x11>;
snps,dcb-algorithm;
};
queue2 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
};
queue3 {
+ snps,weight = <0x13>;
snps,dcb-algorithm;
};
queue4 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
};
queue5 {
+ snps,weight = <0x15>;
snps,dcb-algorithm;
};
queue6 {
+ snps,weight = <0x16>;
snps,dcb-algorithm;
};
queue7 {
+ snps,weight = <0x17>;
snps,dcb-algorithm;
};
};
@@ -790,36 +799,45 @@ queue7 {
mtl_tx_setup1: tx-queues-config {
snps,tx-queues-to-use = <8>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
};
queue1 {
+ snps,weight = <0x11>;
snps,dcb-algorithm;
};
queue2 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
};
queue3 {
+ snps,weight = <0x13>;
snps,dcb-algorithm;
};
queue4 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
};
queue5 {
+ snps,weight = <0x15>;
snps,dcb-algorithm;
};
queue6 {
+ snps,weight = <0x16>;
snps,dcb-algorithm;
};
queue7 {
+ snps,weight = <0x17>;
snps,dcb-algorithm;
};
};
@@ -937,36 +955,45 @@ queue7 {
mtl_tx_setup2: tx-queues-config {
snps,tx-queues-to-use = <8>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
};
queue1 {
+ snps,weight = <0x11>;
snps,dcb-algorithm;
};
queue2 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
};
queue3 {
+ snps,weight = <0x13>;
snps,dcb-algorithm;
};
queue4 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
};
queue5 {
+ snps,weight = <0x15>;
snps,dcb-algorithm;
};
queue6 {
+ snps,weight = <0x16>;
snps,dcb-algorithm;
};
queue7 {
+ snps,weight = <0x17>;
snps,dcb-algorithm;
};
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 035/438] IB/iser: reject a remote invalidation of an unregistered direction
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (33 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 034/438] arm64: dts: renesas: r9a09g087: " Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 036/438] IB/isert: wait for deferred control PDU completions before releasing the connection Greg Kroah-Hartman
` (414 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Max Gurtovoy,
Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit d85f0f0a7c85756fc992c70d869706f19dac9259 ]
A write command whose data is sent entirely as immediate data is not
registered. iser_reg_mem_fastreg() takes the DMA key path and leaves
rdma_reg[ISER_DIR_OUT].desc at NULL, while iser_dma_map_task_data() has
already set dir[ISER_DIR_OUT].
iser_check_remote_inv() looks at dir[] alone and hands the descriptor to
iser_inv_desc(), which reads desc->sig_protected. A target that answers
such a command with IB_WR_SEND_WITH_INV faults the initiator.
Leaving those commands unregistered is deliberate.
The same function already terminates the connection when a target sends
a remote invalidation the initiator did not ask for. A target that
invalidates a direction that was never registered is in the same class,
so give it the same answer.
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]
CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy)
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: rxe_wq do_work
RIP: 0010:iser_task_rsp+0x6d6/0xec0
Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04
RSP: 0018:ffff88811b008db8 EFLAGS: 00010202
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848
RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020
RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0
R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800
R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0
PKRU: 55555554
Call Trace:
<IRQ>
__ib_process_cq+0xe1/0x390
ib_poll_handler+0x6e/0x200
irq_poll_softirq+0x1df/0x480
? clockevents_program_event+0x2ba/0x860
? __pfx_irq_poll_softirq+0x10/0x10
handle_softirqs+0x18e/0x590
? __pfx_handle_softirqs+0x10/0x10
? __hrtimer_rearm_deferred+0x156/0x450
do_softirq+0x3b/0x60
</IRQ>
<TASK>
__local_bh_enable_ip+0x61/0x70
__alloc_skb+0x732/0x890
? _raw_spin_lock_irqsave+0x85/0xe0
? __pfx___alloc_skb+0x10/0x10
? _raw_read_unlock_irqrestore+0x16/0x50
rxe_init_packet+0x16b/0x4f0
prepare_ack_packet+0xb8/0x830
rxe_receiver+0x499/0x9980
? __pfx_rxe_receiver+0x10/0x10
? rxe_completer+0x29e5/0x38c0
? hrtimer_start_range_ns_common+0x75f/0x1730
? hrtimer_start_range_ns+0xa6/0x2c0
? __pfx__raw_spin_lock_irqsave+0x10/0x10
? __pfx_rxe_receiver+0x10/0x10
do_work+0x144/0x470
process_one_work+0x633/0x1030
? assign_work+0x11d/0x370
worker_thread+0x45b/0xd10
? __pfx_worker_thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc_sigpending+0x15c/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x36e/0x5a0
? __pfx_ret_from_fork+0x10/0x10
? __switch_to+0x572/0xdd0
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
Fixes: 59caaed7a72a ("IB/iser: Support the remote invalidation exception")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260819010804.641772-1-yhlee@isslab.korea.ac.kr
Reviewed-by: Max Gurtovoy <mgurtovoy@nvidia.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/iser/iser_initiator.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/ulp/iser/iser_initiator.c b/drivers/infiniband/ulp/iser/iser_initiator.c
index 12a2d12fef070..7ea6888b479cf 100644
--- a/drivers/infiniband/ulp/iser/iser_initiator.c
+++ b/drivers/infiniband/ulp/iser/iser_initiator.c
@@ -598,11 +598,8 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
iser_dbg("conn %p: remote invalidation for rkey %#x\n",
iser_conn, rkey);
- if (unlikely(!iser_conn->snd_w_inv)) {
- iser_err("conn %p: unexpected remote invalidation, terminating connection\n",
- iser_conn);
- return -EPROTO;
- }
+ if (unlikely(!iser_conn->snd_w_inv))
+ goto bad_inv;
task = iscsi_itt_to_ctask(iser_conn->iscsi_conn, hdr->itt);
if (likely(task)) {
@@ -611,12 +608,16 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
if (iser_task->dir[ISER_DIR_IN]) {
desc = iser_task->rdma_reg[ISER_DIR_IN].desc;
+ if (unlikely(!desc))
+ goto bad_inv;
if (unlikely(iser_inv_desc(desc, rkey)))
return -EINVAL;
}
if (iser_task->dir[ISER_DIR_OUT]) {
desc = iser_task->rdma_reg[ISER_DIR_OUT].desc;
+ if (unlikely(!desc))
+ goto bad_inv;
if (unlikely(iser_inv_desc(desc, rkey)))
return -EINVAL;
}
@@ -627,6 +628,11 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
}
return 0;
+
+bad_inv:
+ iser_err("conn %p: unexpected remote invalidation, terminating connection\n",
+ iser_conn);
+ return -EPROTO;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 036/438] IB/isert: wait for deferred control PDU completions before releasing the connection
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (34 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 035/438] IB/iser: reject a remote invalidation of an unregistered direction Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 037/438] RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup Greg Kroah-Hartman
` (413 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Leon Romanovsky,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit a8fe3dfce8c0d8a76dc3d8486a5bff5feebe156f ]
isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and
ISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns. The work
item then runs isert_completion_put() -> isert_put_cmd(), which reads
isert_conn->conn and takes conn->cmd_lock.
Nothing orders that work item against teardown. isert_wait_conn() queues
isert_release_work, which frees isert_conn, and iscsit_close_connection()
frees the iscsit_conn right after it returns, so the queued work can run
against freed memory.
Count the deferred control PDU completions per connection and let
isert_wait_conn() wait for them before the release work is queued.
ISTATE_SEND_LOGOUTRSP is deliberately not counted: that branch runs
iscsit_logout_post_handler(), which ends up waiting for
conn->conn_wait_comp, and that completion is only sent by
iscsit_close_connection() after it has called iscsit_wait_conn().
Waiting for it here would deadlock. Its wait stays the existing
isert_wait4logout().
The splat below is from a kernel with tracing printk()s and an msleep(200)
injected into isert_do_control_comp() to widen the window:
BUG: KASAN: slab-use-after-free in isert_put_cmd+0x53d/0x620
Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182
CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G B 7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy)
Tainted: [B]=BAD_PAGE
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: isert_comp_wq isert_do_control_comp
Call Trace:
<TASK>
dump_stack_lvl+0x53/0x70
print_report+0xd0/0x630
? __pfx__raw_spin_lock_irqsave+0x10/0x10
? _raw_spin_unlock_irqrestore+0x3e/0x70
? isert_put_cmd+0x53d/0x620
kasan_report+0xce/0x100
? isert_put_cmd+0x53d/0x620
isert_put_cmd+0x53d/0x620
? isert_completion_put+0x305/0x330
? isert_do_control_comp+0x2ef/0x310
process_one_work+0x633/0x1030
? assign_work+0x11d/0x370
worker_thread+0x45b/0xd10
? __pfx_worker_thread+0x10/0x10
? __pfx_worker_thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc_sigpending+0x15c/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x36e/0x5a0
? __pfx_ret_from_fork+0x10/0x10
? __switch_to+0x572/0xdd0
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Allocated by task 48:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
__kasan_kmalloc+0x8f/0xa0
__kmalloc_cache_noprof+0x158/0x370
isert_cma_handler+0x1e3/0x2ae0
cma_cm_event_handler+0x3e/0x240
cma_ib_req_handler+0x17d9/0x4490
cm_process_work+0x41/0x330
cm_work_handler+0x5727/0xc160
process_one_work+0x633/0x1030
worker_thread+0x45b/0xd10
kthread+0x2c6/0x3b0
ret_from_fork+0x36e/0x5a0
ret_from_fork_asm+0x1a/0x30
Freed by task 184:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x43/0x70
kfree+0x121/0x380
iscsit_close_connection+0x7cf/0x1e60
iscsit_take_action_for_connection_exit+0x1b6/0x360
iscsi_target_tx_thread+0x472/0x690
kthread+0x2c6/0x3b0
ret_from_fork+0x36e/0x5a0
ret_from_fork_asm+0x1a/0x30
Fixes: b8d26b3be8b3 ("iser-target: Add iSCSI Extensions for RDMA (iSER) target driver")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260821080620.1694119-1-yhlee@isslab.korea.ac.kr
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/isert/ib_isert.c | 22 ++++++++++++++++++++++
drivers/infiniband/ulp/isert/ib_isert.h | 2 ++
2 files changed, 24 insertions(+)
diff --git a/drivers/infiniband/ulp/isert/ib_isert.c b/drivers/infiniband/ulp/isert/ib_isert.c
index df5d8295a7fc1..6a9e76d60f816 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.c
+++ b/drivers/infiniband/ulp/isert/ib_isert.c
@@ -21,6 +21,7 @@
#include <target/target_core_fabric.h>
#include <target/iscsi/iscsi_transport.h>
#include <linux/semaphore.h>
+#include <linux/wait_bit.h>
#include "ib_isert.h"
@@ -310,6 +311,7 @@ isert_init_conn(struct isert_conn *isert_conn)
init_completion(&isert_conn->login_req_comp);
init_waitqueue_head(&isert_conn->rem_wait);
kref_init(&isert_conn->kref);
+ atomic_set(&isert_conn->ctrl_comp_cnt, 0);
mutex_init(&isert_conn->mutex);
INIT_WORK(&isert_conn->release_work, isert_release_work);
}
@@ -1695,6 +1697,8 @@ isert_do_control_comp(struct work_struct *work)
struct isert_conn *isert_conn = isert_cmd->conn;
struct ib_device *ib_dev = isert_conn->cm_id->device;
struct iscsit_cmd *cmd = isert_cmd->iscsit_cmd;
+ /* The switch below may free isert_cmd. */
+ bool counted = isert_cmd->ctrl_counted;
isert_dbg("Cmd %p i_state %d\n", isert_cmd, cmd->i_state);
@@ -1716,6 +1720,14 @@ isert_do_control_comp(struct work_struct *work)
dump_stack();
break;
}
+
+ /*
+ * The count is what keeps isert_conn alive, so drop it last. The wait
+ * queue lives in the global hash table, not in isert_conn, so this is
+ * safe even if the waiter has already freed the connection.
+ */
+ if (counted && atomic_dec_and_test(&isert_conn->ctrl_comp_cnt))
+ wake_up_var(&isert_conn->ctrl_comp_cnt);
}
static void
@@ -1759,6 +1771,12 @@ isert_send_done(struct ib_cq *cq, struct ib_wc *wc)
case ISTATE_SEND_TEXTRSP:
isert_unmap_tx_desc(tx_desc, ib_dev);
+ /* Paired with the wait in isert_wait_conn(). */
+ isert_cmd->ctrl_counted =
+ isert_cmd->iscsit_cmd->i_state != ISTATE_SEND_LOGOUTRSP;
+ if (isert_cmd->ctrl_counted)
+ atomic_inc(&isert_conn->ctrl_comp_cnt);
+
INIT_WORK(&isert_cmd->comp_work, isert_do_control_comp);
queue_work(isert_comp_wq, &isert_cmd->comp_work);
return;
@@ -2603,6 +2621,10 @@ static void isert_wait_conn(struct iscsit_conn *conn)
isert_wait4cmds(conn);
isert_wait4logout(isert_conn);
+ /* Paired with the count taken in isert_send_done(). */
+ wait_var_event(&isert_conn->ctrl_comp_cnt,
+ !atomic_read(&isert_conn->ctrl_comp_cnt));
+
queue_work(isert_release_wq, &isert_conn->release_work);
}
diff --git a/drivers/infiniband/ulp/isert/ib_isert.h b/drivers/infiniband/ulp/isert/ib_isert.h
index 0bac5aa66c802..519b17e54bd34 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.h
+++ b/drivers/infiniband/ulp/isert/ib_isert.h
@@ -153,6 +153,7 @@ struct isert_cmd {
struct work_struct comp_work;
struct scatterlist sg;
bool ctx_init_done;
+ bool ctrl_counted;
};
static inline struct isert_cmd *tx_desc_to_cmd(struct iser_tx_desc *desc)
@@ -187,6 +188,7 @@ struct isert_conn {
struct mutex mutex;
struct kref kref;
struct work_struct release_work;
+ atomic_t ctrl_comp_cnt;
bool logout_posted;
bool snd_w_inv;
wait_queue_head_t rem_wait;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 037/438] RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (35 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 036/438] IB/isert: wait for deferred control PDU completions before releasing the connection Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 038/438] RDMA/rtrs: guard against null kobj name Greg Kroah-Hartman
` (412 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linkai Gong, Leon Romanovsky,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linkai Gong <gonglinkai@kylinos.cn>
[ Upstream commit 6c368f7baaea63c1c7c28c6df271511f2a1562c9 ]
bnxt_re_init_dcb_wq() ignores a failed allocation. The async DCB
handler later calls queue_work() on the NULL pointer.
Fixes: 51dc5312dcd9 ("RDMA/bnxt_re: Add support to handle DCB_CONFIG_CHANGE event")
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/bnxt_re/main.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/hw/bnxt_re/main.c b/drivers/infiniband/hw/bnxt_re/main.c
index d25fdc458120e..c2fa83eb0da59 100644
--- a/drivers/infiniband/hw/bnxt_re/main.c
+++ b/drivers/infiniband/hw/bnxt_re/main.c
@@ -356,9 +356,13 @@ static int bnxt_re_update_qp1_tos_dscp(struct bnxt_re_dev *rdev)
return bnxt_qplib_modify_qp(&rdev->qplib_res, &qp->qplib_qp);
}
-static void bnxt_re_init_dcb_wq(struct bnxt_re_dev *rdev)
+static int bnxt_re_init_dcb_wq(struct bnxt_re_dev *rdev)
{
rdev->dcb_wq = create_singlethread_workqueue("bnxt_re_dcb_wq");
+ if (!rdev->dcb_wq)
+ return -ENOMEM;
+
+ return 0;
}
static void bnxt_re_uninit_dcb_wq(struct bnxt_re_dev *rdev)
@@ -2343,7 +2347,9 @@ static int bnxt_re_dev_init(struct bnxt_re_dev *rdev, u8 op_type)
bnxt_re_debugfs_add_pdev(rdev);
- bnxt_re_init_dcb_wq(rdev);
+ rc = bnxt_re_init_dcb_wq(rdev);
+ if (rc)
+ goto fail;
bnxt_re_net_register_async_event(rdev);
if (!rdev->is_virtfn)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 038/438] RDMA/rtrs: guard against null kobj name
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (36 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 037/438] RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup Greg Kroah-Hartman
@ 2026-09-23 14:00 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 039/438] RDMA/bnxt_re: Avoid exposing umdbr to userspace Greg Kroah-Hartman
` (411 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:00 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1695193198994f4e7fed,
Ryan Mehri, Jack Wang, Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ryan Mehri <ryan.mehri1@gmail.com>
[ Upstream commit 99c24a8968ebef0573825b5cb89d5985d51635b9 ]
In the client, if `init_path()` errors, the callee tries to clean up
with `rtrs_clt_close_conns()`. However, this can lead to calling the
event tracing code with `clt_path->kobj->name` being `NULL` and thus
causing a null pointer dereference when trying to copy from it.
This just adds a guard to check that the name is not `NULL` before
copying from it. The server appears to have a similar pattern.
Fixes: 5a93929d9f9a1 ("RDMA/rtrs-clt: Add event tracing support")
Fixes: c16762b7bf54d ("RDMA/rtrs-srv: Add event tracing support")
Reported-by: syzbot+1695193198994f4e7fed@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1695193198994f4e7fed
Signed-off-by: Ryan Mehri <ryan.mehri1@gmail.com>
Link: https://patch.msgid.link/20260823034303.163403-1-ryan.mehri1@gmail.com
Reviewed-by: Jack Wang <jinpu.wang@cloud.ionos.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/rtrs/rtrs-clt-trace.h | 2 +-
drivers/infiniband/ulp/rtrs/rtrs-srv-trace.h | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt-trace.h b/drivers/infiniband/ulp/rtrs/rtrs-clt-trace.h
index 7738e26768557..29e23404bb7b8 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt-trace.h
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt-trace.h
@@ -55,7 +55,7 @@ DECLARE_EVENT_CLASS(rtrs_clt_conn_class,
__entry->max_reconnect_attempts = clt->max_reconnect_attempts;
__entry->fail_cnt = clt_path->stats->reconnects.fail_cnt;
__entry->success_cnt = clt_path->stats->reconnects.successful_cnt;
- memcpy(__entry->sessname, kobject_name(&clt_path->kobj), NAME_MAX);
+ strscpy(__entry->sessname, kobject_name(&clt_path->kobj) ?: "", NAME_MAX);
),
TP_printk("RTRS-CLT: sess='%s' state=%s attempts='%d' max-attempts='%d' fail='%d' success='%d'",
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-srv-trace.h b/drivers/infiniband/ulp/rtrs/rtrs-srv-trace.h
index 587d3e0330812..a7d7b971e6c80 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-srv-trace.h
+++ b/drivers/infiniband/ulp/rtrs/rtrs-srv-trace.h
@@ -61,7 +61,7 @@ TRACE_EVENT(send_io_resp_imm,
__entry->msg_id = id->msg_id;
__entry->wr_cnt = atomic_read(&con->c.wr_cnt);
__entry->signal_interval = s->signal_interval;
- memcpy(__entry->sessname, kobject_name(&srv_path->kobj), NAME_MAX);
+ strscpy(__entry->sessname, kobject_name(&srv_path->kobj) ?: "", NAME_MAX);
),
TP_printk("sess='%s' state='%s' dir=%s err='%d' inval='%d' glob-inval='%d' msgid='%u' wrcnt='%d' sig-interval='%u'",
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 039/438] RDMA/bnxt_re: Avoid exposing umdbr to userspace
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (37 preceding siblings ...)
2026-09-23 14:00 ` [PATCH 7.2 038/438] RDMA/rtrs: guard against null kobj name Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 040/438] RDMA/uverbs: Fix potential leak of resources->collection in flow_resources_alloc() Greg Kroah-Hartman
` (410 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sriharsha Basavapatna, Selvin Xavier,
Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
[ Upstream commit 23d7e03a52ece66b992620aa9b8fa5f164077c0f ]
The umdbr field in struct bnxt_re_db_region returns the raw
unmapped PCI BAR address of the doorbell region. Avoid sharing
this field to the userspace. Change this to a reserved field
and stop populating it, keeping the ABI layout and size
unchanged for existing binaries.
Fixes: 1234a9d8aebb ("RDMA/bnxt_re: Support doorbell extensions")
Signed-off-by: Sriharsha Basavapatna <sriharsha.basavapatna@broadcom.com>
Link: https://patch.msgid.link/20260824172443.33943-1-sriharsha.basavapatna@broadcom.com
Reviewed-by: Selvin Xavier <selvin.xavier@broadcom.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/bnxt_re/uapi.c | 6 ++----
include/uapi/rdma/bnxt_re-abi.h | 2 +-
2 files changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/hw/bnxt_re/uapi.c b/drivers/infiniband/hw/bnxt_re/uapi.c
index 263238a6e4cdd..f278c4f70ff7b 100644
--- a/drivers/infiniband/hw/bnxt_re/uapi.c
+++ b/drivers/infiniband/hw/bnxt_re/uapi.c
@@ -409,7 +409,6 @@ static int UVERBS_HANDLER(BNXT_RE_METHOD_DBR_ALLOC)(struct uverbs_attr_bundle *a
uobj->object = obj;
uverbs_finalize_uobj_create(attrs, BNXT_RE_ALLOC_DBR_HANDLE);
- dbr.umdbr = dpi->umdbr;
dbr.dpi = dpi->dpi;
ret = uverbs_copy_to_struct_or_zero(attrs, BNXT_RE_ALLOC_DBR_ATTR,
&dbr, sizeof(dbr));
@@ -472,7 +471,6 @@ static int UVERBS_HANDLER(BNXT_RE_METHOD_GET_DEFAULT_DBR)(struct uverbs_attr_bun
return PTR_ERR(ib_uctx);
uctx = container_of(ib_uctx, struct bnxt_re_ucontext, ib_uctx);
- dpi.umdbr = uctx->dpi.umdbr;
dpi.dpi = uctx->dpi.dpi;
ret = uverbs_copy_to_struct_or_zero(attrs, BNXT_RE_DEFAULT_DBR_ATTR,
@@ -490,7 +488,7 @@ DECLARE_UVERBS_NAMED_METHOD(BNXT_RE_METHOD_DBR_ALLOC,
UA_MANDATORY),
UVERBS_ATTR_PTR_OUT(BNXT_RE_ALLOC_DBR_ATTR,
UVERBS_ATTR_STRUCT(struct bnxt_re_db_region,
- umdbr),
+ reserved2),
UA_MANDATORY),
UVERBS_ATTR_PTR_OUT(BNXT_RE_ALLOC_DBR_OFFSET,
UVERBS_ATTR_TYPE(u64),
@@ -510,7 +508,7 @@ DECLARE_UVERBS_NAMED_OBJECT(BNXT_RE_OBJECT_DBR,
DECLARE_UVERBS_NAMED_METHOD(BNXT_RE_METHOD_GET_DEFAULT_DBR,
UVERBS_ATTR_PTR_OUT(BNXT_RE_DEFAULT_DBR_ATTR,
UVERBS_ATTR_STRUCT(struct bnxt_re_db_region,
- umdbr),
+ reserved2),
UA_MANDATORY));
DECLARE_UVERBS_GLOBAL_METHODS(BNXT_RE_OBJECT_DEFAULT_DBR,
diff --git a/include/uapi/rdma/bnxt_re-abi.h b/include/uapi/rdma/bnxt_re-abi.h
index a4599d7b736aa..0a125c2a8cc4e 100644
--- a/include/uapi/rdma/bnxt_re-abi.h
+++ b/include/uapi/rdma/bnxt_re-abi.h
@@ -247,7 +247,7 @@ struct bnxt_re_query_device_ex_resp {
struct bnxt_re_db_region {
__u32 dpi;
__u32 reserved;
- __aligned_u64 umdbr;
+ __aligned_u64 reserved2;
};
enum bnxt_re_obj_dbr_alloc_attrs {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 040/438] RDMA/uverbs: Fix potential leak of resources->collection in flow_resources_alloc()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (38 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 039/438] RDMA/bnxt_re: Avoid exposing umdbr to userspace Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 041/438] RDMA/mad: Fix receive buffer leak when PKey enforcement fails Greg Kroah-Hartman
` (409 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li RongQing, Leon Romanovsky,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li RongQing <lirongqing@baidu.com>
[ Upstream commit 08d4d9802d58bf032099091e6acf719f3298f28e ]
The two array allocations are done unconditionally and only checked
afterwards, so if the counters allocation fails while the collection
allocation succeeds, the error path frees counters and the containing
struct but never frees resources->collection, losing the only pointer
to it.
Fixes: de7498147d00 ("RDMA/uverbs: Refactor flow_resources_alloc() function")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
Link: https://patch.msgid.link/20260826073146.2203-1-lirongqing@baidu.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/uverbs_flow.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/infiniband/core/uverbs_flow.c b/drivers/infiniband/core/uverbs_flow.c
index 1528a294f7f85..de5a2769f0847 100644
--- a/drivers/infiniband/core/uverbs_flow.c
+++ b/drivers/infiniband/core/uverbs_flow.c
@@ -26,6 +26,7 @@ struct ib_uflow_resources *flow_resources_alloc(size_t num_specs)
return resources;
err:
+ kfree(resources->collection);
kfree(resources->counters);
kfree(resources);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 041/438] RDMA/mad: Fix receive buffer leak when PKey enforcement fails
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (39 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 040/438] RDMA/uverbs: Fix potential leak of resources->collection in flow_resources_alloc() Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 042/438] RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables Greg Kroah-Hartman
` (408 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li RongQing, Leon Romanovsky,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li RongQing <lirongqing@baidu.com>
[ Upstream commit 3476c28c9addfa253f505e6bd87f1f5598b961d0 ]
ib_mad_complete_recv() initializes mad_recv_wc->rmpp_list and then runs
ib_mad_enforce_security() before linking recv_buf onto that list. On
failure it calls ib_free_recv_mad(), which only walks rmpp_list and frees
the ib_mad_private of every buffer found there. As the list is still
empty at that point, nothing is freed at all.
The caller cannot clean up either: ib_mad_recv_done() sets recv to NULL
right after ib_mad_complete_recv() returns, assuming the MAD layer took
ownership of the buffer. Every MAD that fails the PKey check therefore
leaks one ib_mad_private (about 300 bytes per IB port MAD, ~2K for OPA),
and a remote node can trigger this repeatedly by sending MADs with a
wrong PKey.
Link recv_buf onto rmpp_list right after the list is initialized, so the
error path has something to free.
Fixes: 47a2b338fe63 ("IB/core: Enforce security on management datagrams")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
Link: https://patch.msgid.link/20260826073216.2367-1-lirongqing@baidu.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/mad.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/core/mad.c b/drivers/infiniband/core/mad.c
index e0b3b36b8b149..3c91f00d09c6b 100644
--- a/drivers/infiniband/core/mad.c
+++ b/drivers/infiniband/core/mad.c
@@ -2059,6 +2059,8 @@ static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
int ret;
INIT_LIST_HEAD(&mad_recv_wc->rmpp_list);
+ list_add(&mad_recv_wc->recv_buf.list, &mad_recv_wc->rmpp_list);
+
ret = ib_mad_enforce_security(mad_agent_priv,
mad_recv_wc->wc->pkey_index);
if (ret) {
@@ -2067,7 +2069,6 @@ static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
return;
}
- list_add(&mad_recv_wc->recv_buf.list, &mad_recv_wc->rmpp_list);
if (is_kernel_rmpp_data_response(mad_agent_priv, mad_recv_wc)) {
spin_lock_irqsave(&mad_agent_priv->lock, flags);
mad_send_wr = ib_find_send_mad(mad_agent_priv, mad_recv_wc);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 042/438] RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (40 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 041/438] RDMA/mad: Fix receive buffer leak when PKey enforcement fails Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 043/438] RDMA/irdma: Enforce local fence for IB_WR_REG_MR Greg Kroah-Hartman
` (407 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Cheng Xu, Leon Romanovsky,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cheng Xu <chengyou@linux.alibaba.com>
[ Upstream commit 00baeade709fb66da647e8327e8398bb532e30f7 ]
Locked QP and CQ lookups from EQ interrupts can deadlock with
create-path XArray updates. If an interrupt arrives while the create
path holds the plain xa_lock, the lookup spins forever trying to
acquire the same lock.
Use IRQ-safe XArray helpers for all QP and CQ create-path updates,
including the GSI QP store and error paths. Initialize both arrays with
XA_FLAGS_LOCK_IRQ so sleeping allocations preserve interrupt state.
Fixes: 98df2aee1459 ("RDMA/erdma: Hold CQ references when processing EQ events")
Fixes: a52eeff32024 ("RDMA/erdma: Hold QP references for AE and CM processing")
Signed-off-by: Cheng Xu <chengyou@linux.alibaba.com>
Link: https://patch.msgid.link/20260828030344.88021-1-chengyou@linux.alibaba.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/erdma/erdma_main.c | 4 ++--
drivers/infiniband/hw/erdma/erdma_verbs.c | 18 +++++++++---------
2 files changed, 11 insertions(+), 11 deletions(-)
diff --git a/drivers/infiniband/hw/erdma/erdma_main.c b/drivers/infiniband/hw/erdma/erdma_main.c
index 7e87a815e853b..445182c6bc5d3 100644
--- a/drivers/infiniband/hw/erdma/erdma_main.c
+++ b/drivers/infiniband/hw/erdma/erdma_main.c
@@ -572,8 +572,8 @@ static int erdma_ib_device_add(struct pci_dev *pdev)
INIT_LIST_HEAD(&dev->cep_list);
spin_lock_init(&dev->lock);
- xa_init_flags(&dev->qp_xa, XA_FLAGS_ALLOC1);
- xa_init_flags(&dev->cq_xa, XA_FLAGS_ALLOC1);
+ xa_init_flags(&dev->qp_xa, XA_FLAGS_ALLOC1 | XA_FLAGS_LOCK_IRQ);
+ xa_init_flags(&dev->cq_xa, XA_FLAGS_ALLOC1 | XA_FLAGS_LOCK_IRQ);
dev->next_alloc_cqn = 1;
dev->next_alloc_qpn = 1;
diff --git a/drivers/infiniband/hw/erdma/erdma_verbs.c b/drivers/infiniband/hw/erdma/erdma_verbs.c
index 20944d506da77..5efd3bfb59d65 100644
--- a/drivers/infiniband/hw/erdma/erdma_verbs.c
+++ b/drivers/infiniband/hw/erdma/erdma_verbs.c
@@ -1023,15 +1023,15 @@ int erdma_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
init_completion(&qp->safe_free);
if (qp->ibqp.qp_type == IB_QPT_GSI) {
- old_entry = xa_store(&dev->qp_xa, 1, qp, GFP_KERNEL);
+ old_entry = xa_store_irq(&dev->qp_xa, 1, qp, GFP_KERNEL);
if (xa_is_err(old_entry))
ret = xa_err(old_entry);
else
qp->ibqp.qp_num = 1;
} else {
- ret = xa_alloc_cyclic(&dev->qp_xa, &qp->ibqp.qp_num, qp,
- XA_LIMIT(1, dev->attrs.max_qp - 1),
- &dev->next_alloc_qpn, GFP_KERNEL);
+ ret = xa_alloc_cyclic_irq(&dev->qp_xa, &qp->ibqp.qp_num, qp,
+ XA_LIMIT(1, dev->attrs.max_qp - 1),
+ &dev->next_alloc_qpn, GFP_KERNEL);
}
if (ret < 0) {
@@ -1091,7 +1091,7 @@ int erdma_create_qp(struct ib_qp *ibqp, struct ib_qp_init_attr *attrs,
else
free_kernel_qp(qp);
err_out_xa:
- xa_erase(&dev->qp_xa, QP_ID(qp));
+ xa_erase_irq(&dev->qp_xa, QP_ID(qp));
err_out:
return ret;
}
@@ -1995,9 +1995,9 @@ int erdma_create_cq(struct ib_cq *ibcq, const struct ib_cq_init_attr *attr,
refcount_set(&cq->refcount, 1);
init_completion(&cq->free);
- ret = xa_alloc_cyclic(&dev->cq_xa, &cq->cqn, cq,
- XA_LIMIT(1, dev->attrs.max_cq - 1),
- &dev->next_alloc_cqn, GFP_KERNEL);
+ ret = xa_alloc_cyclic_irq(&dev->cq_xa, &cq->cqn, cq,
+ XA_LIMIT(1, dev->attrs.max_cq - 1),
+ &dev->next_alloc_cqn, GFP_KERNEL);
if (ret < 0)
return ret;
@@ -2043,7 +2043,7 @@ int erdma_create_cq(struct ib_cq *ibcq, const struct ib_cq_init_attr *attr,
}
err_out_xa:
- xa_erase(&dev->cq_xa, cq->cqn);
+ xa_erase_irq(&dev->cq_xa, cq->cqn);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 043/438] RDMA/irdma: Enforce local fence for IB_WR_REG_MR
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (41 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 042/438] RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 044/438] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted Greg Kroah-Hartman
` (406 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Leon Romanovsky,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jacob Moroni <jmoroni@google.com>
[ Upstream commit 3fb905f07ea45b31c8f67ba6e4668de46f527e65 ]
Enforce local fence for IB_WR_REG_MR to avoid spurious
FASTREG_VALID_MKEY async events during heavy invalidation
and registration activity.
Commit 69e8e429bca2 ("RDMA/irdma: Enforce local fence for LOCAL_INV WRs")
was very similar, but was not sufficient to prevent all occurrences
of these async events.
Fixes: b48c24c2d710 ("RDMA/irdma: Implement device supported verb APIs")
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Link: https://patch.msgid.link/20260901160014.2026285-1-jmoroni@google.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/irdma/verbs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index 04d5af78686b5..e926eb37982c6 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -4244,7 +4244,7 @@ static int irdma_post_send(struct ib_qp *ibqp,
stag_info.total_len = iwmr->ibmr.length;
stag_info.reg_addr_pa = *palloc->level1.addr;
stag_info.first_pm_pbl_index = palloc->level1.idx;
- stag_info.local_fence = ib_wr->send_flags & IB_SEND_FENCE;
+ stag_info.local_fence = true;
if (iwmr->npages > IRDMA_MIN_PAGES_PER_FMR)
stag_info.chunk_size = 1;
err = irdma_sc_mr_fast_register(&iwqp->sc_qp, &stag_info,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 044/438] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (42 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 043/438] RDMA/irdma: Enforce local fence for IB_WR_REG_MR Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 045/438] dmaengine: mmp_pdma: fix wrong extended DRCMR base for SpacemiT K3 Greg Kroah-Hartman
` (405 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+d396918a29afb8543e1c,
Quanye Yang, Jack Wang, Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Quanye Yang <quanyeyang@proton.me>
[ Upstream commit 2ae16aaa78b5edc6e6d0904c84fd9cdfb762bcda ]
The client borrows shared CQ credits in the ADDR_RESOLVED handler via
ib_cq_pool_get(), before the peer is connected. create_cm() can return
-ERESTARTSYS from wait_event_interruptible_timeout() without destroying
the CM ID. The init_conns() and stop-and-destroy paths then call
destroy_con_cq_qp() while cq is still NULL (no PUT) and only afterwards
rdma_destroy_id().
CMA serializes the handler against rdma_destroy_id() with handler_mutex,
but that does not order the GET against destroy_con_cq_qp(). If
ADDR_RESOLVED has already passed the DESTROYING check, it can take
con_mutex, GET credits, and then lose the con to kfree. Device
unregister later hits WARN_ON(cq->cqe_used) in ib_cq_pool_cleanup().
Set a per-connection flag under con_mutex before CQ/QP teardown so a
racing ADDR_RESOLVED cannot borrow credits after teardown has begun.
Reported-by: syzbot+d396918a29afb8543e1c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=d396918a29afb8543e1c
Fixes: 3b89e92c2a95 ("RDMA/rtrs: Use new shared CQ mechanism")
Signed-off-by: Quanye Yang <quanyeyang@proton.me>
Link: https://patch.msgid.link/20260830-rdma-rtrs-clt-cq-pool-leak-v1-1-b169434fd3df@proton.me
Reviewed-by: Jack Wang <jinpu.wang@cloud.ionos.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/rtrs/rtrs-clt.c | 8 ++++++++
drivers/infiniband/ulp/rtrs/rtrs-clt.h | 2 ++
2 files changed, 10 insertions(+)
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.c b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
index d34d7e5f34d6f..62cc93be7b877 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt.c
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
@@ -1735,6 +1735,8 @@ static void destroy_con_cq_qp(struct rtrs_clt_con *con)
/*
* Be careful here: destroy_con_cq_qp() can be called even
* create_con_cq_qp() failed, see comments there.
+ * Caller must set con->destroyed under this lock first so a
+ * racing ADDR_RESOLVED cannot ib_cq_pool_get() after we PUT/SKIP.
*/
lockdep_assert_held(&con->con_mutex);
rtrs_cq_qp_destroy(&con->c);
@@ -1769,6 +1771,10 @@ static int rtrs_rdma_addr_resolved(struct rtrs_clt_con *con)
int err;
mutex_lock(&con->con_mutex);
+ if (con->destroyed) {
+ mutex_unlock(&con->con_mutex);
+ return -ECONNABORTED;
+ }
err = create_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
if (err) {
@@ -2224,6 +2230,7 @@ static void rtrs_clt_stop_and_destroy_conns(struct rtrs_clt_path *clt_path)
break;
con = to_clt_con(clt_path->s.con[cid]);
mutex_lock(&con->con_mutex);
+ con->destroyed = true;
destroy_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
destroy_cm(con);
@@ -2390,6 +2397,7 @@ static int init_conns(struct rtrs_clt_path *clt_path)
if (con->c.cm_id) {
stop_cm(con);
mutex_lock(&con->con_mutex);
+ con->destroyed = true;
destroy_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
destroy_cm(con);
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.h b/drivers/infiniband/ulp/rtrs/rtrs-clt.h
index 1305601a6251e..ad64f4517c4b3 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt.h
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.h
@@ -75,6 +75,8 @@ struct rtrs_clt_con {
unsigned int cpu;
struct mutex con_mutex;
int cm_err;
+ /* Set under con_mutex before CQ/QP teardown. */
+ bool destroyed;
};
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 045/438] dmaengine: mmp_pdma: fix wrong extended DRCMR base for SpacemiT K3
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (43 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 044/438] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 046/438] dmaengine: sprd: Fix runtime PM reference leak in probe Greg Kroah-Hartman
` (404 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Troy Mitchell, Frank Li, Vinod Koul,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Troy Mitchell <troy.mitchell@linux.spacemit.com>
[ Upstream commit d1fc569fcbc7be6de06b034cf954a95e30ca1fb2 ]
The extended DRCMR window on SpacemiT K3 starts at 0x1100. Commit
6587b8661a0b ("dmaengine: mmp_pdma: add SpacemiT K3 support") incorrectly
set it to 0x1000, causing DRCMR accesses for request IDs >= 64 to target
offsets 0x100 too low.
The 0x1100 base has been verified on K3 silicon using real SPI and QSPI
DMA transactions. The K3 DMA documentation [1] was updated on June 24,
2026, to reflect the corrected register addresses.
Drop the bogus DRCMR_EXT_BASE_K3 macro and reuse
DRCMR_EXT_BASE_DEFAULT for the K3 ops.
Fixes: 6587b8661a0b ("dmaengine: mmp_pdma: add SpacemiT K3 support")
Link: https://www.spacemit.com/community/document/info?nodepath=hardware/key_stone/k3/k3_docs/k3_usermanual/16_peripherals/dma.md&lang=en [1]
Signed-off-by: Troy Mitchell <troy.mitchell@linux.spacemit.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260727-k3-pdma-fix-drcmr-base-v2-1-afba55cba1f3@linux.spacemit.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/mmp_pdma.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/dma/mmp_pdma.c b/drivers/dma/mmp_pdma.c
index 386e85cd4882a..78e3e07e681df 100644
--- a/drivers/dma/mmp_pdma.c
+++ b/drivers/dma/mmp_pdma.c
@@ -52,7 +52,6 @@
#define DCSR_EORINTR BIT(9) /* The end of Receive */
#define DRCMR_BASE 0x0100
-#define DRCMR_EXT_BASE_K3 0x1000
#define DRCMR_EXT_BASE_DEFAULT 0x1100
#define DRCMR_REQ_LIMIT 64
#define DRCMR_MAPVLD BIT(7) /* Map Valid (read / write) */
@@ -1219,7 +1218,7 @@ static const struct mmp_pdma_ops spacemit_k3_pdma_ops = {
.get_desc_dst_addr = get_desc_dst_addr_64,
.run_bits = (DCSR_RUN | DCSR_LPAEEN | DCSR_EORIRQEN | DCSR_EORSTOPEN),
.dma_width = 64,
- .drcmr_ext_base = DRCMR_EXT_BASE_K3,
+ .drcmr_ext_base = DRCMR_EXT_BASE_DEFAULT,
};
static const struct of_device_id mmp_pdma_dt_ids[] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 046/438] dmaengine: sprd: Fix runtime PM reference leak in probe
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (44 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 045/438] dmaengine: mmp_pdma: fix wrong extended DRCMR base for SpacemiT K3 Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 047/438] wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic Greg Kroah-Hartman
` (403 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Frank Li, Baolin Wang,
Vinod Koul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit a7df136ec529ee49a789c5029bc37b98b0d4bedd ]
pm_runtime_get_sync() increments a device's usage counter even when it
fails. sprd_dma_probe() currently jumps directly to controller clock
cleanup on that error, bypassing both pm_runtime_put_noidle() and
pm_runtime_disable(). This can happen if the preceding unchecked
pm_runtime_set_active() fails and the following runtime-resume attempt
also returns an error.
Enter the existing runtime-PM unwind path instead. This drops the
reference without idling the partially initialized device, disables
runtime PM, and then releases the controller clocks. The success path
and propagated error code are unchanged.
This issue was found by a static analysis checker and confirmed by manual
source review.
Fixes: 9b3b8171f7f4 ("dmaengine: sprd: Add Spreadtrum DMA driver")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Link: https://patch.msgid.link/20260813153149.3953497-1-ruoyuw560@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/sprd-dma.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/dma/sprd-dma.c b/drivers/dma/sprd-dma.c
index 087fea3af2e41..19b32a23c882d 100644
--- a/drivers/dma/sprd-dma.c
+++ b/drivers/dma/sprd-dma.c
@@ -1212,7 +1212,7 @@ static int sprd_dma_probe(struct platform_device *pdev)
ret = pm_runtime_get_sync(&pdev->dev);
if (ret < 0)
- goto err_rpm;
+ goto err_register;
ret = dma_async_device_register(&sdev->dma_dev);
if (ret < 0) {
@@ -1234,7 +1234,6 @@ static int sprd_dma_probe(struct platform_device *pdev)
err_register:
pm_runtime_put_noidle(&pdev->dev);
pm_runtime_disable(&pdev->dev);
-err_rpm:
sprd_dma_disable(sdev);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 047/438] wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (45 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 046/438] dmaengine: sprd: Fix runtime PM reference leak in probe Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 048/438] wifi: virt_wifi: free skb when disconnected Greg Kroah-Hartman
` (402 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lachlan Hodges, Johannes Berg,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lachlan Hodges <lachlan.hodges@morsemicro.com>
[ Upstream commit af72b5946d493cecced27d0951ea37c1d178601e ]
Currently when building the S1G TIM element, we only build the bitmap
control if we have buffered unicast traffic. Since AID 0 sits within
the bitmap control if we have buffered multicast traffic with no
buffered unicast traffic the bitmap control won't be emitted and
dozing stations will be unaware of buffered multicast.
To fix, only exclude the bitmap control byte when we don't have
both buffered unicast and multicast traffic.
Fixes: ee6360945483 ("wifi: mac80211: support block bitmap S1G TIM encoding")
Signed-off-by: Lachlan Hodges <lachlan.hodges@morsemicro.com>
Link: https://patch.msgid.link/20260827054302.254124-1-lachlan.hodges@morsemicro.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tx.c | 41 ++++++++++++++++++++++-------------------
1 file changed, 22 insertions(+), 19 deletions(-)
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index fd4c379b3f201..7cb9dd1b27314 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -5063,10 +5063,18 @@ static void ieee80211_beacon_add_tim_pvb(struct ps_data *ps,
*/
static void ieee80211_s1g_beacon_add_tim_pvb(struct ps_data *ps,
struct sk_buff *skb,
- bool mcast_traffic)
+ bool mcast_traffic,
+ bool ucast_traffic)
{
int blk;
+ /*
+ * if no unicast and multicast traffic don't emit a bitmap control
+ * or pvb
+ */
+ if (!mcast_traffic && !ucast_traffic)
+ return;
+
/*
* Emit a bitmap control block with a page slice number of 31 and a
* page index of 0 which indicates as per IEEE80211-2024 9.4.2.5.1
@@ -5075,6 +5083,10 @@ static void ieee80211_s1g_beacon_add_tim_pvb(struct ps_data *ps,
*/
skb_put_u8(skb, mcast_traffic | (31 << 1));
+ /* If there's no unicast traffic we don't need to include a PVB. */
+ if (!ucast_traffic)
+ return;
+
/* Emit an encoded block for each non-zero sub-block */
for (blk = 0; blk < IEEE80211_MAX_SUPPORTED_S1G_TIM_BLOCKS; blk++) {
u8 blk_bmap = 0;
@@ -5156,25 +5168,16 @@ static void __ieee80211_beacon_add_tim(struct ieee80211_sub_if_data *sdata,
ps->dtim_bc_mc = mcast_traffic;
- if (have_bits) {
- if (s1g)
- ieee80211_s1g_beacon_add_tim_pvb(ps, skb,
- mcast_traffic);
- else
- ieee80211_beacon_add_tim_pvb(ps, skb, mcast_traffic);
+ if (s1g) {
+ ieee80211_s1g_beacon_add_tim_pvb(ps, skb, mcast_traffic,
+ have_bits);
+ } else if (have_bits) {
+ ieee80211_beacon_add_tim_pvb(ps, skb, mcast_traffic);
} else {
- /*
- * If there is no buffered unicast traffic for an S1G
- * interface, we can exclude the bitmap control. This is in
- * contrast to other phy types as they do include the bitmap
- * control and pvb even when there is no buffered traffic.
- */
- if (!s1g) {
- /* Bitmap control */
- skb_put_u8(skb, mcast_traffic);
- /* Part Virt Bitmap */
- skb_put_u8(skb, 0);
- }
+ /* Bitmap control */
+ skb_put_u8(skb, mcast_traffic);
+ /* Part Virt Bitmap */
+ skb_put_u8(skb, 0);
}
tim->datalen = skb_tail_pointer(skb) - tim->data;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 048/438] wifi: virt_wifi: free skb when disconnected
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (46 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 047/438] wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 049/438] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path Greg Kroah-Hartman
` (401 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mariano Baragiola, Johannes Berg,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mariano Baragiola <mbaragiola@linux.com>
[ Upstream commit f9edf7cf63b96d2b776fca8d258d3c5256e40c8e ]
When the simulated link is disconnected, virt_wifi_start_xmit() returns
NET_XMIT_DROP without freeing the skb. dev_hard_start_xmit() treats this
return value as consumed, so every packet sent while disconnected leaks its
skb.
Free the skb before returning the drop status.
Fixes: c7cdba31ed8b ("mac80211-next: rtnetlink wifi simulation device")
Signed-off-by: Mariano Baragiola <mbaragiola@linux.com>
Link: https://patch.msgid.link/20260809124947.3590270-1-mbaragiola@linux.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virtual/virt_wifi.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wireless/virtual/virt_wifi.c b/drivers/net/wireless/virtual/virt_wifi.c
index 2335e45db8b85..b69a4650fba85 100644
--- a/drivers/net/wireless/virtual/virt_wifi.c
+++ b/drivers/net/wireless/virtual/virt_wifi.c
@@ -434,6 +434,7 @@ static netdev_tx_t virt_wifi_start_xmit(struct sk_buff *skb,
priv->tx_packets++;
if (!priv->is_connected) {
priv->tx_failed++;
+ dev_kfree_skb_any(skb);
return NET_XMIT_DROP;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 049/438] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (47 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 048/438] wifi: virt_wifi: free skb when disconnected Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 050/438] wifi: brcmfmac: cyw: pass PMKID to firmware if present Greg Kroah-Hartman
` (400 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peng Hao, Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peng Hao <flyingpenghao@gmail.com>
[ Upstream commit a3d722190cdef18da4878b5efc27c3c386dda248 ]
mwifiex_pcie_request_irq() registers each MSI-X vector with a per-index
dev_id (&card->msix_ctx[i]). On a request_irq() failure the cleanup loop
"for (j = 0; j < i; j++)" frees msix_entries[j].vector but passes the
failed index's &card->msix_ctx[i] as the dev_id. free_irq() matches on
(irq, dev_id), so it fails to find the action registered with
&card->msix_ctx[j]: the already-requested IRQ j is not freed (leaked) and
free_irq() warns about freeing a non-existent IRQ. Use &card->msix_ctx[j].
Fixes: 99074fc1e67b ("mwifiex: enable pcie MSIx interrupt mode support")
Signed-off-by: Peng Hao <flyingpeng@tencent.com>
Link: https://patch.msgid.link/20260828111531.56723-1-flyingpeng@tencent.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/marvell/mwifiex/pcie.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/marvell/mwifiex/pcie.c b/drivers/net/wireless/marvell/mwifiex/pcie.c
index a760de191fce7..a9425e9a94f45 100644
--- a/drivers/net/wireless/marvell/mwifiex/pcie.c
+++ b/drivers/net/wireless/marvell/mwifiex/pcie.c
@@ -3068,7 +3068,7 @@ static int mwifiex_pcie_request_irq(struct mwifiex_adapter *adapter)
ret);
for (j = 0; j < i; j++)
free_irq(card->msix_entries[j].vector,
- &card->msix_ctx[i]);
+ &card->msix_ctx[j]);
pci_disable_msix(pdev);
} else {
mwifiex_dbg(adapter, MSG, "MSIx enabled!");
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 050/438] wifi: brcmfmac: cyw: pass PMKID to firmware if present
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (48 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 049/438] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 051/438] wifi: libipw: reject too-short beacon and probe responses Greg Kroah-Hartman
` (399 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bogdan Nicolae, Arend van Spriel,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bogdan Nicolae <bogdan.nicolae@gmail.com>
[ Upstream commit e2de8d5eb2984416affdd9559e55f37c7f1bbf47 ]
Zero out auth_status on initialization. Otherwise, garbage will
leak from the stack to the firmware (when ssid is less than 32 bytes
and/or when params->pmkid is set). Then, pass the params->pmkid to the
firmware (without it, the firmware caches a garbage PMKID on successful
authentication and denies a subsequent association request that includes
the PMKID).
Fixes: 66f909308a7c ("wifi: brcmfmac: cyw: support external SAE authentication in station mode")
Signed-off-by: Bogdan Nicolae <bogdan.nicolae@gmail.com>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260807163418.487508-1-bogdan.nicolae@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
index 873754be5174b..c86d0bdde8326 100644
--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
@@ -200,7 +200,7 @@ brcmf_cyw_external_auth(struct wiphy *wiphy, struct net_device *dev,
{
struct brcmf_if *ifp;
struct brcmf_pub *drvr;
- struct brcmf_auth_req_status_le auth_status;
+ struct brcmf_auth_req_status_le auth_status = {};
int ret = 0;
brcmf_dbg(TRACE, "Enter\n");
@@ -208,6 +208,9 @@ brcmf_cyw_external_auth(struct wiphy *wiphy, struct net_device *dev,
ifp = netdev_priv(dev);
drvr = ifp->drvr;
if (params->status == WLAN_STATUS_SUCCESS) {
+ if (params->pmkid)
+ memcpy(auth_status.pmkid, params->pmkid,
+ WLAN_PMKID_LEN);
auth_status.flags = cpu_to_le16(BRCMF_EXTAUTH_SUCCESS);
} else {
bphy_err(drvr, "External authentication failed: status=%d\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 051/438] wifi: libipw: reject too-short beacon and probe responses
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (49 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 050/438] wifi: brcmfmac: cyw: pass PMKID to firmware if present Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 052/438] wifi: libipw: reject too-short association responses Greg Kroah-Hartman
` (398 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shmulik Cohen, Johannes Berg,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shmulik Cohen <anuk909@gmail.com>
[ Upstream commit 5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b ]
libipw_process_probe_response() and the libipw_network_init() call it
makes assume the frame contains the full 36-byte beacon and probe
response prefix, but the ipw2100 and ipw2200 receive paths only
establish that a management frame carries the generic 24-byte
three-address header.
libipw_network_init() then computes the information element length as
stats->len - sizeof(*beacon)
stats->len is a u16 and sizeof() has type size_t, so the subtraction is
evaluated as size_t and wraps instead of going negative. Truncating
that to the u16 length parameter of libipw_parse_info_param() yields
65524 for a 24-byte beacon, and the parser then walks the receive
buffer as if it held almost 64 KiB of information elements, reading
past the allocation.
Reject the frame before any fixed field is touched.
Found by an AI-assisted review of length arithmetic in management frame
parsers. Verified with a KUnit case under Generic KASAN on arm64 under
QEMU; I do not have the hardware, so it is not tested on a real device.
Fixes: b453872c35cf ("[NET] ieee80211 subsystem")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Shmulik Cohen <anuk909@gmail.com>
Link: https://patch.msgid.link/20260812190412.18333-2-anuk909@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
index c8841f9b9ad91..2661dac6985e4 100644
--- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
@@ -1421,6 +1421,9 @@ static void libipw_process_probe_response(struct libipw_device
#endif
unsigned long flags;
+ if (stats->len < sizeof(*beacon))
+ return;
+
LIBIPW_DEBUG_SCAN("'%*pE' (%pM): %c%c%c%c %c%c%c%c-%c%c%c%c %c%c%c%c\n",
info_element->len, info_element->data,
beacon->header.addr3,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 052/438] wifi: libipw: reject too-short association responses
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (50 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 051/438] wifi: libipw: reject too-short beacon and probe responses Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 053/438] IB/IPoIB: Avoid restoring OPER_UP after multicast flush Greg Kroah-Hartman
` (397 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shmulik Cohen, Johannes Berg,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shmulik Cohen <anuk909@gmail.com>
[ Upstream commit adb7118b7d2cfd7e8213c17d7d2829f353017754 ]
libipw_handle_assoc_resp() reads the capability, status and aid fields
of the 30-byte association response prefix and then computes the
information element length as
stats->len - sizeof(*frame)
stats->len is a u16 and sizeof() has type size_t, so the subtraction is
evaluated as size_t and wraps instead of going negative. Truncating
that to the u16 length parameter of libipw_parse_info_param() turns a
frame shorter than the fixed fields into a length near 64 KiB, and the
parser then reads past the receive buffer.
Both the ipw2100 and ipw2200 management receive paths reach this
function having established only that the frame carries the generic
24-byte three-address header.
Reject the frame before any fixed field is touched.
Found by an AI-assisted review of length arithmetic in management frame
parsers. Verified with a KUnit case under Generic KASAN on arm64 under
QEMU; I do not have the hardware, so it is not tested on a real device.
Fixes: 9e8571affd1c ("[PATCH] ieee80211: Add QoS (WME) support to the ieee80211 subsystem")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Shmulik Cohen <anuk909@gmail.com>
Link: https://patch.msgid.link/20260812190412.18333-3-anuk909@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
index 2661dac6985e4..424349a6935e4 100644
--- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
@@ -1209,6 +1209,9 @@ static int libipw_handle_assoc_resp(struct libipw_device *ieee, struct libipw_as
struct libipw_network *network = &network_resp;
struct net_device *dev = ieee->dev;
+ if (stats->len < sizeof(*frame))
+ return 1;
+
network->flags = 0;
network->qos_data.active = 0;
network->qos_data.supported = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 000/398] 6.18.54-rc1 review
@ 2026-09-23 14:01 Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 001/398] Revert "perf annotate: Fix build with NO_SLANG=1" Greg Kroah-Hartman
` (402 more replies)
0 siblings, 403 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, linux-kernel, torvalds, akpm, linux,
shuah, patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
This is the start of the stable review cycle for the 6.18.54 release.
There are 398 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Fri, 25 Sep 2026 14:05:48 +0000.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.18.54-rc1.gz
or in the git tree and branch at:
git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.18.y
and the diffstat can be found below.
thanks,
greg k-h
-------------
Pseudo-Shortlog of commits:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Linux 6.18.54-rc1
April Cardenas <april.cardenas@canonical.com>
smb/client: send lease break ACKs thru correct session for multiuser mounts
Namjae Jeon <linkinjeon@kernel.org>
Revert "ksmbd: Fix to handle removal of rfc1002 header from smb_hdr"
Zijun Hu <zijun.hu@oss.qualcomm.com>
Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device
Bard Liao <yung-chuan.liao@linux.intel.com>
ASoC: sdw_utils: subtract the endpoint that is not present
Dmitry Antipov <dmantipov@yandex.ru>
wifi: mac80211: fix list iteration in ieee80211_add_virtual_monitor()
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: fix partial normalized name responses
Maoyi Xie <maoyixie.tju@gmail.com>
time/namespace: Export init_time_ns and do_timens_ktime_to_host()
Frank Sorenson <sorenson@redhat.com>
smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
Daehyeon Ko <4ncienth@gmail.com>
wifi: libipw: reject TKIP frames without a full MIC
Eric Biggers <ebiggers@kernel.org>
wifi: ipw2x00: Use michael_mic() from cfg80211
Eric Biggers <ebiggers@kernel.org>
wifi: mac80211, cfg80211: Export michael_mic() and move it to cfg80211
Eric Biggers <ebiggers@kernel.org>
wifi: ipw2x00: Rename michael_mic() to libipw_michael_mic()
Mike Lothian <mike@fireburn.co.uk>
drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments
Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
drm/amdgpu: lock bo before calling amdgpu_vm_bo_update_shared
Darrick J. Wong <djwong@kernel.org>
xfs: fix under-reservation of blocks when repairing sf directories
Christoph Hellwig <hch@lst.de>
xfs: remove the i_ino field in struct xfs_inode
Christoph Hellwig <hch@lst.de>
xfs: convert xchk_inode_xref_set_corrupt to xchk_ip_xref_set_corrupt
Christoph Hellwig <hch@lst.de>
xfs: add a xfs_rmap_inode_owner helper
Fan Wu <fanwu01@zju.edu.cn>
smb: client: fix cifsFileInfo reference leak in deferred close
Arun Easi <aeasi@cisco.com>
scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU
Karan Tilak Kumar <kartilak@cisco.com>
scsi: fnic: Bump up version number again
Karan Tilak Kumar <kartilak@cisco.com>
scsi: fnic: Make debug logging protocol independent
Karan Tilak Kumar <kartilak@cisco.com>
scsi: fnic: Bump up version number
Karan Tilak Kumar <kartilak@cisco.com>
scsi: fnic: Rename fnic_scsi_fcpio_reset()
Devin Wittmayer <lucid_duck@justthetip.ca>
wifi: mac80211: refuse to make a monitor active when it has no queue
Benjamin Berg <benjamin.berg@intel.com>
wifi: mac80211: track MU-MIMO configuration on disabled interfaces
Lorenzo Stoakes (ARM) <ljs@kernel.org>
mm/vma: correctly unaccount on mmap_prepare() failure
David Howells <dhowells@redhat.com>
9p: Fix v9fs_issue_write() to update i_size and remote_i_size
David Howells <dhowells@redhat.com>
cifs: Fix specification of function pointers
Lorenzo Stoakes (ARM) <ljs@kernel.org>
mm/huge_memory: bypass THP tuneables for huge pfnmap mappings
David Hildenbrand (Arm) <david@kernel.org>
mm: move vma_kernel_pagesize() from hugetlb to mm.h
Zhiling Zou <zhilinz@nebusec.ai>
xfrm: save input state data before secpath resets
Dong Chenchen <dongchenchen2@huawei.com>
xfrm: Fix dev use-after-free in xfrm async resumption
Jianbo Liu <jianbol@nvidia.com>
xfrm: Refactor xfrm_input lock to reduce contention with RSS
Thomas Gleixner <tglx@kernel.org>
signal: Prevent exec() race
Thomas Gleixner <tglx@linutronix.de>
signal: Move MMCID exit out of sighand lock
Xiang Mei <xmei5@asu.edu>
ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity
Takashi Iwai <tiwai@suse.de>
ALSA: usb-audio: Optimize the copy of packet sizes for implicit fb handling
Zizhi Wo <wozizhi@huawei.com>
smb: client: fix busy dentry warning on unmount after DIO
Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
ntsync: reject wait ioctls with zero owner
Maoyi Xie <maoyixie.tju@gmail.com>
ntsync: Honour caller's time namespace for absolute MONOTONIC timeouts
Antheas Kapenekakis <lkml@antheas.dev>
HID: asus: fortify keyboard handshake
Frank Sorenson <sorenson@redhat.com>
smb: client: fix missing iov bounds check in parse_posix_sids()
Frank Sorenson <sorenson@redhat.com>
smb: client: fix missing lower-bound check on DFS referral string offsets
Frank Sorenson <sorenson@redhat.com>
smb: client: fix server->total_read for compound encrypted PDUs
Frank Sorenson <sorenson@redhat.com>
smb: client: fix potential OOB read in smb3_enum_snapshots()
Frank Sorenson <sorenson@redhat.com>
smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
Frank Sorenson <sorenson@redhat.com>
smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
Paulo Alcantara <pc@manguebit.org>
smb: client: fix unaligned access in WSL reparse point parser
Paulo Alcantara <pc@manguebit.org>
smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
Frank Sorenson <sorenson@redhat.com>
smb: client: reject short Next offsets in parse_server_interfaces()
Joseph Qi <joseph.qi@linux.alibaba.com>
smb: client: fix use-after-free of iface in cifs_try_adding_channels()
Paulo Alcantara <pc@manguebit.org>
smb: client: fix rlist race and missing initialization
Paulo Alcantara <pc@manguebit.org>
smb: client: cancel reconnect work in clean_demultiplex_info()
Chengjun Yao <Chengjun.Yao@amd.com>
drm/amdgpu: fix rmmio iounmap skipped on device removal
Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
drm/msm: RCU-free the scheduler-containing ring and VM objects
Guangshuo Li <lgs201920130244@gmail.com>
drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure
Saim Shujah <saimzst@gmail.com>
drm/msm/dpu: clear pending peripheral flush state
Guangshuo Li <lgs201920130244@gmail.com>
drm/msm/adreno: fix autosuspend cleanup during teardown
Sophie D <patches@scd31.com>
drm/gud: Ignore damage clips in full update mode
Sajal Gupta <sajal2005gupta@gmail.com>
drm/gud: fix out-of-bounds write in gud_plane_atomic_check()
Rik van Riel <riel@surriel.com>
wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver
Zhao Li <enderaoelyther@gmail.com>
wifi: mwifiex: validate action frame fixed fields
Linmao Li <lilinmao@kylinos.cn>
wifi: mwifiex: prevent authentication frame length truncation
Pengpeng Hou <pengpeng@iscas.ac.cn>
wifi: mwifiex: validate scan response extents
Doruk Tan Ozturk <doruk@0sec.ai>
wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length
Shengzhuo Wei <me@cherr.cc>
wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
Shengzhuo Wei <me@cherr.cc>
wifi: p54: validate curve data length in the calibration curve converters
Tianchu Chen <flynnnchen@tencent.com>
wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext()
Ali Ahmet Memis <ali@iusegentoo.com>
wifi: wilc1000: fix out-of-bounds read in P2P public action frames
Runyu Xiao <runyu.xiao@seu.edu.cn>
wifi: wlcore: release runtime PM ref on regdomain config failure
Fan Wu <fanwu01@zju.edu.cn>
wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown
Tianchu Chen <flynnnchen@tencent.com>
wifi: rsi: fix heap OOB write on key removal
Jiangshan Yi <yijiangshan@kylinos.cn>
wifi: libertas_tf: fix UAF in lbtf_free_adapter()
Stanislaw Gruszka <stf_xl@wp.pl>
wifi: iwlegacy: fix broadcast stations deallocation
Jiangshan Yi <yijiangshan@kylinos.cn>
wifi: brcmsmac: fix UAF in brcms_free_timer()
Wentao Liang <vulab@iscas.ac.cn>
watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start()
Wentao Liang <vulab@iscas.ac.cn>
watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init()
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: rzv2h: Avoid division by zero
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: rtd119x: Avoid division by zero
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: msc313e: Propagate error code in resume()
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: msc313e: Fix premature reset during timeout update
Tzung-Bi Shih <tzungbi@kernel.org>
watchdog: digicolor: Avoid division by zero
Li Jun <lijun01@kylinos.cn>
watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
hwmon: (cgbc-hwmon) Add missing sensors
Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
hwmon: (cgbc-hwmon) Fix current sensors ID lookup
Guangshuo Li <lgs201920130244@gmail.com>
hwmon: (w83793) release probe data through kref
Guangshuo Li <lgs201920130244@gmail.com>
hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
Yibo Tan <lhfff@tju.edu.cn>
hwmon: (pwm-fan) Stop RPM timer before freeing tach data
Sanman Pradhan <psanman@juniper.net>
hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
Sanman Pradhan <psanman@juniper.net>
hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
Nuno Sá <nuno.sa@analog.com>
hwmon: (pmbus/core) increase number of phases and add new mask
Muhammad Bilal <meatuni001@gmail.com>
hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Input: zero ff_effect before compat copy in input_ff_effect_from_user
Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
Raphaël Larocque <rlarocque@disroot.org>
Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
Hans de Goede <johannes.goede@oss.qualcomm.com>
Input: soc_button_array - check btns_desc->package.count
Hans de Goede <johannes.goede@oss.qualcomm.com>
Input: soc_button_array - fix MS Surface Pro 11 probe failure
Dmitry Torokhov <dmitry.torokhov@gmail.com>
Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
Chris Sommers <chris.sommers@icloud.com>
Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
Runyu Xiao <runyu.xiao@seu.edu.cn>
Input: hp_sdc - shut down kicker timer on module exit
Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Input: evdev - zero absinfo before partial copy in EVIOCSABS
Linkai Gong <gonglinkai@kylinos.cn>
Input: cyttsp5 - clamp the HID report size before memcpy
Alexei Turtanov <9alexei9@gmail.com>
Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
Alvin Šipraga <alvin.sipraga@analog.com>
Input: adp5588-keys - cache GPIO state before registering the gpiochip
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning failure
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Clear ITAPDLY on tuning failure
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Reset command and data lines on failed tuning
Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
mmc: sdhci_am654: Move tuning_loop to local variable
Xu Rao <raoxu@uniontech.com>
mmc: spi: reset bytes_xfered before retrying CRC failures
Runyu Xiao <runyu.xiao@seu.edu.cn>
mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt
Felix Gu <ustc.gu@gmail.com>
mmc: sdio_uart: fix xmit_fifo leak when the port table is full
Myeonghun Pak <mhun512@gmail.com>
mmc: sdhci-of-aspeed: Remove children before releasing SDC resources
Florian Maillard <florian.maillard@mailoo.org>
mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260
Fan Wu <fanwu01@zju.edu.cn>
mmc: mxcmmc: cancel data work and watchdog on remove
Fan Wu <fanwu01@zju.edu.cn>
mmc: mmci: Fix use-after-free in busy-timeout work
Fan Wu <fanwu01@zju.edu.cn>
mmc: hsq: Fix use-after-free in retry work
Zhu Ling <zhuling0805@qq.com>
mmc: core: Fix OF node reference leak on card add failure
Fan Wu <fanwu01@zju.edu.cn>
mmc: core: Cancel SDIO IRQ work before freeing host
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
power: sequencing: fix NULL-pointer dereference in pwrseq_device_register()
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new()
Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
power: sequencing: don't call .post_enable() if pwrseq_unit_enable() failed
Christian Göttsche <cgzones@googlemail.com>
selinux: always fill AVC decision in avc_has_perm_noaudit()
Karl Mehltretter <kmehltretter@gmail.com>
selinux: recheck intermediate backing files on mprotect()
Karl Mehltretter <kmehltretter@gmail.com>
selinux: preserve user SID across nested backing files
Shuhei Takeshita <jyohuku.alterego@gmail.com>
IB/hfi1: Fix the PIO_CRED credit-return mmap
Shuhei Takeshita <jyohuku.alterego@gmail.com>
IB/hfi1: Resolve the credit-return buffer through the send context's node
Shuangpeng Bai <shuangpeng.kernel@gmail.com>
IB/mlx4: Fix use-after-free on pkey sysfs registration failure
Guangshuo Li <lgs201920130244@gmail.com>
i2c: imx: disable autosuspend on remove
Shengzhuo Wei <me@cherr.cc>
i2c: imx: release DMA channels on probe error
Liu Zhenlong <dragonliu2018@gmail.com>
i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
Linkai Gong <gonglinkai@kylinos.cn>
i2c: atr: fix dangling adapter pointer on add failure
Shengzhuo Wei <me@cherr.cc>
i2c: at91: release DMA channels on remove and probe error
Jarkko Sakkinen <jarkko@kernel.org>
KEYS: trusted: Fix tpm2_load_cmd() boundary check
Maoyi Xie <maoyixie.tju@gmail.com>
keys: translate request_key_auth pid for the reading procfs instance
Cen Zhang <cenzhang@linux.microsoft.com>
KEYS: encrypted: fix integer overflow of datablob_len
Wenjie Qi <qiwenjie@xiaomi.com>
mm: filemap: retain mapped dropbehind folios
Lorenzo Stoakes (ARM) <ljs@kernel.org>
mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP
Shakeel Butt <shakeel.butt@linux.dev>
mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio()
Nhat Pham <nphamcs@gmail.com>
mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count
Yifei Gao <gyf161023@gmail.com>
memstick: ms_block: destroy io_queue workqueue on removal
Shakeel Butt <shakeel.butt@linux.dev>
memcg: avoid charging the root memcg from obj_cgroup_charge_pages()
Alexey Klimov <alexey.klimov@linaro.org>
soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node
Siwei Zhang <fourdizhang@tencent.com>
xfrm: use hlist_del_init_rcu for state_cache and state_cache_input
Chengfeng Ye <nicoyip.dev@gmail.com>
xfrm: serialize state GC with device state flush
Alberto Carboneri <acarboneri@drivesec.com>
scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()
Mark Amirkan <markdamirkan@gmail.com>
net/packet: avoid truncating TPACKET_V3 private size
Mark Amirkan <markdamirkan@gmail.com>
net/packet: clear RX owner on VNET header error
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: hhf: cap hh_flows_limit at change time
Xuanqiang Luo <luoxuanqiang@kylinos.cn>
net/sched: act_api: release tail references on DELACTION failure
Guanglei Zhu <zhugl3@xiaopeng.com>
net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value
Guanglei Zhu <zhugl3@xiaopeng.com>
net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain
Guanglei Zhu <zhugl3@xiaopeng.com>
net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()
Ahmed Naseef <naseefkm@gmail.com>
net: phy: mediatek: do not report link and per-speed LED rules together
Mark Amirkan <markdamirkan@gmail.com>
net: lan743x: fix RX checksum use-after-free
Gris Ge <cnfourt@gmail.com>
net: ip_tunnel: initialize `options_len` before referencing options
Zhiling Zou <zhilinz@nebusec.ai>
ipv6: xfrm: use full sockets in local error paths
Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
Christian Lugnberg <christian.lugnberg@soundtrack.io>
dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
Christian Lugnberg <christian.lugnberg@soundtrack.io>
dmaengine: sun6i: fix non-atomic read of DMA position registers
Guanghui Yang <3497809730@qq.com>
btrfs: clear free space tree creation state on rebuild failure
Hongling Zeng <zenghongling@kylinos.cn>
btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
Chengfeng Ye <nicoyip.dev@gmail.com>
Bluetooth: hci_sync: Serialize local codec list cleanup
Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Bluetooth: hci_codec: validate vendor codec count length
Aamir Ahmed <elb12345@hotmail.co.uk>
Bluetooth: eir: validate service data length before reading UUID
Nicolas Thibert <nithibert@gmail.com>
Bluetooth: btusb: fix NXP IW610 composite device handling
Mark Rutland <mark.rutland@arm.com>
arm64: percpu: Fix LSE operations on {8,16}-bit types
Mark Rutland <mark.rutland@arm.com>
arm64: percpu: Fix this_cpu_and() mask generation
Mark Rutland <mark.rutland@arm.com>
arm64: percpu: Fix this_cpu_write() casting
Koichiro Den <den@valinux.co.jp>
arm64: dts: renesas: r8a779f0: Set UFS lane count
Bradley Morgan <include@grrlz.net>
arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
Thomas Huth <thuth@redhat.com>
kselftest/arm64: Fix size of thread_data values for pthread_join()
Benoît Sevens <bsevens@google.com>
HID: logitech-hidpp: fix race condition when accessing stale stack pointer
Wyatt Feng <wf.kernel.dev@gmail.com>
net: xfrm: reject unrepresentable espintcp transport headers
Zhiling Zou <zhilinz@nebusec.ai>
openvswitch: avoid reallocating confirmed conntrack labels
Jeffin Philip <jeffinphilip14@gmail.com>
RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
Quanye Yang <quanyeyang@proton.me>
RDMA/ucma: Serialize join and leave on copy_to_user failure
Hao-Qun Huang <alvinhuang0603@gmail.com>
spi: virtio: Use the per-transfer bits per word
Itai Handler <itai.handler@gmail.com>
spi: spi-zynqmp-gqspi: stop the controller on shutdown
Frieder Schrempf <frieder.schrempf@kontron.de>
spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
swiotlb: use the adjusted address for the highmem page lookup
Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
tcp: exclude old ACKs from tcp fast path
Chang S. Bae <chang.seok.bae@intel.com>
x86/microcode/intel: Reject problematic loading on Granite Rapids systems
Chang S. Bae <chang.seok.bae@intel.com>
x86/build/64: Prevent native builds from generating EGPR use
Lyude Paul <lyude@redhat.com>
drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP
Lyude Paul <lyude@redhat.com>
drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr
Lyude Paul <lyude@redhat.com>
drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini()
Lyude Paul <lyude@redhat.com>
Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware"
Chunfeng Song <springbreeze@stu.pku.edu.cn>
rust: net: phy: fix off-by-one bit positions in device status accessors
Aohan Mei <henrymei@tencent.com>
rds: ib: use rds_conn_drop() on protocol version mismatch
Thomas Gleixner <tglx@kernel.org>
posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context
Seunguk Shin <seunguk.shin@arm.com>
fs/dax: check zero or empty entry before converting xarray entry
Hyunwoo Kim <imv4bel@gmail.com>
exec: Cleanup POSIX timers right after de_thread()
Wentao Liang <vulab@iscas.ac.cn>
cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
Wentao Liang <vulab@iscas.ac.cn>
ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
Niklas Cassel <cassel@kernel.org>
ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
Jiangshan Yi <yijiangshan@kylinos.cn>
ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type
Yuho Choi <oss.patchbox@gmail.com>
ALSA: virtio: reset device before deleting virtqueues
Takashi Iwai <tiwai@suse.de>
ALSA: core: Fix potential UAF after asynchronous card release
Jeremy Nyberg <slickstretch3.0@gmail.com>
Input: xpad - fix PDP Marvel Xbox 360 controller
Roberts Kursitis <roberts.kursitis@azeron.eu>
Input: xpad - add support for Azeron devices
Erich Sartison <byt.es@mailbox.org>
Input: xpad - add support for Victrix Pro BFG Controller
Bitterblue Smith <rtl8821cerfe2@gmail.com>
wifi: rtw88: TX QOS Null data the same way as Null data
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
ACPI: processor: Update cpuidle driver check in __acpi_processor_start()
Li Jun <lijun01@kylinos.cn>
watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog
James Seo <james@equiv.tech>
hwmon: (hp-wmi-sensors) Improve raw WMI string handling
Cong Nguyen <congnt264@gmail.com>
hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler
hpp.iscas <hppiscas@163.com>
Input: eeti_ts - publish the OF module alias
Matthew Schwartz <matthew.schwartz@linux.dev>
x86/fred: Reconstruct the #GP context for rejected INT instructions
Filipe Manana <fdmanana@suse.com>
btrfs: check if there is space for chunk item when validating sys chunk array
Filipe Manana <fdmanana@suse.com>
btrfs: abort transaction on failure to update inode for hole punching and reflinking
Dmitriy Chumachenko <Dmitry.Chumachenko@cyberprotect.ru>
drm/amdgpu: check ras and obj before dereference
Eric Dumazet <edumazet@google.com>
net: skbuff: do not leave stale header offsets after pskb_carve()
Dmitriy Okunev <dokunevdmitriy@gmail.com>
net: mvpp2: prevent buffer overflow in page_pool allocation
James Clark <jjc@jclark.com>
net: macb: fix ordering around PTP timestamp read
Jinke Han <jinkehan@didiglobal.com>
x86/kprobes: Fix crash when probing CS CALL instructions
Josh Poimboeuf <jpoimboe@kernel.org>
x86/alternative: Refactor INT3 call emulation selftest
Daniel Zahka <daniel.zahka@gmail.com>
net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: stmmac: propagate FPE preemption-class mapping errors
Linus Walleij <linusw@kernel.org>
net: ethernet: cortina: Ack RX overrun interrupt correctly
Eric Dumazet <edumazet@google.com>
net: lock the socket in sock_gettstamp()
Jakub Kicinski <kuba@kernel.org>
eth: fbnic: ring the doorbell if a burst ends in a drop
Yige Jiang <yigejiang86@gmail.com>
net: netsec: fix device_node reference leak on phy_np
Vijendar Mukunda <Vijendar.Mukunda@amd.com>
ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID
Vijendar Mukunda <Vijendar.Mukunda@amd.com>
ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver
Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints()
Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
ASoC: sdw_utils: tidyup .count_sidecar
Charles Keepax <ckeepax@opensource.cirrus.com>
ASoC: intel: sof_sdw: Add ability to have auxiliary devices
Charles Keepax <ckeepax@opensource.cirrus.com>
ASoC: sdw_utils: Add codec_conf for every DAI
Vijendar Mukunda <Vijendar.Mukunda@amd.com>
ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers
HyeongJun An <sammiee5311@gmail.com>
ASoC: hdmi-codec: Report a change when the channel status moves
Sasha Levin <sashal@kernel.org>
ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments
Daniel Linjama <daniel@dev.linjama.com>
btrfs: handle lack of space when cleaning up verity items
Sun YangKai <sunk67188@gmail.com>
btrfs: more trivial BTRFS_PATH_AUTO_FREE conversions
Peter Zijlstra <peterz@infradead.org>
futex: Also allocate private hash on vfork()
Shivaprasad G Bhat <sbhat@linux.ibm.com>
powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
Amit Machhiwal <amachhiw@linux.ibm.com>
KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure
Amit Machhiwal <amachhiw@linux.ibm.com>
KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
net: stmmac: do not overwrite phc_index when no PTP clock is registered
Eric Dumazet <edumazet@google.com>
drop_monitor: fix out-of-bounds write in reset_per_cpu_data()
Eric Dumazet <edumazet@google.com>
drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown
Eric Dumazet <edumazet@google.com>
drop_monitor: synchronize tracepoint unregistration on error path
Eric Dumazet <edumazet@google.com>
pppoatm: ensure a writable skb header and linear data
Kuniyuki Iwashima <kuniyu@google.com>
af_unix: Unify scc_index when finalising SCC in __unix_walk_scc().
Juan Perdomo <jcperdomo100@gmail.com>
Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
Sai Teja Aluvala <aluvala.sai.teja@intel.com>
Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
Tzung-Bi Shih <tzungbi@kernel.org>
Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown
Chris Lu <chris.lu@mediatek.com>
Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events
Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync
Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()
Ibrahim Abdelkader <iabdelka@qti.qualcomm.com>
Bluetooth: hci_qca: Do not write to the serial port after it is closed
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Bluetooth: qca: enable pwrseq support for WCN39xx devices
Vivek Sahu <vivek.sahu@oss.qualcomm.com>
Bluetooth: qca: Refactor code on the basis of chipset names
Mengshi Wu <mengshi.wu@oss.qualcomm.com>
Bluetooth: hci_qca: Refactor HFP hardware offload capability handling
Weiming Shi <bestswngs@gmail.com>
Bluetooth: coredump: Quiesce dump work on unregister
Chandrashekar Devegowda <chandrashekar.devegowda@intel.com>
Bluetooth: btintel_pcie: validate TX skb length in send_sync
ThangNN99 <ngocthang2710.1999@gmail.com>
Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
Baineng Shou <shoubaineng@gmail.com>
dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: keep compound responses on query info errors
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: fix partial file information responses
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: return buffer overflow for partial filesystem info
Eric Dumazet <edumazet@google.com>
tcp: do not let tcp_rmem be set below 4096
Kuniyuki Iwashima <kuniyu@google.com>
tcp: Don't call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().
Nikolay Aleksandrov <razor@blackwall.org>
net: bridge: mst: move switchdev call outside rcu
Karl Mehltretter <kmehltretter@gmail.com>
wifi: brcmfmac: fix lost 802.1x TX completion wakeup
Hohyun Sim <tlaghgus0425@korea.ac.kr>
net: fddi: skfp: fix NULL deref when setting the MAC address while down
Dong Chenchen <dongchenchen2@huawei.com>
ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
Nicolai Buchwitz <nb@tipi-net.de>
net: bcmgenet: restore the hardware filters on open
Nicolai Buchwitz <nb@tipi-net.de>
net: bcmgenet: convert RX path to page_pool
Andrea Mayer <andrea.mayer@uniroma2.it>
seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL
Filipe Manana <fdmanana@suse.com>
btrfs: tree-checker: print dev extent offset in error message
Nicolas Escande <nico.escande@gmail.com>
wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()
Slavin Liu <bolin.liu@seu.edu.cn>
ALSA: hda: trace PCM open only after assigning a stream
Karl Mehltretter <kmehltretter@gmail.com>
drm/vc4: Use managed KMS polling to fix UAF on unbind
Shuicheng Lin <shuicheng.lin@intel.com>
drm/xe/shrinker: Return the freed page count through a parameter
Shuicheng Lin <shuicheng.lin@intel.com>
drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy
Ilia Levi <ilia.levi@intel.com>
drm/xe/mmio_gem: use write-back mapping for dummy page
Ilia Levi <ilia.levi@intel.com>
drm/xe/mmio_gem: forbid VMA split
Zihan Xi <zihanx@nebusec.ai>
wifi: virt_wifi: don't transfer operstate before register
Xiang Mei <xmei5@asu.edu>
ALSA: 6fire: fix OOB write from device-reported iso length
Takashi Iwai <tiwai@suse.de>
ALSA: usb: 6fire: Avoid embedded URBs
Runyu Xiao <runyu.xiao@seu.edu.cn>
gpio: virtuser: skip free_irq when no IRQ is installed
Karl Mehltretter <kmehltretter@gmail.com>
Input: trackpoint - fix the inertia attribute name in the ABI document
Gabor Juhos <j4g8y7@gmail.com>
spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register
Richard Fitzgerald <rf@opensource.cirrus.com>
ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params
Richard Fitzgerald <rf@opensource.cirrus.com>
ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map
Richard Fitzgerald <rf@opensource.cirrus.com>
ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask
William Bright <william.bright@imd-tec.com>
drm/msm/dp: fix link bandwidth check when wide bus is enabled
Jesse Casco <jesse.casco@gmail.com>
drm/msm/dp: skip PUSH_IDLE when the link was never enabled
Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
ALSA: pcm: set timer->private_data before registering the PCM timer
AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting
AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow
Takashi Iwai <tiwai@suse.de>
ALSA: bcd2000: Fix race between rawmidi and disconnect
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Skip default parms when resumed in neightbl_dump_info().
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Add missing RCU annotation for neightbl_dump_info().
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Convert RTM_GETNEIGHTBL to RCU.
Kuniyuki Iwashima <kuniyu@google.com>
neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.
Karl Mehltretter <kmehltretter@gmail.com>
keys: fix lost wakeup when reaping a dead key type
Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
Breno Leitao <leitao@debian.org>
arm64: hibernate: clone only the linear map that exists at runtime
Shouping Wang <allen.wang@hj-micro.com>
perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: flowtable: hold reference on ct until flow is released
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: nf_nat: unregister and release hooks on error
Fernando Fernandez Mancera <fmancera@suse.de>
netfilter: nf_tables: fix device name and prefix match in hook lookup
Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
netfilter: nft_nat: fully initialise new_addr in netmap setup
Karl Mehltretter <kmehltretter@gmail.com>
drm/msm/adreno: Fix the skip_gpu parameter description
Karl Mehltretter <kmehltretter@gmail.com>
drm/msm: Fix the separate_gpu_kms parameter description
Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
RDMA/siw: Bound fragmented header copies by the remaining length
Leon Romanovsky <leon@kernel.org>
RDMA/efa: Keep EQ resources alive while IRQ is registered
Leon Romanovsky <leon@kernel.org>
RDMA/efa: Keep admin queues alive while IRQ is registered
Alex Bereza <alex@bereza.email>
dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
Alex Bereza <alex@bereza.email>
dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
Karl Mehltretter <kmehltretter@gmail.com>
scsi: qla2xxx: Fix the ql2xfc2target parameter description
Meijing Zhao <zhaomeijing@lixiang.com>
mm: memblock: show all region flags in debugfs
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: set up the TX info early to fix failure paths
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: mesh: release the channel if start fails
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: mesh: reset the CSA state when leaving
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: add HE 6 GHz capability in the scan elems len
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't access the TSF of a down interface
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't RCU-dereference the mesh CSA settings we just set
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't allow link changes when iface is down
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: require a peer station for TDLS setup confirm
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't allow injecting frames wider than the chanctx
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211_hwsim: don't hand frames to mac80211 while stopping
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: get the wiphy out of a dying network namespace
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: unlist vifs when their netdev is unregistered
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: undo netns switch if renaming the wiphy fails
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: restore netns_immutable on failures
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: reset state when starting AP fails
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: abort chanswitch when leaving a mesh
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: suppress chanctx warning for debugfs reset
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't offload TC setup on AP_VLAN interfaces
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't warn when an IBSS has no channel to scan
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: don't start a ROC while scanning
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: don't filter by BSS type when removing stale entries
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: only group hidden BSSes with beacon entries
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: don't free driver-owned scan requests
Shivank Garg <shivankg@amd.com>
dmaengine: wait for RCU readers before releasing dma_device
Shivank Garg <shivankg@amd.com>
dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
Shivank Garg <shivankg@amd.com>
dmaengine: Fix device kref underflow in dma_chan_put()
Donggeun Yoo <donggeunyoo.kernel@gmail.com>
dma-coherent: report a failed reserved memory assignment
Orgad Shaneh <orgads@gmail.com>
MIPS: Octeon: apply USB FDT fixups also when USB is modular
Bard Liao <yung-chuan.liao@linux.intel.com>
soundwire: cadence_master: wait and cancel cdns->work before clock stop
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: check IP header size in cfg80211_classify8021d()
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: don't get the radio mask for netdev-less wdevs
Carolina Jubran <cjubran@nvidia.com>
IB/IPoIB: Avoid restoring OPER_UP after multicast flush
Shmulik Cohen <anuk909@gmail.com>
wifi: libipw: reject too-short association responses
Shmulik Cohen <anuk909@gmail.com>
wifi: libipw: reject too-short beacon and probe responses
Bogdan Nicolae <bogdan.nicolae@gmail.com>
wifi: brcmfmac: cyw: pass PMKID to firmware if present
Peng Hao <flyingpenghao@gmail.com>
wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path
Mariano Baragiola <mbaragiola@linux.com>
wifi: virt_wifi: free skb when disconnected
Lachlan Hodges <lachlan.hodges@morsemicro.com>
wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic
Ruoyu Wang <ruoyuw560@gmail.com>
dmaengine: sprd: Fix runtime PM reference leak in probe
Quanye Yang <quanyeyang@proton.me>
RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
Jacob Moroni <jmoroni@google.com>
RDMA/irdma: Enforce local fence for IB_WR_REG_MR
Li RongQing <lirongqing@baidu.com>
RDMA/mad: Fix receive buffer leak when PKey enforcement fails
Linkai Gong <gonglinkai@kylinos.cn>
RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
IB/isert: wait for deferred control PDU completions before releasing the connection
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
IB/iser: reject a remote invalidation of an unregistered direction
Ovidiu Panait <ovidiu.panait.rb@renesas.com>
arm64: dts: renesas: r9a09g047: Switch GBETH TX queue scheduling to WRR
Ovidiu Panait <ovidiu.panait.rb@renesas.com>
arm64: dts: renesas: r9a09g056: Switch GBETH TX queue scheduling to WRR
Ovidiu Panait <ovidiu.panait.rb@renesas.com>
arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR
Biju Das <biju.das.jz@bp.renesas.com>
power: sequencing: Fix build issue with COMPILE_TEST
Krystian Kaniewski <krystianmkaniewski@gmail.com>
RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
Or Har-Toov <ohartoov@nvidia.com>
RDMA/mlx5: Remove warn on missing representor in query_port_speed
Michael Bommarito <michael.bommarito@gmail.com>
RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds
Weiming Shi <bestswngs@gmail.com>
RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths
Xixin Liu <liuxixin@kylinos.cn>
clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
Xixin Liu <liuxixin@kylinos.cn>
firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
Gang Yan <yangang@kylinos.cn>
RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
Norbert Szetei <norbert@doyensec.com>
RDMA/rxe: validate access flags before swapping the MR's PD
Guoqing Jiang <guoqing.jiang@linux.dev>
RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
Pengpeng Hou <pengpeng@iscas.ac.cn>
ARM: socfpga: select the PL310 erratum 753970 workaround
Maher Azzouzi <maherazz04@gmail.com>
esp: downgrade zerocopy managed frags before mutating skb frags
Eric Dumazet <edumazet@google.com>
xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()
Kyle Zeng <kylebot@openai.com>
xfrm: fix compat ALLOCSPI request use-after-free
Sabrina Dubroca <sd@queasysnail.net>
xfrm: avoid RCU warnings around the per-netns netlink socket
Henry Martin <bsdhenrymartin@gmail.com>
xfrm: iptfs: fix runt reassembly panic from short inner tot_len
Roshan Kumar <roshaen09@gmail.com>
xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()
Ido Schimmel <idosch@nvidia.com>
ipv6: Honor oif when choosing nexthop for locally generated traffic
Ido Schimmel <idosch@nvidia.com>
ipv6: Select best matching nexthop object in fib6_table_lookup()
Arash Golgol <arash.golgol@gmail.com>
media: video-i2c: fix buffer queue ordering
Jens Axboe <axboe@kernel.dk>
sunvdc: fix -EIO issue due to lack of retries
Günther Noack <gnoack@google.com>
selftests/landlock: Add audit test for whiteout object creation
Günther Noack <gnoack@google.com>
selftests/landlock: Add tests for whiteout object creation
Günther Noack <gnoack@google.com>
selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
Mickaël Salaün <mic@digikod.net>
selftests/landlock: Add disconnected leafs and branch test suites
Tingmao Wang <m@maowtm.org>
selftests/landlock: Add tests for access through disconnected paths
Maximilian Heyne <mheyne@amazon.de>
selftests/landlock: Explicitly disable audit in teardowns
Mickaël Salaün <mic@digikod.net>
selftests/landlock: Increase default audit socket timeout
Mickaël Salaün <mic@digikod.net>
selftests/landlock: Fix socket file descriptor leaks in audit helpers
Matthieu Buffet <matthieu@buffet.re>
selftests/landlock: Add missing connect(minimal AF_UNSPEC) test
Matthieu Buffet <matthieu@buffet.re>
selftests/landlock: Add test for TCP fast open
Matthieu Buffet <matthieu@buffet.re>
landlock: Fix TCP Fast Open connection bypass
Sasha Levin <sashal@kernel.org>
Revert "perf annotate: Fix build with NO_SLANG=1"
-------------
Diffstat:
.../ABI/testing/sysfs-devices-platform-trackpoint | 2 +-
Documentation/hwmon/cgbc-hwmon.rst | 42 +-
Documentation/netlink/specs/rt-neigh.yaml | 3 +
Documentation/networking/ip-sysctl.rst | 4 +-
Makefile | 4 +-
arch/arm/mach-socfpga/Kconfig | 2 +-
arch/arm64/boot/dts/renesas/r8a779f0.dtsi | 1 +
arch/arm64/boot/dts/renesas/r9a09g047.dtsi | 10 +
arch/arm64/boot/dts/renesas/r9a09g056.dtsi | 10 +
arch/arm64/boot/dts/renesas/r9a09g057.dtsi | 10 +
arch/arm64/include/asm/percpu.h | 20 +-
arch/arm64/kernel/hibernate-asm.S | 2 +
arch/arm64/kernel/hibernate.c | 4 +-
arch/mips/cavium-octeon/octeon-platform.c | 4 +-
arch/powerpc/kernel/iommu.c | 2 +-
arch/powerpc/kvm/book3s_hv_nested.c | 2 +
arch/powerpc/kvm/book3s_hv_uvmem.c | 5 +-
arch/x86/Kconfig.cpu | 11 +
arch/x86/Makefile | 5 +
arch/x86/entry/entry_fred.c | 11 +-
arch/x86/include/asm/text-patching.h | 4 +-
arch/x86/kernel/alternative.c | 55 +-
arch/x86/kernel/cpu/microcode/intel.c | 26 +
arch/x86/kernel/kprobes/core.c | 5 +-
drivers/acpi/processor_driver.c | 2 +-
drivers/ata/libahci.c | 15 +-
drivers/ata/libahci_platform.c | 2 +-
drivers/block/sunvdc.c | 9 +-
drivers/bluetooth/btintel_pcie.c | 8 +-
drivers/bluetooth/btmtk.c | 7 +-
drivers/bluetooth/btmtksdio.c | 4 +-
drivers/bluetooth/btqca.c | 37 +-
drivers/bluetooth/btusb.c | 17 +
drivers/bluetooth/hci_qca.c | 80 +-
drivers/clk/clk-scpi.c | 2 +-
drivers/dma/dmaengine.c | 10 +-
drivers/dma/mmp_pdma.c | 2 +-
drivers/dma/sprd-dma.c | 3 +-
drivers/dma/sun6i-dma.c | 9 +-
drivers/dma/ti/k3-udma-glue.c | 5 +-
drivers/dma/xilinx/xilinx_dma.c | 26 +-
drivers/firmware/arm_scpi.c | 4 +-
drivers/gpio/gpio-virtuser.c | 3 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_device.c | 6 +-
drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c | 48 +
drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c | 2 +-
drivers/gpu/drm/drm_atomic_uapi.c | 13 +-
drivers/gpu/drm/gud/gud_pipe.c | 7 +-
drivers/gpu/drm/msm/adreno/adreno_device.c | 2 +-
drivers/gpu/drm/msm/adreno/adreno_gpu.c | 2 +
drivers/gpu/drm/msm/disp/dpu1/dpu_hw_ctl.c | 1 +
drivers/gpu/drm/msm/dp/dp_display.c | 21 +-
drivers/gpu/drm/msm/dsi/dsi_host.c | 36 +-
drivers/gpu/drm/msm/hdmi/hdmi_phy.c | 8 +-
drivers/gpu/drm/msm/msm_drv.c | 2 +-
drivers/gpu/drm/msm/msm_gem.h | 3 +
drivers/gpu/drm/msm/msm_gem_vma.c | 2 +-
drivers/gpu/drm/msm/msm_ringbuffer.c | 2 +-
drivers/gpu/drm/msm/msm_ringbuffer.h | 1 +
.../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/fbsr.c | 2 +-
.../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c | 8 +-
.../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c | 8 +-
.../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c | 3 +-
.../drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/gsp.h | 8 +
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h | 2 +-
drivers/gpu/drm/vc4/vc4_kms.c | 2 +-
drivers/gpu/drm/xe/xe_mmio_gem.c | 33 +-
drivers/gpu/drm/xe/xe_mmio_gem.h | 2 +-
drivers/gpu/drm/xe/xe_shrinker.c | 62 +-
drivers/hid/hid-asus.c | 34 +-
drivers/hid/hid-logitech-hidpp.c | 24 +-
drivers/hwmon/cgbc-hwmon.c | 129 +-
drivers/hwmon/gpio-fan.c | 4 +-
drivers/hwmon/hp-wmi-sensors.c | 32 +-
drivers/hwmon/pmbus/pmbus.h | 3 +-
drivers/hwmon/pmbus/tps53679.c | 11 +-
drivers/hwmon/pwm-fan.c | 13 +-
drivers/hwmon/w83791d.c | 1 +
drivers/hwmon/w83793.c | 4 +-
drivers/i2c/busses/i2c-at91-core.c | 3 +
drivers/i2c/busses/i2c-at91-master.c | 12 +-
drivers/i2c/busses/i2c-at91.h | 1 +
drivers/i2c/busses/i2c-imx.c | 3 +
drivers/i2c/busses/i2c-qcom-cci.c | 20 +-
drivers/i2c/i2c-atr.c | 1 +
drivers/infiniband/core/iwpm_util.c | 9 +-
drivers/infiniband/core/mad.c | 3 +-
drivers/infiniband/core/ucma.c | 7 +-
drivers/infiniband/core/verbs.c | 12 +-
drivers/infiniband/hw/bnxt_re/main.c | 10 +-
drivers/infiniband/hw/efa/efa_com.c | 7 +-
drivers/infiniband/hw/efa/efa_com.h | 1 +
drivers/infiniband/hw/efa/efa_main.c | 35 +-
drivers/infiniband/hw/hfi1/file_ops.c | 23 +-
drivers/infiniband/hw/irdma/verbs.c | 2 +-
drivers/infiniband/hw/mlx4/sysfs.c | 4 +
drivers/infiniband/hw/mlx5/main.c | 7 +-
drivers/infiniband/sw/rxe/rxe_mcast.c | 50 +-
drivers/infiniband/sw/rxe/rxe_mr.c | 3 +-
drivers/infiniband/sw/rxe/rxe_odp.c | 16 +-
drivers/infiniband/sw/rxe/rxe_verbs.c | 13 +-
drivers/infiniband/sw/siw/siw_cm.c | 7 +-
drivers/infiniband/sw/siw/siw_qp_rx.c | 2 +-
drivers/infiniband/ulp/ipoib/ipoib.h | 7 +
drivers/infiniband/ulp/ipoib/ipoib_ib.c | 12 +-
drivers/infiniband/ulp/ipoib/ipoib_multicast.c | 16 +-
drivers/infiniband/ulp/iser/iser_initiator.c | 16 +-
drivers/infiniband/ulp/isert/ib_isert.c | 22 +
drivers/infiniband/ulp/isert/ib_isert.h | 2 +
drivers/infiniband/ulp/rtrs/rtrs-clt.c | 8 +
drivers/infiniband/ulp/rtrs/rtrs-clt.h | 2 +
drivers/input/evdev.c | 2 +
drivers/input/input-compat.c | 2 +
drivers/input/joystick/xpad.c | 10 +-
drivers/input/keyboard/adp5588-keys.c | 12 +-
drivers/input/keyboard/atkbd.c | 8 +
drivers/input/misc/soc_button_array.c | 16 +-
drivers/input/mouse/synaptics.c | 8 +
drivers/input/rmi4/rmi_driver.c | 13 +
drivers/input/rmi4/rmi_smbus.c | 10 +-
drivers/input/serio/hp_sdc.c | 2 +-
drivers/input/serio/i8042-acpipnpio.h | 7 +
drivers/input/touchscreen/cyttsp5.c | 1 +
drivers/input/touchscreen/eeti_ts.c | 1 +
drivers/media/i2c/video-i2c.c | 5 +-
drivers/memstick/core/ms_block.c | 2 +
drivers/misc/ntsync.c | 6 +
drivers/mmc/core/bus.c | 2 +-
drivers/mmc/core/host.c | 1 +
drivers/mmc/core/sdio_uart.c | 3 +
drivers/mmc/host/mmc_hsq.c | 8 +-
drivers/mmc/host/mmc_spi.c | 1 +
drivers/mmc/host/mmci.c | 3 +
drivers/mmc/host/mxcmmc.c | 4 +
drivers/mmc/host/rtsx_pci_sdmmc.c | 5 +
drivers/mmc/host/sdhci-of-aspeed.c | 5 +-
drivers/mmc/host/sdhci_am654.c | 43 +-
drivers/mmc/host/sh_mmcif.c | 3 +-
drivers/net/ethernet/broadcom/Kconfig | 1 +
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 245 +--
drivers/net/ethernet/broadcom/genet/bcmgenet.h | 5 +-
drivers/net/ethernet/cadence/macb_ptp.c | 9 +
drivers/net/ethernet/cortina/gemini.c | 2 +-
drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 3 +-
drivers/net/ethernet/meta/fbnic/fbnic_txrx.c | 42 +-
drivers/net/ethernet/meta/fbnic/fbnic_txrx.h | 9 +-
drivers/net/ethernet/microchip/lan743x_main.c | 2 +-
drivers/net/ethernet/socionext/netsec.c | 2 +
drivers/net/ethernet/stmicro/stmmac/hwif.h | 2 +-
.../net/ethernet/stmicro/stmmac/stmmac_ethtool.c | 2 -
drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c | 19 +-
drivers/net/fddi/skfp/skfddi.c | 3 +-
drivers/net/phy/mediatek/mtk-phy-lib.c | 27 +-
drivers/net/wireless/ath/ath11k/mac.c | 25 +-
drivers/net/wireless/ath/wcn36xx/dxe.c | 2 +-
.../wireless/broadcom/brcm80211/brcmfmac/core.c | 2 +
.../broadcom/brcm80211/brcmfmac/cyw/core.c | 5 +-
.../broadcom/brcm80211/brcmsmac/mac80211_if.c | 4 +
drivers/net/wireless/intel/ipw2x00/Kconfig | 1 -
.../wireless/intel/ipw2x00/libipw_crypto_tkip.c | 130 +-
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 6 +
drivers/net/wireless/intel/iwlegacy/common.c | 2 +-
drivers/net/wireless/intersil/p54/eeprom.c | 22 +-
drivers/net/wireless/marvell/libertas_tf/main.c | 2 +-
drivers/net/wireless/marvell/mwifiex/cfg80211.c | 12 +-
drivers/net/wireless/marvell/mwifiex/pcie.c | 2 +-
drivers/net/wireless/marvell/mwifiex/scan.c | 54 +-
drivers/net/wireless/marvell/mwifiex/util.c | 10 +-
drivers/net/wireless/microchip/wilc1000/cfg80211.c | 14 +
drivers/net/wireless/microchip/wilc1000/wlan.c | 9 +
drivers/net/wireless/realtek/rtw88/tx.c | 2 +-
drivers/net/wireless/rsi/rsi_91x_mgmt.c | 2 -
drivers/net/wireless/ti/wlcore/main.c | 4 +-
drivers/net/wireless/virtual/mac80211_hwsim.c | 39 +-
drivers/net/wireless/virtual/virt_wifi.c | 4 +-
drivers/net/wwan/mhi_wwan_mbim.c | 28 +-
drivers/net/wwan/t7xx/t7xx_netdev.c | 4 +
drivers/perf/arm-cmn.c | 10 +-
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c | 4 +-
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h | 3 +
drivers/phy/renesas/phy-rcar-gen3-usb2.c | 310 +++-
drivers/power/sequencing/Kconfig | 3 +-
drivers/power/sequencing/core.c | 11 +-
drivers/scsi/fnic/fdls_disc.c | 730 ++++-----
drivers/scsi/fnic/fip.c | 119 +-
drivers/scsi/fnic/fip.h | 2 +-
drivers/scsi/fnic/fnic.h | 69 +-
drivers/scsi/fnic/fnic_fcs.c | 166 +-
drivers/scsi/fnic/fnic_fdls.h | 2 +-
drivers/scsi/fnic/fnic_isr.c | 41 +-
drivers/scsi/fnic/fnic_main.c | 89 +-
drivers/scsi/fnic/fnic_scsi.c | 264 ++-
drivers/scsi/qla2xxx/qla_os.c | 2 +-
drivers/scsi/scsi.c | 24 +-
drivers/soc/samsung/exynos-pmu.c | 7 +-
drivers/soundwire/cadence_master.c | 7 +
drivers/spi/spi-fsl-qspi.c | 5 +-
drivers/spi/spi-qpic-snand.c | 4 -
drivers/spi/spi-virtio.c | 2 +-
drivers/spi/spi-zynqmp-gqspi.c | 34 +
drivers/watchdog/da9062_wdt.c | 4 +-
drivers/watchdog/da9063_wdt.c | 4 +-
drivers/watchdog/digicolor_wdt.c | 13 +-
drivers/watchdog/msc313e_wdt.c | 16 +-
drivers/watchdog/rtd119x_wdt.c | 7 +-
drivers/watchdog/rzv2h_wdt.c | 7 +-
drivers/watchdog/sp5100_tco.c | 6 +-
drivers/watchdog/starfive-wdt.c | 2 +-
fs/9p/vfs_addr.c | 29 +-
fs/btrfs/dev-replace.c | 1 +
fs/btrfs/disk-io.c | 4 +
fs/btrfs/file.c | 4 +-
fs/btrfs/free-space-tree.c | 14 +-
fs/btrfs/inode.c | 3 +-
fs/btrfs/tree-checker.c | 2 +-
fs/btrfs/uuid-tree.c | 120 +-
fs/btrfs/verity.c | 47 +-
fs/btrfs/volumes.c | 153 +-
fs/btrfs/xattr.c | 36 +-
fs/dax.c | 9 +-
fs/exec.c | 29 +-
fs/smb/client/cifs_fs_sb.h | 1 +
fs/smb/client/cifsfs.c | 12 +
fs/smb/client/cifsglob.h | 12 +-
fs/smb/client/cifsproto.h | 8 +-
fs/smb/client/cifssmb.c | 2 +-
fs/smb/client/connect.c | 10 +
fs/smb/client/file.c | 28 +-
fs/smb/client/misc.c | 12 +-
fs/smb/client/reparse.c | 4 +-
fs/smb/client/reparse.h | 7 +-
fs/smb/client/sess.c | 104 +-
fs/smb/client/smb2inode.c | 11 +
fs/smb/client/smb2ops.c | 51 +-
fs/smb/client/smb2pdu.c | 13 +-
fs/smb/client/trace.h | 1 +
fs/smb/client/transport.c | 4 +-
fs/smb/server/server.c | 2 +-
fs/smb/server/smb2pdu.c | 89 +-
fs/smb/server/smb2pdu.h | 1 +
fs/smb/server/smb_common.c | 20 +-
fs/xfs/libxfs/xfs_bmap.c | 2 +-
fs/xfs/libxfs/xfs_da_btree.c | 2 +-
fs/xfs/libxfs/xfs_da_btree.h | 2 +
fs/xfs/libxfs/xfs_rmap.h | 2 +
fs/xfs/scrub/attr_repair.c | 4 +-
fs/xfs/scrub/bmap.c | 6 +-
fs/xfs/scrub/common.c | 6 +-
fs/xfs/scrub/common.h | 4 +-
fs/xfs/scrub/dir_repair.c | 4 +-
fs/xfs/scrub/dirtree.c | 4 +-
fs/xfs/scrub/inode.c | 6 +-
fs/xfs/scrub/nlinks.c | 2 +-
fs/xfs/scrub/reap.c | 3 +-
fs/xfs/scrub/rtbitmap.c | 4 +-
fs/xfs/scrub/rtsummary.c | 4 +-
fs/xfs/scrub/tempfile.c | 29 +-
fs/xfs/xfs_inode.h | 3 +
include/keys/request_key_auth-type.h | 2 +-
include/linux/hugetlb.h | 7 -
include/linux/ieee80211.h | 5 +
include/linux/mm.h | 24 +-
include/net/bluetooth/coredump.h | 2 +
include/net/mac80211.h | 5 +-
include/net/netns/xfrm.h | 2 +-
include/net/sock.h | 2 +
include/sound/soc.h | 3 +-
include/sound/soc_sdw_utils.h | 42 +-
kernel/dma/coherent.c | 3 +-
kernel/dma/swiotlb.c | 4 +-
kernel/exit.c | 12 +-
kernel/fork.c | 4 +-
kernel/sched/core.c | 6 +-
kernel/signal.c | 119 +-
kernel/time/namespace.c | 2 +
kernel/time/posix-cpu-timers.c | 40 +-
mm/filemap.c | 2 +-
mm/huge_memory.c | 86 +-
mm/hugetlb.c | 17 -
mm/memblock.c | 18 +-
mm/memcontrol.c | 2 +-
mm/mlock.c | 2 +-
mm/mremap.c | 9 +-
mm/swapfile.c | 2 +-
mm/vma.c | 6 +-
net/atm/pppoatm.c | 42 +-
net/bluetooth/coredump.c | 65 +-
net/bluetooth/eir.c | 10 +-
net/bluetooth/hci_codec.c | 36 +-
net/bluetooth/hci_core.c | 18 +-
net/bluetooth/hci_sync.c | 2 +
net/bluetooth/iso.c | 53 +-
net/bluetooth/rfcomm/sock.c | 13 +-
net/bridge/br_mst.c | 20 +-
net/core/drop_monitor.c | 12 +-
net/core/neighbour.c | 56 +-
net/core/skbuff.c | 32 +-
net/core/sock.c | 16 +-
net/ipv4/esp4.c | 6 +
net/ipv4/icmp.c | 17 +-
net/ipv4/ip_tunnel_core.c | 16 +-
net/ipv4/sysctl_net_ipv4.c | 4 +-
net/ipv4/tcp_input.c | 3 +-
net/ipv4/tcp_ulp.c | 4 +
net/ipv4/xfrm4_input.c | 2 -
net/ipv6/esp6.c | 6 +
net/ipv6/route.c | 22 +-
net/ipv6/seg6_local.c | 3 +
net/ipv6/tcp_ipv6.c | 3 +-
net/ipv6/xfrm6_input.c | 2 -
net/ipv6/xfrm6_output.c | 10 +-
net/mac80211/Makefile | 1 -
net/mac80211/cfg.c | 63 +-
net/mac80211/debugfs.c | 2 +-
net/mac80211/debugfs_netdev.c | 9 +
net/mac80211/ieee80211_i.h | 5 +-
net/mac80211/iface.c | 79 +-
net/mac80211/main.c | 4 +
net/mac80211/mesh.c | 34 +-
net/mac80211/michael.h | 22 -
net/mac80211/offchannel.c | 7 +
net/mac80211/pm.c | 8 +-
net/mac80211/scan.c | 2 +-
net/mac80211/tdls.c | 19 +-
net/mac80211/tx.c | 107 +-
net/mac80211/util.c | 3 +-
net/mac80211/wpa.c | 1 -
net/netfilter/nf_flow_table_core.c | 12 +-
net/netfilter/nf_nat_core.c | 46 +-
net/netfilter/nf_tables_api.c | 22 +-
net/netfilter/nft_nat.c | 2 +-
net/openvswitch/conntrack.c | 2 +-
net/packet/af_packet.c | 4 +-
net/packet/internal.h | 2 +-
net/psp/psp_sock.c | 4 +
net/rds/ib_cm.c | 2 +-
net/sched/act_api.c | 11 +-
net/sched/sch_hhf.c | 9 +-
net/unix/garbage.c | 17 +-
net/wireless/Makefile | 2 +-
net/wireless/core.c | 150 +-
net/wireless/core.h | 10 +
net/{mac80211/michael.c => wireless/michael-mic.c} | 5 +-
net/wireless/rdev-ops.h | 3 +
net/wireless/scan.c | 43 +-
net/wireless/util.c | 35 +-
net/xfrm/espintcp.c | 6 +-
net/xfrm/xfrm_input.c | 65 +-
net/xfrm/xfrm_iptfs.c | 12 +-
net/xfrm/xfrm_state.c | 9 +-
net/xfrm/xfrm_user.c | 37 +-
rust/kernel/net/phy.rs | 38 +-
scripts/generate_rust_target.rs | 5 +
security/keys/encrypted-keys/encrypted.c | 20 +-
security/keys/gc.c | 4 +-
security/keys/request_key_auth.c | 12 +-
security/keys/trusted-keys/trusted_tpm2.c | 12 +-
security/landlock/net.c | 14 +
security/selinux/avc.c | 5 +-
security/selinux/hooks.c | 158 +-
security/selinux/include/objsec.h | 10 +-
sound/core/init.c | 3 +-
sound/core/pcm_timer.c | 7 +-
sound/hda/common/controller.c | 2 +-
sound/soc/amd/acp/acp-sdw-legacy-mach.c | 33 +-
sound/soc/amd/acp/acp-sdw-sof-mach.c | 31 +-
sound/soc/codecs/hdmi-codec.c | 6 +-
sound/soc/codecs/rt712-sdca-dmic.c | 14 +-
sound/soc/intel/boards/sof_sdw.c | 21 +-
sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c | 4 +-
sound/soc/sdw_utils/soc_sdw_utils.c | 59 +-
sound/soc/soc-pcm.c | 18 +-
sound/soc/ux500/ux500_msp_i2s.h | 4 +-
sound/usb/6fire/comm.c | 42 +-
sound/usb/6fire/comm.h | 2 +-
sound/usb/6fire/midi.c | 43 +-
sound/usb/6fire/midi.h | 2 +-
sound/usb/6fire/pcm.c | 138 +-
sound/usb/6fire/pcm.h | 5 +-
sound/usb/bcd2000/bcd2000.c | 33 +-
sound/usb/card.h | 3 +-
sound/usb/endpoint.c | 16 +-
sound/virtio/virtio_card.c | 4 +-
tools/perf/util/hist.h | 8 +-
.../selftests/arm64/mte/check_gcr_el1_cswitch.c | 2 +-
tools/testing/selftests/landlock/audit.h | 119 +-
tools/testing/selftests/landlock/audit_test.c | 4 +-
tools/testing/selftests/landlock/fs_test.c | 1694 +++++++++++++++++++-
tools/testing/selftests/landlock/net_test.c | 169 +-
389 files changed, 6902 insertions(+), 2843 deletions(-)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 053/438] IB/IPoIB: Avoid restoring OPER_UP after multicast flush
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (51 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 052/438] wifi: libipw: reject too-short association responses Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 054/438] wifi: cfg80211: dont get the radio mask for netdev-less wdevs Greg Kroah-Hartman
` (396 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ben Davies, Carolina Jubran,
Cosmin Ratiu, Edward Srouji, Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Carolina Jubran <cjubran@nvidia.com>
[ Upstream commit 9a141d3dc869d18b2eab35e999f4790a9b84e40f ]
ipoib_ib_dev_flush_light() temporarily clears IPOIB_FLAG_OPER_UP to
prevent multicast joins while ipoib_mcast_dev_flush() is running, and
restores the flag afterwards if it was previously set.
This restore races with ipoib_ib_dev_down(). If the interface is brought
down while the flush is in progress, ipoib_ib_dev_down() clears
IPOIB_FLAG_OPER_UP, but the flush path may set it again after the device
has already gone down.
Since commit 894021a75291 ("IB/ipoib: Make the carrier_on_task race
aware"), ipoib_mcast_carrier_on_task() relies on IPOIB_FLAG_OPER_UP
being cleared to terminate its rtnl_trylock() retry loop. If the flag is
left set after shutdown, the workqueue retries forever, causing teardown
to deadlock when ipoib_ndo_uninit() waits in destroy_workqueue() while
holding RTNL.
Instead of overloading IPOIB_FLAG_OPER_UP to block multicast joins
during a light flush, introduce a dedicated IPOIB_FLAG_MCAST_FLUSH flag.
Use it together with IPOIB_FLAG_OPER_UP to determine whether multicast
joins are allowed, avoiding the race with device shutdown.
Fixes: 344bacca8cd8 ("IB/ipoib: Don't allow MC joins during light MC flush")
Reported-by: Ben Davies <ben.davies@gresearch.co.uk>
Signed-off-by: Carolina Jubran <cjubran@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260902-avoid-rest-oper-up-v1-1-04fcd4916cae@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/ipoib/ipoib.h | 7 +++++++
drivers/infiniband/ulp/ipoib/ipoib_ib.c | 12 +++++++-----
drivers/infiniband/ulp/ipoib/ipoib_multicast.c | 16 ++++++++--------
3 files changed, 22 insertions(+), 13 deletions(-)
diff --git a/drivers/infiniband/ulp/ipoib/ipoib.h b/drivers/infiniband/ulp/ipoib/ipoib.h
index 91f866e3fb8bd..143e03b649021 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib.h
+++ b/drivers/infiniband/ulp/ipoib/ipoib.h
@@ -87,6 +87,7 @@ enum {
IPOIB_FLAG_INITIALIZED = 1,
IPOIB_FLAG_ADMIN_UP = 2,
IPOIB_PKEY_ASSIGNED = 3,
+ IPOIB_FLAG_MCAST_FLUSH = 4,
IPOIB_FLAG_SUBINTERFACE = 5,
IPOIB_STOP_REAPER = 7,
IPOIB_FLAG_ADMIN_CM = 9,
@@ -414,6 +415,12 @@ struct ipoib_dev_priv {
const struct net_device_ops *rn_ops;
};
+static inline bool ipoib_mcast_allowed(struct ipoib_dev_priv *priv)
+{
+ return test_bit(IPOIB_FLAG_OPER_UP, &priv->flags) &&
+ !test_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
+}
+
struct ipoib_ah {
struct net_device *dev;
struct ib_ah *ah;
diff --git a/drivers/infiniband/ulp/ipoib/ipoib_ib.c b/drivers/infiniband/ulp/ipoib/ipoib_ib.c
index 5061d52a7b12c..81bbb3f7c1132 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib_ib.c
+++ b/drivers/infiniband/ulp/ipoib/ipoib_ib.c
@@ -1227,17 +1227,19 @@ static void __ipoib_ib_dev_flush(struct ipoib_dev_priv *priv,
}
if (level == IPOIB_FLUSH_LIGHT) {
- int oper_up;
ipoib_mark_paths_invalid(dev);
- /* Set IPoIB operation as down to prevent races between:
+ /* Set MCAST_FLUSH to prevent races between:
* the flush flow which leaves MCG and on the fly joins
* which can happen during that time. mcast restart task
* should deal with join requests we missed.
+ *
+ * Do not clear OPER_UP for this; restoring it races with
+ * ipoib_ib_dev_down() and can leave OPER_UP set after the
+ * device is down.
*/
- oper_up = test_and_clear_bit(IPOIB_FLAG_OPER_UP, &priv->flags);
+ set_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
ipoib_mcast_dev_flush(dev);
- if (oper_up)
- set_bit(IPOIB_FLAG_OPER_UP, &priv->flags);
+ clear_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
ipoib_reap_dead_ahs(priv);
}
diff --git a/drivers/infiniband/ulp/ipoib/ipoib_multicast.c b/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
index 6401af2fd548f..379b78374e210 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
+++ b/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
@@ -74,7 +74,7 @@ static void __ipoib_mcast_schedule_join_thread(struct ipoib_dev_priv *priv,
struct ipoib_mcast *mcast,
bool delay)
{
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
return;
/*
@@ -469,7 +469,7 @@ static int ipoib_mcast_join(struct net_device *dev, struct ipoib_mcast *mcast)
int ret = 0;
if (!priv->broadcast ||
- !test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ !ipoib_mcast_allowed(priv))
return -EINVAL;
init_completion(&mcast->done);
@@ -555,7 +555,7 @@ void ipoib_mcast_join_task(struct work_struct *work)
unsigned long delay_until = 0;
struct ipoib_mcast *mcast = NULL;
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
return;
if (ib_query_port(priv->ca, priv->port, &port_attr)) {
@@ -577,7 +577,7 @@ void ipoib_mcast_join_task(struct work_struct *work)
netif_addr_unlock_bh(dev);
spin_lock_irq(&priv->lock);
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
goto out;
if (!priv->broadcast) {
@@ -749,7 +749,7 @@ void ipoib_mcast_send(struct net_device *dev, u8 *daddr, struct sk_buff *skb)
spin_lock_irqsave(&priv->lock, flags);
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags) ||
+ if (!ipoib_mcast_allowed(priv) ||
!priv->broadcast ||
!test_bit(IPOIB_MCAST_FLAG_ATTACHED, &priv->broadcast->flags)) {
++dev->stats.tx_dropped;
@@ -871,7 +871,7 @@ void ipoib_mcast_restart_task(struct work_struct *work)
LIST_HEAD(remove_list);
struct ib_sa_mcmember_rec rec;
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
/*
* shortcut...on shutdown flush is called next, just
* let it do all the work
@@ -965,9 +965,9 @@ void ipoib_mcast_restart_task(struct work_struct *work)
ipoib_mcast_remove_list(&remove_list);
/*
- * Double check that we are still up
+ * Double check that we are still up and not flushing
*/
- if (test_bit(IPOIB_FLAG_OPER_UP, &priv->flags)) {
+ if (ipoib_mcast_allowed(priv)) {
spin_lock_irq(&priv->lock);
__ipoib_mcast_schedule_join_thread(priv, NULL, 0);
spin_unlock_irq(&priv->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 001/398] Revert "perf annotate: Fix build with NO_SLANG=1"
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 002/398] landlock: Fix TCP Fast Open connection bypass Greg Kroah-Hartman
` (401 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
This reverts commit e97bd4417010c648acf9b1e509cfb77fc506e09e.
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/hist.h | 8 ++------
1 file changed, 2 insertions(+), 6 deletions(-)
diff --git a/tools/perf/util/hist.h b/tools/perf/util/hist.h
index a4f244a046866..c64005278687c 100644
--- a/tools/perf/util/hist.h
+++ b/tools/perf/util/hist.h
@@ -709,8 +709,6 @@ struct block_hist {
struct hist_entry he;
};
-#define NO_ADDR 0
-
#ifdef HAVE_SLANG_SUPPORT
#include "../ui/keysyms.h"
void attr_to_script(char *buf, struct perf_event_attr *attr);
@@ -748,16 +746,14 @@ int evlist__tui_browse_hists(struct evlist *evlist __maybe_unused,
static inline int __hist_entry__tui_annotate(struct hist_entry *he __maybe_unused,
struct map_symbol *ms __maybe_unused,
struct evsel *evsel __maybe_unused,
- struct hist_browser_timer *hbt __maybe_unused,
- u64 al_addr __maybe_unused)
+ struct hist_browser_timer *hbt __maybe_unused)
{
return 0;
}
static inline int hist_entry__tui_annotate(struct hist_entry *he __maybe_unused,
struct evsel *evsel __maybe_unused,
- struct hist_browser_timer *hbt __maybe_unused,
- u64 al_addr __maybe_unused)
+ struct hist_browser_timer *hbt __maybe_unused)
{
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 054/438] wifi: cfg80211: dont get the radio mask for netdev-less wdevs
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (52 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 053/438] IB/IPoIB: Avoid restoring OPER_UP after multicast flush Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 055/438] wifi: cfg80211: check IP header size in cfg80211_classify8021d() Greg Kroah-Hartman
` (395 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+abff43d2d045e37c0bb2,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit a7783e585360ee05dfe21d3173dbbe985c94f29e ]
cfg80211_calculate_bi_data() calls rdev_get_radio_mask() with
wdev->netdev, which can be NULL and then crashes in mac80211.
To avoid that, invert the order of checks since wdev->netdev
is always valid for beaconing interfaces.
Assisted-by: LLM
Fixes: abb4cfe3661a ("wifi: cfg80211: extend interface combination check for multi-radio")
Reported-by: syzbot+abff43d2d045e37c0bb2@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=abff43d2d045e37c0bb2
Link: https://patch.msgid.link/20260904165614.2056a8b7dc91.I7412c5062d8166ad6c81ee7252cec49dea19a60f@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/util.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
diff --git a/net/wireless/util.c b/net/wireless/util.c
index 24527bf321b2a..7142b81963d27 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -2426,16 +2426,15 @@ static void cfg80211_calculate_bi_data(struct wiphy *wiphy, u32 new_beacon_int,
if (wdev->valid_links)
continue;
+ wdev_bi = cfg80211_wdev_bi(wdev);
+ if (!wdev_bi)
+ continue;
+
/* skip wdevs not active on the given wiphy radio */
if (radio_idx >= 0 &&
!(rdev_get_radio_mask(rdev, wdev->netdev) & BIT(radio_idx)))
continue;
- wdev_bi = cfg80211_wdev_bi(wdev);
-
- if (!wdev_bi)
- continue;
-
if (!*beacon_int_gcd) {
*beacon_int_gcd = wdev_bi;
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 002/398] landlock: Fix TCP Fast Open connection bypass
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 001/398] Revert "perf annotate: Fix build with NO_SLANG=1" Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 003/398] selftests/landlock: Add test for TCP fast open Greg Kroah-Hartman
` (400 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthieu Buffet,
Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthieu Buffet <matthieu@buffet.re>
[ Upstream commit 33cb713db0161b54f04fe830e062c9e102c29a04 ]
The documentation of the socket_connect() LSM hook states that it
controls connecting a socket to a remote address. It has not been the
case since the addition of TCP Fast Open (RFC 7413) support, which
allows opening a TCP connection (thus, setting a socket's destination
address) via the MSG_FASTOPEN flag passed to
sendto()/sendmsg()/sendmmsg(). The problem then got duplicated into
MPTCP.
Landlock did not take it into account when its TCP support was added,
leaving a bypass of TCP connect policy.
Ideally a call to the LSM hook would be added in the fastopen code path,
in order to fix this generically. But connect() hooks are designed to
run with the socket locked, unlike sendmsg() hooks.
Closes: https://github.com/landlock-lsm/linux/issues/41
Fixes: fff69fb03dde ("landlock: Support network rules with TCP bind and connect")
Signed-off-by: Matthieu Buffet <matthieu@buffet.re>
Link: https://patch.msgid.link/20260701214628.33319-1-matthieu@buffet.re
Cc: stable@vger.kernel.org
[mic: Wrap commit message]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: adapt the TCP Fast Open check to the TCP-only network
hooks]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/landlock/net.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/security/landlock/net.c b/security/landlock/net.c
index 7ae97dec04342..9224d9b26429f 100644
--- a/security/landlock/net.c
+++ b/security/landlock/net.c
@@ -235,9 +235,23 @@ static int hook_socket_connect(struct socket *const sock,
LANDLOCK_ACCESS_NET_CONNECT_TCP);
}
+static int hook_socket_sendmsg(struct socket *const sock,
+ struct msghdr *const msg, const int size)
+{
+ struct sockaddr *const address = msg->msg_name;
+
+ if ((msg->msg_flags & MSG_FASTOPEN) && address)
+ return current_check_access_socket(
+ sock, address, msg->msg_namelen,
+ LANDLOCK_ACCESS_NET_CONNECT_TCP);
+
+ return 0;
+}
+
static struct security_hook_list landlock_hooks[] __ro_after_init = {
LSM_HOOK_INIT(socket_bind, hook_socket_bind),
LSM_HOOK_INIT(socket_connect, hook_socket_connect),
+ LSM_HOOK_INIT(socket_sendmsg, hook_socket_sendmsg),
};
__init void landlock_add_net_hooks(void)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 055/438] wifi: cfg80211: check IP header size in cfg80211_classify8021d()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (53 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 054/438] wifi: cfg80211: dont get the radio mask for netdev-less wdevs Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 056/438] soundwire: cadence_master: wait and cancel cdns->work before clock stop Greg Kroah-Hartman
` (394 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+878ddc3962f792e9af59,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 48b2c5c628b09cf36cbeca53e0432fc2a7518be7 ]
A frame that looks like IP can be transmitted, but be too short, so
the DS field is read incorrectly:
BUG: KMSAN: uninit-value in cfg80211_classify8021d+0x99d/0x12b0 net/wireless/util.c:1027
cfg80211_classify8021d+0x99d/0x12b0 net/wireless/util.c:1027
ieee80211_select_queue+0x37a/0x9e0 net/mac80211/wme.c:180
__ieee80211_subif_start_xmit+0x60f/0x1d90 net/mac80211/tx.c:4304
ieee80211_subif_start_xmit+0xa8/0x6d0 net/mac80211/tx.c:4538
...
packet_sendmsg+0x9173/0xa2a0 net/packet/af_packet.c:3108
Use skb_header_pointer() like the MPLS case.
Assisted-by: LLM
Fixes: e31a16d6f64e ("wireless: move some utility functions from mac80211 to cfg80211")
Reported-by: syzbot+878ddc3962f792e9af59@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=878ddc3962f792e9af59
Link: https://patch.msgid.link/20260904165614.5e61a4c80b92.I37d68d3f406cb3b90b32e6943418d66070b65197@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/util.c | 26 ++++++++++++++++++++++----
1 file changed, 22 insertions(+), 4 deletions(-)
diff --git a/net/wireless/util.c b/net/wireless/util.c
index 7142b81963d27..ef56fe0ac41b2 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -988,12 +988,30 @@ unsigned int cfg80211_classify8021d(struct sk_buff *skb,
}
switch (skb->protocol) {
- case htons(ETH_P_IP):
- dscp = ipv4_get_dsfield(ip_hdr(skb)) & 0xfc;
+ case htons(ETH_P_IP): {
+ const struct iphdr *iph;
+ struct iphdr _iph;
+
+ iph = skb_header_pointer(skb, sizeof(struct ethhdr),
+ sizeof(*iph), &_iph);
+ if (!iph)
+ return 0;
+
+ dscp = ipv4_get_dsfield(iph) & 0xfc;
break;
- case htons(ETH_P_IPV6):
- dscp = ipv6_get_dsfield(ipv6_hdr(skb)) & 0xfc;
+ }
+ case htons(ETH_P_IPV6): {
+ const struct ipv6hdr *ip6h;
+ struct ipv6hdr _ip6h;
+
+ ip6h = skb_header_pointer(skb, sizeof(struct ethhdr),
+ sizeof(*ip6h), &_ip6h);
+ if (!ip6h)
+ return 0;
+
+ dscp = ipv6_get_dsfield(ip6h) & 0xfc;
break;
+ }
case htons(ETH_P_MPLS_UC):
case htons(ETH_P_MPLS_MC): {
struct mpls_label mpls_tmp, *mpls;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 003/398] selftests/landlock: Add test for TCP fast open
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 001/398] Revert "perf annotate: Fix build with NO_SLANG=1" Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 002/398] landlock: Fix TCP Fast Open connection bypass Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 004/398] selftests/landlock: Add missing connect(minimal AF_UNSPEC) test Greg Kroah-Hartman
` (399 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthieu Buffet,
Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthieu Buffet <matthieu@buffet.re>
[ Upstream commit f4b30e0b1d488e7ffd8ea28d1365b9ba8e551edb ]
Enforce that TCP Fast Open is controlled by
LANDLOCK_ACCESS_NET_CONNECT_TCP. Semantics of connect() and
sendmsg(MSG_FASTOPEN) should be identical from Landlock's perspective.
Also enforce error code consistency, since UDP sockets ignore the
MSG_FASTOPEN flag while Unix sockets reject it.
Signed-off-by: Matthieu Buffet <matthieu@buffet.re>
Link: https://patch.msgid.link/20260701214628.33319-2-matthieu@buffet.re
Cc: stable@vger.kernel.org
[mic: Fix formatting]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: adapt the test to the older network fixture and add the
required send helper]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/net_test.c | 155 ++++++++++++++++++++
1 file changed, 155 insertions(+)
diff --git a/tools/testing/selftests/landlock/net_test.c b/tools/testing/selftests/landlock/net_test.c
index 6fecd36f74c63..c725c08414a10 100644
--- a/tools/testing/selftests/landlock/net_test.c
+++ b/tools/testing/selftests/landlock/net_test.c
@@ -258,6 +258,64 @@ static int connect_variant(const int sock_fd,
return connect_variant_addrlen(sock_fd, srv, get_addrlen(srv, false));
}
+static int sendto_variant_addrlen(const int sock_fd,
+ const struct service_fixture *const srv,
+ const socklen_t addrlen, void *buf,
+ size_t len, size_t flags)
+{
+ const struct sockaddr *dst = NULL;
+ ssize_t ret;
+
+ /*
+ * We never want our processes to be killed by SIGPIPE: we check return
+ * codes and errno, so that we have actual error messages.
+ */
+ flags |= MSG_NOSIGNAL;
+
+ if (srv != NULL) {
+ switch (srv->protocol.domain) {
+ case AF_UNSPEC:
+ case AF_INET:
+ dst = (const struct sockaddr *)&srv->ipv4_addr;
+ break;
+
+ case AF_INET6:
+ dst = (const struct sockaddr *)&srv->ipv6_addr;
+ break;
+
+ case AF_UNIX:
+ dst = (const struct sockaddr *)&srv->unix_addr;
+ break;
+
+ default:
+ errno = EAFNOSUPPORT;
+ return -errno;
+ }
+ }
+
+ ret = sendto(sock_fd, buf, len, flags, dst, addrlen);
+ if (ret < 0)
+ return -errno;
+
+ /* errno is not set in cases of partial writes. */
+ if (ret != len)
+ return -EINTR;
+
+ return 0;
+}
+
+static int sendto_variant(const int sock_fd,
+ const struct service_fixture *const srv, void *buf,
+ size_t len, size_t flags)
+{
+ socklen_t addrlen = 0;
+
+ if (srv != NULL)
+ addrlen = get_addrlen(srv, false);
+
+ return sendto_variant_addrlen(sock_fd, srv, addrlen, buf, len, flags);
+}
+
FIXTURE(protocol)
{
struct service_fixture srv0, srv1, srv2, unspec_any0, unspec_srv0;
@@ -938,6 +996,103 @@ TEST_F(protocol, connect_unspec)
EXPECT_EQ(0, close(bind_fd));
}
+TEST_F(protocol, tcp_fastopen)
+{
+ const bool restricted = variant->sandbox == TCP_SANDBOX &&
+ variant->prot.type == SOCK_STREAM &&
+ (variant->prot.protocol == IPPROTO_TCP ||
+ variant->prot.protocol == IPPROTO_IP) &&
+ (variant->prot.domain == AF_INET ||
+ variant->prot.domain == AF_INET6);
+ const struct landlock_ruleset_attr ruleset_attr = {
+ .handled_access_net = LANDLOCK_ACCESS_NET_CONNECT_TCP,
+ };
+ int bind_fd, client_fd, status;
+ char buf;
+ pid_t child;
+
+ bind_fd = socket_variant(&self->srv0);
+ ASSERT_LE(0, bind_fd);
+ EXPECT_EQ(0, bind_variant(bind_fd, &self->srv0));
+ if (self->srv0.protocol.type == SOCK_STREAM)
+ EXPECT_EQ(0, listen(bind_fd, backlog));
+
+ child = fork();
+ ASSERT_LE(0, child);
+ if (child == 0) {
+ int connect_fd, ret;
+
+ /* Closes listening socket for the child. */
+ EXPECT_EQ(0, close(bind_fd));
+
+ connect_fd = socket_variant(&self->srv0);
+ ASSERT_LE(0, connect_fd);
+
+ if (variant->sandbox == TCP_SANDBOX) {
+ const int ruleset_fd = landlock_create_ruleset(
+ &ruleset_attr, sizeof(ruleset_attr), 0);
+ ASSERT_LE(0, ruleset_fd);
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+ }
+
+ /* Fast Open with no address. */
+ ret = sendto_variant(connect_fd, NULL, NULL, 0, MSG_FASTOPEN);
+ if (self->srv0.protocol.domain == AF_UNIX) {
+ EXPECT_EQ(-ENOTCONN, ret);
+ } else if (self->srv0.protocol.type == SOCK_DGRAM) {
+ EXPECT_EQ(-EDESTADDRREQ, ret);
+ } else {
+ EXPECT_EQ(-EINVAL, ret);
+ }
+
+ /* Fast Open to a denied address. */
+ ret = sendto_variant(connect_fd, &self->srv0, "A", 1,
+ MSG_FASTOPEN);
+ if (restricted) {
+ EXPECT_EQ(-EACCES, ret);
+ } else if (self->srv0.protocol.domain == AF_UNIX &&
+ self->srv0.protocol.type == SOCK_STREAM) {
+ EXPECT_EQ(-EOPNOTSUPP, ret);
+ } else {
+ EXPECT_EQ(0, ret);
+ }
+
+ EXPECT_EQ(0, close(connect_fd));
+ _exit(_metadata->exit_code);
+ return;
+ }
+
+ client_fd = bind_fd;
+ if (!restricted && self->srv0.protocol.type == SOCK_STREAM &&
+ self->srv0.protocol.domain != AF_UNIX) {
+ client_fd = accept(bind_fd, NULL, 0);
+ ASSERT_LE(0, client_fd);
+ }
+
+ if (restricted) {
+ EXPECT_EQ(-1, read(client_fd, &buf, 1));
+ EXPECT_EQ(ENOTCONN, errno);
+ } else if (self->srv0.protocol.domain == AF_UNIX &&
+ self->srv0.protocol.type == SOCK_STREAM) {
+ EXPECT_EQ(-1, read(client_fd, &buf, 1));
+ EXPECT_EQ(EINVAL, errno);
+ } else {
+ EXPECT_EQ(1, read(client_fd, &buf, 1));
+ EXPECT_EQ('A', buf);
+ }
+
+ EXPECT_EQ(child, waitpid(child, &status, 0));
+ EXPECT_EQ(1, WIFEXITED(status));
+ EXPECT_EQ(EXIT_SUCCESS, WEXITSTATUS(status));
+
+ if (client_fd != bind_fd)
+ EXPECT_LE(0, close(client_fd));
+
+ EXPECT_EQ(0, close(bind_fd));
+}
+
FIXTURE(ipv4)
{
struct service_fixture srv0, srv1;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 056/438] soundwire: cadence_master: wait and cancel cdns->work before clock stop
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (54 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 055/438] wifi: cfg80211: check IP header size in cfg80211_classify8021d() Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 057/438] mips: econet: fix unmet dependencies for ECONET Greg Kroah-Hartman
` (393 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bard Liao, David Lin, Shuming Fan,
Pierre-Louis Bossart, Vinod Koul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bard Liao <yung-chuan.liao@linux.intel.com>
[ Upstream commit aba7b41faeecb7692458095ce6fafc341fe0b80e ]
A peripheral event could happen during the clock stop process. We need
to wait for the event be handled before stopping the bus clock.
Otherwise, we will get the IO transfer timed out issue.
Fixes: af4cc917826f ("soundwire: cadence: mask Slave interrupt before stopping clock")
Signed-off-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: David Lin <david.lin@intel.com>
Reviewed-by: Shuming Fan <shumingf@realtek.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260901031019.233254-1-yung-chuan.liao@linux.intel.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soundwire/cadence_master.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/soundwire/cadence_master.c b/drivers/soundwire/cadence_master.c
index 98ed337fb9b01..cf456d7cf0a8f 100644
--- a/drivers/soundwire/cadence_master.c
+++ b/drivers/soundwire/cadence_master.c
@@ -1701,6 +1701,13 @@ int sdw_cdns_clock_stop(struct sdw_cdns *cdns, bool block_wake)
return 0;
}
+ /*
+ * wait for any in-flight peripheral event handling to complete before stopping the clock.
+ * No need to disable peripheral interrupts before canceling the work, as the peripheral
+ * interrupts are already masked before the work is scheduled.
+ */
+ cancel_work_sync(&cdns->work);
+
/*
* Before entering clock stop we mask the Slave
* interrupts. This helps avoid having to deal with e.g. a
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 004/398] selftests/landlock: Add missing connect(minimal AF_UNSPEC) test
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (2 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 003/398] selftests/landlock: Add test for TCP fast open Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 005/398] selftests/landlock: Fix socket file descriptor leaks in audit helpers Greg Kroah-Hartman
` (398 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthieu Buffet,
Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthieu Buffet <matthieu@buffet.re>
[ Upstream commit 6685201ebfacff0c889bcd569181fa6e8af5575e ]
connect_variant(unspec_any0) is called twice. Both calls end
up in connect_variant_addrlen() with an address length of
get_addrlen(minimal=false).
However, the connect() syscall and its variants (e.g.
iouring/compat) accept much shorter addresses of 4 bytes
and that behaviour was not tested.
Replace one of these calls with one using a minimal address
length (just a bare sa_family=AF_UNSPEC field with no actual
address). Also add a call using a truncated address for good
measure.
Signed-off-by: Matthieu Buffet <matthieu@buffet.re>
Link: https://lore.kernel.org/r/20251027190726.626244-3-matthieu@buffet.re
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/net_test.c | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/landlock/net_test.c b/tools/testing/selftests/landlock/net_test.c
index c725c08414a10..8f3a780d354b7 100644
--- a/tools/testing/selftests/landlock/net_test.c
+++ b/tools/testing/selftests/landlock/net_test.c
@@ -964,7 +964,19 @@ TEST_F(protocol, connect_unspec)
EXPECT_EQ(0, close(ruleset_fd));
}
- ret = connect_variant(connect_fd, &self->unspec_any0);
+ /* Try to re-disconnect with a truncated address struct. */
+ EXPECT_EQ(-EINVAL,
+ connect_variant_addrlen(
+ connect_fd, &self->unspec_any0,
+ get_addrlen(&self->unspec_any0, true) - 1));
+
+ /*
+ * Re-disconnect, with a minimal sockaddr struct (just a
+ * bare af_family=AF_UNSPEC field).
+ */
+ ret = connect_variant_addrlen(connect_fd, &self->unspec_any0,
+ get_addrlen(&self->unspec_any0,
+ true));
if (self->srv0.protocol.domain == AF_UNIX &&
self->srv0.protocol.type == SOCK_STREAM) {
EXPECT_EQ(-EINVAL, ret);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 057/438] mips: econet: fix unmet dependencies for ECONET
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (55 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 056/438] soundwire: cadence_master: wait and cancel cdns->work before clock stop Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 058/438] MIPS: Octeon: apply USB FDT fixups also when USB is modular Greg Kroah-Hartman
` (392 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Julian Braha,
Caleb James DeLisle, Thomas Bogendoerfer, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Julian Braha <julianbraha@gmail.com>
[ Upstream commit fb5a08026a68be0ec5f660588311fb1091bf5d58 ]
ECONET selects EARLY_PRINTK_8250, SERIAL_OF_PLATFORM, and SERIAL_8250
without ensuring their dependencies, EARLY_PRINTK and TTY are met. This
causes unmet dependencies:
WARNING: unmet direct dependencies detected for SERIAL_8250
Depends on [n]: TTY [=n] && HAS_IOMEM [=y] && !S390
Selected by [y]:
- ECONET [=y]
WARNING: unmet direct dependencies detected for EARLY_PRINTK_8250
Depends on [n]: EARLY_PRINTK [=n] && USE_GENERIC_EARLY_PRINTK_8250 [=y]
Selected by [y]:
- ECONET [=y]
WARNING: unmet direct dependencies detected for SERIAL_OF_PLATFORM
Depends on [n]: TTY [=n] && HAS_IOMEM [=y] && SERIAL_8250 [=y] && OF [=y]
Selected by [y]:
- ECONET [=y]
However, in the discussion of v1 of this patch, Arnd pointed out that these
selects don't belong here in the first place. [1]
Let's remove them to resolve the unmet dependencies.
These unmet dependencies were found by kconfirm, a static analysis tool for
Kconfig.
Fixes: 79ee1d20e37c ("mips: econet: Fix incorrect Kconfig dependencies")
Fixes: 35fb26f94dfa ("mips: Add EcoNet MIPS platform support")
Suggested-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Julian Braha <julianbraha@gmail.com>
Tested-by: Caleb James DeLisle <cjd@cjdns.fr>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/Kconfig | 3 ---
1 file changed, 3 deletions(-)
diff --git a/arch/mips/Kconfig b/arch/mips/Kconfig
index 8555bbf47c633..4a1e665bf012a 100644
--- a/arch/mips/Kconfig
+++ b/arch/mips/Kconfig
@@ -397,10 +397,7 @@ config ECONET
select BOOT_RAW
select CPU_BIG_ENDIAN
select DEBUG_ZBOOT if DEBUG_KERNEL
- select EARLY_PRINTK_8250
select ECONET_EN751221_TIMER
- select SERIAL_8250
- select SERIAL_OF_PLATFORM
select SYS_SUPPORTS_BIG_ENDIAN
select SYS_HAS_CPU_MIPS32_R1
select SYS_HAS_CPU_MIPS32_R2
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 005/398] selftests/landlock: Fix socket file descriptor leaks in audit helpers
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (3 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 004/398] selftests/landlock: Add missing connect(minimal AF_UNSPEC) test Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 006/398] selftests/landlock: Increase default audit socket timeout Greg Kroah-Hartman
` (397 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack,
Günther Noack, Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mickaël Salaün <mic@digikod.net>
[ Upstream commit 9143d790337a0d066c2d632c802f69b981e6c23a ]
audit_init() opens a netlink socket and configures it, but leaks the
file descriptor if audit_set_status() or setsockopt() fails. Fix this
by jumping to an error path that closes the socket before returning.
Apply the same fix to audit_init_with_exe_filter(), which leaks the file
descriptor from audit_init() if audit_init_filter_exe() or
audit_filter_exe() fails, and to audit_cleanup(), which leaks it if
audit_init_filter_exe() fails in FIXTURE_TEARDOWN_PARENT().
Cc: Günther Noack <gnoack@google.com>
Cc: stable@vger.kernel.org
Fixes: 6a500b22971c ("selftests/landlock: Add tests for audit flags and domain IDs")
Reviewed-by: Günther Noack <gnoack3000@gmail.com>
Link: https://lore.kernel.org/r/20260402192608.1458252-3-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/audit.h | 26 +++++++++++++++++-------
1 file changed, 19 insertions(+), 7 deletions(-)
diff --git a/tools/testing/selftests/landlock/audit.h b/tools/testing/selftests/landlock/audit.h
index d6d6f5116dc96..f6d7b9ad60168 100644
--- a/tools/testing/selftests/landlock/audit.h
+++ b/tools/testing/selftests/landlock/audit.h
@@ -443,17 +443,19 @@ static int audit_init(void)
err = audit_set_status(fd, AUDIT_STATUS_ENABLED, 1);
if (err)
- return err;
+ goto err_close;
err = audit_set_status(fd, AUDIT_STATUS_PID, getpid());
if (err)
- return err;
+ goto err_close;
/* Sets a timeout for negative tests. */
err = setsockopt(fd, SOL_SOCKET, SO_RCVTIMEO, &audit_tv_default,
sizeof(audit_tv_default));
- if (err)
- return -errno;
+ if (err) {
+ err = -errno;
+ goto err_close;
+ }
/*
* Drains stale audit records that accumulated in the kernel backlog
@@ -466,6 +468,10 @@ static int audit_init(void)
;
return fd;
+
+err_close:
+ close(fd);
+ return err;
}
static int audit_init_filter_exe(struct audit_filter *filter, const char *path)
@@ -515,8 +521,10 @@ static int audit_cleanup(int audit_fd, struct audit_filter *filter)
filter = &new_filter;
err = audit_init_filter_exe(filter, NULL);
- if (err)
+ if (err) {
+ close(audit_fd);
return err;
+ }
}
/* Filters might not be in place. */
@@ -542,11 +550,15 @@ static int audit_init_with_exe_filter(struct audit_filter *filter)
err = audit_init_filter_exe(filter, NULL);
if (err)
- return err;
+ goto err_close;
err = audit_filter_exe(fd, filter, AUDIT_ADD_RULE);
if (err)
- return err;
+ goto err_close;
return fd;
+
+err_close:
+ close(fd);
+ return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 058/438] MIPS: Octeon: apply USB FDT fixups also when USB is modular
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (56 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 057/438] mips: econet: fix unmet dependencies for ECONET Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 059/438] dma-coherent: report a failed reserved memory assignment Greg Kroah-Hartman
` (391 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Orgad Shaneh, Thomas Bogendoerfer,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Orgad Shaneh <orgads@gmail.com>
[ Upstream commit 126f16e0a1b353c2ba5c7e2c8626cfa865934f9f ]
The uctl/usbn device-tree fixups in octeon_prune_device_tree() - which
set the board's USB reference-clock frequency and type from
__cvmx_helper_board_usb_get_clock_type() - are guarded by
"#ifdef CONFIG_USB", which is false when USB is built as a module. The
fixups then silently disappear and octeon-hcd sees whatever default the
DTS carries (12MHz crystal in octeon_3xxx.dts), leaving the PHY dead or
the bus erroring on boards with a different reference clock.
Use IS_ENABLED() so USB=m gets the same fixups as USB=y.
Fixes: 7fd57ab9d9cf ("MIPS: Octeon: Fix compile error when USB is not enabled.")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Orgad Shaneh <orgads@gmail.com>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/cavium-octeon/octeon-platform.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/mips/cavium-octeon/octeon-platform.c b/arch/mips/cavium-octeon/octeon-platform.c
index 47677b5d7ed00..f53c98372e0be 100644
--- a/arch/mips/cavium-octeon/octeon-platform.c
+++ b/arch/mips/cavium-octeon/octeon-platform.c
@@ -18,7 +18,7 @@
#include <asm/octeon/octeon.h>
#include <asm/octeon/cvmx-helper-board.h>
-#ifdef CONFIG_USB
+#if IS_ENABLED(CONFIG_USB)
#include <linux/usb/ehci_def.h>
#include <linux/usb/ehci_pdriver.h>
#include <linux/usb/ohci_pdriver.h>
@@ -1080,7 +1080,7 @@ int __init octeon_prune_device_tree(void)
;
}
-#ifdef CONFIG_USB
+#if IS_ENABLED(CONFIG_USB)
/* OHCI/UHCI USB */
alias_prop = fdt_getprop(initial_boot_params, aliases,
"uctl", NULL);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 006/398] selftests/landlock: Increase default audit socket timeout
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (4 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 005/398] selftests/landlock: Fix socket file descriptor leaks in audit helpers Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 007/398] selftests/landlock: Explicitly disable audit in teardowns Greg Kroah-Hartman
` (396 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack,
Thomas Weißschuh, Günther Noack, kernel test robot,
Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mickaël Salaün <mic@digikod.net>
[ Upstream commit d8dfb4c7faa87c3e41a8678f38f136c2c7c036fa ]
matches_log_fs() and other audit_match_record() callers intermittently
return -EAGAIN under heavy debug configs (KASAN, lockdep). The audit
record delivery pipeline is asynchronous: landlock_log_denial() queues
the record to audit_queue, and kauditd_thread dequeues and delivers via
netlink. Under debug configs, kauditd scheduling between
audit_log_end() and netlink_unicast() can exceed a syscall round trip
(more than 1 usec), which was the value of the socket timeout used for
the recvfrom() calls.
The observed failure [1] is an EAGAIN error code (-11) which means that
the access record had not arrived within the 1 usec timeout of
recvfrom(). The expected record does arrive, but only after
matches_log_fs() has already returned. It is then consumed by a later
audit_count_records() call, making records.access == 1 instead of 0.
Switch the default socket timeout to the slow value (1 second) so all
audit_match_record() callers wait long enough for kauditd delivery, and
lower it to the fast value (1 usec) only on the two paths that expect no
record: audit_count_records() and the expected_domain_id == 0 probe in
matches_log_domain_deallocated(). audit_init() drains stale records
with the fast timeout (terminating on -EAGAIN once the backlog is empty)
and switches to the patient default before returning. 1 second gives
~10x margin over the observed maximum (~100 ms, while the happy path is
~23 us).
Rename the timeval constants to reflect their new roles:
- audit_tv_dom_drop (1 second) -> audit_tv_default: default socket
timeout, patient enough for asynchronous kauditd delivery.
- audit_tv_default (1 usec) -> audit_tv_fast: fast timeout for paths
that expect no record (drain, audit_count_records(), probes).
Invert the conditional in matches_log_domain_deallocated(). Check
setsockopt returns on both the lower and restore paths; preserve the
first error via !err when the restore fails after a prior error so the
actionable return code is not masked by a bookkeeping failure.
Cc: Günther Noack <gnoack@google.com>
Cc: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Cc: stable@vger.kernel.org
Depends-on: 07c2572a8757 ("selftests/landlock: Skip stale records in audit_match_record()")
Fixes: 6a500b22971c ("selftests/landlock: Add tests for audit flags and domain IDs")
Reported-by: Günther Noack <gnoack3000@gmail.com>
Closes: https://lore.kernel.org/r/20260402.eb5c4e85f472@gnoack.org [1]
Reported-by: kernel test robot <oliver.sang@intel.com>
Closes: https://lore.kernel.org/oe-lkp/202605111649.a8b30a62-lkp@intel.com
Closes: https://lore.kernel.org/oe-lkp/202604300436.a07fae12-lkp@intel.com
Tested-by: Günther Noack <gnoack3000@gmail.com>
Link: https://patch.msgid.link/20260513105112.140137-2-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/audit.h | 80 +++++++++++++++++++-----
1 file changed, 63 insertions(+), 17 deletions(-)
diff --git a/tools/testing/selftests/landlock/audit.h b/tools/testing/selftests/landlock/audit.h
index f6d7b9ad60168..34efa5d9b0a90 100644
--- a/tools/testing/selftests/landlock/audit.h
+++ b/tools/testing/selftests/landlock/audit.h
@@ -45,17 +45,25 @@ struct audit_message {
};
};
-static const struct timeval audit_tv_dom_drop = {
+static const struct timeval audit_tv_default = {
/*
- * Because domain deallocation is tied to asynchronous credential
- * freeing, receiving such event may take some time. In practice,
- * on a small VM, it should not exceed 100k usec, but let's wait up
- * to 1 second to be safe.
+ * Default socket timeout for audit_match_record() callers that expect a
+ * record to arrive. Asynchronous kauditd delivery can exceed 1 usec
+ * under heavy debug configs (KASAN, lockdep), where kauditd_thread
+ * scheduling between audit_log_end() and netlink_unicast() takes longer
+ * than the previous 1 usec timeout. 1 second is a generous ceiling: on
+ * the happy path, kauditd delivers within dozens of usec.
*/
.tv_sec = 1,
};
-static const struct timeval audit_tv_default = {
+static const struct timeval audit_tv_fast = {
+ /*
+ * Fast timeout for paths that expect no record (audit_init() drain,
+ * audit_count_records(), probes). Causes audit_recv() to return
+ * -EAGAIN once the socket buffer is empty, naturally terminating the
+ * read loop.
+ */
.tv_usec = 1,
};
@@ -334,8 +342,13 @@ static int __maybe_unused matches_log_domain_allocated(int audit_fd, pid_t pid,
* Matches a domain deallocation record. When expected_domain_id is non-zero,
* the pattern includes the specific domain ID so that stale deallocation
* records from a previous test (with a different domain ID) are skipped by
- * audit_match_record(), and the socket timeout is temporarily increased to
- * audit_tv_dom_drop to wait for the asynchronous kworker deallocation.
+ * audit_match_record(), waiting for the asynchronous kworker deallocation with
+ * the default patient timeout.
+ *
+ * When expected_domain_id is zero, the caller is probing for any dealloc record
+ * that may or may not arrive. Temporarily lowers the socket timeout to
+ * audit_tv_fast for this probe so it returns promptly when no record is
+ * pending; restores audit_tv_default after.
*/
static int __maybe_unused
matches_log_domain_deallocated(int audit_fd, unsigned int num_denials,
@@ -361,16 +374,21 @@ matches_log_domain_deallocated(int audit_fd, unsigned int num_denials,
if (log_match_len >= sizeof(log_match))
return -E2BIG;
- if (expected_domain_id)
- setsockopt(audit_fd, SOL_SOCKET, SO_RCVTIMEO,
- &audit_tv_dom_drop, sizeof(audit_tv_dom_drop));
+ if (!expected_domain_id) {
+ if (setsockopt(audit_fd, SOL_SOCKET, SO_RCVTIMEO,
+ &audit_tv_fast, sizeof(audit_tv_fast)))
+ return -errno;
+ }
err = audit_match_record(audit_fd, AUDIT_LANDLOCK_DOMAIN, log_match,
domain_id);
- if (expected_domain_id)
- setsockopt(audit_fd, SOL_SOCKET, SO_RCVTIMEO, &audit_tv_default,
- sizeof(audit_tv_default));
+ if (!expected_domain_id) {
+ if (setsockopt(audit_fd, SOL_SOCKET, SO_RCVTIMEO,
+ &audit_tv_default, sizeof(audit_tv_default)) &&
+ !err)
+ err = -errno;
+ }
return err;
}
@@ -387,6 +405,11 @@ struct audit_records {
* audit_init() and after the preceding audit_match_record() call. Allocation
* records are emitted synchronously during landlock_log_denial() in the current
* test's syscall context, so only those are counted in records->domain.
+ *
+ * Temporarily lowers SO_RCVTIMEO to audit_tv_fast for the read loop: this is a
+ * "no record expected" path that should terminate on the first -EAGAIN. The
+ * default patient timeout is restored on exit for subsequent
+ * audit_match_record() callers.
*/
static int audit_count_records(int audit_fd, struct audit_records *records)
{
@@ -403,6 +426,12 @@ static int audit_count_records(int audit_fd, struct audit_records *records)
records->access = 0;
records->domain = 0;
+ if (setsockopt(audit_fd, SOL_SOCKET, SO_RCVTIMEO, &audit_tv_fast,
+ sizeof(audit_tv_fast))) {
+ err = -errno;
+ goto out;
+ }
+
do {
memset(&msg, 0, sizeof(msg));
err = audit_recv(audit_fd, &msg);
@@ -429,6 +458,10 @@ static int audit_count_records(int audit_fd, struct audit_records *records)
} while (true);
out:
+ if (setsockopt(audit_fd, SOL_SOCKET, SO_RCVTIMEO, &audit_tv_default,
+ sizeof(audit_tv_default)) &&
+ !err)
+ err = -errno;
regfree(&dealloc_re);
return err;
}
@@ -449,9 +482,9 @@ static int audit_init(void)
if (err)
goto err_close;
- /* Sets a timeout for negative tests. */
- err = setsockopt(fd, SOL_SOCKET, SO_RCVTIMEO, &audit_tv_default,
- sizeof(audit_tv_default));
+ /* Uses the fast timeout to drain stale records below. */
+ err = setsockopt(fd, SOL_SOCKET, SO_RCVTIMEO, &audit_tv_fast,
+ sizeof(audit_tv_fast));
if (err) {
err = -errno;
goto err_close;
@@ -467,6 +500,19 @@ static int audit_init(void)
while (audit_recv(fd, NULL) == 0)
;
+ /*
+ * Restores the default timeout for audit_match_record() callers that
+ * expect a record to arrive. Paths that expect no record restore the
+ * fast timeout locally (audit_count_records(), the expected_domain_id
+ * == 0 probe in matches_log_domain_deallocated()).
+ */
+ err = setsockopt(fd, SOL_SOCKET, SO_RCVTIMEO, &audit_tv_default,
+ sizeof(audit_tv_default));
+ if (err) {
+ err = -errno;
+ goto err_close;
+ }
+
return fd;
err_close:
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 059/438] dma-coherent: report a failed reserved memory assignment
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (57 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 058/438] MIPS: Octeon: apply USB FDT fixups also when USB is modular Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 060/438] dma-mapping: dont trace the DMA address when the allocation fails Greg Kroah-Hartman
` (390 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Marek Szyprowski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
[ Upstream commit 504981db4f69bdd28054fb98c96a3a67f7248dde ]
rmem_dma_device_init() drops the return value of
dma_assign_coherent_memory() and always reports success. That call fails
with -EBUSY when the device already has a coherent pool, and the file
allows only "*one* such region of memory" per device.
of_reserved_mem_device_init_by_idx() reads the zero as success. It logs
"assigned reserved memory node" for a region that was not assigned and
records the pairing, so of_reserved_mem_device_release() later runs
rmem_dma_device_release() for it. That clears dev->dma_mem without
looking at which region it was called for, dropping the pool the device
did get and leaving it on ordinary memory.
dma_declare_coherent_memory() checks the same call and releases the
memory on failure, and rmem_swiotlb_device_init() propagates its own
errors. Return the error here as well, so a device tree that assigns two
pools to one device fails the probe instead of half working.
Fixes: 7bfa5ab6fa1b ("drivers: dma-coherent: add initialization from device tree")
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Link: https://lore.kernel.org/r/20260905074727.108029-1-donggeunyoo.kernel@gmail.com
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/dma/coherent.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/kernel/dma/coherent.c b/kernel/dma/coherent.c
index bcdc0f76d2e80..b6fe902c6a6db 100644
--- a/kernel/dma/coherent.c
+++ b/kernel/dma/coherent.c
@@ -351,8 +351,7 @@ static int rmem_dma_device_init(struct reserved_mem *rmem, struct device *dev)
min_not_zero(dev->coherent_dma_mask, dev->bus_dma_limit))
dev_warn(dev, "reserved memory is beyond device's set DMA address range\n");
- dma_assign_coherent_memory(dev, mem);
- return 0;
+ return dma_assign_coherent_memory(dev, mem);
}
static void rmem_dma_device_release(struct reserved_mem *rmem,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 007/398] selftests/landlock: Explicitly disable audit in teardowns
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (5 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 006/398] selftests/landlock: Increase default audit socket timeout Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 008/398] selftests/landlock: Add tests for access through disconnected paths Greg Kroah-Hartman
` (395 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maximilian Heyne,
Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maximilian Heyne <mheyne@amazon.de>
[ Upstream commit 0302cd72fe196aee933e3fb76f6d175d1ab0e843 ]
I'm seeing sporadic selftest failures, such as
# RUN scoped_audit.connect_to_child ...
# scoped_abstract_unix_test.c:314:connect_to_child:Expected 0 (0) == records.access (8)
# connect_to_child: Test failed
# FAIL scoped_audit.connect_to_child
not ok 19 scoped_audit.connect_to_child
This seems similar to what commit 3647a4977fb73d ("selftests/landlock:
Drain stale audit records on init") tried to fix. However, the added
drain loop is not effective. When setting the AUDIT_STATUS_PID, the
kauditd_thread is woken up starting to send messages from the hold queue
to the netlink. Depending on scheduling of this kthread not all messages
might be send via the netlink in the 1 us interval.
Therefore, instead of trying to drain the queue, let's just disable
audit when running non-audit tests or more precisely disable it after
audit-tests. This way we won't generate any new audit message that could
interfere with the other tests.
The comment saying that on process exit audit will be disabled is wrong.
The closed file descriptor just causes an auditd_reset(), not a
disablement. So future messages will be queued in the hold queue.
Cc: stable@vger.kernel.org
Fixes: 6a500b22971c ("selftests/landlock: Add tests for audit flags and domain IDs")
Signed-off-by: Maximilian Heyne <mheyne@amazon.de>
Link: https://patch.msgid.link/20260529-welsh-nagoya-b4d9ca60@mheyne-amazon
[mic: Fix FD leak, update subject, call audit_cleanup() in audit_exec teardown]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/audit.h | 21 +++++++------------
tools/testing/selftests/landlock/audit_test.c | 4 +---
2 files changed, 9 insertions(+), 16 deletions(-)
diff --git a/tools/testing/selftests/landlock/audit.h b/tools/testing/selftests/landlock/audit.h
index 34efa5d9b0a90..a1768a4dbf39d 100644
--- a/tools/testing/selftests/landlock/audit.h
+++ b/tools/testing/selftests/landlock/audit.h
@@ -553,10 +553,9 @@ static int audit_init_filter_exe(struct audit_filter *filter, const char *path)
static int audit_cleanup(int audit_fd, struct audit_filter *filter)
{
struct audit_filter new_filter;
+ int err = 0;
if (audit_fd < 0 || !filter) {
- int err;
-
/*
* Simulates audit_init_with_exe_filter() when called from
* FIXTURE_TEARDOWN_PARENT().
@@ -567,23 +566,19 @@ static int audit_cleanup(int audit_fd, struct audit_filter *filter)
filter = &new_filter;
err = audit_init_filter_exe(filter, NULL);
- if (err) {
- close(audit_fd);
- return err;
- }
+ if (err)
+ goto err_close;
}
/* Filters might not be in place. */
audit_filter_exe(audit_fd, filter, AUDIT_DEL_RULE);
audit_filter_drop(audit_fd, AUDIT_DEL_RULE);
- /*
- * Because audit_cleanup() might not be called by the test auditd
- * process, it might not be possible to explicitly set it. Anyway,
- * AUDIT_STATUS_ENABLED will implicitly be set to 0 when the auditd
- * process will exit.
- */
- return close(audit_fd);
+ err = audit_set_status(audit_fd, AUDIT_STATUS_ENABLED, 0);
+
+err_close:
+ close(audit_fd);
+ return err;
}
static int audit_init_with_exe_filter(struct audit_filter *filter)
diff --git a/tools/testing/selftests/landlock/audit_test.c b/tools/testing/selftests/landlock/audit_test.c
index 67ab175ef5e3f..dcf63b2f822e9 100644
--- a/tools/testing/selftests/landlock/audit_test.c
+++ b/tools/testing/selftests/landlock/audit_test.c
@@ -617,10 +617,8 @@ FIXTURE_SETUP(audit_exec)
FIXTURE_TEARDOWN(audit_exec)
{
set_cap(_metadata, CAP_AUDIT_CONTROL);
- EXPECT_EQ(0, audit_filter_exe(self->audit_fd, &self->audit_filter,
- AUDIT_DEL_RULE));
+ EXPECT_EQ(0, audit_cleanup(self->audit_fd, &self->audit_filter));
clear_cap(_metadata, CAP_AUDIT_CONTROL);
- EXPECT_EQ(0, close(self->audit_fd));
}
TEST_F(audit_exec, signal_and_open)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 060/438] dma-mapping: dont trace the DMA address when the allocation fails
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (58 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 059/438] dma-coherent: report a failed reserved memory assignment Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 061/438] dmaengine: Fix device kref underflow in dma_chan_put() Greg Kroah-Hartman
` (389 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marek Szyprowski, Donggeun Yoo,
Sean Anderson, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
[ Upstream commit 92c6a8d6470f7e7aa86c1f144818d8fa4fcbd5aa ]
dma_alloc_attrs() passes *dma_handle to trace_dma_alloc() without
checking whether the allocation succeeded. No backend writes it on
failure: dma_direct_alloc(), iommu_dma_alloc() and the dma_map_ops
instances assign it only on the path that returns a buffer. Callers
usually pass an uninitialized automatic variable, so a failed allocation
records whatever the stack held, next to the virt_addr=(null) that marks
the record as an error:
dma_alloc: dmatrace dir=BIDIRECTIONAL dma_addr=deadbeefdeadbeef
size=1099511627776 virt_addr=0000000000000000
The device coherent pool path reaches the same call: a non-zero return
from dma_alloc_from_dev_coherent() means the request was handled, not
that it succeeded, so cpu_addr is NULL and dma_handle is untouched once
the pool runs out.
For an allocation event a NULL virt_addr already means the request
failed, so the address field carries nothing. Report 0 for it in the
event class rather than at each call site, which covers dma_alloc_pages()
and dma_alloc_sgt_err() as well.
Fixes: 038eb433dc14 ("dma-mapping: add tracing for dma-mapping API calls")
Fixes: 68b6dbf1f441 ("dma-mapping: trace more error paths")
Suggested-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Link: https://lore.kernel.org/r/20260907120124.603373-1-donggeunyoo.kernel@gmail.com
Reviewed-by: Sean Anderson <sean.anderson@linux.dev>
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/trace/events/dma.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/include/trace/events/dma.h b/include/trace/events/dma.h
index 31c9ddf72c9d3..daef2c176ecd8 100644
--- a/include/trace/events/dma.h
+++ b/include/trace/events/dma.h
@@ -133,7 +133,7 @@ DECLARE_EVENT_CLASS(dma_alloc_class,
TP_fast_assign(
__assign_str(device);
__entry->virt_addr = virt_addr;
- __entry->dma_addr = dma_addr;
+ __entry->dma_addr = virt_addr ? dma_addr : 0;
__entry->size = size;
__entry->flags = flags;
__entry->dir = dir;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 008/398] selftests/landlock: Add tests for access through disconnected paths
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (6 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 007/398] selftests/landlock: Explicitly disable audit in teardowns Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 009/398] selftests/landlock: Add disconnected leafs and branch test suites Greg Kroah-Hartman
` (394 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack, Song Liu,
Tingmao Wang, Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tingmao Wang <m@maowtm.org>
[ Upstream commit a18ee3f31fd714173a62515d049d77e76ab55649 ]
This adds tests for the edge case discussed in [1], with specific ones
for rename and link operations when the operands are through
disconnected paths, as that go through a separate code path in Landlock.
This has resulted in a warning, due to collect_domain_accesses() not
expecting to reach a different root from path->mnt:
# RUN layout1_bind.path_disconnected ...
# OK layout1_bind.path_disconnected
ok 96 layout1_bind.path_disconnected
# RUN layout1_bind.path_disconnected_rename ...
[..] ------------[ cut here ]------------
[..] WARNING: CPU: 3 PID: 385 at security/landlock/fs.c:1065 collect_domain_accesses
[..] ...
[..] RIP: 0010:collect_domain_accesses (security/landlock/fs.c:1065 (discriminator 2) security/landlock/fs.c:1031 (discriminator 2))
[..] current_check_refer_path (security/landlock/fs.c:1205)
[..] ...
[..] hook_path_rename (security/landlock/fs.c:1526)
[..] security_path_rename (security/security.c:2026 (discriminator 1))
[..] do_renameat2 (fs/namei.c:5264)
# OK layout1_bind.path_disconnected_rename
ok 97 layout1_bind.path_disconnected_rename
Move the const char definitions a bit above so that we can use the path
for s4d1 in cleanup code.
Cc: Günther Noack <gnoack@google.com>
Cc: Song Liu <song@kernel.org>
Link: https://lore.kernel.org/r/027d5190-b37a-40a8-84e9-4ccbc352bcdf@maowtm.org [1]
Signed-off-by: Tingmao Wang <m@maowtm.org>
Link: https://lore.kernel.org/r/20251128172200.760753-4-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 423 ++++++++++++++++++++-
1 file changed, 415 insertions(+), 8 deletions(-)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 29cdbb8367358..83ead11e3bcd8 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -4559,6 +4559,18 @@ TEST_F_FORK(ioctl, handle_file_access_file)
FIXTURE(layout1_bind) {};
/* clang-format on */
+static const char bind_dir_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3";
+static const char bind_file1_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3/f1";
+
+/* Move targets for disconnected path tests. */
+static const char dir_s4d1[] = TMP_DIR "/s4d1";
+static const char file1_s4d1[] = TMP_DIR "/s4d1/f1";
+static const char file2_s4d1[] = TMP_DIR "/s4d1/f2";
+static const char dir_s4d2[] = TMP_DIR "/s4d1/s4d2";
+static const char file1_s4d2[] = TMP_DIR "/s4d1/s4d2/f1";
+static const char file1_name[] = "f1";
+static const char file2_name[] = "f2";
+
FIXTURE_SETUP(layout1_bind)
{
prepare_layout(_metadata);
@@ -4574,14 +4586,14 @@ FIXTURE_TEARDOWN_PARENT(layout1_bind)
{
/* umount(dir_s2d2)) is handled by namespace lifetime. */
+ remove_path(file1_s4d1);
+ remove_path(file2_s4d1);
+
remove_layout1(_metadata);
cleanup_layout(_metadata);
}
-static const char bind_dir_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3";
-static const char bind_file1_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3/f1";
-
/*
* layout1_bind hierarchy:
*
@@ -4592,20 +4604,25 @@ static const char bind_file1_s1d3[] = TMP_DIR "/s2d1/s2d2/s1d3/f1";
* │ └── s1d2
* │ ├── f1
* │ ├── f2
- * │ └── s1d3
+ * │ └── s1d3 [disconnected by path_disconnected]
* │ ├── f1
* │ └── f2
* ├── s2d1
* │ ├── f1
- * │ └── s2d2
+ * │ └── s2d2 [bind mount from s1d2]
* │ ├── f1
* │ ├── f2
* │ └── s1d3
* │ ├── f1
* │ └── f2
- * └── s3d1
- * └── s3d2
- * └── s3d3
+ * ├── s3d1
+ * │ └── s3d2
+ * │ └── s3d3
+ * └── s4d1 [renamed from s1d3 by path_disconnected]
+ * ├── f1
+ * ├── f2
+ * └── s4d2
+ * └── f1
*/
TEST_F_FORK(layout1_bind, no_restriction)
@@ -4804,6 +4821,396 @@ TEST_F_FORK(layout1_bind, reparent_cross_mount)
ASSERT_EQ(0, rename(bind_file1_s1d3, file1_s2d2));
}
+/*
+ * Make sure access to file through a disconnected path works as expected.
+ * This test moves s1d3 to s4d1.
+ */
+TEST_F_FORK(layout1_bind, path_disconnected)
+{
+ const struct rule layer1_allow_all[] = {
+ {
+ .path = TMP_DIR,
+ .access = ACCESS_ALL,
+ },
+ {},
+ };
+ const struct rule layer2_allow_just_f1[] = {
+ {
+ .path = file1_s1d3,
+ .access = LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {},
+ };
+ const struct rule layer3_only_s1d2[] = {
+ {
+ .path = dir_s1d2,
+ .access = LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {},
+ };
+
+ /* Landlock should not deny access just because it is disconnected. */
+ int ruleset_fd_l1 =
+ create_ruleset(_metadata, ACCESS_ALL, layer1_allow_all);
+
+ /* Creates the new ruleset now before we move the dir containing the file. */
+ int ruleset_fd_l2 =
+ create_ruleset(_metadata, ACCESS_RW, layer2_allow_just_f1);
+ int ruleset_fd_l3 =
+ create_ruleset(_metadata, ACCESS_RW, layer3_only_s1d2);
+ int bind_s1d3_fd;
+
+ ASSERT_LE(0, ruleset_fd_l1);
+ ASSERT_LE(0, ruleset_fd_l2);
+ ASSERT_LE(0, ruleset_fd_l3);
+
+ enforce_ruleset(_metadata, ruleset_fd_l1);
+ EXPECT_EQ(0, close(ruleset_fd_l1));
+
+ bind_s1d3_fd = open(bind_dir_s1d3, O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, bind_s1d3_fd);
+
+ /* Tests access is possible before we move. */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, "..", O_RDONLY | O_DIRECTORY));
+
+ /* Makes it disconnected. */
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d1))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d1,
+ strerror(errno));
+ }
+
+ /* Tests that access is still possible. */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+
+ /*
+ * Tests that ".." is not possible (not because of Landlock, but just
+ * because it's disconnected).
+ */
+ EXPECT_EQ(ENOENT,
+ test_open_rel(bind_s1d3_fd, "..", O_RDONLY | O_DIRECTORY));
+
+ /* This should still work with a narrower rule. */
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+
+ EXPECT_EQ(0, test_open(file1_s4d1, O_RDONLY));
+ /*
+ * Accessing a file through a disconnected file descriptor can still be
+ * allowed by a rule tied to this file, even if it is no longer visible in
+ * its mount point.
+ */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(EACCES, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+
+ enforce_ruleset(_metadata, ruleset_fd_l3);
+ EXPECT_EQ(0, close(ruleset_fd_l3));
+
+ EXPECT_EQ(EACCES, test_open(file1_s4d1, O_RDONLY));
+ /*
+ * Accessing a file through a disconnected file descriptor can still be
+ * allowed by a rule tied to the original mount point, even if it is no
+ * longer visible in its mount point.
+ */
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(EACCES, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+}
+
+/*
+ * Test that renameat with disconnected paths works under Landlock. This test
+ * moves s1d3 to s4d2, so that we can have a rule allowing refers on the move
+ * target's immediate parent.
+ */
+TEST_F_FORK(layout1_bind, path_disconnected_rename)
+{
+ const struct rule layer1[] = {
+ {
+ .path = dir_s1d2,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_DIR |
+ LANDLOCK_ACCESS_FS_REMOVE_DIR |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {
+ .path = dir_s4d1,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_DIR |
+ LANDLOCK_ACCESS_FS_REMOVE_DIR |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {}
+ };
+
+ /* This layer only handles LANDLOCK_ACCESS_FS_READ_FILE. */
+ const struct rule layer2_only_s1d2[] = {
+ {
+ .path = dir_s1d2,
+ .access = LANDLOCK_ACCESS_FS_READ_FILE,
+ },
+ {},
+ };
+ int ruleset_fd_l1, ruleset_fd_l2;
+ pid_t child_pid;
+ int bind_s1d3_fd, status;
+
+ ASSERT_EQ(0, mkdir(dir_s4d1, 0755))
+ {
+ TH_LOG("Failed to create %s: %s", dir_s4d1, strerror(errno));
+ }
+ ruleset_fd_l1 = create_ruleset(_metadata, ACCESS_ALL, layer1);
+ ruleset_fd_l2 = create_ruleset(_metadata, LANDLOCK_ACCESS_FS_READ_FILE,
+ layer2_only_s1d2);
+ ASSERT_LE(0, ruleset_fd_l1);
+ ASSERT_LE(0, ruleset_fd_l2);
+
+ enforce_ruleset(_metadata, ruleset_fd_l1);
+ EXPECT_EQ(0, close(ruleset_fd_l1));
+
+ bind_s1d3_fd = open(bind_dir_s1d3, O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, bind_s1d3_fd);
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+
+ /* Tests ENOENT priority over EACCES for disconnected directory. */
+ EXPECT_EQ(EACCES, test_open_rel(bind_s1d3_fd, "..", O_DIRECTORY));
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d2))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d2,
+ strerror(errno));
+ }
+ EXPECT_EQ(ENOENT, test_open_rel(bind_s1d3_fd, "..", O_DIRECTORY));
+
+ /*
+ * The file is no longer under s1d2 but we should still be able to access it
+ * with layer 2 because its mount point is evaluated as the first valid
+ * directory because it was initially a parent. Do a fork to test this so
+ * we don't prevent ourselves from renaming it back later.
+ */
+ child_pid = fork();
+ ASSERT_LE(0, child_pid);
+ if (child_pid == 0) {
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(EACCES, test_open(file1_s4d2, O_RDONLY));
+
+ /*
+ * Tests that access widening checks indeed prevents us from renaming it
+ * back.
+ */
+ EXPECT_EQ(-1, rename(dir_s4d2, dir_s1d3));
+ EXPECT_EQ(EXDEV, errno);
+
+ /*
+ * Including through the now disconnected fd (but it should return
+ * EXDEV).
+ */
+ EXPECT_EQ(-1, renameat(bind_s1d3_fd, file1_name, AT_FDCWD,
+ file1_s2d2));
+ EXPECT_EQ(EXDEV, errno);
+ _exit(_metadata->exit_code);
+ return;
+ }
+
+ EXPECT_EQ(child_pid, waitpid(child_pid, &status, 0));
+ EXPECT_EQ(1, WIFEXITED(status));
+ EXPECT_EQ(EXIT_SUCCESS, WEXITSTATUS(status));
+
+ ASSERT_EQ(0, rename(dir_s4d2, dir_s1d3))
+ {
+ TH_LOG("Failed to rename %s back to %s: %s", dir_s4d1, dir_s1d3,
+ strerror(errno));
+ }
+
+ /* Now checks that we can access it under l2. */
+ child_pid = fork();
+ ASSERT_LE(0, child_pid);
+ if (child_pid == 0) {
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open(file1_s1d3, O_RDONLY));
+ _exit(_metadata->exit_code);
+ return;
+ }
+
+ EXPECT_EQ(child_pid, waitpid(child_pid, &status, 0));
+ EXPECT_EQ(1, WIFEXITED(status));
+ EXPECT_EQ(EXIT_SUCCESS, WEXITSTATUS(status));
+
+ /*
+ * Also test that we can rename via a disconnected path. We move the
+ * dir back to the disconnected place first, then we rename file1 to
+ * file2 through our dir fd.
+ */
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d2))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d2,
+ strerror(errno));
+ }
+ ASSERT_EQ(0,
+ renameat(bind_s1d3_fd, file1_name, bind_s1d3_fd, file2_name))
+ {
+ TH_LOG("Failed to rename %s to %s within disconnected %s: %s",
+ file1_name, file2_name, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file2_name, O_RDONLY));
+ ASSERT_EQ(0, renameat(bind_s1d3_fd, file2_name, AT_FDCWD, file1_s2d2))
+ {
+ TH_LOG("Failed to rename %s to %s through disconnected %s: %s",
+ file2_name, file1_s2d2, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file1_s2d2, O_RDONLY));
+ EXPECT_EQ(0, test_open(file1_s1d2, O_RDONLY));
+
+ /* Move it back using the disconnected path as the target. */
+ ASSERT_EQ(0, renameat(AT_FDCWD, file1_s2d2, bind_s1d3_fd, file1_name))
+ {
+ TH_LOG("Failed to rename %s to %s through disconnected %s: %s",
+ file1_s1d2, file1_name, bind_dir_s1d3, strerror(errno));
+ }
+
+ /* Now make it connected again. */
+ ASSERT_EQ(0, rename(dir_s4d2, dir_s1d3))
+ {
+ TH_LOG("Failed to rename %s back to %s: %s", dir_s4d2, dir_s1d3,
+ strerror(errno));
+ }
+
+ /* Checks again that we can access it under l2. */
+ enforce_ruleset(_metadata, ruleset_fd_l2);
+ EXPECT_EQ(0, close(ruleset_fd_l2));
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+ EXPECT_EQ(0, test_open(file1_s1d3, O_RDONLY));
+}
+
+/*
+ * Test that linkat(2) with disconnected paths works under Landlock. This
+ * test moves s1d3 to s4d1.
+ */
+TEST_F_FORK(layout1_bind, path_disconnected_link)
+{
+ /* Ruleset to be applied after renaming s1d3 to s4d1. */
+ const struct rule layer1[] = {
+ {
+ .path = dir_s4d1,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE,
+ },
+ {
+ .path = dir_s2d2,
+ .access = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_REMOVE_FILE,
+ },
+ {}
+ };
+ int ruleset_fd, bind_s1d3_fd;
+
+ /* Removes unneeded files created by layout1, otherwise it will EEXIST. */
+ ASSERT_EQ(0, unlink(file1_s1d2));
+ ASSERT_EQ(0, unlink(file2_s1d3));
+
+ bind_s1d3_fd = open(bind_dir_s1d3, O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, bind_s1d3_fd);
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY));
+
+ /* Disconnects bind_s1d3_fd. */
+ ASSERT_EQ(0, rename(dir_s1d3, dir_s4d1))
+ {
+ TH_LOG("Failed to rename %s to %s: %s", dir_s1d3, dir_s4d1,
+ strerror(errno));
+ }
+
+ /* Need this later to test different parent link. */
+ ASSERT_EQ(0, mkdir(dir_s4d2, 0755))
+ {
+ TH_LOG("Failed to create %s: %s", dir_s4d2, strerror(errno));
+ }
+
+ ruleset_fd = create_ruleset(_metadata, ACCESS_ALL, layer1);
+ ASSERT_LE(0, ruleset_fd);
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+
+ /* From disconnected to connected. */
+ ASSERT_EQ(0, linkat(bind_s1d3_fd, file1_name, AT_FDCWD, file1_s2d2, 0))
+ {
+ TH_LOG("Failed to link %s to %s via disconnected %s: %s",
+ file1_name, file1_s2d2, bind_dir_s1d3, strerror(errno));
+ }
+
+ /* Tests that we can access via the new link... */
+ EXPECT_EQ(0, test_open(file1_s2d2, O_RDONLY))
+ {
+ TH_LOG("Failed to open newly linked %s: %s", file1_s2d2,
+ strerror(errno));
+ }
+
+ /* ...as well as the old one. */
+ EXPECT_EQ(0, test_open(file1_s4d1, O_RDONLY))
+ {
+ TH_LOG("Failed to open original %s: %s", file1_s4d1,
+ strerror(errno));
+ }
+
+ /* From connected to disconnected. */
+ ASSERT_EQ(0, unlink(file1_s4d1));
+ ASSERT_EQ(0, linkat(AT_FDCWD, file1_s2d2, bind_s1d3_fd, file2_name, 0))
+ {
+ TH_LOG("Failed to link %s to %s via disconnected %s: %s",
+ file1_s2d2, file2_name, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file2_s4d1, O_RDONLY));
+ ASSERT_EQ(0, unlink(file1_s2d2));
+
+ /* From disconnected to disconnected (same parent). */
+ ASSERT_EQ(0,
+ linkat(bind_s1d3_fd, file2_name, bind_s1d3_fd, file1_name, 0))
+ {
+ TH_LOG("Failed to link %s to %s within disconnected %s: %s",
+ file2_name, file1_name, bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file1_s4d1, O_RDONLY))
+ {
+ TH_LOG("Failed to open newly linked %s: %s", file1_s4d1,
+ strerror(errno));
+ }
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, file1_name, O_RDONLY))
+ {
+ TH_LOG("Failed to open %s through newly created link under disconnected path: %s",
+ file1_name, strerror(errno));
+ }
+ ASSERT_EQ(0, unlink(file2_s4d1));
+
+ /* From disconnected to disconnected (different parent). */
+ ASSERT_EQ(0,
+ linkat(bind_s1d3_fd, file1_name, bind_s1d3_fd, "s4d2/f1", 0))
+ {
+ TH_LOG("Failed to link %s to %s within disconnected %s: %s",
+ file1_name, "s4d2/f1", bind_dir_s1d3, strerror(errno));
+ }
+ EXPECT_EQ(0, test_open(file1_s4d2, O_RDONLY))
+ {
+ TH_LOG("Failed to open %s after link: %s", file1_s4d2,
+ strerror(errno));
+ }
+ EXPECT_EQ(0, test_open_rel(bind_s1d3_fd, "s4d2/f1", O_RDONLY))
+ {
+ TH_LOG("Failed to open %s through disconnected path after link: %s",
+ "s4d2/f1", strerror(errno));
+ }
+}
+
#define LOWER_BASE TMP_DIR "/lower"
#define LOWER_DATA LOWER_BASE "/data"
static const char lower_fl1[] = LOWER_DATA "/fl1";
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 061/438] dmaengine: Fix device kref underflow in dma_chan_put()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (59 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 060/438] dma-mapping: dont trace the DMA address when the allocation fails Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 062/438] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() Greg Kroah-Hartman
` (388 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit 44dab659064eb5c10adb0306510eebe848ed592d ]
dma_chan_get() takes chan->device->ref only on the slow path:
/* no kref on fast path */
if (chan->client_count) {
__module_get(owner);
chan->client_count++;
return 0;
}
if (!try_module_get(owner))
return -ENODEV;
if (!dma_device_get(chan->device)) { // calls kref_get_unless_zero()
dma_chan_put() drops the ref unconditionally, so every fast-path
get/put pair drops one extra device reference.
The bug fires when two conditions hold together: a non-private
provider has a persistent client holding chan->client_count > 0
and another client cycles dmaengine_get()/dmaengine_put().
When the kref hits zero, the subsequent dma_find_channel() returns
NULL even though the provider module is still loaded.
Fix this by dropping device->ref only on the last put, matching the
single slow-path get.
Fixes: 8ad342a86359 ("dmaengine: Add reference counting to dma_device struct")
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-2-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index 9049171df8578..4d8c6655c7a15 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -515,7 +515,9 @@ static void dma_chan_put(struct dma_chan *chan)
chan->route_data = NULL;
}
- dma_device_put(chan->device);
+ /* This channel is not in use anymore, drop the device ref */
+ if (!chan->client_count)
+ dma_device_put(chan->device);
module_put(dma_chan_to_owner(chan));
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 009/398] selftests/landlock: Add disconnected leafs and branch test suites
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (7 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 008/398] selftests/landlock: Add tests for access through disconnected paths Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 010/398] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test Greg Kroah-Hartman
` (393 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack, Song Liu,
Tingmao Wang, Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mickaël Salaün <mic@digikod.net>
[ Upstream commit 54f9baf537b0a091adad860ec92e3e18e0a0754c ]
Test disconnected directories with two test suites
(layout4_disconnected_leafs and layout5_disconnected_branch) and 43
variants to cover the main corner cases.
These tests are complementary to the previous commit.
Add test_renameat() and test_exchangeat() helpers.
Test coverage for security/landlock is 92.1% of 1927 lines according to
LLVM 20.
Cc: Günther Noack <gnoack@google.com>
Cc: Song Liu <song@kernel.org>
Cc: Tingmao Wang <m@maowtm.org>
Link: https://lore.kernel.org/r/20251128172200.760753-5-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 1051 ++++++++++++++++++++
1 file changed, 1051 insertions(+)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 83ead11e3bcd8..6b573ca53855e 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -2267,6 +2267,22 @@ static int test_exchange(const char *const oldpath, const char *const newpath)
return 0;
}
+static int test_renameat(int olddirfd, const char *oldpath, int newdirfd,
+ const char *newpath)
+{
+ if (renameat2(olddirfd, oldpath, newdirfd, newpath, 0))
+ return errno;
+ return 0;
+}
+
+static int test_exchangeat(int olddirfd, const char *oldpath, int newdirfd,
+ const char *newpath)
+{
+ if (renameat2(olddirfd, oldpath, newdirfd, newpath, RENAME_EXCHANGE))
+ return errno;
+ return 0;
+}
+
TEST_F_FORK(layout1, rename_file)
{
const struct rule rules[] = {
@@ -5211,6 +5227,1041 @@ TEST_F_FORK(layout1_bind, path_disconnected_link)
}
}
+/*
+ * layout4_disconnected_leafs with bind mount and renames:
+ *
+ * tmp
+ * ├── s1d1
+ * │ └── s1d2 [source of the bind mount]
+ * │ ├── s1d31
+ * │ │ └── s1d41 [now renamed beneath s3d1]
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d32
+ * │ └── s1d42 [now renamed beneath s4d1]
+ * │ ├── f3
+ * │ └── f4
+ * ├── s2d1
+ * │ └── s2d2 [bind mount of s1d2]
+ * │ ├── s1d31
+ * │ │ └── s1d41 [opened FD, now renamed beneath s3d1]
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d32
+ * │ └── s1d42 [opened FD, now renamed beneath s4d1]
+ * │ ├── f3
+ * │ └── f4
+ * ├── s3d1
+ * │ └── s1d41 [renamed here]
+ * │ ├── f1
+ * │ └── f2
+ * └── s4d1
+ * └── s1d42 [renamed here]
+ * ├── f3
+ * └── f4
+ */
+/* clang-format off */
+FIXTURE(layout4_disconnected_leafs) {
+ int s2d2_fd;
+};
+/* clang-format on */
+
+FIXTURE_SETUP(layout4_disconnected_leafs)
+{
+ prepare_layout(_metadata);
+
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f1");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f2");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d32/s1d42/f3");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d32/s1d42/f4");
+ create_directory(_metadata, TMP_DIR "/s2d1/s2d2");
+ create_directory(_metadata, TMP_DIR "/s3d1");
+ create_directory(_metadata, TMP_DIR "/s4d1");
+
+ self->s2d2_fd =
+ open(TMP_DIR "/s2d1/s2d2", O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, self->s2d2_fd);
+
+ set_cap(_metadata, CAP_SYS_ADMIN);
+ ASSERT_EQ(0, mount(TMP_DIR "/s1d1/s1d2", TMP_DIR "/s2d1/s2d2", NULL,
+ MS_BIND, NULL));
+ clear_cap(_metadata, CAP_SYS_ADMIN);
+}
+
+FIXTURE_TEARDOWN_PARENT(layout4_disconnected_leafs)
+{
+ /* umount(TMP_DIR "/s2d1") is handled by namespace lifetime. */
+
+ /* Removes files after renames. */
+ remove_path(TMP_DIR "/s3d1/s1d41/f1");
+ remove_path(TMP_DIR "/s3d1/s1d41/f2");
+ remove_path(TMP_DIR "/s4d1/s1d42/f1");
+ remove_path(TMP_DIR "/s4d1/s1d42/f3");
+ remove_path(TMP_DIR "/s4d1/s1d42/f4");
+ remove_path(TMP_DIR "/s4d1/s1d42/f5");
+
+ cleanup_layout(_metadata);
+}
+
+FIXTURE_VARIANT(layout4_disconnected_leafs)
+{
+ /*
+ * Parent of the bind mount source. It should always be ignored when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s1d1;
+ /*
+ * Source of bind mount (to s2d2). It should always be enforced when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s1d2;
+ /*
+ * Original parent of s1d41. It should always be ignored when testing
+ * against files under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_s1d31;
+ /*
+ * Original parent of s1d42. It should always be ignored when testing
+ * against files under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_s1d32;
+ /*
+ * Opened and disconnected source directory. It should always be enforced
+ * when testing against files under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_s1d41;
+ /*
+ * Opened and disconnected source directory. It should always be enforced
+ * when testing against files under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_s1d42;
+ /*
+ * File in the s1d41 disconnected directory. It should always be enforced
+ * when testing against itself under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_f1;
+ /*
+ * File in the s1d41 disconnected directory. It should always be enforced
+ * when testing against itself under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_f2;
+ /*
+ * File in the s1d42 disconnected directory. It should always be enforced
+ * when testing against itself under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_f3;
+ /*
+ * Parent of the bind mount destination. It should always be enforced when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s2d1;
+ /*
+ * Directory covered by the bind mount. It should always be ignored when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s2d2;
+ /*
+ * New parent of the renamed s1d41. It should always be ignored when
+ * testing against files under the s1d41 disconnected directory.
+ */
+ const __u64 allowed_s3d1;
+ /*
+ * New parent of the renamed s1d42. It should always be ignored when
+ * testing against files under the s1d42 disconnected directory.
+ */
+ const __u64 allowed_s4d1;
+
+ /* Expected result of the call to open([fd:s1d41]/f1, O_RDONLY). */
+ const int expected_read_result;
+ /* Expected result of the call to renameat([fd:s1d41]/f1, [fd:s1d42]/f1). */
+ const int expected_rename_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d41]/f2, [fd:s1d42]/f3,
+ * RENAME_EXCHANGE).
+ */
+ const int expected_exchange_result;
+ /* Expected result of the call to renameat([fd:s1d42]/f4, [fd:s1d42]/f5). */
+ const int expected_same_dir_rename_result;
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d1_mount_src_parent) {
+ /* clang-format on */
+ .allowed_s1d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d2_mount_src_refer) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d2_mount_src_create) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d2_mount_src_rename) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d31_s1d32_old_parent) {
+ /* clang-format on */
+ .allowed_s1d31 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d32 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_refer) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_create) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_rename_even) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* The destination directory has more access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_rename_more) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access denied. */
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* The destination directory has less access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s1d41_s1d42_disconnected_rename_less) {
+ /* clang-format on */
+ .allowed_s1d41 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .allowed_s1d42 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access allowed. */
+ .expected_rename_result = 0,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d1_mount_dst_parent_create) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d1_mount_dst_parent_refer) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d1_mount_dst_parent_mini) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s2d2_covered_by_mount) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* Tests collect_domain_accesses(). */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_new_parent_refer) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_new_parent_create) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs,
+ s3d1_s4d1_disconnected_rename_even){
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* The destination directory has more access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_disconnected_rename_more) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access denied. */
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* The destination directory has less access right. */
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, s3d1_s4d1_disconnected_rename_less) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG |
+ LANDLOCK_ACCESS_FS_EXECUTE,
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ /* Access allowed. */
+ .expected_rename_result = 0,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout4_disconnected_leafs, f1_f2_f3) {
+ /* clang-format on */
+ .allowed_f1 = LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_f2 = LANDLOCK_ACCESS_FS_READ_FILE,
+ .allowed_f3 = LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+TEST_F_FORK(layout4_disconnected_leafs, read_rename_exchange)
+{
+ const __u64 handled_access =
+ LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE | LANDLOCK_ACCESS_FS_MAKE_REG;
+ const struct rule rules[] = {
+ {
+ .path = TMP_DIR "/s1d1",
+ .access = variant->allowed_s1d1,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2",
+ .access = variant->allowed_s1d2,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31",
+ .access = variant->allowed_s1d31,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d32",
+ .access = variant->allowed_s1d32,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31/s1d41",
+ .access = variant->allowed_s1d41,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d32/s1d42",
+ .access = variant->allowed_s1d42,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f1",
+ .access = variant->allowed_f1,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d31/s1d41/f2",
+ .access = variant->allowed_f2,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d32/s1d42/f3",
+ .access = variant->allowed_f3,
+ },
+ {
+ .path = TMP_DIR "/s2d1",
+ .access = variant->allowed_s2d1,
+ },
+ /* s2d2_fd */
+ {
+ .path = TMP_DIR "/s3d1",
+ .access = variant->allowed_s3d1,
+ },
+ {
+ .path = TMP_DIR "/s4d1",
+ .access = variant->allowed_s4d1,
+ },
+ {},
+ };
+ int ruleset_fd, s1d41_bind_fd, s1d42_bind_fd;
+
+ ruleset_fd = create_ruleset(_metadata, handled_access, rules);
+ ASSERT_LE(0, ruleset_fd);
+
+ /* Adds rule for the covered directory. */
+ if (variant->allowed_s2d2) {
+ ASSERT_EQ(0, landlock_add_rule(
+ ruleset_fd, LANDLOCK_RULE_PATH_BENEATH,
+ &(struct landlock_path_beneath_attr){
+ .parent_fd = self->s2d2_fd,
+ .allowed_access =
+ variant->allowed_s2d2,
+ },
+ 0));
+ }
+ EXPECT_EQ(0, close(self->s2d2_fd));
+
+ s1d41_bind_fd = open(TMP_DIR "/s2d1/s2d2/s1d31/s1d41",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, s1d41_bind_fd);
+ s1d42_bind_fd = open(TMP_DIR "/s2d1/s2d2/s1d32/s1d42",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, s1d42_bind_fd);
+
+ /* Disconnects and checks source and destination directories. */
+ EXPECT_EQ(0, test_open_rel(s1d41_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(0, test_open_rel(s1d42_bind_fd, "..", O_DIRECTORY));
+ /* Renames to make it accessible through s3d1/s1d41 */
+ ASSERT_EQ(0, test_renameat(AT_FDCWD, TMP_DIR "/s1d1/s1d2/s1d31/s1d41",
+ AT_FDCWD, TMP_DIR "/s3d1/s1d41"));
+ /* Renames to make it accessible through s4d1/s1d42 */
+ ASSERT_EQ(0, test_renameat(AT_FDCWD, TMP_DIR "/s1d1/s1d2/s1d32/s1d42",
+ AT_FDCWD, TMP_DIR "/s4d1/s1d42"));
+ EXPECT_EQ(ENOENT, test_open_rel(s1d41_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(ENOENT, test_open_rel(s1d42_bind_fd, "..", O_DIRECTORY));
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+
+ EXPECT_EQ(variant->expected_read_result,
+ test_open_rel(s1d41_bind_fd, "f1", O_RDONLY));
+
+ EXPECT_EQ(variant->expected_rename_result,
+ test_renameat(s1d41_bind_fd, "f1", s1d42_bind_fd, "f1"));
+ EXPECT_EQ(variant->expected_exchange_result,
+ test_exchangeat(s1d41_bind_fd, "f2", s1d42_bind_fd, "f3"));
+
+ EXPECT_EQ(variant->expected_same_dir_rename_result,
+ test_renameat(s1d42_bind_fd, "f4", s1d42_bind_fd, "f5"));
+}
+
+/*
+ * layout5_disconnected_branch before rename:
+ *
+ * tmp
+ * ├── s1d1
+ * │ └── s1d2 [source of the first bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * ├── s2d1
+ * │ └── s2d2 [source of the second bind mount]
+ * │ └── s2d3
+ * │ └── s2d4 [first s1d2 bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * ├── s3d1
+ * │ └── s3d2 [second s2d2 bind mount]
+ * │ └── s2d3
+ * │ └── s2d4 [first s1d2 bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * └── s4d1
+ *
+ * After rename:
+ *
+ * tmp
+ * ├── s1d1
+ * │ └── s1d2 [source of the first bind mount]
+ * │ └── s1d3
+ * │ ├── s1d41
+ * │ │ ├── f1
+ * │ │ └── f2
+ * │ └── s1d42
+ * │ ├── f3
+ * │ └── f4
+ * ├── s2d1
+ * │ └── s2d2 [source of the second bind mount]
+ * ├── s3d1
+ * │ └── s3d2 [second s2d2 bind mount]
+ * └── s4d1
+ * └── s2d3 [renamed here]
+ * └── s2d4 [first s1d2 bind mount]
+ * └── s1d3
+ * ├── s1d41
+ * │ ├── f1
+ * │ └── f2
+ * └── s1d42
+ * ├── f3
+ * └── f4
+ *
+ * Decision path for access from the s3d1/s3d2/s2d3/s2d4/s1d3 file descriptor:
+ * 1. first bind mount: s1d3 -> s1d2
+ * 2. second bind mount: s2d3
+ * 3. tmp mount: s4d1 -> tmp [disconnected branch]
+ * 4. second bind mount: s2d2
+ * 5. tmp mount: s3d1 -> tmp
+ * 6. parent mounts: [...] -> /
+ *
+ * The s4d1 directory is evaluated even if it is not in the s2d2 mount.
+ */
+
+/* clang-format off */
+FIXTURE(layout5_disconnected_branch) {
+ int s2d4_fd, s3d2_fd;
+};
+/* clang-format on */
+
+FIXTURE_SETUP(layout5_disconnected_branch)
+{
+ prepare_layout(_metadata);
+
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f1");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f2");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f3");
+ create_file(_metadata, TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f4");
+ create_directory(_metadata, TMP_DIR "/s2d1/s2d2/s2d3/s2d4");
+ create_directory(_metadata, TMP_DIR "/s3d1/s3d2");
+ create_directory(_metadata, TMP_DIR "/s4d1");
+
+ self->s2d4_fd = open(TMP_DIR "/s2d1/s2d2/s2d3/s2d4",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, self->s2d4_fd);
+
+ self->s3d2_fd =
+ open(TMP_DIR "/s3d1/s3d2", O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, self->s3d2_fd);
+
+ set_cap(_metadata, CAP_SYS_ADMIN);
+ ASSERT_EQ(0, mount(TMP_DIR "/s1d1/s1d2", TMP_DIR "/s2d1/s2d2/s2d3/s2d4",
+ NULL, MS_BIND, NULL));
+ ASSERT_EQ(0, mount(TMP_DIR "/s2d1/s2d2", TMP_DIR "/s3d1/s3d2", NULL,
+ MS_BIND | MS_REC, NULL));
+ clear_cap(_metadata, CAP_SYS_ADMIN);
+}
+
+FIXTURE_TEARDOWN_PARENT(layout5_disconnected_branch)
+{
+ /* Bind mounts are handled by namespace lifetime. */
+
+ /* Removes files after renames. */
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f1");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d41/f2");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f1");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f3");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f4");
+ remove_path(TMP_DIR "/s1d1/s1d2/s1d3/s1d42/f5");
+
+ cleanup_layout(_metadata);
+}
+
+FIXTURE_VARIANT(layout5_disconnected_branch)
+{
+ /*
+ * Parent of all files. It should always be enforced when testing against
+ * files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_base;
+ /*
+ * Parent of the first bind mount source. It should always be ignored when
+ * testing against files under the s1d41 or s1d42 disconnected directories.
+ */
+ const __u64 allowed_s1d1;
+ const __u64 allowed_s1d2;
+ const __u64 allowed_s1d3;
+ const __u64 allowed_s2d1;
+ const __u64 allowed_s2d2;
+ const __u64 allowed_s2d3;
+ const __u64 allowed_s2d4;
+ const __u64 allowed_s3d1;
+ const __u64 allowed_s3d2;
+ const __u64 allowed_s4d1;
+
+ /* Expected result of the call to open([fd:s1d3]/s1d41/f1, O_RDONLY). */
+ const int expected_read_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d3]/s1d41/f1,
+ * [fd:s1d3]/s1d42/f1).
+ */
+ const int expected_rename_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d3]/s1d41/f2,
+ * [fd:s1d3]/s1d42/f3, RENAME_EXCHANGE).
+ */
+ const int expected_exchange_result;
+ /*
+ * Expected result of the call to renameat([fd:s1d3]/s1d42/f4,
+ * [fd:s1d3]/s1d42/f5).
+ */
+ const int expected_same_dir_rename_result;
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d1_mount1_src_parent) {
+ /* clang-format on */
+ .allowed_s1d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d2_mount1_src_refer) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d2_mount1_src_create) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d2_mount1_src_rename) {
+ /* clang-format on */
+ .allowed_s1d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_refer) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_create) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_rename) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s1d3_fd_full) {
+ /* clang-format on */
+ .allowed_s1d3 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d1_mount2_src_parent) {
+ /* clang-format on */
+ .allowed_s2d1 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d2_mount2_src_refer) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d2_mount2_src_create) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d2_mount2_src_rename) {
+ /* clang-format on */
+ .allowed_s2d2 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d3_mount1_dst_parent_refer) {
+ /* clang-format on */
+ .allowed_s2d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d3_mount1_dst_parent_create) {
+ /* clang-format on */
+ .allowed_s2d3 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d3_mount1_dst_parent_rename) {
+ /* clang-format on */
+ .allowed_s2d3 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s2d4_mount1_dst) {
+ /* clang-format on */
+ .allowed_s2d4 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d1_mount2_dst_parent_refer) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d1_mount2_dst_parent_create) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d1_mount2_dst_parent_rename) {
+ /* clang-format on */
+ .allowed_s3d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s3d2_mount1_dst) {
+ /* clang-format on */
+ .allowed_s3d2 = LANDLOCK_ACCESS_FS_REFER |
+ LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s4d1_rename_parent_refer) {
+ /* clang-format on */
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = EACCES,
+ .expected_rename_result = EACCES,
+ .expected_exchange_result = EACCES,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s4d1_rename_parent_create) {
+ /* clang-format on */
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = 0,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = EXDEV,
+ .expected_exchange_result = EXDEV,
+};
+
+/* clang-format off */
+FIXTURE_VARIANT_ADD(layout5_disconnected_branch, s4d1_rename_parent_rename) {
+ /* clang-format on */
+ .allowed_s4d1 = LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_MAKE_REG,
+ .expected_read_result = EACCES,
+ .expected_same_dir_rename_result = 0,
+ .expected_rename_result = 0,
+ .expected_exchange_result = 0,
+};
+
+TEST_F_FORK(layout5_disconnected_branch, read_rename_exchange)
+{
+ const __u64 handled_access =
+ LANDLOCK_ACCESS_FS_REFER | LANDLOCK_ACCESS_FS_READ_FILE |
+ LANDLOCK_ACCESS_FS_EXECUTE | LANDLOCK_ACCESS_FS_MAKE_REG;
+ const struct rule rules[] = {
+ {
+ .path = TMP_DIR "/s1d1",
+ .access = variant->allowed_s1d1,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2",
+ .access = variant->allowed_s1d2,
+ },
+ {
+ .path = TMP_DIR "/s1d1/s1d2/s1d3",
+ .access = variant->allowed_s1d3,
+ },
+ {
+ .path = TMP_DIR "/s2d1",
+ .access = variant->allowed_s2d1,
+ },
+ {
+ .path = TMP_DIR "/s2d1/s2d2",
+ .access = variant->allowed_s2d2,
+ },
+ {
+ .path = TMP_DIR "/s2d1/s2d2/s2d3",
+ .access = variant->allowed_s2d3,
+ },
+ /* s2d4_fd */
+ {
+ .path = TMP_DIR "/s3d1",
+ .access = variant->allowed_s3d1,
+ },
+ /* s3d2_fd */
+ {
+ .path = TMP_DIR "/s4d1",
+ .access = variant->allowed_s4d1,
+ },
+ {},
+ };
+ int ruleset_fd, s1d3_bind_fd;
+
+ ruleset_fd = create_ruleset(_metadata, handled_access, rules);
+ ASSERT_LE(0, ruleset_fd);
+
+ /* Adds rules for the covered directories. */
+ if (variant->allowed_s2d4) {
+ ASSERT_EQ(0, landlock_add_rule(
+ ruleset_fd, LANDLOCK_RULE_PATH_BENEATH,
+ &(struct landlock_path_beneath_attr){
+ .parent_fd = self->s2d4_fd,
+ .allowed_access =
+ variant->allowed_s2d4,
+ },
+ 0));
+ }
+ EXPECT_EQ(0, close(self->s2d4_fd));
+
+ if (variant->allowed_s3d2) {
+ ASSERT_EQ(0, landlock_add_rule(
+ ruleset_fd, LANDLOCK_RULE_PATH_BENEATH,
+ &(struct landlock_path_beneath_attr){
+ .parent_fd = self->s3d2_fd,
+ .allowed_access =
+ variant->allowed_s3d2,
+ },
+ 0));
+ }
+ EXPECT_EQ(0, close(self->s3d2_fd));
+
+ s1d3_bind_fd = open(TMP_DIR "/s3d1/s3d2/s2d3/s2d4/s1d3",
+ O_DIRECTORY | O_PATH | O_CLOEXEC);
+ ASSERT_LE(0, s1d3_bind_fd);
+
+ /* Disconnects and checks source and destination directories. */
+ EXPECT_EQ(0, test_open_rel(s1d3_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(0, test_open_rel(s1d3_bind_fd, "../..", O_DIRECTORY));
+ /* Renames to make it accessible through s3d1/s1d41 */
+ ASSERT_EQ(0, test_renameat(AT_FDCWD, TMP_DIR "/s2d1/s2d2/s2d3",
+ AT_FDCWD, TMP_DIR "/s4d1/s2d3"));
+ EXPECT_EQ(0, test_open_rel(s1d3_bind_fd, "..", O_DIRECTORY));
+ EXPECT_EQ(ENOENT, test_open_rel(s1d3_bind_fd, "../..", O_DIRECTORY));
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+
+ EXPECT_EQ(variant->expected_read_result,
+ test_open_rel(s1d3_bind_fd, "s1d41/f1", O_RDONLY));
+
+ EXPECT_EQ(variant->expected_rename_result,
+ test_renameat(s1d3_bind_fd, "s1d41/f1", s1d3_bind_fd,
+ "s1d42/f1"));
+ EXPECT_EQ(variant->expected_exchange_result,
+ test_exchangeat(s1d3_bind_fd, "s1d41/f2", s1d3_bind_fd,
+ "s1d42/f3"));
+
+ EXPECT_EQ(variant->expected_same_dir_rename_result,
+ test_renameat(s1d3_bind_fd, "s1d42/f4", s1d3_bind_fd,
+ "s1d42/f5"));
+}
+
#define LOWER_BASE TMP_DIR "/lower"
#define LOWER_DATA LOWER_BASE "/data"
static const char lower_fl1[] = LOWER_DATA "/fl1";
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 062/438] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (60 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 061/438] dmaengine: Fix device kref underflow in dma_chan_put() Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 063/438] dmaengine: wait for RCU readers before releasing dma_device Greg Kroah-Hartman
` (387 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit e873c74132f0c5f1452816cd9bb26208f0bba1e1 ]
When dma_device_put() drops the last reference on chan->device->ref,
dma_device_release() runs and may free the dma_device along with its
channels.
dma_chan_put() then still reads chan->device->owner via
dma_chan_to_owner() for the trailing module_put(). KASAN catches it:
slab-use-after-free in dma_chan_put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
kfree+0x225/0x470
dma_chan_put+0x395/0x4c0
dmaengine_put+0xf8/0x160
Cache the module owner in dma_chan_put() before the put so the trailing
module_put() does not need chan->device.
Fixes: 8ad342a86359 ("dmaengine: Add reference counting to dma_device struct")
Suggested-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260518-dmaengine-kref-fix-v1-1-4d6125048fb7@amd.com
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-3-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index 4d8c6655c7a15..7de33df0529a7 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -495,10 +495,13 @@ static int dma_chan_get(struct dma_chan *chan)
*/
static void dma_chan_put(struct dma_chan *chan)
{
+ struct module *owner;
+
/* This channel is not in use, bail out */
if (!chan->client_count)
return;
+ owner = dma_chan_to_owner(chan);
chan->client_count--;
/* This channel is not in use anymore, free it */
@@ -518,7 +521,7 @@ static void dma_chan_put(struct dma_chan *chan)
/* This channel is not in use anymore, drop the device ref */
if (!chan->client_count)
dma_device_put(chan->device);
- module_put(dma_chan_to_owner(chan));
+ module_put(owner);
}
enum dma_status dma_sync_wait(struct dma_chan *chan, dma_cookie_t cookie)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 010/398] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (8 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 009/398] selftests/landlock: Add disconnected leafs and branch test suites Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 011/398] selftests/landlock: Add tests for whiteout object creation Greg Kroah-Hartman
` (392 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack,
Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Günther Noack <gnoack@google.com>
[ Upstream commit 173b1bd8730825e1f6862dbd07856e7d68447a41 ]
By passing a (0, 0) device number, the audit test for
LANDLOCK_ACCESS_FS_MAKE_CHAR was accidentally creating a whiteout object
rather than a char device. In preparation to treating whiteout objects
differently, use an actual character device instead.
Signed-off-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260813093157.1436894-2-gnoack@google.com
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 6b573ca53855e..d8a351273482c 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -7315,7 +7315,7 @@ TEST_F(audit_layout1, make_char)
.handled_access_fs = access_fs_16,
});
- EXPECT_EQ(-1, mknod(file1_s1d3, S_IFCHR | 0644, 0));
+ EXPECT_EQ(-1, mknod(file1_s1d3, S_IFCHR | 0644, makedev(7, 0)));
EXPECT_EQ(EACCES, errno);
EXPECT_EQ(0, matches_log_fs(_metadata, self->audit_fd, "fs\\.make_char",
dir_s1d3));
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 063/438] dmaengine: wait for RCU readers before releasing dma_device
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (61 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 062/438] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 064/438] wifi: cfg80211: dont free driver-owned scan requests Greg Kroah-Hartman
` (386 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit dc750422170a563c7a81f6e49d36bb02c62ae37f ]
dma_issue_pending_all() walks the dma_device_list with
list_for_each_entry_rcu() under rcu_read_lock(). dma_device_release()
unlinks the device with list_del_rcu() and then calls
device->device_release() (which in many drivers, such as plx_dma.c,
directly calls kfree()).
Because there is no grace period between unlinking the device and
freeing it, concurrent RCU readers in dma_issue_pending_all() can
access the device after it has been freed.
The lockless walk originally relied on clients holding a dmaengine
reference to pin the provider module, and therefore the device, for as
long as they might traverse the list. Commit 8ad342a86359 ("dmaengine:
Add reference counting to dma_device struct") decoupled the dma_device
lifetime from the module reference, so the device can now be released
while a reader is still walking the list.
Add synchronize_rcu() before the device is freed, so RCU readers are
guaranteed to have finished. Keep it unconditional: providers that do
not implement device_release() free the device themselves once
dma_async_device_unregister() returns. This call will delay for a grace
period with dma_list_mutex held, which is safe and only teardown path is
delayed.
Fixes: 2ba05622b8b1 ("dmaengine: provide a common 'issue_pending_all' implementation")
Suggested-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260526-dmaengine-kref-fix-v2-0-3df60afac01d@amd.com
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-4-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index 7de33df0529a7..5b5673fc7344f 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -428,6 +428,7 @@ static void dma_device_release(struct kref *ref)
list_del_rcu(&device->global_node);
dma_channel_rebalance();
+ synchronize_rcu();
if (device->device_release)
device->device_release(device);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 011/398] selftests/landlock: Add tests for whiteout object creation
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (9 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 010/398] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 012/398] selftests/landlock: Add audit test " Greg Kroah-Hartman
` (391 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack,
Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Günther Noack <gnoack@google.com>
[ Upstream commit ee890889b30b22f9a21636061def7a04e4f89380 ]
Add tests to check that whiteout object creation is guarded by
LANDLOCK_ACCESS_FS_MAKE_REG, in the cases where these are created from
userspace:
* Conventional creation with mknod()
* Linking or renaming an existing whiteout object
* renameat2() with RENAME_WHITEOUT,
which creates a new whiteout object in the source location
* renameat2() with RENAME_EXCHANGE,
with one of the renamed objects being a whiteout object
Signed-off-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260813093157.1436894-4-gnoack@google.com
[mic: Update commit message as requested]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: add enforce_fs() for the older ruleset helpers]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 197 +++++++++++++++++++++
1 file changed, 197 insertions(+)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index d8a351273482c..3088d301073e4 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -791,6 +791,27 @@ static int create_ruleset(struct __test_metadata *const _metadata,
return ruleset_fd;
}
+static void enforce_fs(struct __test_metadata *const _metadata,
+ const __u64 access_fs, const struct rule rules[])
+{
+ int ruleset_fd;
+
+ if (rules) {
+ ruleset_fd = create_ruleset(_metadata, access_fs, rules);
+ } else {
+ const struct landlock_ruleset_attr ruleset_attr = {
+ .handled_access_fs = access_fs,
+ };
+
+ ruleset_fd = landlock_create_ruleset(&ruleset_attr,
+ sizeof(ruleset_attr), 0);
+ ASSERT_LE(0, ruleset_fd);
+ }
+
+ enforce_ruleset(_metadata, ruleset_fd);
+ EXPECT_EQ(0, close(ruleset_fd));
+}
+
TEST_F_FORK(layout0, proc_nsfs)
{
const struct rule rules[] = {
@@ -2365,6 +2386,170 @@ TEST_F_FORK(layout1, rename_file)
RENAME_EXCHANGE));
}
+TEST_F_FORK(layout1, rename_whiteout_denied)
+{
+ /* The affected file is a FIFO. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+
+ /* Deny MAKE_REG, but allow MAKE_FIFO. */
+ enforce_fs(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, NULL);
+
+ /*
+ * Try to rename a file with RENAME_WHITEOUT.
+ * file1_s3d3 is in dir_s3d2 (tmpfs), so it supports RENAME_WHITEOUT.
+ * Denied, because whiteout creation is guarded with MAKE_REG.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+ EXPECT_EQ(EACCES, errno);
+}
+
+static bool is_whiteout(const char *const path)
+{
+ struct stat st;
+
+ if (stat(path, &st) == -1)
+ return false;
+
+ return S_ISCHR(st.st_mode) && st.st_rdev == makedev(0, 0);
+}
+
+static bool is_fifo(const char *const path)
+{
+ struct stat st;
+
+ return stat(path, &st) == 0 && S_ISFIFO(st.st_mode);
+}
+
+TEST_F_FORK(layout1, rename_whiteout_allowed)
+{
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The affected file is a FIFO. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+
+ /* Allow MAKE_REG below dir_s3d3. */
+ enforce_fs(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, rules);
+
+ /*
+ * Rename a file with RENAME_WHITEOUT within the same directory.
+ * Allowed, because MAKE_REG is granted for the whiteout object which
+ * gets created in the source location.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+
+ /* A whiteout object took the place of the moved FIFO. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(TMP_DIR "/s3d1/s3d2/s3d3/f2"));
+}
+
+TEST_F_FORK(layout1, rename_whiteout_reparenting)
+{
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d2,
+ .access = LANDLOCK_ACCESS_FS_REFER,
+ },
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The moved files are FIFOs. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+ ASSERT_EQ(0, unlink(file1_s3d4));
+ ASSERT_EQ(0, mknod(file1_s3d4, S_IFIFO | 0600, 0));
+
+ /* Allow REFER below dir_s3d2, but MAKE_REG only below dir_s3d3. */
+ enforce_fs(_metadata,
+ LANDLOCK_ACCESS_FS_MAKE_REG | LANDLOCK_ACCESS_FS_REFER,
+ rules);
+
+ /*
+ * The whiteout object is created in the source directory: Moving the
+ * FIFO out of dir_s3d4 is denied because MAKE_REG is not granted
+ * there, even though it is granted in the destination directory
+ * dir_s3d3.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d4, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d3/f2", RENAME_WHITEOUT));
+ EXPECT_EQ(EACCES, errno);
+
+ /*
+ * Moving the FIFO out of dir_s3d3 is allowed, because MAKE_REG is
+ * granted there for the created whiteout object.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD,
+ TMP_DIR "/s3d1/s3d2/s3d4/f2", RENAME_WHITEOUT));
+
+ /* A whiteout object took the place of the moved FIFO. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(TMP_DIR "/s3d1/s3d2/s3d4/f2"));
+}
+
+TEST_F_FORK(layout1, rename_whiteout_exchange)
+{
+ const char *const whiteout_s3d3 = TMP_DIR "/s3d1/s3d2/s3d3/f2";
+ const struct rule rules[] = {
+ {
+ .path = dir_s3d2,
+ .access = LANDLOCK_ACCESS_FS_REFER,
+ },
+ {
+ .path = dir_s3d3,
+ .access = LANDLOCK_ACCESS_FS_MAKE_REG,
+ },
+ {},
+ };
+
+ /* The exchanged files are FIFOs and an existing whiteout object. */
+ ASSERT_EQ(0, unlink(file1_s3d3));
+ ASSERT_EQ(0, mknod(file1_s3d3, S_IFIFO | 0600, 0));
+ ASSERT_EQ(0, mknod(whiteout_s3d3, S_IFCHR | 0600, makedev(0, 0)));
+ ASSERT_EQ(0, unlink(file1_s3d4));
+ ASSERT_EQ(0, mknod(file1_s3d4, S_IFIFO | 0600, 0));
+
+ /* Allow REFER below dir_s3d2, but MAKE_REG only below dir_s3d3. */
+ enforce_fs(_metadata,
+ LANDLOCK_ACCESS_FS_MAKE_REG | LANDLOCK_ACCESS_FS_REFER,
+ rules);
+
+ /*
+ * With RENAME_EXCHANGE, the whiteout object moves into the source
+ * directory of the rename: Exchanging the FIFO in dir_s3d4 with the
+ * whiteout object is denied because MAKE_REG is not granted in
+ * dir_s3d4, even though it is granted in the whiteout object's own
+ * directory dir_s3d3.
+ */
+ EXPECT_EQ(-1, renameat2(AT_FDCWD, file1_s3d4, AT_FDCWD, whiteout_s3d3,
+ RENAME_EXCHANGE));
+ EXPECT_EQ(EACCES, errno);
+
+ /*
+ * Exchanging the FIFO in dir_s3d3 with the whiteout object is
+ * allowed, because MAKE_REG is granted in the directory into which
+ * the whiteout object moves.
+ */
+ EXPECT_EQ(0, renameat2(AT_FDCWD, file1_s3d3, AT_FDCWD, whiteout_s3d3,
+ RENAME_EXCHANGE));
+
+ /* The FIFO and the whiteout object swapped places. */
+ EXPECT_TRUE(is_whiteout(file1_s3d3));
+ EXPECT_TRUE(is_fifo(whiteout_s3d3));
+}
+
TEST_F_FORK(layout1, rename_dir)
{
const struct rule rules[] = {
@@ -3456,6 +3641,18 @@ TEST_F_FORK(layout1, make_char)
makedev(1, 3));
}
+TEST_F_FORK(layout1, make_whiteout)
+{
+ /*
+ * Creates a whiteout object (creation guarded by MAKE_REG).
+ *
+ * Contrary to the other character devices, this does not require
+ * CAP_MKNOD, cf. vfs_mknod().
+ */
+ test_make_file(_metadata, LANDLOCK_ACCESS_FS_MAKE_REG, S_IFCHR,
+ makedev(0, 0));
+}
+
TEST_F_FORK(layout1, make_block)
{
/* Creates a /dev/loop0 device. */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 064/438] wifi: cfg80211: dont free driver-owned scan requests
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (62 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 063/438] dmaengine: wait for RCU readers before releasing dma_device Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 065/438] wifi: cfg80211: only group hidden BSSes with beacon entries Greg Kroah-Hartman
` (385 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+189dcafc06865d38178d,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit dab68a74e90b8e07f08ed9deaa5884857a3cfe89 ]
When an interface goes down while a scan is running, cfg80211 completes
the scan towards userspace and frees the scan request. However, the
driver can be convinced that it owns the request, since the cancellation
is (intended to be) asynchronous.
The WARN_ON() in the netdev notifier was meant to catch this, but it's
not actually avoidable, so it triggers and we get a UAF in scan_done().
There doesn't seem to be a great way around it, so just track that the
driver is still convinced it owns the request, and then just free it on
completion if it was already cancelled. Also remove the warnings since
they can trigger in the intended architecture.
Assisted-by: LLM
Fixes: 4a58e7c38443 ("cfg80211: don't "leak" uncompleted scans")
Reported-by: syzbot+189dcafc06865d38178d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=189dcafc06865d38178d
Link: https://patch.msgid.link/20260904165614.375e543228b1.I03cbb5a54cb02d6bba5034286af1ed73aba134d1@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/core.c | 11 +++++------
net/wireless/core.h | 10 ++++++++++
net/wireless/rdev-ops.h | 3 +++
net/wireless/scan.c | 31 +++++++++++++++++++++++++++++--
4 files changed, 47 insertions(+), 8 deletions(-)
diff --git a/net/wireless/core.c b/net/wireless/core.c
index d13310fef691a..8bb2cbd66b488 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -244,9 +244,8 @@ void cfg80211_stop_p2p_device(struct cfg80211_registered_device *rdev,
rdev->opencount--;
if (rdev->scan_req && rdev->scan_req->req.wdev == wdev) {
- if (WARN_ON(!rdev->scan_req->notified &&
- (!rdev->int_scan_req ||
- !rdev->int_scan_req->notified)))
+ if (!rdev->scan_req->notified &&
+ (!rdev->int_scan_req || !rdev->int_scan_req->notified))
rdev->scan_req->info.aborted = true;
___cfg80211_scan_done(rdev, false);
}
@@ -1758,9 +1757,9 @@ static int cfg80211_netdev_notifier_call(struct notifier_block *nb,
wiphy_lock(&rdev->wiphy);
cfg80211_update_iface_num(rdev, wdev->iftype, -1);
if (rdev->scan_req && rdev->scan_req->req.wdev == wdev) {
- if (WARN_ON(!rdev->scan_req->notified &&
- (!rdev->int_scan_req ||
- !rdev->int_scan_req->notified)))
+ if (!rdev->scan_req->notified &&
+ (!rdev->int_scan_req ||
+ !rdev->int_scan_req->notified))
rdev->scan_req->info.aborted = true;
___cfg80211_scan_done(rdev, false);
}
diff --git a/net/wireless/core.h b/net/wireless/core.h
index ac6ce9f967ec7..979e968ff5959 100644
--- a/net/wireless/core.h
+++ b/net/wireless/core.h
@@ -24,6 +24,16 @@
struct cfg80211_scan_request_int {
struct cfg80211_scan_info info;
bool notified;
+ /*
+ * set while the request is handed to the driver, i.e. between
+ * rdev_scan() and cfg80211_scan_done()
+ */
+ bool driver_owns;
+ /*
+ * set when cfg80211 is done with the request but the driver still
+ * owns it, so that cfg80211_scan_done() knows to just free it
+ */
+ bool stale;
/* must be last - variable members */
struct cfg80211_scan_request req;
};
diff --git a/net/wireless/rdev-ops.h b/net/wireless/rdev-ops.h
index 63c26e8b11395..8f466e1ab1d72 100644
--- a/net/wireless/rdev-ops.h
+++ b/net/wireless/rdev-ops.h
@@ -464,7 +464,10 @@ static inline int rdev_scan(struct cfg80211_registered_device *rdev,
return -EINVAL;
trace_rdev_scan(&rdev->wiphy, request);
+ request->driver_owns = true;
ret = rdev->ops->scan(&rdev->wiphy, &request->req);
+ if (ret)
+ request->driver_owns = false;
trace_rdev_return_int(&rdev->wiphy, ret);
return ret;
}
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 071083cc33672..1a28f95246764 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -1114,6 +1114,21 @@ int cfg80211_scan(struct cfg80211_registered_device *rdev)
return 0;
}
+/*
+ * Release the scan request, but free it only if the driver is also done,
+ * e.g. mac80211 may cancel it asynchronously and still use it.
+ */
+static void cfg80211_put_scan_req(struct cfg80211_scan_request_int *req)
+{
+ if (!req)
+ return;
+
+ if (req->driver_owns)
+ req->stale = true;
+ else
+ kfree(req);
+}
+
void ___cfg80211_scan_done(struct cfg80211_registered_device *rdev,
bool send_message)
{
@@ -1173,10 +1188,10 @@ void ___cfg80211_scan_done(struct cfg80211_registered_device *rdev,
dev_put(wdev->netdev);
- kfree(rdev->int_scan_req);
+ cfg80211_put_scan_req(rdev->int_scan_req);
rdev->int_scan_req = NULL;
- kfree(rdev->scan_req);
+ cfg80211_put_scan_req(rdev->scan_req);
rdev->scan_req = NULL;
if (!send_message)
@@ -1199,6 +1214,18 @@ void cfg80211_scan_done(struct cfg80211_scan_request *request,
struct cfg80211_scan_info old_info = intreq->info;
trace_cfg80211_scan_done(intreq, info);
+
+ intreq->driver_owns = false;
+
+ if (intreq->stale) {
+ /*
+ * The scan is already completed as far as we're concerned,
+ * it was just kept around for the driver - done now, free it.
+ */
+ kfree(intreq);
+ return;
+ }
+
WARN_ON(intreq != rdev->scan_req &&
intreq != rdev->int_scan_req);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 012/398] selftests/landlock: Add audit test for whiteout object creation
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (10 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 011/398] selftests/landlock: Add tests for whiteout object creation Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 013/398] sunvdc: fix -EIO issue due to lack of retries Greg Kroah-Hartman
` (390 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Günther Noack,
Mickaël Salaün, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Günther Noack <gnoack@google.com>
[ Upstream commit 8c46c6acbebe0d8544fd1b55e5ddf36828d7b9ea ]
Add audit_layout1.make_whiteout: This test looks similar to
audit_layout1.make_char, but creates a whiteout object through mknod().
Since whiteout object creation is now guarded with
LANDLOCK_ACCESS_FS_MAKE_REG rather than LANDLOCK_ACCESS_FS_MAKE_CHAR, it
also needs to log the matching denial to audit.
Signed-off-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260813093157.1436894-5-gnoack@google.com
Signed-off-by: Mickaël Salaün <mic@digikod.net>
[mic: Backport: adapt the audit test to the older ruleset helper]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/landlock/fs_test.c | 21 +++++++++++++++++++++
1 file changed, 21 insertions(+)
diff --git a/tools/testing/selftests/landlock/fs_test.c b/tools/testing/selftests/landlock/fs_test.c
index 3088d301073e4..ab5d7f792ee2a 100644
--- a/tools/testing/selftests/landlock/fs_test.c
+++ b/tools/testing/selftests/landlock/fs_test.c
@@ -7522,6 +7522,27 @@ TEST_F(audit_layout1, make_char)
EXPECT_EQ(1, records.domain);
}
+TEST_F(audit_layout1, make_whiteout)
+{
+ struct audit_records records;
+
+ EXPECT_EQ(0, unlink(file1_s1d3));
+
+ drop_access_rights(_metadata, &(struct landlock_ruleset_attr){
+ .handled_access_fs = access_fs_16,
+ });
+
+ /* Whiteout creation is denied and logged as fs.make_reg. */
+ EXPECT_EQ(-1, mknod(file1_s1d3, S_IFCHR | 0644, makedev(0, 0)));
+ EXPECT_EQ(EACCES, errno);
+ EXPECT_EQ(0, matches_log_fs(_metadata, self->audit_fd, "fs\\.make_reg",
+ dir_s1d3));
+
+ EXPECT_EQ(0, audit_count_records(self->audit_fd, &records));
+ EXPECT_EQ(0, records.access);
+ EXPECT_EQ(1, records.domain);
+}
+
TEST_F(audit_layout1, make_dir)
{
struct audit_records records;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 065/438] wifi: cfg80211: only group hidden BSSes with beacon entries
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (63 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 064/438] wifi: cfg80211: dont free driver-owned scan requests Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 066/438] wifi: cfg80211: dont filter by BSS type when removing stale entries Greg Kroah-Hartman
` (384 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1a797e1c81be78a2ace7,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 068843ed0902c552a13860c5ec6b2ca65b57a065 ]
When a probe response for an unknown BSS comes in, __cfg80211_bss_update()
looks for an existing entry with the same BSSID and a hidden (zero-length
or NUL-filled) SSID, and if it finds one it groups them, using the beacon
IEs from the existing entry.
But that could find another entry without a beacon, if it was also from a
probe response (with SSID), so there's a group without beacon elements.
If a beacon with a hidden SSID for that BSSID arrives later,
cfg80211_combine_bsses() goes looking for the probe response entries that
belong to it - i.e. entries with the same BSSID and channel that have no
beacon IEs - and finds those two. They are already grouped with each
other, so it hits its
WARN_ON_ONCE(bss->pub.hidden_beacon_bss)
WARN_ON_ONCE(!list_empty(&bss->hidden_list))
which are there because an entry without beacon elements is not supposed
to be part of a group yet.
Only combine entries when a beacon was already received, ones that are
kept separate will be combined when a beacon arrives.
Assisted-by: LLM
Fixes: 4593c4cbe1c9 ("cfg80211: fix BSS list hidden SSID lookup")
Reported-by: syzbot+1a797e1c81be78a2ace7@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1a797e1c81be78a2ace7
Link: https://patch.msgid.link/20260904165614.bcfa64715745.Iad740347c86de56d4ff4f96a95f3c3afc47c42de@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/scan.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 1a28f95246764..4f7d17e7f8337 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -2049,6 +2049,13 @@ __cfg80211_bss_update(struct cfg80211_registered_device *rdev,
if (!hidden)
hidden = rb_find_bss(rdev, tmp,
BSS_CMP_HIDE_NUL);
+ /*
+ * Only group with an entry with beacon data, otherwise
+ * beacon data can never be filled/updated.
+ */
+ if (hidden &&
+ !rcu_access_pointer(hidden->pub.beacon_ies))
+ hidden = NULL;
if (hidden) {
new->pub.hidden_beacon_bss = &hidden->pub;
list_add(&new->hidden_list,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 066/438] wifi: cfg80211: dont filter by BSS type when removing stale entries
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (64 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 065/438] wifi: cfg80211: only group hidden BSSes with beacon entries Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 067/438] wifi: cfg80211: ibss: ref BSS entry for joined event Greg Kroah-Hartman
` (383 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+dc6f4dce0d707900cdea,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit b377e1000d963e7182a987082b4b06580bd7ac84 ]
When an assoc AP switches to a channel that already has a BSS entry,
cfg80211_update_assoc_bss_entry() removes that entry before rehashing
the real one, since the two would otherwise collide in the BSS rbtree.
The lookup for that entry also required it to match the connection's BSS
type, so an entry advertising e.g. the IBSS capability bit was left in
place, and the following cfg80211_rehash_bss() then ran into it:
WARN_ON(!cmp)
Changing the type shouldn't really happen, but can be triggered by a
rogue AP/device, so drop the check and remove any entries matching
the comparison.
Assisted-by: LLM
Fixes: 0afd425b1b64 ("cfg80211: fix duplicated scan entries after channel switch")
Reported-by: syzbot+dc6f4dce0d707900cdea@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dc6f4dce0d707900cdea
Link: https://patch.msgid.link/20260904165614.1f05dae1c546.Ib52d57b57caa912efee020f9d4a033a5160617ce@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/scan.c | 5 -----
1 file changed, 5 deletions(-)
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 4f7d17e7f8337..4a1ec7e3547d8 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -3477,11 +3477,6 @@ void cfg80211_update_assoc_bss_entry(struct wireless_dev *wdev,
cbss->pub.channel = chan;
list_for_each_entry(bss, &rdev->bss_list, list) {
- if (!cfg80211_bss_type_match(bss->pub.capability,
- bss->pub.channel->band,
- wdev->conn_bss_type))
- continue;
-
if (bss == cbss)
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 013/398] sunvdc: fix -EIO issue due to lack of retries
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (11 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 012/398] selftests/landlock: Add audit test " Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 014/398] media: video-i2c: fix buffer queue ordering Greg Kroah-Hartman
` (389 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Paul Adrian Glaubitz,
Stian Halseth, Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Axboe <axboe@kernel.dk>
[ Upstream commit 5067d4ba713961d8ccea1e06cd4c453793f3121e ]
John reports that since commit:
a11f6ca9aef9 ("sunvdc: Do not spin in an infinite loop when vio_ldc_send() returns EAGAIN")
users of Linux inside Solaris ldom see occasional -EIO errors because
the request send loop now times out. The current loop does 10 retries,
and inside vio_ldc_send() a further 1000 1usec retries are done as well.
Even with 10.5 msec of busy loop retries that's apparently not enough to
always succeed.
Rather than introduce continued busy looping, requeue the request and
have the delayed queue kicking retry the request after another 10ms.
This obviously isn't ideal, but there's seemingly no way to wait for
this type of event. And if 10ms of busy looping was not enough to make
progress, then presumably this is an edge condition and we just need to
guarantee to make forward progress at some later point in time. That's
more suitably done through letting the CPU tend to other work, rather
than sitting in a tight loop retrying.
[stian: rebased on top of the cookie-unmap fix, without which every
requeued attempt leaks LDC map table entries; tested on an
UltraSPARC T4 LDOM where the vdc_tx_trigger failure condition was
reproduced and absorbed by the requeue with no I/O error]
Reported-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Link: https://lore.kernel.org/all/20251006100226.4246-2-glaubitz@physik.fu-berlin.de/
Link: https://lore.kernel.org/all/418310b3-2b77-4534-b2fd-27dcc11e333c@kernel.dk/
Signed-off-by: Stian Halseth <stian@itx.no>
Link: https://patch.msgid.link/20260901173947.3292110-3-stian@itx.no
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/block/sunvdc.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/block/sunvdc.c b/drivers/block/sunvdc.c
index 2eb96136632ac..1b5757aae57bd 100644
--- a/drivers/block/sunvdc.c
+++ b/drivers/block/sunvdc.c
@@ -556,6 +556,7 @@ static blk_status_t vdc_queue_rq(struct blk_mq_hw_ctx *hctx,
struct vdc_port *port = hctx->queue->queuedata;
struct vio_dring_state *dr;
unsigned long flags;
+ int ret;
dr = &port->vio.drings[VIO_DRIVER_TX_RING];
@@ -577,7 +578,13 @@ static blk_status_t vdc_queue_rq(struct blk_mq_hw_ctx *hctx,
return BLK_STS_DEV_RESOURCE;
}
- if (__send_request(bd->rq) < 0) {
+ ret = __send_request(bd->rq);
+ if (ret == -EAGAIN) {
+ spin_unlock_irqrestore(&port->vio.lock, flags);
+ /* already spun for 10msec, defer 10msec and retry */
+ blk_mq_delay_kick_requeue_list(hctx->queue, 10);
+ return BLK_STS_DEV_RESOURCE;
+ } else if (ret < 0) {
spin_unlock_irqrestore(&port->vio.lock, flags);
return BLK_STS_IOERR;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 067/438] wifi: cfg80211: ibss: ref BSS entry for joined event
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (65 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 066/438] wifi: cfg80211: dont filter by BSS type when removing stale entries Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 068/438] wifi: cfg80211: fix NAN regulatory enforcement Greg Kroah-Hartman
` (382 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+7f064ba1704c2466e36d,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 708f9d43d6a2eb9c6b83fe62af628de9dffd9314 ]
When the IBSS is joined, we only record the BSSID/channel in the event
and look up the BSS entry when processing it. However, that's racy,
e.g. a new scan with NL80211_SCAN_FLAG_FLUSH can remove it, causing a
warning in the event work:
!bss
WARNING: net/wireless/ibss.c:37 at __cfg80211_ibss_joined+0x3d3/0x440
Workqueue: cfg80211 cfg80211_event_work
cfg80211_process_wdev_events+0x39f/0x5b0 net/wireless/util.c:1144
cfg80211_process_rdev_events+0xa1/0x110 net/wireless/util.c:1179
cfg80211_event_work+0x2f/0x40 net/wireless/core.c:393
Do the lookup early (the driver is expected to only join an IBSS that
has a BSS entry) and keep a reference to it.
Assisted-by: LLM
Fixes: 667503ddcb96 ("cfg80211: fix locking")
Reported-by: syzbot+7f064ba1704c2466e36d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=7f064ba1704c2466e36d
Link: https://patch.msgid.link/20260904165614.f49a213f0e49.I192bfe738750ebb5f2c4faa3019a428da64cd3ec@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/core.h | 6 ++----
net/wireless/ibss.c | 36 ++++++++++++++++++++----------------
net/wireless/util.c | 3 +--
3 files changed, 23 insertions(+), 22 deletions(-)
diff --git a/net/wireless/core.h b/net/wireless/core.h
index 979e968ff5959..81e595247b932 100644
--- a/net/wireless/core.h
+++ b/net/wireless/core.h
@@ -290,8 +290,7 @@ struct cfg80211_event {
bool locally_generated;
} dc;
struct {
- u8 bssid[ETH_ALEN];
- struct ieee80211_channel *channel;
+ struct cfg80211_bss *bss;
} ij;
struct {
u8 peer_addr[ETH_ALEN];
@@ -354,8 +353,7 @@ int __cfg80211_join_ibss(struct cfg80211_registered_device *rdev,
void cfg80211_clear_ibss(struct net_device *dev, bool nowext);
int cfg80211_leave_ibss(struct cfg80211_registered_device *rdev,
struct net_device *dev, bool nowext);
-void __cfg80211_ibss_joined(struct net_device *dev, const u8 *bssid,
- struct ieee80211_channel *channel);
+void __cfg80211_ibss_joined(struct net_device *dev, struct cfg80211_bss *bss);
int cfg80211_ibss_wext_join(struct cfg80211_registered_device *rdev,
struct wireless_dev *wdev);
diff --git a/net/wireless/ibss.c b/net/wireless/ibss.c
index b1d748bdb504e..7f6779d326b81 100644
--- a/net/wireless/ibss.c
+++ b/net/wireless/ibss.c
@@ -16,26 +16,18 @@
#include "rdev-ops.h"
-void __cfg80211_ibss_joined(struct net_device *dev, const u8 *bssid,
- struct ieee80211_channel *channel)
+void __cfg80211_ibss_joined(struct net_device *dev, struct cfg80211_bss *bss)
{
struct wireless_dev *wdev = dev->ieee80211_ptr;
- struct cfg80211_bss *bss;
#ifdef CONFIG_CFG80211_WEXT
union iwreq_data wrqu;
#endif
if (WARN_ON(wdev->iftype != NL80211_IFTYPE_ADHOC))
- return;
+ goto put_bss;
if (!wdev->u.ibss.ssid_len)
- return;
-
- bss = cfg80211_get_bss(wdev->wiphy, channel, bssid, NULL, 0,
- IEEE80211_BSS_TYPE_IBSS, IEEE80211_PRIVACY_ANY);
-
- if (WARN_ON(!bss))
- return;
+ goto put_bss;
if (wdev->u.ibss.current_bss) {
cfg80211_unhold_bss(wdev->u.ibss.current_bss);
@@ -43,17 +35,22 @@ void __cfg80211_ibss_joined(struct net_device *dev, const u8 *bssid,
}
cfg80211_hold_bss(bss_from_pub(bss));
+ /* the reference from the event is transferred to current_bss */
wdev->u.ibss.current_bss = bss_from_pub(bss);
cfg80211_upload_connect_keys(wdev);
- nl80211_send_ibss_bssid(wiphy_to_rdev(wdev->wiphy), dev, bssid,
+ nl80211_send_ibss_bssid(wiphy_to_rdev(wdev->wiphy), dev, bss->bssid,
GFP_KERNEL);
#ifdef CONFIG_CFG80211_WEXT
memset(&wrqu, 0, sizeof(wrqu));
- memcpy(wrqu.ap_addr.sa_data, bssid, ETH_ALEN);
+ memcpy(wrqu.ap_addr.sa_data, bss->bssid, ETH_ALEN);
wireless_send_event(dev, SIOCGIWAP, &wrqu, NULL);
#endif
+ return;
+
+put_bss:
+ cfg80211_put_bss(wdev->wiphy, bss);
}
void cfg80211_ibss_joined(struct net_device *dev, const u8 *bssid,
@@ -62,6 +59,7 @@ void cfg80211_ibss_joined(struct net_device *dev, const u8 *bssid,
struct wireless_dev *wdev = dev->ieee80211_ptr;
struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
struct cfg80211_event *ev;
+ struct cfg80211_bss *bss;
unsigned long flags;
trace_cfg80211_ibss_joined(dev, bssid, channel);
@@ -69,13 +67,19 @@ void cfg80211_ibss_joined(struct net_device *dev, const u8 *bssid,
if (WARN_ON(!channel))
return;
+ bss = cfg80211_get_bss(wdev->wiphy, channel, bssid, NULL, 0,
+ IEEE80211_BSS_TYPE_IBSS, IEEE80211_PRIVACY_ANY);
+ if (WARN_ON(!bss))
+ return;
+
ev = kzalloc_obj(*ev, gfp);
- if (!ev)
+ if (!ev) {
+ cfg80211_put_bss(wdev->wiphy, bss);
return;
+ }
ev->type = EVENT_IBSS_JOINED;
- memcpy(ev->ij.bssid, bssid, ETH_ALEN);
- ev->ij.channel = channel;
+ ev->ij.bss = bss;
spin_lock_irqsave(&wdev->event_lock, flags);
list_add_tail(&ev->list, &wdev->event_list);
diff --git a/net/wireless/util.c b/net/wireless/util.c
index ef56fe0ac41b2..12285bbd29730 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -1184,8 +1184,7 @@ void cfg80211_process_wdev_events(struct wireless_dev *wdev)
!ev->dc.locally_generated);
break;
case EVENT_IBSS_JOINED:
- __cfg80211_ibss_joined(wdev->netdev, ev->ij.bssid,
- ev->ij.channel);
+ __cfg80211_ibss_joined(wdev->netdev, ev->ij.bss);
break;
case EVENT_STOPPED:
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 014/398] media: video-i2c: fix buffer queue ordering
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (12 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 013/398] sunvdc: fix -EIO issue due to lack of retries Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 015/398] ipv6: Select best matching nexthop object in fib6_table_lookup() Greg Kroah-Hartman
` (388 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Arash Golgol, Hans Verkuil,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arash Golgol <arash.golgol@gmail.com>
[ Upstream commit bc4574c265ed738849e46d942617100580fcedd2 ]
Queued buffers are added to the tail of vid_cap_active in
buffer_queue(), but the capture kthread also retrieves buffers from
the tail of the list.
This makes the queue behave as LIFO instead of FIFO when multiple
buffers are queued.
Fix this by retrieving buffers from the head of the list.
Signed-off-by: Arash Golgol <arash.golgol@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/i2c/video-i2c.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/media/i2c/video-i2c.c b/drivers/media/i2c/video-i2c.c
index 20889f94610cb..3584678756979 100644
--- a/drivers/media/i2c/video-i2c.c
+++ b/drivers/media/i2c/video-i2c.c
@@ -454,8 +454,9 @@ static int video_i2c_thread_vid_cap(void *priv)
spin_lock(&data->slock);
if (!list_empty(&data->vid_cap_active)) {
- vid_cap_buf = list_last_entry(&data->vid_cap_active,
- struct video_i2c_buffer, list);
+ vid_cap_buf = list_first_entry(&data->vid_cap_active,
+ struct video_i2c_buffer,
+ list);
list_del(&vid_cap_buf->list);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 068/438] wifi: cfg80211: fix NAN regulatory enforcement
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (66 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 067/438] wifi: cfg80211: ibss: ref BSS entry for joined event Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 069/438] wifi: mac80211: dont start a ROC while scanning Greg Kroah-Hartman
` (381 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 17a5f8571d1d40c88b78cfc154a7da0d60f13f37 ]
reg_wdev_chan_valid() returns early for any wdev that has no netdev,
which is fine for P2P originally (and later PD still), but NAN has
no netdev and yet enforcement code was added and is needed, but is
dead code right now.
Use wdev_running() instead so that netdev-less wdevs aren't skipped.
P2P/PD don't do anything in the later switch, but NAN code can now
be reached.
Assisted-by: LLM
Fixes: 0e8ec738a71e ("wifi: cfg80211: add support for NAN data interface")
Link: https://patch.msgid.link/20260904165614.6abc075b5401.Ib90696e3fa49b1698c27d64db5360d51f6f187a9@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/reg.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/wireless/reg.c b/net/wireless/reg.c
index 1e8214d6b6d88..3454afa038bf7 100644
--- a/net/wireless/reg.c
+++ b/net/wireless/reg.c
@@ -2345,7 +2345,7 @@ static bool reg_wdev_chan_valid(struct wiphy *wiphy, struct wireless_dev *wdev)
iftype = wdev->iftype;
/* make sure the interface is active */
- if (!wdev->netdev || !netif_running(wdev->netdev))
+ if (!wdev_running(wdev))
return true;
/* NAN doesn't have links, handle it separately */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 015/398] ipv6: Select best matching nexthop object in fib6_table_lookup()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (13 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 014/398] media: video-i2c: fix buffer queue ordering Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 016/398] ipv6: Honor oif when choosing nexthop for locally generated traffic Greg Kroah-Hartman
` (387 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, David Ahern,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ido Schimmel <idosch@nvidia.com>
[ Upstream commit 484bb9d164df397a53e0f533b262b27b1590efcb ]
Currently, when using multipath routes without nexthop objects,
fib6_table_lookup() selects the nexthop with the highest score. This
means that when both a source address and an oif are specified, the
nexthop that is chosen is the one that matches in terms of oif:
# sysctl -wq net.ipv6.conf.all.forwarding=1
# ip address add 2001:db8:2::1/64 dev lo
# ip route add 2001:db8:10::/64 nexthop via fe80::1 dev dummy1 nexthop via fe80::2 dev dummy2
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy1; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
When using nexthop objects, fib6_table_lookup() selects the first
matching nexthop and not necessarily the one with the highest score:
# ip nexthop add id 1 via fe80::1 dev dummy1
# ip nexthop add id 2 via fe80::2 dev dummy2
# ip nexthop add id 3 group 1/2
# ip route add 2001:db8:20::/64 nhid 3
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy1; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
This is not very significant right now because the nexthop is later
overwritten during path selection in fib6_select_path(). However, the
next patch is going to skip path selection when we have an oif match
during output route lookup.
As a preparation for this change, align the nexthop object behavior with
the legacy one and make sure that fib6_table_lookup() always selects the
best matching nexthop. Do that by always returning 0 from
rt6_nh_find_match() in order not to terminate the loop in
nexthop_for_each_fib6_nh() and storing in arg->nh the best matching
nexthop so far.
Behavior after the change:
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy1; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy1
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:20::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: David Ahern <dsahern@kernel.org>
Link: https://patch.msgid.link/20260611154605.992528-2-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/route.c | 17 +++++++++--------
1 file changed, 9 insertions(+), 8 deletions(-)
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index ddaf51eacc2d1..03b26738bd718 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -819,9 +819,11 @@ static int rt6_nh_find_match(struct fib6_nh *nh, void *_arg)
{
struct fib6_nh_frl_arg *arg = _arg;
- arg->nh = nh;
- return find_match(nh, arg->flags, arg->oif, arg->strict,
- arg->mpri, arg->do_rr);
+ if (find_match(nh, arg->flags, arg->oif, arg->strict, arg->mpri,
+ arg->do_rr))
+ arg->nh = nh;
+
+ return 0;
}
static void __find_rr_leaf(struct fib6_info *f6i_start,
@@ -861,11 +863,10 @@ static void __find_rr_leaf(struct fib6_info *f6i_start,
res->nh = nexthop_fib6_nh(f6i->nh);
return;
}
- if (nexthop_for_each_fib6_nh(f6i->nh, rt6_nh_find_match,
- &arg)) {
- matched = true;
- nh = arg.nh;
- }
+ nexthop_for_each_fib6_nh(f6i->nh, rt6_nh_find_match,
+ &arg);
+ matched = !!arg.nh;
+ nh = arg.nh;
} else {
nh = f6i->fib6_nh;
if (find_match(nh, f6i->fib6_flags, oif, strict,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 069/438] wifi: mac80211: dont start a ROC while scanning
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (67 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 068/438] wifi: cfg80211: fix NAN regulatory enforcement Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 070/438] wifi: mac80211: dont warn when an IBSS has no channel to scan Greg Kroah-Hartman
` (380 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+c3a167b5615df4ccd7fb,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 733f0fde95392ed5f61a4e36aee661ea8d0e8581 ]
The ROC work can be pending when a scan starts (which requires
ROC list to be empty, but that's possible), and then a new ROC
can be added to the list and the work will pick it up.
Avoid starting that ROC if a scan made it between things, as
otherwise we'll hit a warning later:
WARNING: net/mac80211/offchannel.c:404 at ieee80211_start_next_roc+0x256/0x2d0
Workqueue: events_unbound cfg80211_wiphy_work
Call Trace:
__ieee80211_scan_completed+0x4fd/0xe40 net/mac80211/scan.c:537
ieee80211_scan_work+0x472/0x1ff0 net/mac80211/scan.c:1193
cfg80211_wiphy_work+0x410/0x570 net/wireless/core.c:513
Assisted-by: LLM
Fixes: aaa016ccd5df ("mac80211: rewrite remain-on-channel logic")
Reported-by: syzbot+c3a167b5615df4ccd7fb@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c3a167b5615df4ccd7fb
Link: https://patch.msgid.link/20260904165722.f9d5b150edd8.I61bc9de8c8d089096ad695213b9c85c7df38c3bd@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/offchannel.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/mac80211/offchannel.c b/net/mac80211/offchannel.c
index 2bceb73717c66..6f8de5d4a20d3 100644
--- a/net/mac80211/offchannel.c
+++ b/net/mac80211/offchannel.c
@@ -460,6 +460,13 @@ static void __ieee80211_roc_work(struct ieee80211_local *local)
return;
if (!roc->started) {
+ /*
+ * The work can be started by a previous ROC work, but a scan
+ * can get between things; scan finish will retrigger us.
+ */
+ if (local->scanning)
+ return;
+
WARN_ON(!local->emulate_chanctx);
_ieee80211_start_next_roc(local);
} else {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 016/398] ipv6: Honor oif when choosing nexthop for locally generated traffic
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (14 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 015/398] ipv6: Select best matching nexthop object in fib6_table_lookup() Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 017/398] xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() Greg Kroah-Hartman
` (386 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Ahern, Ido Schimmel,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ido Schimmel <idosch@nvidia.com>
[ Upstream commit d25e7e9d8a6c1e2afb854613e417c6aa1a28ce6f ]
Commit 741a11d9e410 ("net: ipv6: Add RT6_LOOKUP_F_IFACE flag if oif is
set") made the kernel honor the oif parameter when specified as part of
output route lookup:
# ip route add 2001:db8:1::/64 dev dummy1
# ip route add ::/0 dev dummy2
# ip route get 2001:db8:1::1 oif dummy2 fibmatch
default dev dummy2 metric 1024 pref medium
Due to regression reports, the behavior was partially reverted in commit
d46a9d678e4c ("net: ipv6: Dont add RT6_LOOKUP_F_IFACE flag if saddr
set") to only honor the oif if source address is not specified:
# ip route get 2001:db8:1::1 from 2001:db8:2::1 oif dummy2 fibmatch
2001:db8:1::/64 dev dummy1 metric 1024 pref medium
That is, when source address is specified, the kernel will choose the
most specific route even if its nexthop device does not match the
specified oif.
This creates a problem for multipath routes. After looking up a route,
when source address is not specified, the kernel will choose a nexthop
whose nexthop device matches the specified oif:
# sysctl -wq net.ipv6.conf.all.forwarding=1
# ip route add 2001:db8:10::/64 nexthop via fe80::1 dev dummy1 nexthop via fe80::2 dev dummy2
# for i in {1..100}; do ip route get 2001:db8:10::${i} oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
But will disregard the oif when source address is specified despite the
fact that a matching nexthop exists:
# for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
53 dummy1
47 dummy2
This behavior differs from IPv4:
# ip address add 192.0.2.1/32 dev lo
# ip route add 198.51.100.0/24 nexthop via inet6 fe80::1 dev dummy1 nexthop via inet6 fe80::2 dev dummy2
# for i in {1..100}; do ip route get 198.51.100.${i} from 192.0.2.1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
What happens is that fib6_table_lookup() returns a route with a matching
nexthop device (assuming it exists):
# perf record -e fib6:fib6_table_lookup -- bash -c "for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done > /dev/null"
# perf script | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
But it is later overwritten during path selection in fib6_select_path()
which instead chooses a nexthop according to the calculated hash.
Solve this by telling fib6_select_path() to skip path selection if we
have an oif match during output route lookup (iif being
LOOPBACK_IFINDEX).
Behavior after the change:
# sysctl -wq net.ipv6.conf.all.forwarding=1
# ip route add 2001:db8:10::/64 nexthop via fe80::1 dev dummy1 nexthop via fe80::2 dev dummy2
# for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
100 dummy2
Note that enabling forwarding is only needed because we did not add
neighbor entries for the gateway addresses. When forwarding is disabled
and CONFIG_IPV6_ROUTER_PREF is not enabled in kernel config, the kernel
will treat non-existing neighbor entries as errors and perform
round-robin between the nexthops:
# sysctl -wq net.ipv6.conf.all.forwarding=0
# for i in {1..100}; do ip route get 2001:db8:10::${i} from 2001:db8:2::1 oif dummy2; done | grep -o dummy[0-9] | sort | uniq -c
50 dummy1
50 dummy2
Reviewed-by: David Ahern <dsahern@kernel.org>
Signed-off-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260611154605.992528-3-idosch@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/route.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index 03b26738bd718..71a38034f5ca8 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -2272,6 +2272,7 @@ struct rt6_info *ip6_pol_route(struct net *net, struct fib6_table *table,
{
struct fib6_result res = {};
struct rt6_info *rt = NULL;
+ bool have_oif_match;
int strict = 0;
WARN_ON_ONCE((flags & RT6_LOOKUP_F_DST_NOREF) &&
@@ -2288,7 +2289,9 @@ struct rt6_info *ip6_pol_route(struct net *net, struct fib6_table *table,
if (res.f6i == net->ipv6.fib6_null_entry)
goto out;
- fib6_select_path(net, &res, fl6, oif, false, skb, strict);
+ have_oif_match = fl6->flowi6_iif == LOOPBACK_IFINDEX &&
+ oif == res.nh->fib_nh_dev->ifindex;
+ fib6_select_path(net, &res, fl6, oif, have_oif_match, skb, strict);
/*Search through exception table */
rt = rt6_find_cached_rt(&res, &fl6->daddr, &fl6->saddr);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 070/438] wifi: mac80211: dont warn when an IBSS has no channel to scan
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (68 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 069/438] wifi: mac80211: dont start a ROC while scanning Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 071/438] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces Greg Kroah-Hartman
` (379 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1634c5399e29d8b66789,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit a7491b7efbd9136b120a12ed72af9c12121dd134 ]
ieee80211_request_ibss_scan() warns when regulatory leaves no
allowed channel, but that can happen as the regdomain can change
while IBSS is operating, and it can continue to operate briefly
during the 60s grace period until it's shut down.
Just remove the warning in this case.
Assisted-by: LLM
Fixes: 34bcf7150241 ("mac80211: fix ibss scanning")
Reported-by: syzbot+1634c5399e29d8b66789@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1634c5399e29d8b66789
Link: https://patch.msgid.link/20260904165722.fe380c27fef4.I0e8bee2e12a40d240851a4bc724d47753af46159@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/scan.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/mac80211/scan.c b/net/mac80211/scan.c
index eeff230bd909f..8e950ef6d1ead 100644
--- a/net/mac80211/scan.c
+++ b/net/mac80211/scan.c
@@ -1242,7 +1242,7 @@ int ieee80211_request_ibss_scan(struct ieee80211_sub_if_data *sdata,
}
}
- if (WARN_ON_ONCE(n_ch == 0))
+ if (n_ch == 0)
return -EINVAL;
local->int_scan_req->n_channels = n_ch;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 017/398] xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (15 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 016/398] ipv6: Honor oif when choosing nexthop for locally generated traffic Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 018/398] xfrm: iptfs: fix runt reassembly panic from short inner tot_len Greg Kroah-Hartman
` (385 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Roshan Kumar, Steffen Klassert,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Roshan Kumar <roshaen09@gmail.com>
[ Upstream commit d042487dc118e494db2e2c1382310255c90ff544 ]
iptfs_skb_reset_frag_walk() advances to the fragment containing @offset
with an unbounded loop:
while (offset >= walk->past + walk->frags[walk->fragi].len)
walk->past += walk->frags[walk->fragi++].len;
walk->fragi is advanced and walk->frags[walk->fragi] is dereferenced
without ever checking fragi against walk->nr_frags. When the requested
offset is at or beyond the total length spanned by the walk's fragments,
fragi runs past nr_frags and off the end of the fixed-size on-stack
frags[MAX_SKB_FRAGS + 1] array, reading out-of-bounds stack memory.
The two callers behave differently: iptfs_skb_add_frags() already guards
against this with
if (!walk->nr_frags ||
offset >= walk->total + walk->initial_offset)
return len;
but iptfs_skb_can_add_frags() has no such guard and calls
iptfs_skb_reset_frag_walk() unconditionally, so it performs the
out-of-range walk. Its own "fragi < walk->nr_frags" bound check runs only
afterwards, too late to prevent the read.
This is reachable from the receive path: a crafted IP-TFS (AGGFRAG)
payload delivered to an IPTFS SA drives iptfs_reassem_cont() ->
iptfs_skb_can_add_frags() with an offset past the fragment total, e.g.:
BUG: KASAN: stack-out-of-bounds in iptfs_skb_reset_frag_walk+0x235/0x250
Read of size 4 at addr ffff888008ad7210 by task repro/345
iptfs_skb_reset_frag_walk+0x235/0x250 net/xfrm/xfrm_iptfs.c:392
iptfs_skb_can_add_frags+0x155/0x310 net/xfrm/xfrm_iptfs.c:420
iptfs_reassem_cont+0xcf8/0x1140 net/xfrm/xfrm_iptfs.c:902
iptfs_input_ordered+0x552/0x670 net/xfrm/xfrm_iptfs.c:1280
iptfs_input+0x3d6/0xde0 net/xfrm/xfrm_iptfs.c:1741
xfrm_input+0x282f/0x6140 net/xfrm/xfrm_input.c:700
xfrm4_esp_rcv+0x93/0x120 net/ipv4/xfrm4_protocol.c:104
ip_rcv+0x278/0x2d0 net/ipv4/ip_input.c:612
Give iptfs_skb_can_add_frags() the same up-front guard that
iptfs_skb_add_frags() already has, so the walk is never entered with an
out-of-range offset. When it triggers, the caller falls back to the
existing linearize-and-copy path, which is safe.
Fixes: 5f2b6a909574 ("xfrm: iptfs: add skb-fragment sharing code")
Reported-by: Roshan Kumar <roshaen09@gmail.com>
Signed-off-by: Roshan Kumar <roshaen09@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_iptfs.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/net/xfrm/xfrm_iptfs.c b/net/xfrm/xfrm_iptfs.c
index d39253b06c4ef..0f562301ceb34 100644
--- a/net/xfrm/xfrm_iptfs.c
+++ b/net/xfrm/xfrm_iptfs.c
@@ -416,6 +416,14 @@ static bool iptfs_skb_can_add_frags(const struct sk_buff *skb,
if (skb_has_frag_list(skb) || skb->pp_recycle != walk->pp_recycle)
return false;
+ /* Reject an @offset that is at or beyond the end of the walk's data
+ * before calling iptfs_skb_reset_frag_walk(), whose fragment-advance
+ * loop is otherwise unbounded and would index past walk->frags[].
+ * This mirrors the guard already present in iptfs_skb_add_frags().
+ */
+ if (!walk->nr_frags || offset >= walk->total + walk->initial_offset)
+ return false;
+
/* Make offset relative to current frag after setting that */
offset = iptfs_skb_reset_frag_walk(walk, offset);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 071/438] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (69 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 070/438] wifi: mac80211: dont warn when an IBSS has no channel to scan Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 072/438] wifi: mac80211: suppress chanctx warning for debugfs reset Greg Kroah-Hartman
` (378 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f1ba58d6b55abd13239e,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 362bd5bce29ed0f6fd3d39a7065567777d70606e ]
AP_VLAN interfaces are purely virtual, so don't try to offload
TC setup to drivers. We can't really use the AP interface either
since we may not know it all the time, and it could technically
even change.
Just reject the TC offload so things get done in software.
Assisted-by: LLM
Fixes: 61587f1556fe ("wifi: mac80211: add support for letting drivers register tc offload support")
Reported-by: syzbot+f1ba58d6b55abd13239e@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f1ba58d6b55abd13239e
Link: https://patch.msgid.link/20260904165722.726cc076cecb.Iccfd88b13635425e850ce031376eb60a4ce5f4f8@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 43460a705a6bd..8c300e045fdf9 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -935,6 +935,9 @@ static int ieee80211_netdev_setup_tc(struct net_device *dev,
struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
struct ieee80211_local *local = sdata->local;
+ if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
+ return -EOPNOTSUPP;
+
return drv_net_setup_tc(local, sdata, dev, type, type_data);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 018/398] xfrm: iptfs: fix runt reassembly panic from short inner tot_len
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (16 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 017/398] xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 019/398] xfrm: avoid RCU warnings around the per-netns netlink socket Greg Kroah-Hartman
` (384 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Henry Martin, Steffen Klassert,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Henry Martin <bsdhenrymartin@gmail.com>
[ Upstream commit dc33262be1fe43d0eb0b84fb58c6ed42e2f64a8c ]
When the start of an inner packet is split across two outer packets
such that fewer than 4 bytes land at the end of the first one,
__input_process_payload() saves those bytes as a runt and skips the
iplen/iphlen validation performed for in-place packets. When the
continuation packet arrives, iptfs_reassem_cont() only requires the
declared inner length to be >= sizeof(ra_runt) (6) before allocating
the reassembly skb with that attacker-controlled length.
However, __iptfs_iphlen() always returns the fixed minimum IP header
size (20 for IPv4, 40 for IPv6), so for an inner IPv4 tot_len in
[6, 19] the header-completion copy writes past the declared packet
length, and the subsequent "ipremain -= copylen" underflows to ~4GB,
leaving the payload copy length bounded only by blkoff (up to 64KB).
At runtime the skb_put() tailroom check turns this into
skb_over_panic(), i.e. an unprivileged kernel panic (DoS), reachable
locally via userns+netns IPTFS SAs and remotely against IPTFS VPN
gateways when the decrypted outer skb is linear (e.g. AF_PACKET taps,
tun/tap delivery).
Align the runt path with the normal path by requiring the declared
inner length to cover at least the IP header size. This also subsumes
the previous >= sizeof(ra_runt) check, since the minimum IP header
is always larger than the runt buffer.
This issue was found by the autokbug dynamic kernel fuzzer at
Tencent Yunding Lab.
Fixes: 075694765446 ("xfrm: iptfs: handle received fragmented inner packets")
Reported-by: Henry Martin <bsdhenrymartin@gmail.com>
Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_iptfs.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/xfrm/xfrm_iptfs.c b/net/xfrm/xfrm_iptfs.c
index 0f562301ceb34..4d3489acb099a 100644
--- a/net/xfrm/xfrm_iptfs.c
+++ b/net/xfrm/xfrm_iptfs.c
@@ -828,8 +828,8 @@ static u32 iptfs_reassem_cont(struct xfrm_iptfs_data *xtfs, u64 seq,
* allocate an in progress skb
*/
ipremain = __iptfs_iplen(xtfs->ra_runt);
- if (ipremain < sizeof(xtfs->ra_runt)) {
- /* length has to be at least runtsize large */
+ if (ipremain < __iptfs_iphlen(xtfs->ra_runt)) {
+ /* length has to be at least the IP header size */
XFRM_INC_STATS(xs_net(xtfs->x),
LINUX_MIB_XFRMINIPTFSERROR);
goto abandon;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 072/438] wifi: mac80211: suppress chanctx warning for debugfs reset
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (70 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 071/438] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 073/438] wifi: mac80211: abort chanswitch when leaving a mesh Greg Kroah-Hartman
` (377 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+56a1a45a9a2c04d425ff,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit bf29d085e0eba92388518719d044f4702a8c6644 ]
Before suspend all the channel contexts should removed, so the
warning makes sense and should be there, but during reset the
same code is called without first removing. Limit the check to
the real suspend case.
Assisted-by: LLM
Fixes: 12e7f517029d ("mac80211: cleanup generic suspend/resume procedures")
Reported-by: syzbot+56a1a45a9a2c04d425ff@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=56a1a45a9a2c04d425ff
Link: https://patch.msgid.link/20260904165722.fe46395e310b.Ic4aaa95bd9d0ceb6a3cd7d84c425afee7d7d3dd7@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 2 +-
net/mac80211/debugfs.c | 2 +-
net/mac80211/ieee80211_i.h | 2 +-
net/mac80211/pm.c | 8 +++++---
4 files changed, 8 insertions(+), 6 deletions(-)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index 43f142624d33e..213f1d39f9e07 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -3475,7 +3475,7 @@ static int ieee80211_set_txq_params(struct wiphy *wiphy,
static int ieee80211_suspend(struct wiphy *wiphy,
struct cfg80211_wowlan *wowlan)
{
- return __ieee80211_suspend(wiphy_priv(wiphy), wowlan);
+ return __ieee80211_suspend(wiphy_priv(wiphy), wowlan, false);
}
static int ieee80211_resume(struct wiphy *wiphy)
diff --git a/net/mac80211/debugfs.c b/net/mac80211/debugfs.c
index a4d5461f6480f..f36cc25903050 100644
--- a/net/mac80211/debugfs.c
+++ b/net/mac80211/debugfs.c
@@ -388,7 +388,7 @@ static ssize_t reset_write(struct file *file, const char __user *user_buf,
rtnl_lock();
wiphy_lock(local->hw.wiphy);
- __ieee80211_suspend(&local->hw, NULL);
+ __ieee80211_suspend(&local->hw, NULL, true);
ret = __ieee80211_resume(&local->hw);
wiphy_unlock(local->hw.wiphy);
diff --git a/net/mac80211/ieee80211_i.h b/net/mac80211/ieee80211_i.h
index 34a9ea8b6f857..0564370419fba 100644
--- a/net/mac80211/ieee80211_i.h
+++ b/net/mac80211/ieee80211_i.h
@@ -2433,7 +2433,7 @@ int ieee80211_reconfig(struct ieee80211_local *local);
void ieee80211_stop_device(struct ieee80211_local *local, bool suspend);
int __ieee80211_suspend(struct ieee80211_hw *hw,
- struct cfg80211_wowlan *wowlan);
+ struct cfg80211_wowlan *wowlan, bool reset);
static inline int __ieee80211_resume(struct ieee80211_hw *hw)
{
diff --git a/net/mac80211/pm.c b/net/mac80211/pm.c
index 5a508d99e84f7..f63676c448536 100644
--- a/net/mac80211/pm.c
+++ b/net/mac80211/pm.c
@@ -18,7 +18,8 @@ static void ieee80211_sched_scan_cancel(struct ieee80211_local *local)
cfg80211_sched_scan_stopped_locked(local->hw.wiphy, 0);
}
-int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan)
+int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan,
+ bool reset)
{
struct ieee80211_local *local = hw_to_local(hw);
struct ieee80211_sub_if_data *sdata;
@@ -166,9 +167,10 @@ int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan)
/*
* We disconnected on all interfaces before suspend, all channel
- * contexts should be released.
+ * contexts should be released, but on 'reset' debugfs that's
+ * not true so don't check there.
*/
- WARN_ON(!list_empty(&local->chanctx_list));
+ WARN_ON(!reset && !list_empty(&local->chanctx_list));
/* stop hardware - this must stop RX */
ieee80211_stop_device(local, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 019/398] xfrm: avoid RCU warnings around the per-netns netlink socket
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (17 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 018/398] xfrm: iptfs: fix runt reassembly panic from short inner tot_len Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 020/398] xfrm: fix compat ALLOCSPI request use-after-free Greg Kroah-Hartman
` (383 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sabrina Dubroca, Simon Horman,
Steffen Klassert, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sabrina Dubroca <sd@queasysnail.net>
[ Upstream commit d87f8bc47fbf012a7f115e311d0603d97e47c34c ]
net->xfrm.nlsk is used in 2 types of contexts:
- fully under RCU, with rcu_read_lock + rcu_dereference and a NULL check
- in the netlink handlers, with requests coming from a userspace socket
In the 2nd case, net->xfrm.nlsk is guaranteed to stay non-NULL and the
object is alive, since we can't enter the netns destruction path while
the user socket holds a reference on the netns.
After adding the __rcu annotation to netns_xfrm.nlsk (which silences
sparse warnings in the RCU users and __net_init code), we need to tell
sparse that the 2nd case is safe. Add a helper for that.
Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Stable-dep-of: d1ebd9081879 ("xfrm: fix compat ALLOCSPI request use-after-free")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/netns/xfrm.h | 2 +-
net/xfrm/xfrm_user.c | 25 +++++++++++++++++--------
2 files changed, 18 insertions(+), 9 deletions(-)
diff --git a/include/net/netns/xfrm.h b/include/net/netns/xfrm.h
index 23dd647fe0248..b73983a17e088 100644
--- a/include/net/netns/xfrm.h
+++ b/include/net/netns/xfrm.h
@@ -59,7 +59,7 @@ struct netns_xfrm {
struct list_head inexact_bins;
- struct sock *nlsk;
+ struct sock __rcu *nlsk;
struct sock *nlsk_stash;
u32 sysctl_aevent_etime;
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 0f0384b6a11d0..4e80e1b5ef4b4 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -35,6 +35,15 @@
#endif
#include <linux/unaligned.h>
+static struct sock *xfrm_net_nlsk(const struct net *net, const struct sk_buff *skb)
+{
+ /* get the source of this request, see netlink_unicast_kernel */
+ const struct sock *sk = NETLINK_CB(skb).sk;
+
+ /* sk is refcounted, the netns stays alive and nlsk with it */
+ return rcu_dereference_protected(net->xfrm.nlsk, sk->sk_net_refcnt);
+}
+
static int verify_one_alg(struct nlattr **attrs, enum xfrm_attr_type_t type,
struct netlink_ext_ack *extack)
{
@@ -1727,7 +1736,7 @@ static int xfrm_get_spdinfo(struct sk_buff *skb, struct nlmsghdr *nlh,
err = build_spdinfo(r_skb, net, sportid, seq, *flags);
BUG_ON(err < 0);
- return nlmsg_unicast(net->xfrm.nlsk, r_skb, sportid);
+ return nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, sportid);
}
static inline unsigned int xfrm_sadinfo_msgsize(void)
@@ -1787,7 +1796,7 @@ static int xfrm_get_sadinfo(struct sk_buff *skb, struct nlmsghdr *nlh,
err = build_sadinfo(r_skb, net, sportid, seq, *flags);
BUG_ON(err < 0);
- return nlmsg_unicast(net->xfrm.nlsk, r_skb, sportid);
+ return nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, sportid);
}
static int xfrm_get_sa(struct sk_buff *skb, struct nlmsghdr *nlh,
@@ -1807,7 +1816,7 @@ static int xfrm_get_sa(struct sk_buff *skb, struct nlmsghdr *nlh,
if (IS_ERR(resp_skb)) {
err = PTR_ERR(resp_skb);
} else {
- err = nlmsg_unicast(net->xfrm.nlsk, resp_skb, NETLINK_CB(skb).portid);
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid);
}
xfrm_state_put(x);
out_noput:
@@ -1898,7 +1907,7 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
}
}
- err = nlmsg_unicast(net->xfrm.nlsk, resp_skb, NETLINK_CB(skb).portid);
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid);
out:
xfrm_state_put(x);
@@ -2542,7 +2551,7 @@ static int xfrm_get_default(struct sk_buff *skb, struct nlmsghdr *nlh,
r_up->out = READ_ONCE(net->xfrm.policy_default[XFRM_POLICY_OUT]);
nlmsg_end(r_skb, r_nlh);
- return nlmsg_unicast(net->xfrm.nlsk, r_skb, portid);
+ return nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, portid);
}
static int xfrm_get_policy(struct sk_buff *skb, struct nlmsghdr *nlh,
@@ -2608,7 +2617,7 @@ static int xfrm_get_policy(struct sk_buff *skb, struct nlmsghdr *nlh,
if (IS_ERR(resp_skb)) {
err = PTR_ERR(resp_skb);
} else {
- err = nlmsg_unicast(net->xfrm.nlsk, resp_skb,
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb,
NETLINK_CB(skb).portid);
}
} else {
@@ -2787,7 +2796,7 @@ static int xfrm_get_ae(struct sk_buff *skb, struct nlmsghdr *nlh,
return err;
}
- err = nlmsg_unicast(net->xfrm.nlsk, r_skb, NETLINK_CB(skb).portid);
+ err = nlmsg_unicast(xfrm_net_nlsk(net, skb), r_skb, NETLINK_CB(skb).portid);
spin_unlock_bh(&x->lock);
xfrm_state_put(x);
return err;
@@ -3491,7 +3500,7 @@ static int xfrm_user_rcv_msg(struct sk_buff *skb, struct nlmsghdr *nlh,
goto err;
}
- err = netlink_dump_start(net->xfrm.nlsk, skb, nlh, &c);
+ err = netlink_dump_start(xfrm_net_nlsk(net, skb), skb, nlh, &c);
goto err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 073/438] wifi: mac80211: abort chanswitch when leaving a mesh
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (71 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 072/438] wifi: mac80211: suppress chanctx warning for debugfs reset Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 074/438] wifi: mac80211: reset state when starting AP fails Greg Kroah-Hartman
` (376 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+81cd9dc1596563141d19,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit ac7472a24bd433b81c06582835dd1d5547c10da9 ]
The code in ieee80211_stop_mesh() leaves CSA active, but leaving
the mesh released the channel context, so the CSA finalize work
crashes:
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000003
KASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f]
RIP: 0010:ieee80211_put_srates_elem+0x42/0x640 net/mac80211/util.c:3272
Call Trace:
ieee80211_mesh_build_beacon+0xa83/0x1b50 net/mac80211/mesh.c:1093
ieee80211_mesh_rebuild_beacon+0xc7/0x170 net/mac80211/mesh.c:1147
ieee80211_mesh_finish_csa+0x131/0x210 net/mac80211/mesh.c:1542
ieee80211_set_after_csa_beacon net/mac80211/cfg.c:4085 [inline]
__ieee80211_csa_finalize net/mac80211/cfg.c:4133 [inline]
ieee80211_csa_finalize+0x633/0x1150 net/mac80211/cfg.c:4155
cfg80211_wiphy_work+0x2ab/0x450 net/wireless/core.c:438
Abort the channel switch properly.
Assisted-by: LLM
Fixes: b8456a14e9d2 ("{nl,cfg,mac}80211: implement mesh channel switch userspace API")
Reported-by: syzbot+81cd9dc1596563141d19@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=81cd9dc1596563141d19
Link: https://patch.msgid.link/20260904165722.d0b87eee08aa.I80550d6127e0bb26efb49a5fbe95be1aef1cd0cb@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mesh.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index d4507e4e6ec16..bed7ac8382505 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -1204,6 +1204,10 @@ void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
netif_carrier_off(sdata->dev);
+ /* abort any running channel switch */
+ sdata->vif.bss_conf.csa_active = false;
+ ieee80211_vif_unblock_queues_csa(sdata);
+
/* flush STAs and mpaths on this iface */
sta_info_flush(sdata, -1);
ieee80211_free_keys(sdata, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 020/398] xfrm: fix compat ALLOCSPI request use-after-free
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (18 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 019/398] xfrm: avoid RCU warnings around the per-netns netlink socket Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 021/398] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() Greg Kroah-Hartman
` (382 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kyle Zeng, David Lee,
Steffen Klassert, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kyle Zeng <kylebot@openai.com>
[ Upstream commit d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320 ]
xfrm_state_netlink() builds the ALLOCSPI response with
dump_one_state(), which already calls alloc_compat() with the response
skb and header.
xfrm_alloc_userspi() then calls alloc_compat() again, but passes the
original request skb and its header. For a compat request, the
translator therefore interprets the 228-byte compat xfrm_userspi_info
as the 232-byte native layout and reads four bytes past the declared
payload. It also publishes the translated child through the request's
frag_list.
A multicast clone of the request shares skb_shared_info and can observe
that child. xfrm_user_rcv_msg() frees it after the request handler
returns, racing a compat receiver which may still be copying from it and
resulting in a use-after-free.
Remove the redundant conversion. The response keeps its correct compat
translation from dump_one_state(), and no child is attached to the
inbound request.
Fixes: 5f3eea6b7e8f ("xfrm/compat: Attach xfrm dumps to 64=>32 bit translator")
Assisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber
Signed-off-by: Kyle Zeng <kylebot@openai.com>
Co-developed-by: David Lee <david.lee@trailofbits.com>
Signed-off-by: David Lee <david.lee@trailofbits.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_user.c | 12 ------------
1 file changed, 12 deletions(-)
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 4e80e1b5ef4b4..2560f3653bd38 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -1830,7 +1830,6 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
struct net *net = sock_net(skb->sk);
struct xfrm_state *x;
struct xfrm_userspi_info *p;
- struct xfrm_translator *xtr;
struct sk_buff *resp_skb;
xfrm_address_t *daddr;
int family;
@@ -1896,17 +1895,6 @@ static int xfrm_alloc_userspi(struct sk_buff *skb, struct nlmsghdr *nlh,
goto out;
}
- xtr = xfrm_get_translator();
- if (xtr) {
- err = xtr->alloc_compat(skb, nlmsg_hdr(skb));
-
- xfrm_put_translator(xtr);
- if (err) {
- kfree_skb(resp_skb);
- goto out;
- }
- }
-
err = nlmsg_unicast(xfrm_net_nlsk(net, skb), resp_skb, NETLINK_CB(skb).portid);
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 074/438] wifi: mac80211: reset state when starting AP fails
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (72 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 073/438] wifi: mac80211: abort chanswitch when leaving a mesh Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 075/438] wifi: mac80211: reset the LED state when ifup fails Greg Kroah-Hartman
` (375 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+ca7a2759caaa6cd4e3db,
syzbot+c4686c3eb8b64032618f, Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 3f28551d0241254a75626d868041c6340285088b ]
ieee80211_start_ap() can set enable_beacon (and beacon_int) and fail
later, leaving it set forever. Scanning can then attempt to restore
beaconing on such an interface, leading to:
Oops: divide error: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:mac80211_hwsim_link_info_changed+0xca7/0xf00
Call Trace:
drv_link_info_changed+0x413/0x860 net/mac80211/driver-ops.c:495
ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427
ieee80211_offchannel_return+0x381/0x580 net/mac80211/offchannel.c:160
__ieee80211_scan_completed+0x993/0xe30 net/mac80211/scan.c:519
ieee80211_scan_work+0x472/0x2010 net/mac80211/scan.c:1193
cfg80211_wiphy_work+0x2b7/0x550 net/wireless/core.c:538
in hwsim. Also, cfg80211 then allows changing the interface type,
and the off-channel path getgs confused about beaconing as well,
leading to another warning:
WARNING: net/mac80211/driver-ops.c:468 at drv_link_info_changed+0x583/0x880
ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427
ieee80211_offchannel_stop_vifs+0x328/0x5c0 net/mac80211/offchannel.c:122
ieee80211_start_sw_scan net/mac80211/scan.c:583 [inline]
__ieee80211_start_scan+0xfb6/0x1af0 net/mac80211/scan.c:882
Reset the state on failures to always have it correct.
Assisted-by: LLM
Fixes: d6a83228823f ("mac80211: track enable_beacon explicitly")
Reported-by: syzbot+ca7a2759caaa6cd4e3db@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=ca7a2759caaa6cd4e3db
Reported-by: syzbot+c4686c3eb8b64032618f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c4686c3eb8b64032618f
Link: https://patch.msgid.link/20260904165722.9629429a5221.I7f599412bfe12a09d41ea4901be9ad165d07d133@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index 213f1d39f9e07..45f8e3c87884a 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -1929,6 +1929,9 @@ static int ieee80211_start_ap(struct wiphy *wiphy, struct net_device *dev,
return 0;
error:
+ link_conf->enable_beacon = false;
+ link_conf->beacon_int = prev_beacon_int;
+ sdata->vif.cfg.ssid_len = 0;
ieee80211_link_release_channel(link);
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 021/398] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (19 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 020/398] xfrm: fix compat ALLOCSPI request use-after-free Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 022/398] esp: downgrade zerocopy managed frags before mutating skb frags Greg Kroah-Hartman
` (381 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot, Eric Dumazet,
Steffen Klassert, Liu Jian, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit d2f5082f9e84653fa1a9e8aebaaff23e688f5e19 ]
syzbot reported a suspicious RCU usage warning in ip6_pkt_drop():
WARNING: suspicious RCU usage in ip6_pkt_drop
include/net/addrconf.h:389 suspicious rcu_dereference_check() usage!
Call Trace:
__in6_dev_get_safely include/net/addrconf.h:389 [inline]
ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620
ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651
xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806
process_one_work kernel/workqueue.c:3322 [inline]
process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405
worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486
When commit 4f4920669d21 ("xfrm: Reinject transport-mode packets through
workqueue") converted xfrm_trans_reinject from a tasklet to a workqueue,
the reinjection loop ceased running in softirq context. Workqueue workers
run in process context where local_bh_disable() does not enter an RCU
read-side critical section under CONFIG_PREEMPT_RCU.
Because finish callbacks (such as ip6_rcv_finish) expect to run under an
RCU read lock (performing route lookups, l3mdev lookups, and accessing
RCU-protected data structures), invoking them in workqueue context without
rcu_read_lock() triggers RCU lockdep warnings.
Furthermore, packets queued to the workqueue via xfrm_trans_queue_net()
may carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref).
Additionally, on netdevice unregistration, dst_dev_put() replaces dst->dev
with blackhole_netdev, so dst entries do not keep skb->dev alive while
queued in the workqueue.
Fix these issues by:
1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the
caller's RCU section to ensure dst is reference-counted before queuing.
2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue
deferral so skb->dev remains valid during finish() callback processing.
3. Acquiring rcu_read_lock() around the finish callback invocation loop in
xfrm_trans_reinject().
Fixes: 4f4920669d21 ("xfrm: Reinject transport-mode packets through workqueue")
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Steffen Klassert <steffen.klassert@secunet.com>
Cc: Liu Jian <liujian56@huawei.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_input.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/net/xfrm/xfrm_input.c b/net/xfrm/xfrm_input.c
index cfee63a6c87d2..b4c1cee1dbae7 100644
--- a/net/xfrm/xfrm_input.c
+++ b/net/xfrm/xfrm_input.c
@@ -794,12 +794,17 @@ static void xfrm_trans_reinject(struct work_struct *work)
spin_unlock_bh(&trans->queue_lock);
local_bh_disable();
+ rcu_read_lock();
while ((skb = __skb_dequeue(&queue))) {
struct net *net = XFRM_TRANS_SKB_CB(skb)->net;
+ struct net_device *dev = skb->dev;
XFRM_TRANS_SKB_CB(skb)->finish(net, NULL, skb);
+ if (dev)
+ dev_put(dev);
put_net(net);
}
+ rcu_read_unlock();
local_bh_enable();
}
@@ -815,12 +820,18 @@ int xfrm_trans_queue_net(struct net *net, struct sk_buff *skb,
if (skb_queue_len(&trans->queue) >= READ_ONCE(net_hotdata.max_backlog))
return -ENOBUFS;
+ if (skb_dst(skb) && !skb_dst_force(skb))
+ return -EHOSTUNREACH;
+
BUILD_BUG_ON(sizeof(struct xfrm_trans_cb) > sizeof(skb->cb));
hold_net = maybe_get_net(net);
if (!hold_net)
return -ENODEV;
+ if (skb->dev)
+ dev_hold(skb->dev);
+
XFRM_TRANS_SKB_CB(skb)->finish = finish;
XFRM_TRANS_SKB_CB(skb)->net = hold_net;
spin_lock_bh(&trans->queue_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 075/438] wifi: mac80211: reset the LED state when ifup fails
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (73 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 074/438] wifi: mac80211: reset state when starting AP fails Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 076/438] wifi: mac80211: only operate on TDLS peers in the TDLS code Greg Kroah-Hartman
` (374 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+e84ecca6d1fa09a9b3d9,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 78183e8331958fda11cd2b6850bb424a9747c4b2 ]
When the first interface comes up, the radio LED is turned on. This can
start the TPT trigger timer, which continues running.
But if bringing up the interface fails then the timer keeps running and
won't be stopped by anything, eventually it can be freed:
ODEBUG: free active (active state 0) object: ffff888127e12130 object type: timer_list hint: tpt_trig_timer+0x0/0x300 net/mac80211/led.c:145
WARNING: CPU: 0 PID: 5923 at lib/debugobjects.c:612 debug_print_object+0x1a2/0x2b0
debug_check_no_obj_freed+0x4b7/0x600 lib/debugobjects.c:1129
kfree+0x436/0x670 mm/slub.c:6818
ieee80211_led_exit+0x162/0x1c0 net/mac80211/led.c:210
ieee80211_unregister_hw+0x27e/0x3a0 net/mac80211/main.c:1706
rt2x00lib_remove_dev+0x55b/0x670
Undo the LED state in the error path.
Assisted-by: LLM
Fixes: 67408c8c7b9d ("mac80211: selective throughput LED trigger active")
Reported-by: syzbot+e84ecca6d1fa09a9b3d9@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e84ecca6d1fa09a9b3d9
Link: https://patch.msgid.link/20260904165722.044aa432f873.I601a67a2cd558b8ef8416a07554ae7efe896e9d8@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 8c300e045fdf9..4c34c3287eb4a 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -1606,8 +1606,12 @@ int ieee80211_do_open(struct wireless_dev *wdev, bool coming_up)
err_del_interface:
drv_remove_interface(local, sdata);
err_stop:
- if (!local->open_count)
+ if (!local->open_count) {
+ ieee80211_led_radio(local, false);
+ ieee80211_mod_tpt_led_trig(local, 0,
+ IEEE80211_TPT_LEDTRIG_FL_RADIO);
drv_stop(local, false);
+ }
if (sdata->vif.type == NL80211_IFTYPE_NAN_DATA)
RCU_INIT_POINTER(sdata->u.nan_data.nmi, NULL);
if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 022/398] esp: downgrade zerocopy managed frags before mutating skb frags
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (20 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 021/398] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 023/398] ARM: socfpga: select the PL310 erratum 753970 workaround Greg Kroah-Hartman
` (380 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maher Azzouzi, Steffen Klassert,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maher Azzouzi <maherazz04@gmail.com>
[ Upstream commit f89416eb3db151170a6f3c6dfc5239d26cdce4d2 ]
On the out-of-place output path (esp->inplace == false) ESP rewrites the
skb frag array: esp_output_head() appends a trailer frag and
esp_output_tail() replaces the frags with a destination page, both
referenced with get_page().
When the skb carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS) the
payload frags are owned by the ubuf and must not be referenced or
unreferenced individually, but ESP mutates the frag array without ever
downgrading the skb. This breaks the managed-frag invariant two ways:
- esp_ssg_unref() walks the source scatterlist and drops a page
reference for every frag, including the ubuf-owned payload frags,
pushing their refcount below the GUP pin bias while the pages are
still pinned, i.e. a use-after-free of the zerocopy pages;
- esp_output_tail() installs its destination page as frag 0 with
get_page() but leaves SKBFL_MANAGED_FRAG_REFS set, so
skb_release_data() takes the skip_unref branch and never drops that
reference, leaking the x->xfrag page at packet rate.
Fix this the way every other frag-mutating site does (__ip_append_data(),
__ip6_append_data(), tcp_sendmsg_locked()) and call
skb_zcopy_downgrade_managed() before ESP touches the frag array: it takes
a real reference on each existing frag and clears SKBFL_MANAGED_FRAG_REFS,
so the per-frag unref in esp_ssg_unref() and the frag release in
skb_release_data() are both balanced and no mixed-ownership frag array is
left behind.
Fixes: 753f1ca4e1e5 ("net: introduce managed frags infrastructure")
Signed-off-by: Maher Azzouzi <maherazz04@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/esp4.c | 6 ++++++
net/ipv6/esp6.c | 6 ++++++
2 files changed, 12 insertions(+)
diff --git a/net/ipv4/esp4.c b/net/ipv4/esp4.c
index 513c8215c947f..346e78c23af00 100644
--- a/net/ipv4/esp4.c
+++ b/net/ipv4/esp4.c
@@ -438,6 +438,12 @@ int esp_output_head(struct xfrm_state *x, struct sk_buff *skb, struct esp_info *
esp->inplace = false;
+ /* Take real page refs and clear SKBFL_MANAGED_FRAG_REFS before
+ * we mutate the frag array, so the per-frag unref stays balanced
+ * for zerocopy managed frags (see __ip_append_data()).
+ */
+ skb_zcopy_downgrade_managed(skb);
+
allocsize = ALIGN(tailen, L1_CACHE_BYTES);
spin_lock_bh(&x->lock);
diff --git a/net/ipv6/esp6.c b/net/ipv6/esp6.c
index 57481e423e59e..b26b85afb92ed 100644
--- a/net/ipv6/esp6.c
+++ b/net/ipv6/esp6.c
@@ -467,6 +467,12 @@ int esp6_output_head(struct xfrm_state *x, struct sk_buff *skb, struct esp_info
esp->inplace = false;
+ /* Take real page refs and clear SKBFL_MANAGED_FRAG_REFS before
+ * we mutate the frag array, so the per-frag unref stays balanced
+ * for zerocopy managed frags (see __ip_append_data()).
+ */
+ skb_zcopy_downgrade_managed(skb);
+
allocsize = ALIGN(tailen, L1_CACHE_BYTES);
spin_lock_bh(&x->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 076/438] wifi: mac80211: only operate on TDLS peers in the TDLS code
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (74 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 075/438] wifi: mac80211: reset the LED state when ifup fails Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 077/438] wifi: cfg80211: restore netns_immutable on failures Greg Kroah-Hartman
` (373 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+a59b5291776979816910,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 6f0a100df8539ce90f37c14e1945f396ca2410bc ]
ieee80211_tdls_oper() can operate on the AP station, which then
yields various warnings when the AP station is removed then or
at a later point in time after being confused for a TDLS peer.
Always check that the station is a TDLS peer.
Assisted-by: LLM
Fixes: dfe018bf9953 ("mac80211: handle TDLS high-level commands and frames")
Fixes: 17e6a59a365a ("mac80211: cleanup TDLS state during failed setup")
Reported-by: syzbot+a59b5291776979816910@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=a59b5291776979816910
Link: https://patch.msgid.link/20260904165722.3bad8b79679b.I99618745e83cbe9b9804179387be15fcd3505ae3@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tdls.c | 21 +++++++++------------
1 file changed, 9 insertions(+), 12 deletions(-)
diff --git a/net/mac80211/tdls.c b/net/mac80211/tdls.c
index ffd575a8d188f..5f2f89795dc99 100644
--- a/net/mac80211/tdls.c
+++ b/net/mac80211/tdls.c
@@ -1142,6 +1142,7 @@ ieee80211_tdls_mgmt_setup(struct wiphy *wiphy, struct net_device *dev,
struct ieee80211_local *local = sdata->local;
enum ieee80211_smps_mode smps_mode =
sdata->deflink.u.mgd.driver_smps_mode;
+ struct sta_info *sta;
int ret;
/* don't support setup with forced SMPS mode that's not off */
@@ -1168,14 +1169,10 @@ ieee80211_tdls_mgmt_setup(struct wiphy *wiphy, struct net_device *dev,
* Allow error packets to be sent - sometimes we don't even add a STA
* before failing the setup.
*/
- if (status_code == 0) {
- rcu_read_lock();
- if (!sta_info_get(sdata, peer)) {
- rcu_read_unlock();
- ret = -ENOLINK;
- goto out_unlock;
- }
- rcu_read_unlock();
+ sta = sta_info_get(sdata, peer);
+ if ((status_code == 0 && !sta) || (sta && !sta->sta.tdls)) {
+ ret = -ENOLINK;
+ goto out_unlock;
}
ieee80211_flush_queues(local, sdata, false);
@@ -1442,6 +1439,10 @@ int ieee80211_tdls_oper(struct wiphy *wiphy, struct net_device *dev,
*/
tdls_dbg(sdata, "TDLS oper %d peer %pM\n", oper, peer);
+ sta = sta_info_get(sdata, peer);
+ if (!sta || !sta->sta.tdls)
+ return -ENOLINK;
+
switch (oper) {
case NL80211_TDLS_ENABLE_LINK:
if (sdata->vif.bss_conf.csa_active) {
@@ -1449,10 +1450,6 @@ int ieee80211_tdls_oper(struct wiphy *wiphy, struct net_device *dev,
return -EBUSY;
}
- sta = sta_info_get(sdata, peer);
- if (!sta || !sta->sta.tdls)
- return -ENOLINK;
-
iee80211_tdls_recalc_chanctx(sdata, sta);
iee80211_tdls_recalc_ht_protection(sdata, sta);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 023/398] ARM: socfpga: select the PL310 erratum 753970 workaround
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (21 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 022/398] esp: downgrade zerocopy managed frags before mutating skb frags Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 024/398] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept Greg Kroah-Hartman
` (379 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Dinh Nguyen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit cfc1e9a543e3589ba200795b6e7fd8ef4314efdf ]
ARCH_INTEL_SOCFPGA selects CACHE_L2X0 and several PL310 erratum
workarounds. The 753970 workaround is still conditioned on PL310, but that
Kconfig symbol no longer exists, so this one selection is always disabled.
Select PL310_ERRATA_753970 directly, consistently with the other PL310
workarounds required by the platform.
Fixes: fbc125afdc50 ("ARM: socfpga: Turn on ARM errata for L2 cache")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Dinh Nguyen <dinguyen@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mach-socfpga/Kconfig | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm/mach-socfpga/Kconfig b/arch/arm/mach-socfpga/Kconfig
index eb72c240c2486..528c5c1368c37 100644
--- a/arch/arm/mach-socfpga/Kconfig
+++ b/arch/arm/mach-socfpga/Kconfig
@@ -16,7 +16,7 @@ menuconfig ARCH_INTEL_SOCFPGA
select ARM_ERRATA_775420
select PL310_ERRATA_588369
select PL310_ERRATA_727915
- select PL310_ERRATA_753970 if PL310
+ select PL310_ERRATA_753970
select PL310_ERRATA_769419
select RESET_CONTROLLER
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 077/438] wifi: cfg80211: restore netns_immutable on failures
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (75 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 076/438] wifi: mac80211: only operate on TDLS peers in the TDLS code Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 078/438] wifi: cfg80211: undo netns switch if renaming the wiphy fails Greg Kroah-Hartman
` (372 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit eeee52cfd1d639774c9812e8890631404a057dd2 ]
Switching a wiphy's netns has to clear netns_immutable before moving
interfaces, but then if any of the interfaces fails to move, it gets
netns_immutable cleared forever. Then userspace can move it by itself,
breaking the assumption that they all move together.
Fix the order here and always reset netns_immutable after attempting
the move.
Assisted-by: LLM
Fixes: 463d018323851 ("cfg80211: make aware of net namespaces")
Link: https://patch.msgid.link/20260904170220.7ea88157dcbc.Id868585a790be8b9ece9b39b0db464a5963faaf3@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/wireless/core.c b/net/wireless/core.c
index 8bb2cbd66b488..6c0c97e57ebb2 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -167,9 +167,9 @@ int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
continue;
wdev->netdev->netns_immutable = false;
err = dev_change_net_namespace(wdev->netdev, net, "wlan%d");
+ wdev->netdev->netns_immutable = true;
if (err)
break;
- wdev->netdev->netns_immutable = true;
}
if (err) {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 024/398] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (22 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 023/398] ARM: socfpga: select the PL310 erratum 753970 workaround Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 025/398] RDMA/rxe: validate access flags before swapping the MRs PD Greg Kroah-Hartman
` (378 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Guoqing Jiang,
Bernard Metzler, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guoqing Jiang <guoqing.jiang@linux.dev>
[ Upstream commit 32cd87f54dd1070020e664ccb0312a9f0fea79b4 ]
We need to clear cep before release state_lock as siw_qp_llp_close and
siw_qp_modify->siw_qp_llp_close did.
Otherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock
is released before the error path cleanup. A concurrent ibv_modify_qp()
transitioning the QP to ERROR can race in this window:
siw_accept() ibv_modify_qp(ERROR)
---------------------- ----------------------
siw_qp_modify() fails
up_write(&qp->state_lock)
down_write(&qp->state_lock)
nextstate_from_idle():
if (qp->cep)
siw_cep_put(qp->cep) <- frees cep
qp->cep = NULL
goto error
cep->qp = NULL <- UAF
Clear qp->cep and drop the association reference taken by siw_cep_get(),
all under the write lock held from the initial down_write(&qp->state_lock).
Thread B therefore sees qp->cep == NULL, skips its own put, and cannot free
the cep before siw_accept() is done with it.
Fixes: 6c52fdc244b5 ("rdma/siw: connection management")
Reported-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Link: https://lore.kernel.org/linux-rdma/d6fbe475-a5c2-f975-99b0-a0bd6b6d10e8@linux.dev/T/#m5876c1ff2de8686a9a1173b8f1aa0ff5363a785c
Signed-off-by: Guoqing Jiang <guoqing.jiang@linux.dev>
Link: https://patch.msgid.link/20260827125553.12831-1-guoqing.jiang@linux.dev
Acked-by: Bernard Metzler <bernard.metzler@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_cm.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/sw/siw/siw_cm.c b/drivers/infiniband/sw/siw/siw_cm.c
index bb7d909639071..04fabab440581 100644
--- a/drivers/infiniband/sw/siw/siw_cm.c
+++ b/drivers/infiniband/sw/siw/siw_cm.c
@@ -1669,9 +1669,12 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
SIW_QP_ATTR_STATE | SIW_QP_ATTR_LLP_HANDLE |
SIW_QP_ATTR_ORD | SIW_QP_ATTR_IRD |
SIW_QP_ATTR_MPA);
+ if (rv) {
+ qp->cep = NULL;
+ siw_cep_put(cep);
+ goto error_unlock;
+ }
up_write(&qp->state_lock);
- if (rv)
- goto error;
siw_dbg_cep(cep, "[QP %u]: send mpa reply, %d byte pdata\n",
qp_id(qp), params->private_data_len);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 078/438] wifi: cfg80211: undo netns switch if renaming the wiphy fails
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (76 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 077/438] wifi: cfg80211: restore netns_immutable on failures Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 079/438] wifi: mac80211: unlist vifs when their netdev is unregistered Greg Kroah-Hartman
` (371 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+3515319a302224e081b4,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit a41bd1938a9bfe226d444172a7e20e4bd5097960 ]
Once all the interfaces have been moved, cfg80211_switch_netns()
moves the wiphy itself by setting its network namespace and then
renaming it, which makes sysfs move it. The rename can fail (but
only on allocation failures), leaving things mixed up and hitting
the warning there.
Ignoring it isn't great, undo the move and let the change fail
in this case. If undo fails then WARN, then things would again
be stuck in two different network namespaces.
Assisted-by: LLM
Reported-by: syzbot+3515319a302224e081b4@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=3515319a302224e081b4
Fixes: 463d018323851 ("cfg80211: make aware of net namespaces")
Link: https://patch.msgid.link/20260904170220.7966cc705e33.Ib398351113bbd3cab85302467060cab378564421@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/core.c | 88 +++++++++++++++++++++++++--------------------
1 file changed, 50 insertions(+), 38 deletions(-)
diff --git a/net/wireless/core.c b/net/wireless/core.c
index 6c0c97e57ebb2..59facacf1a36f 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -153,9 +153,25 @@ int cfg80211_dev_rename(struct cfg80211_registered_device *rdev,
return 0;
}
+static int cfg80211_switch_wdev_netns(struct wireless_dev *wdev,
+ struct net *net)
+{
+ int err;
+
+ if (!wdev->netdev)
+ return 0;
+
+ wdev->netdev->netns_immutable = false;
+ err = dev_change_net_namespace(wdev->netdev, net, "wlan%d");
+ wdev->netdev->netns_immutable = true;
+
+ return err;
+}
+
int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
struct net *net)
{
+ struct net *old_net = wiphy_net(&rdev->wiphy);
struct wireless_dev *wdev;
int err = 0;
@@ -163,58 +179,54 @@ int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
return -EOPNOTSUPP;
list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
- if (!wdev->netdev)
- continue;
- wdev->netdev->netns_immutable = false;
- err = dev_change_net_namespace(wdev->netdev, net, "wlan%d");
- wdev->netdev->netns_immutable = true;
+ err = cfg80211_switch_wdev_netns(wdev, net);
if (err)
- break;
+ goto undo;
}
- if (err) {
- /* failed -- clean up to old netns */
- net = wiphy_net(&rdev->wiphy);
-
- list_for_each_entry_continue_reverse(wdev,
- &rdev->wiphy.wdev_list,
- list) {
+ scoped_guard(wiphy, &rdev->wiphy) {
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
if (!wdev->netdev)
continue;
- wdev->netdev->netns_immutable = false;
- err = dev_change_net_namespace(wdev->netdev, net,
- "wlan%d");
- WARN_ON(err);
- wdev->netdev->netns_immutable = true;
+ nl80211_notify_iface(rdev, wdev,
+ NL80211_CMD_DEL_INTERFACE);
}
- return err;
- }
+ nl80211_notify_wiphy(rdev, NL80211_CMD_DEL_WIPHY);
- guard(wiphy)(&rdev->wiphy);
+ wiphy_net_set(&rdev->wiphy, net);
- list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
- if (!wdev->netdev)
- continue;
- nl80211_notify_iface(rdev, wdev, NL80211_CMD_DEL_INTERFACE);
- }
-
- nl80211_notify_wiphy(rdev, NL80211_CMD_DEL_WIPHY);
+ /* this only fails on allocation failure */
+ err = device_rename(&rdev->wiphy.dev,
+ dev_name(&rdev->wiphy.dev));
+ if (err)
+ wiphy_net_set(&rdev->wiphy, old_net);
- wiphy_net_set(&rdev->wiphy, net);
+ nl80211_notify_wiphy(rdev, NL80211_CMD_NEW_WIPHY);
- err = device_rename(&rdev->wiphy.dev, dev_name(&rdev->wiphy.dev));
- WARN_ON(err);
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ if (!wdev->netdev)
+ continue;
+ nl80211_notify_iface(rdev, wdev,
+ NL80211_CMD_NEW_INTERFACE);
+ }
+ }
- nl80211_notify_wiphy(rdev, NL80211_CMD_NEW_WIPHY);
+ if (!err)
+ return 0;
- list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
- if (!wdev->netdev)
- continue;
- nl80211_notify_iface(rdev, wdev, NL80211_CMD_NEW_INTERFACE);
- }
+ /* set to the last one to undo all of them */
+ wdev = list_entry(&rdev->wiphy.wdev_list, typeof(*wdev), list);
+undo:
+ /*
+ * Move back everything, if this fails again (allocation failures)
+ * then things get stuck in different network namespaces.
+ */
+ list_for_each_entry_continue_reverse(wdev, &rdev->wiphy.wdev_list,
+ list)
+ WARN_ON(cfg80211_switch_wdev_netns(wdev, old_net));
- return 0;
+ return err;
}
static void cfg80211_rfkill_poll(struct rfkill *rfkill, void *data)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 025/398] RDMA/rxe: validate access flags before swapping the MRs PD
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (23 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 024/398] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 026/398] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access Greg Kroah-Hartman
` (377 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Norbert Szetei, Zhu Yanjun,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Norbert Szetei <norbert@doyensec.com>
[ Upstream commit ae36a5b609ae79f4de966328b78d2584be9719a4 ]
rxe_rereg_user_mr() reassigns mr->ibmr.pd first and only then
validates the IB_MR_REREG_ACCESS argument:
if (flags & IB_MR_REREG_PD) {
rxe_put(old_pd);
rxe_get(pd);
mr->ibmr.pd = ibpd;
}
if (flags & IB_MR_REREG_ACCESS) {
if (access & ~RXE_ACCESS_SUPPORTED_MR)
return ERR_PTR(-EOPNOTSUPP);
mr->access = access;
}
Both flags pass the entry check because RXE_MR_REREG_SUPPORTED is
IB_MR_REREG_PD | IB_MR_REREG_ACCESS, so a caller can reach the access
check with mr->ibmr.pd already reassigned.
mr->ibmr.pd is owned by the core, which adjusts pd->usecnt only on the
success path: ib_uverbs_rereg_mr() jumps to put_new_uobj on a driver error
without undoing the reassignment, so mr->pd == new_pd while the usecnts
still charge the MR to orig_pd. ib_dereg_mr_user() then decrements
new_pd, whose count can reach zero while a memory window still references
it; uverbs_free_pd() frees the PD on that count alone and rxe_mw_cleanup()
writes to freed memory:
BUG: KASAN: slab-use-after-free in __rxe_put+0x31/0xa0
Write of size 4 at addr ffff8881301dd690 by task rxe_poc/591
__rxe_put+0x31/0xa0
rxe_mw_cleanup+0x42/0x200
__rxe_cleanup+0x115/0x370
rxe_dealloc_mw+0x4c/0x80
Allocated by task 591:
ib_uverbs_alloc_pd+0x258/0x540
Freed by task 591:
ib_dealloc_pd_user+0x174/0x210
uverbs_free_pd+0x8d/0xc0
ib_uverbs_dealloc_pd+0x18e/0x1d0
Validate the access flags before mutating any state so the callback either
applies every requested change or none.
Fixes: 544c7f62cf32 ("RDMA/rxe: Implement rereg_user_mr")
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Link: https://patch.msgid.link/46E1D5C0-24BE-4D01-BDB3-634FE09B22C5@doyensec.com
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_verbs.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_verbs.c b/drivers/infiniband/sw/rxe/rxe_verbs.c
index 23304765decff..a1c75ccea40d5 100644
--- a/drivers/infiniband/sw/rxe/rxe_verbs.c
+++ b/drivers/infiniband/sw/rxe/rxe_verbs.c
@@ -1346,19 +1346,20 @@ static struct ib_mr *rxe_rereg_user_mr(struct ib_mr *ibmr, int flags,
if (err)
return ERR_PTR(err);
+ if ((flags & IB_MR_REREG_ACCESS) &&
+ (access & ~RXE_ACCESS_SUPPORTED_MR)) {
+ rxe_err_mr(mr, "access = %#x not supported\n", access);
+ return ERR_PTR(-EOPNOTSUPP);
+ }
+
if (flags & IB_MR_REREG_PD) {
rxe_put(old_pd);
rxe_get(pd);
mr->ibmr.pd = ibpd;
}
- if (flags & IB_MR_REREG_ACCESS) {
- if (access & ~RXE_ACCESS_SUPPORTED_MR) {
- rxe_err_mr(mr, "access = %#x not supported\n", access);
- return ERR_PTR(-EOPNOTSUPP);
- }
+ if (flags & IB_MR_REREG_ACCESS)
mr->access = access;
- }
return NULL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 079/438] wifi: mac80211: unlist vifs when their netdev is unregistered
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (77 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 078/438] wifi: cfg80211: undo netns switch if renaming the wiphy fails Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 080/438] wifi: cfg80211: get the wiphy out of a dying network namespace Greg Kroah-Hartman
` (370 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit eee2efd82867b623982ac51925b5a1812a74c50d ]
mac80211 only removes vifs from the local->interfaces list when
an interface is removed via ieee80211_if_remove(), before it
unregisters the netdev. However, it's possible for a netdev to
be unregistered without going through that: When the netns that
holds the wiphy is destroyed, the wiphy is supposed to move to
the init_ns, but that can run into allocation failures.
Then, mac80211 has an interface listed that doesn't exist, and
will eventually hit
BUG: failure at net/wireless/core.h:141/wiphy_to_rdev()!
...
_cfg80211_unregister_wdev+0x24/0x36a [cfg80211]
cfg80211_unregister_wdev+0x15/0x1d [cfg80211]
ieee80211_remove_interfaces+0x1ff/0x257 [mac80211]
ieee80211_unregister_hw+0x73/0x1d1 [mac80211]
mac80211_hwsim_del_radio+0x114/0x166 [mac80211_hwsim]
Remove the interface from the list in ->ndo_uninit if it's still
around to avoid this.
Assisted-by: LLM
Fixes: 463d018323851 ("cfg80211: make aware of net namespaces")
Link: https://patch.msgid.link/20260904170220.038ad73e6c04.I990abca78483e058746b6f42b4796717c3028164@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 26 +++++++++++++++++++++++++-
1 file changed, 25 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 4c34c3287eb4a..842bfb4a7cb68 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -924,9 +924,33 @@ static void ieee80211_teardown_sdata(struct ieee80211_sub_if_data *sdata)
}
}
+/*
+ * The netdev can be unregistered without mac80211 doing it, e.g. by the netdev
+ * core when cfg80211 couldn't move it out of a network namespace that's being
+ * destroyed. Drop it from the interface list either way.
+ */
+static void ieee80211_unlist_sdata(struct ieee80211_sub_if_data *sdata)
+{
+ struct ieee80211_local *local = sdata->local;
+ struct ieee80211_sub_if_data *iter;
+
+ ASSERT_RTNL();
+
+ list_for_each_entry(iter, &local->interfaces, list) {
+ if (iter != sdata)
+ continue;
+ guard(mutex)(&local->iflist_mtx);
+ list_del_rcu(&sdata->list);
+ return;
+ }
+}
+
static void ieee80211_uninit(struct net_device *dev)
{
- ieee80211_teardown_sdata(IEEE80211_DEV_TO_SUB_IF(dev));
+ struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
+
+ ieee80211_unlist_sdata(sdata);
+ ieee80211_teardown_sdata(sdata);
}
static int ieee80211_netdev_setup_tc(struct net_device *dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 026/398] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (24 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 025/398] RDMA/rxe: validate access flags before swapping the MRs PD Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 027/398] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS Greg Kroah-Hartman
` (376 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gang Yan, Zhu Yanjun, Shukai Ni,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gang Yan <yangang@kylinos.cn>
[ Upstream commit d10e2a08799e858d3e71ea4169bcd018f216d444 ]
mr_check_range() validates that [iova, iova+length) falls within the
registered MR range using wraparound-prone arithmetic:
if (iova < mr->ibmr.iova ||
iova + length > mr->ibmr.iova + mr->ibmr.length)
A remote peer can craft an RDMA-Write/Read RETH so that iova + length
wraps to 0 (e.g. iova=0xfffffffffffffff8, length=8), bypassing the
check. rxe_mr_iova_to_index() then computes a huge index (int idx, only
guarded by WARN_ON) and rxe_mr_copy_xarray() dereferences
mr->page_info[huge], causing an out-of-bounds read/write and a kernel
oops that is triggerable by an unauthenticated remote peer.
Rewrite the check in overflow-safe form; the first two clauses guarantee
that the subsequent subtractions do not underflow:
if (iova < mr->ibmr.iova ||
length > mr->ibmr.length ||
iova - mr->ibmr.iova > mr->ibmr.length - length)
With the fix, mr_check_range() returns -EINVAL for the crafted iova and
the responder reports REMOTE_ACCESS_ERROR instead of triggering the OOB.
Fixes: 8700e3e7c485 ("Soft RoCE driver")
Signed-off-by: Gang Yan <yangang@kylinos.cn>
Link: https://patch.msgid.link/20260814093740.292954-1-gang.yan@linux.dev
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Reviewed-by: Shukai Ni <shukai.ni@kuleuven.be>
Tested-by: Shukai Ni <shukai.ni@kuleuven.be>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_mr.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_mr.c b/drivers/infiniband/sw/rxe/rxe_mr.c
index 2c486bb616a7c..cd787e24c9ac6 100644
--- a/drivers/infiniband/sw/rxe/rxe_mr.c
+++ b/drivers/infiniband/sw/rxe/rxe_mr.c
@@ -33,7 +33,8 @@ int mr_check_range(struct rxe_mr *mr, u64 iova, size_t length)
case IB_MR_TYPE_USER:
case IB_MR_TYPE_MEM_REG:
if (iova < mr->ibmr.iova ||
- iova + length > mr->ibmr.iova + mr->ibmr.length) {
+ length > mr->ibmr.length ||
+ iova - mr->ibmr.iova > mr->ibmr.length - length) {
rxe_dbg_mr(mr, "iova/length out of range\n");
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 080/438] wifi: cfg80211: get the wiphy out of a dying network namespace
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (78 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 079/438] wifi: mac80211: unlist vifs when their netdev is unregistered Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 081/438] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping Greg Kroah-Hartman
` (369 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+c5f8a81e794d4a4f2014,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 4635b1a1c1d693178a537446a6e09963f0fdae52 ]
When a network namespace is destroyed, cfg80211_pernet_exit() moves any
wiphy back to the initial namespace, and just warns if that fails. But
moving an interface can fail (due to allocation failures), and then the
wiphy is left behind with a garbage netns pointer:
Kernel mode fault at addr 0x30
genlmsg_multicast_netns.constprop.0+0x46/0xcf [cfg80211]
nl80211_notify_wiphy+0xcd/0xe8 [cfg80211]
wiphy_unregister+0x169/0x3fc [cfg80211]
Note that commit debac3a20dec ("net: Remove conflicting altnames for
dying netns in __dev_change_net_namespace().") fixed another path
that could reach it without allocation failures.
Remove interfaces that cannot be moved instead of failing the switch,
so that the wiphy always ends up in the initial namespace. In this
case the netdev core will unregister the interfaces anyway.
Assisted-by: LLM
Reported-by: syzbot+c5f8a81e794d4a4f2014@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c5f8a81e794d4a4f2014
Fixes: 463d018323851 ("cfg80211: make aware of net namespaces")
Link: https://patch.msgid.link/20260904170220.7f3edc6d9992.I5e57921011244d3d8ef14d89e738aa19a5d972a0@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/core.c | 37 +++++++++++++++++++++++++------------
1 file changed, 25 insertions(+), 12 deletions(-)
diff --git a/net/wireless/core.c b/net/wireless/core.c
index 59facacf1a36f..bc7e2c50cc726 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -168,20 +168,24 @@ static int cfg80211_switch_wdev_netns(struct wireless_dev *wdev,
return err;
}
-int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
- struct net *net)
+static int __cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
+ struct net *net, bool force)
{
struct net *old_net = wiphy_net(&rdev->wiphy);
- struct wireless_dev *wdev;
+ struct wireless_dev *wdev, *tmp;
int err = 0;
- if (!(rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK))
- return -EOPNOTSUPP;
-
- list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ list_for_each_entry_safe(wdev, tmp, &rdev->wiphy.wdev_list, list) {
err = cfg80211_switch_wdev_netns(wdev, net);
- if (err)
+ if (!err)
+ continue;
+ if (!force)
goto undo;
+ /* remove interfaces that fail to allow wiphy switching */
+ dev_close(wdev->netdev);
+ scoped_guard(wiphy, &rdev->wiphy)
+ cfg80211_unregister_wdev(wdev);
+ err = 0;
}
scoped_guard(wiphy, &rdev->wiphy) {
@@ -199,7 +203,7 @@ int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
/* this only fails on allocation failure */
err = device_rename(&rdev->wiphy.dev,
dev_name(&rdev->wiphy.dev));
- if (err)
+ if (err && !force)
wiphy_net_set(&rdev->wiphy, old_net);
nl80211_notify_wiphy(rdev, NL80211_CMD_NEW_WIPHY);
@@ -212,8 +216,8 @@ int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
}
}
- if (!err)
- return 0;
+ if (!err || force)
+ return err;
/* set to the last one to undo all of them */
wdev = list_entry(&rdev->wiphy.wdev_list, typeof(*wdev), list);
@@ -229,6 +233,15 @@ int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
return err;
}
+int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
+ struct net *net)
+{
+ if (!(rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK))
+ return -EOPNOTSUPP;
+
+ return __cfg80211_switch_netns(rdev, net, false);
+}
+
static void cfg80211_rfkill_poll(struct rfkill *rfkill, void *data)
{
struct cfg80211_registered_device *rdev = data;
@@ -1879,7 +1892,7 @@ static void __net_exit cfg80211_pernet_exit(struct net *net)
rtnl_lock();
for_each_rdev(rdev) {
if (net_eq(wiphy_net(&rdev->wiphy), net))
- WARN_ON(cfg80211_switch_netns(rdev, &init_net));
+ WARN_ON(__cfg80211_switch_netns(rdev, &init_net, true));
}
rtnl_unlock();
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 027/398] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (25 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 026/398] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 028/398] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate Greg Kroah-Hartman
` (375 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xixin Liu, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xixin Liu <liuxixin@kylinos.cn>
[ Upstream commit 32471d84a487c7fd74532bc96be56f8028cf4a3f ]
scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted
any larger value from the SCP firmware. The shared-memory reply only holds
MAX_DVFS_OPPS entries in buf.opps[]; a bigger count over-reads that array
and then sizes the allocated OPP table incorrectly (garbage OPPs / OOB).
The missing upper bound dates back to the original SCPI DVFS support.
Reject zero and out-of-range counts in one check and return -EINVAL.
Fixes: 8cb7cf56c9fe ("firmware: add support for ARM System Control and Power Interface(SCPI) protocol")
Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
Link: https://patch.msgid.link/022802f0b38f.v2.1785200642.git.liuxixin@kylinos.cn
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scpi.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/firmware/arm_scpi.c b/drivers/firmware/arm_scpi.c
index 398642cc25d90..b8b7907089d78 100644
--- a/drivers/firmware/arm_scpi.c
+++ b/drivers/firmware/arm_scpi.c
@@ -631,8 +631,8 @@ static struct scpi_dvfs_info *scpi_dvfs_get_info(u8 domain)
if (ret)
return ERR_PTR(ret);
- if (!buf.opp_count)
- return ERR_PTR(-ENOENT);
+ if (!buf.opp_count || buf.opp_count > MAX_DVFS_OPPS)
+ return ERR_PTR(-EINVAL);
info = kmalloc(sizeof(*info), GFP_KERNEL);
if (!info)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 081/438] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (79 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 080/438] wifi: cfg80211: get the wiphy out of a dying network namespace Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 082/438] wifi: mac80211: dont allow injecting frames wider than the chanctx Greg Kroah-Hartman
` (368 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b4aa2b672b18f1d4dc5f,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 87840d4a3a21b1c19b867a80e16ba69dff284de2 ]
The code checks ->started for frames coming from wmediumd, but the
radio can be stopped after the check and before frame delivery,
causing mac80211 to hit the WARN_ON(!local->started).
Expand the mutex for this case and synchronise against it when the
radio is stopped to avoid being able to hit the warning with hwsim.
Drop the error print that would've complicated the error path, it
only triggers for allocation failures (already noisy) and malformed
frames anyway.
Assisted-by: LLM
Fixes: 7882513bacb1 ("mac80211_hwsim driver support userspace frame tx/rx")
Reported-by: syzbot+b4aa2b672b18f1d4dc5f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b4aa2b672b18f1d4dc5f
Link: https://patch.msgid.link/20260904170140.5f69a10d606b.I4a7921d00643f69e439c7a3b221d104f66a3dcdc@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../wireless/virtual/mac80211_hwsim_main.c | 39 ++++++++++++-------
1 file changed, 24 insertions(+), 15 deletions(-)
diff --git a/drivers/net/wireless/virtual/mac80211_hwsim_main.c b/drivers/net/wireless/virtual/mac80211_hwsim_main.c
index b4cabbfa9cdba..8c634cada5ddd 100644
--- a/drivers/net/wireless/virtual/mac80211_hwsim_main.c
+++ b/drivers/net/wireless/virtual/mac80211_hwsim_main.c
@@ -2317,7 +2317,12 @@ static void mac80211_hwsim_stop(struct ieee80211_hw *hw, bool suspend)
struct sk_buff *skb;
int i;
- data->started = false;
+ /*
+ * Serialise against wmediumd userspace, so no more frames
+ * can be handed to mac80211 after this returns.
+ */
+ scoped_guard(mutex, &data->mutex)
+ data->started = false;
for (i = 0; i < ARRAY_SIZE(data->link_data); i++)
hrtimer_cancel(&data->link_data[i].beacon_timer);
@@ -6453,12 +6458,12 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
if (frame_data_len < sizeof(struct ieee80211_hdr_3addr) ||
frame_data_len > IEEE80211_MAX_DATA_LEN)
- goto err;
+ goto out;
/* Allocate new skb here */
skb = alloc_skb(frame_data_len, GFP_KERNEL);
if (skb == NULL)
- goto err;
+ goto out;
/* Copy the data */
skb_put_data(skb, frame_data, frame_data_len);
@@ -6483,10 +6488,17 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
goto out;
}
+ /*
+ * Serialise against mac80211_hwsim_stop() - mac80211 doesn't allow
+ * frames reported while the HW is down, hence the ->started check
+ * must be under mutex.
+ */
+ mutex_lock(&data2->mutex);
+
/* check if radio is configured properly */
if ((data2->idle && !data2->tmp_chan) || !data2->started)
- goto out;
+ goto out_unlock;
/* A frame is received from user space */
memset(&rx_status, 0, sizeof(rx_status));
@@ -6505,22 +6517,18 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
iter_data.channel = ieee80211_get_channel(data2->hw->wiphy,
rx_status.freq);
if (!iter_data.channel)
- goto out;
+ goto out_unlock;
rx_status.band = iter_data.channel->band;
- mutex_lock(&data2->mutex);
if (!hwsim_chans_compat(iter_data.channel, channel)) {
ieee80211_iterate_active_interfaces_atomic(
data2->hw, IEEE80211_IFACE_ITER_NORMAL,
mac80211_hwsim_tx_iter, &iter_data);
- if (!iter_data.receive) {
- mutex_unlock(&data2->mutex);
- goto out;
- }
+ if (!iter_data.receive)
+ goto out_unlock;
}
- mutex_unlock(&data2->mutex);
} else if (!channel) {
- goto out;
+ goto out_unlock;
} else {
rx_status.freq = channel->center_freq;
rx_status.band = channel->band;
@@ -6528,7 +6536,7 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
rx_status.rate_idx = nla_get_u32(info->attrs[HWSIM_ATTR_RX_RATE]);
if (rx_status.rate_idx >= data2->hw->wiphy->bands[rx_status.band]->n_bitrates)
- goto out;
+ goto out_unlock;
rx_status.signal = nla_get_u32(info->attrs[HWSIM_ATTR_SIGNAL]);
hdr = (void *)skb->data;
@@ -6538,10 +6546,11 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
rx_status.boottime_ns = ktime_get_boottime_ns();
mac80211_hwsim_rx(data2, &rx_status, skb);
+ mutex_unlock(&data2->mutex);
return 0;
-err:
- pr_debug("mac80211_hwsim: error occurred in %s\n", __func__);
+out_unlock:
+ mutex_unlock(&data2->mutex);
out:
dev_kfree_skb(skb);
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 028/398] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (26 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 027/398] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 029/398] RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Greg Kroah-Hartman
` (374 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xixin Liu, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xixin Liu <liuxixin@kylinos.cn>
[ Upstream commit 70f4b78d560e592cbf3325b162424737d032fc1d ]
dvfs_get_idx() may return an out-of-range index if the SCP firmware is
buggy or returns a stale value. Only negative indexes were rejected, so a
large index walked past info->opps and could treat garbage as a clock rate
(KASAN OOB / wrong frequency to consumers). The missing upper bound dates
back to the original SCPI clock driver.
Treat indexes >= opp count as invalid and return 0, same as idx < 0.
Fixes: cd52c2a4b5c4 ("clk: add support for clocks provided by SCP(System Control Processor)")
Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
Link: https://patch.msgid.link/04f9ab766e07.v2.1785200642.git.liuxixin@kylinos.cn
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/clk-scpi.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/clk/clk-scpi.c b/drivers/clk/clk-scpi.c
index e082474250fe3..48a0c314fc3dc 100644
--- a/drivers/clk/clk-scpi.c
+++ b/drivers/clk/clk-scpi.c
@@ -85,7 +85,7 @@ static unsigned long scpi_dvfs_recalc_rate(struct clk_hw *hw,
int idx = clk->scpi_ops->dvfs_get_idx(clk->id);
const struct scpi_opp *opp;
- if (idx < 0)
+ if (idx < 0 || idx >= clk->info->count)
return 0;
opp = clk->info->opps + idx;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 082/438] wifi: mac80211: dont allow injecting frames wider than the chanctx
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (80 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 081/438] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 083/438] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown Greg Kroah-Hartman
` (367 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+435fdb053cf98bfa5778,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit e14bf37bb2b3853012ff160131d1c6233f7a9cc9 ]
Frames injected on a monitor interface can carry a radiotap
field requesting a bandwidth, which mac80211 passes down to
the driver regardless of the the actual operational bandwidth.
If the bandwidth requested is too wide, that triggers a warning
in hwsim:
WARN_ON(hwsim_get_chanwidth(bw) > hwsim_get_chanwidth(confbw))
Drop such frames entirely instead since they cannot be sent.
Assisted-by: LLM
Fixes: 646e76bb5daf ("mac80211: parse VHT info in injected frames")
Reported-by: syzbot+435fdb053cf98bfa5778@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=435fdb053cf98bfa5778
Link: https://patch.msgid.link/20260908122838.201719-13-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/mac80211.h | 5 ++++-
net/mac80211/iface.c | 2 +-
net/mac80211/tx.c | 28 ++++++++++++++++++++++++++--
3 files changed, 31 insertions(+), 4 deletions(-)
diff --git a/include/net/mac80211.h b/include/net/mac80211.h
index 4f95da023746f..36055d40172a1 100644
--- a/include/net/mac80211.h
+++ b/include/net/mac80211.h
@@ -7615,11 +7615,14 @@ bool ieee80211_tx_prepare_skb(struct ieee80211_hw *hw,
*
* @skb: packet injected by userspace
* @dev: the &struct device of this 802.11 device
+ * @chandef: the channel definition the frame will be transmitted on, or
+ * %NULL to skip the bandwidth checks
*
* Return: %true if the radiotap header was parsed, %false otherwise
*/
bool ieee80211_parse_tx_radiotap(struct sk_buff *skb,
- struct net_device *dev);
+ struct net_device *dev,
+ const struct cfg80211_chan_def *chandef);
/**
* struct ieee80211_noa_data - holds temporary data for tracking P2P NoA state
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 842bfb4a7cb68..ca66eb493ac7d 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -991,7 +991,7 @@ static u16 ieee80211_monitor_select_queue(struct net_device *dev,
/* reset flags and info before parsing radiotap header */
memset(info, 0, sizeof(*info));
- if (!ieee80211_parse_tx_radiotap(skb, dev))
+ if (!ieee80211_parse_tx_radiotap(skb, dev, NULL))
return 0; /* doesn't matter, frame will be dropped */
len_rthdr = ieee80211_get_radiotap_len(skb->data);
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index 7cb9dd1b27314..a726a697c32d7 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -2096,8 +2096,29 @@ static bool ieee80211_validate_radiotap_len(struct sk_buff *skb)
return true;
}
+static bool ieee80211_rate_bw_usable(u16 rate_flags,
+ const struct cfg80211_chan_def *chandef)
+{
+ int width;
+
+ if (!chandef)
+ return true;
+
+ if (rate_flags & IEEE80211_TX_RC_160_MHZ_WIDTH)
+ width = 160;
+ else if (rate_flags & IEEE80211_TX_RC_80_MHZ_WIDTH)
+ width = 80;
+ else if (rate_flags & IEEE80211_TX_RC_40_MHZ_WIDTH)
+ width = 40;
+ else
+ return true;
+
+ return width <= cfg80211_chandef_get_width(chandef);
+}
+
bool ieee80211_parse_tx_radiotap(struct sk_buff *skb,
- struct net_device *dev)
+ struct net_device *dev,
+ const struct cfg80211_chan_def *chandef)
{
struct ieee80211_local *local = wdev_priv(dev->ieee80211_ptr);
struct ieee80211_radiotap_iterator iterator;
@@ -2271,6 +2292,9 @@ bool ieee80211_parse_tx_radiotap(struct sk_buff *skb,
struct ieee80211_supported_band *sband =
local->hw.wiphy->bands[info->band];
+ if (!ieee80211_rate_bw_usable(rate_flags, chandef))
+ return false;
+
info->control.flags |= IEEE80211_TX_CTRL_RATE_INJECT;
for (i = 0; i < IEEE80211_TX_MAX_RATES; i++) {
@@ -2470,7 +2494,7 @@ netdev_tx_t ieee80211_monitor_start_xmit(struct sk_buff *skb,
* selected chandef above to accurately set injection rates and
* retransmissions.
*/
- if (!ieee80211_parse_tx_radiotap(skb, dev))
+ if (!ieee80211_parse_tx_radiotap(skb, dev, chandef))
goto fail_rcu;
/* remove the injection radiotap header */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 029/398] RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (27 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 028/398] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 030/398] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds Greg Kroah-Hartman
` (373 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Zhu Yanjun,
Hongqiang Luo, Xinyu Ma, Zhanbo Ye, Shaomin Chen, Rui Ding,
Miao Zhao, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit 769001ce838d907ecaa95f1d0a4e8fc86f761f9f ]
Commit 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO
pages") dropped the access permission test from rxe_check_pagefault()
and left only HMM_PFN_VALID. A page faulted in read-only, for example
a page-cache folio behind a PROT_READ file mapping, then satisfies the
check and ODP write operations (RDMA WRITE, RDMA READ response, SEND
payload, atomics) modify it through kmap without ever breaking CoW.
An unprivileged user can register an ODP MR over such a mapping and
have incoming RDMA traffic overwrite the page cache of a file it only
holds O_RDONLY, including /etc/passwd or setuid binaries. This is the
same primitive class as Dirty COW and CVE-2022-2590.
mlx5 has the missing invariant: its ODP path sets the device write bit
only for pfns that carry HMM_PFN_WRITE. Restore it in rxe by requiring
HMM_PFN_WRITE in rxe_check_pagefault() for every operation except
RXE_PAGEFAULT_RDONLY. A write to a non-writable VMA now fails the one
fault attempt with -EPERM from hmm_vma_fault() instead of re-faulting
forever. For a writable VMA the fault breaks CoW and the write lands
in the private page.
Keep pmem flushes on the read-only check. arch_wb_cache_pmem() never
modifies memory, and the FLUSH access bits do not make the umem
writable, so classifying flushes as writes would make every flush
against a flush-only MR fail.
Fixes: 0b261d7c1cd3 ("RDMA/rxe: Break endless pagefault loop for RO pages")
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Link: https://patch.msgid.link/20260726111533.1037819-1-bestswngs@gmail.com
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Tested-by: Hongqiang Luo <wanbafv@gmail.com>
Tested-by: Xinyu Ma <mmmxny@gmail.com>
Tested-by: Zhanbo Ye <cainyzb@gmail.com>
Reported-by: Weiming Shi <bestswngs@gmail.com>
Reported-by: Shaomin Chen <eeesssooo020@gmail.com>
Reported-by: Rui Ding <threonine42@gmail.com>
Reported-by: Miao Zhao <muel@nova.gal>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_odp.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_odp.c b/drivers/infiniband/sw/rxe/rxe_odp.c
index 16b3fbdf2f867..995c1cb5c958e 100644
--- a/drivers/infiniband/sw/rxe/rxe_odp.c
+++ b/drivers/infiniband/sw/rxe/rxe_odp.c
@@ -126,19 +126,23 @@ int rxe_odp_mr_init_user(struct rxe_dev *rxe, u64 start, u64 length,
}
static inline bool rxe_check_pagefault(struct ib_umem_odp *umem_odp, u64 iova,
- int length)
+ int length, bool write)
{
bool need_fault = false;
+ u64 access = HMM_PFN_VALID;
u64 addr;
int idx;
+ if (write)
+ access |= HMM_PFN_WRITE;
+
addr = iova & (~(BIT(umem_odp->page_shift) - 1));
/* Skim through all pages that are to be accessed. */
while (addr < iova + length) {
idx = (addr - ib_umem_start(umem_odp)) >> umem_odp->page_shift;
- if (!(umem_odp->map.pfn_list[idx] & HMM_PFN_VALID)) {
+ if ((umem_odp->map.pfn_list[idx] & access) != access) {
need_fault = true;
break;
}
@@ -161,6 +165,7 @@ static unsigned long rxe_odp_iova_to_page_offset(struct ib_umem_odp *umem_odp, u
static int rxe_odp_map_range_and_lock(struct rxe_mr *mr, u64 iova, int length, u32 flags)
{
struct ib_umem_odp *umem_odp = to_ib_umem_odp(mr->umem);
+ bool write = !(flags & RXE_PAGEFAULT_RDONLY);
bool need_fault;
int err;
@@ -169,7 +174,7 @@ static int rxe_odp_map_range_and_lock(struct rxe_mr *mr, u64 iova, int length, u
mutex_lock(&umem_odp->umem_mutex);
- need_fault = rxe_check_pagefault(umem_odp, iova, length);
+ need_fault = rxe_check_pagefault(umem_odp, iova, length, write);
if (need_fault) {
mutex_unlock(&umem_odp->umem_mutex);
@@ -179,7 +184,7 @@ static int rxe_odp_map_range_and_lock(struct rxe_mr *mr, u64 iova, int length, u
if (err < 0)
return err;
- need_fault = rxe_check_pagefault(umem_odp, iova, length);
+ need_fault = rxe_check_pagefault(umem_odp, iova, length, write);
if (need_fault) {
mutex_unlock(&umem_odp->umem_mutex);
return -EFAULT;
@@ -341,8 +346,9 @@ int rxe_odp_flush_pmem_iova(struct rxe_mr *mr, u64 iova,
int err;
u8 *va;
+ /* A flush never modifies memory; read-only access suffices. */
err = rxe_odp_map_range_and_lock(mr, iova, length,
- RXE_PAGEFAULT_DEFAULT);
+ RXE_PAGEFAULT_RDONLY);
if (err)
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 083/438] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (81 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 082/438] wifi: mac80211: dont allow injecting frames wider than the chanctx Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 084/438] wifi: mac80211: require a peer station for TDLS setup confirm Greg Kroah-Hartman
` (366 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+de3ee5362db09487ea37,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 4504f3960dc4501c73be9f99eabda2e26e9db41e ]
On ifup, AP_VLAN interfaces get crypto_tx_tailroom_needed_cnt from
the AP interface, but it's never decremented again unless the AP is
also brought down. Thus, bringing the same AP_VLAN up again will
increment the counter again and eventually hit the sanity check:
WARN_ON_ONCE(sdata->crypto_tx_tailroom_needed_cnt !=
master->crypto_tx_tailroom_needed_cnt);
Reset it on ifdown to avoid that.
Assisted-by: LLM
Fixes: f9dca80b98ca ("mac80211: fix AP_VLAN crypto tailroom calculation")
Reported-by: syzbot+de3ee5362db09487ea37@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=de3ee5362db09487ea37
Link: https://patch.msgid.link/20260908122838.201719-14-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index ca66eb493ac7d..889c32fd8de19 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -616,6 +616,8 @@ static void ieee80211_do_stop(struct ieee80211_sub_if_data *sdata, bool going_do
RCU_INIT_POINTER(sdata->vif.bss_conf.chanctx_conf, NULL);
/* see comment in the default case below */
ieee80211_free_keys(sdata, true);
+ /* increased by AP value on ifup, so reset on ifdown */
+ sdata->crypto_tx_tailroom_needed_cnt = 0;
/* no need to tell driver */
break;
case NL80211_IFTYPE_MONITOR:
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 030/398] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (28 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 029/398] RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 031/398] RDMA/mlx5: Remove warn on missing representor in query_port_speed Greg Kroah-Hartman
` (372 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Zhu Yanjun,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit 1caceeb2d74bbe88223aea55eb8626b4c5f076fd ]
rxe_get_mcg() publishes a newly allocated multicast group in
rxe->mcg_tree before programming the backing Ethernet multicast address
with rxe_mcast_add(), which runs outside mcg_lock. A local userspace
RDMA client reaches this path with ATTACH_MCAST on a UD QP; if
rxe_mcast_add() then returns an error (for example -ENODEV when the
backing netdev has been removed, or a propagated dev_mc_add() error),
the unwind frees the published group without removing it from the tree.
A later lookup of the same MGID dereferences the freed struct rxe_mcg
from __rxe_lookup_mcg().
Fix this by keeping the new mcg private until rxe_mcast_add() succeeds.
Split the tree publication into __rxe_publish_mcg(), call rxe_mcast_add()
before taking the tree reference, and free the still-private mcg on
failure. Because the group is never visible in mcg_tree until the
multicast address is programmed, no concurrent caller can look it up or
attach a QP to a group that is about to be torn down, so the error path
needs no conditional unwind. If another caller publishes the same MGID
while the address is being programmed, the post-add re-check under
mcg_lock finds the winner; this caller then drops its private object and
balances its own rxe_mcast_add() with rxe_mcast_del() before returning
the winner.
Reproduced by forcing the rxe_mcast_add() error return under KASAN:
without the change the next attach to the same MGID reports a
slab-use-after-free in __rxe_lookup_mcg(); with it the forced failure
returns cleanly. A no-injection attach/detach regression, including a
two-QP shared join/leave and re-attach, stays KASAN- and leak-clean.
Fixes: a926a903b7dc ("RDMA/rxe: Do not call dev_mc_add/del() under a spinlock")
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Link: https://patch.msgid.link/20260617022728.2770116-1-michael.bommarito@gmail.com
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_mcast.c | 50 +++++++++++++++++++--------
1 file changed, 36 insertions(+), 14 deletions(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_mcast.c b/drivers/infiniband/sw/rxe/rxe_mcast.c
index 07ff47bae31df..c14680c9a5362 100644
--- a/drivers/infiniband/sw/rxe/rxe_mcast.c
+++ b/drivers/infiniband/sw/rxe/rxe_mcast.c
@@ -175,7 +175,9 @@ struct rxe_mcg *rxe_lookup_mcg(struct rxe_dev *rxe, union ib_gid *mgid)
* @mgid: multicast address as a gid
* @mcg: new mcg object
*
- * Context: caller should hold rxe->mcg lock
+ * Initializes the mcg fields. The mcg is private and not yet visible in
+ * mcg_tree, so this may run without rxe->mcg_lock; __rxe_publish_mcg()
+ * makes it visible under the lock once it is ready.
*/
static void __rxe_init_mcg(struct rxe_dev *rxe, union ib_gid *mgid,
struct rxe_mcg *mcg)
@@ -184,13 +186,22 @@ static void __rxe_init_mcg(struct rxe_dev *rxe, union ib_gid *mgid,
memcpy(&mcg->mgid, mgid, sizeof(mcg->mgid));
INIT_LIST_HEAD(&mcg->qp_list);
mcg->rxe = rxe;
+}
- /* caller holds a ref on mcg but that will be
- * dropped when mcg goes out of scope. We need to take a ref
- * on the pointer that will be saved in the red-black tree
- * by __rxe_insert_mcg and used to lookup mcg from mgid later.
- * Inserting mcg makes it visible to outside so this should
- * be done last after the object is ready.
+/**
+ * __rxe_publish_mcg - make a fully initialized mcg visible in mcg_tree
+ * @mcg: the mcg object
+ *
+ * Context: caller must hold rxe->mcg_lock and a reference on mcg
+ */
+static void __rxe_publish_mcg(struct rxe_mcg *mcg)
+{
+ /* caller holds a ref on mcg but that will be dropped when mcg goes
+ * out of scope. We need to take a ref on the pointer that will be
+ * saved in the red-black tree by __rxe_insert_mcg and used to lookup
+ * mcg from mgid later. Inserting mcg makes it visible to outside so
+ * this is done last after the object is ready and the multicast
+ * address has been programmed.
*/
kref_get(&mcg->ref_cnt);
__rxe_insert_mcg(mcg);
@@ -228,26 +239,37 @@ static struct rxe_mcg *rxe_get_mcg(struct rxe_dev *rxe, union ib_gid *mgid)
err = -ENOMEM;
goto err_dec;
}
+ __rxe_init_mcg(rxe, mgid, mcg);
+
+ /* program the multicast address while mcg is still private, before
+ * it is inserted into mcg_tree. dev_mc_add() may sleep so this must
+ * run outside mcg_lock. On failure mcg was never published, so a
+ * plain free is correct and the tree is untouched.
+ */
+ err = rxe_mcast_add(rxe, mgid);
+ if (err) {
+ kfree(mcg);
+ goto err_dec;
+ }
spin_lock_bh(&rxe->mcg_lock);
- /* re-check to see if someone else just added it */
+ /* re-check to see if someone else just added it while we were adding
+ * the multicast address; if so use theirs and drop ours
+ */
tmp = __rxe_lookup_mcg(rxe, mgid);
if (tmp) {
spin_unlock_bh(&rxe->mcg_lock);
+ rxe_mcast_del(rxe, mgid);
atomic_dec(&rxe->mcg_num);
kfree(mcg);
return tmp;
}
- __rxe_init_mcg(rxe, mgid, mcg);
+ __rxe_publish_mcg(mcg);
spin_unlock_bh(&rxe->mcg_lock);
- /* add mcast address outside of lock */
- err = rxe_mcast_add(rxe, mgid);
- if (!err)
- return mcg;
+ return mcg;
- kfree(mcg);
err_dec:
atomic_dec(&rxe->mcg_num);
return ERR_PTR(err);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 084/438] wifi: mac80211: require a peer station for TDLS setup confirm
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (82 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 083/438] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 085/438] wifi: mac80211: dont allow link changes when iface is down Greg Kroah-Hartman
` (365 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+e55106f8389651870be0,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 038e1d126304fd25d507fd4e671232df57bd1799 ]
It's nonsense for the setup confirm to go to station that
doesn't even exist, and it hits a warning when building
the frame:
WARN_ON_ONCE(!sta || !ap_sta)
Only accept WLAN_TDLS_SETUP_CONFIRM when the station is
already there as a TDLS station. Need to copy the call
to ieee80211_tdls_prep_mgmt_packet() since the existing
WLAN_TDLS_DISCOVERY_REQUEST already falls through to it.
Assisted-by: LLM
Fixes: 6f7eaa47e1de ("mac80211: add TDLS QoS param IE on setup-confirm")
Reported-by: syzbot+e55106f8389651870be0@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e55106f8389651870be0
Link: https://patch.msgid.link/20260908122838.201719-15-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tdls.c | 19 ++++++++++++++++++-
1 file changed, 18 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/tdls.c b/net/mac80211/tdls.c
index 5f2f89795dc99..9e721d3735e7e 100644
--- a/net/mac80211/tdls.c
+++ b/net/mac80211/tdls.c
@@ -1281,6 +1281,24 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
peer_capability, initiator,
extra_ies, extra_ies_len);
break;
+ case WLAN_TDLS_SETUP_CONFIRM: {
+ struct sta_info *sta;
+
+ sta = sta_info_get(sdata, peer);
+ if (!sta || !sta->sta.tdls) {
+ ret = -ENOLINK;
+ break;
+ }
+
+ ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
+ link_id, action_code,
+ dialog_token,
+ status_code,
+ peer_capability,
+ initiator, extra_ies,
+ extra_ies_len, 0, NULL);
+ break;
+ }
case WLAN_TDLS_DISCOVERY_REQUEST:
/*
* Protect the discovery so we can hear the TDLS discovery
@@ -1289,7 +1307,6 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
*/
drv_mgd_protect_tdls_discover(sdata->local, sdata, link_id);
fallthrough;
- case WLAN_TDLS_SETUP_CONFIRM:
case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
/* no special handling */
ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 031/398] RDMA/mlx5: Remove warn on missing representor in query_port_speed
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (29 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 030/398] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 032/398] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Greg Kroah-Hartman
` (371 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Or Har-Toov, Shay Drory,
Edward Srouji, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Or Har-Toov <ohartoov@nvidia.com>
[ Upstream commit 2be77295316c2dff0a33c0dc3a65abdab4ccf796 ]
The representor ib_device's phys_port_cnt is set to the total vport
count when the uplink vport rep loads. Individual port[i].rep entries
are populated only as each VF/SF vport rep registers. A NULL .rep for
a given port index is therefore expected while VF reps are still
loading or haven't been enabled yet.
Tools like ibstat and ibv_devinfo iterate over all ports of all RDMA
devices. Some ports may not have an eswitch representor, causing
repeated dmesg warnings when these tools run without a device argument.
This causes dmesg to be flooded with this message on every ibstat
invocation.
Remove the warning and return -ENODEV when no representor exists for
the queried port.
Fixes: aaecff5e13cd ("RDMA/mlx5: Implement query_port_speed callback")
Signed-off-by: Or Har-Toov <ohartoov@nvidia.com>
Reviewed-by: Shay Drory <shayd@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260811-remove-warn-on-miss-rep-v1-1-eccf399bc6af@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/mlx5/main.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/hw/mlx5/main.c b/drivers/infiniband/hw/mlx5/main.c
index c6b0bb786739d..3dd100cd91565 100644
--- a/drivers/infiniband/hw/mlx5/main.c
+++ b/drivers/infiniband/hw/mlx5/main.c
@@ -1669,11 +1669,8 @@ static int mlx5_ib_query_port_speed_rep(struct mlx5_ib_dev *dev, u32 port_num,
struct mlx5_core_dev *mdev;
u16 op_mod;
- if (!dev->port[port_num - 1].rep) {
- mlx5_ib_warn(dev, "Representor doesn't exist for port %u\n",
- port_num);
- return -EINVAL;
- }
+ if (!dev->port[port_num - 1].rep)
+ return -ENODEV;
rep = dev->port[port_num - 1].rep;
mdev = mlx5_eswitch_get_core_dev(rep->esw);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 085/438] wifi: mac80211: dont allow link changes when iface is down
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (83 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 084/438] wifi: mac80211: require a peer station for TDLS setup confirm Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 086/438] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set Greg Kroah-Hartman
` (364 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+582469b3a9ef5f13606b,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 370872d30349d81dec519e15ea2949fd63511cf7 ]
ieee80211_set_active_links() only checks that the interface is running in
the inner __ieee80211_set_active_links(), after drv_can_activate_links()
was already called, so using active_links on an interface that's down
triggers the check-sdata-in-driver warning.
Add the missing check in the debugfs file.
Assisted-by: LLM
Fixes: 3d9011029227 ("wifi: mac80211: implement link switching")
Reported-by: syzbot+582469b3a9ef5f13606b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=582469b3a9ef5f13606b
Link: https://patch.msgid.link/20260908122838.201719-16-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/debugfs_netdev.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/mac80211/debugfs_netdev.c b/net/mac80211/debugfs_netdev.c
index f3c6a41e49119..8346d3eb11430 100644
--- a/net/mac80211/debugfs_netdev.c
+++ b/net/mac80211/debugfs_netdev.c
@@ -729,6 +729,9 @@ static ssize_t ieee80211_if_parse_active_links(struct ieee80211_sub_if_data *sda
if (kstrtou16(buf, 0, &active_links) || !active_links)
return -EINVAL;
+ if (!ieee80211_sdata_running(sdata))
+ return -ENETDOWN;
+
return ieee80211_set_active_links(&sdata->vif, active_links) ?: buflen;
}
IEEE80211_IF_FILE_RW(active_links);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 032/398] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (30 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 031/398] RDMA/mlx5: Remove warn on missing representor in query_port_speed Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 033/398] power: sequencing: Fix build issue with COMPILE_TEST Greg Kroah-Hartman
` (370 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+5fe14f2ff4ccbace9a26,
Krystian Kaniewski, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Krystian Kaniewski <krystianmkaniewski@gmail.com>
[ Upstream commit ef9fbe1b93f3b617b96e86d5cd76b3fa44514cb5 ]
ib_device_get_netdev() intentionally returns a referenced net_device even
when it is unregistering, so matching and cleanup callers can still find
the association. The reference keeps struct net_device allocated, but does
not guarantee that the device remains operational.
ib_get_eth_speed() uses the returned device operationally by invoking its
ethtool callback. Although that call is made under RTNL, the function does
not verify the registration state first. An asynchronous RDMA port query
can therefore call into a netdev after NETDEV_UNREGISTER and ndo_uninit
have completed.
Check for NETREG_REGISTERED while holding RTNL and return -ENODEV for a
device which is being unregistered. Keeping RTNL across the check and the
ethtool operation prevents unregister from starting between them.
Keep the speed fallback and warning under RTNL as well, so the warning can
safely read netdev->name. Drop the netdev reference before releasing RTNL
once all accesses to the device are complete.
Fixes: d41861942fc5 ("IB/core: Add generic function to extract IB speed from netdev")
Reported-by: syzbot+5fe14f2ff4ccbace9a26@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=5fe14f2ff4ccbace9a26
Signed-off-by: Krystian Kaniewski <krystianmkaniewski@gmail.com>
Link: https://patch.msgid.link/20260812081708.32468-1-krystianmkaniewski@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/verbs.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c
index 4357164a9976c..fcc21fb5fb86c 100644
--- a/drivers/infiniband/core/verbs.c
+++ b/drivers/infiniband/core/verbs.c
@@ -2051,11 +2051,13 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_num, u16 *speed, u8 *width)
return -ENODEV;
rtnl_lock();
- rc = __ethtool_get_link_ksettings(netdev, &lksettings);
- rtnl_unlock();
-
- dev_put(netdev);
+ if (READ_ONCE(netdev->reg_state) != NETREG_REGISTERED) {
+ dev_put(netdev);
+ rtnl_unlock();
+ return -ENODEV;
+ }
+ rc = __ethtool_get_link_ksettings(netdev, &lksettings);
if (!rc && lksettings.base.speed != (u32)SPEED_UNKNOWN) {
netdev_speed = lksettings.base.speed;
} else {
@@ -2064,6 +2066,8 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_num, u16 *speed, u8 *width)
pr_warn("%s speed is unknown, defaulting to %u\n",
netdev->name, netdev_speed);
}
+ dev_put(netdev);
+ rtnl_unlock();
ib_get_width_and_speed(netdev_speed, lksettings.lanes,
speed, width);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 086/438] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (84 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 085/438] wifi: mac80211: dont allow link changes when iface is down Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 087/438] wifi: mac80211: dont access the TSF of a down interface Greg Kroah-Hartman
` (363 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b59873f5699e941717ca,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit b481e64e4498e2c053d5954f546ee02338f6ab63 ]
In the error path of ieee80211_mesh_csa_beacon() the settings that were
just assigned are read back with rcu_dereference(), which lockdep then
complains about.
There's no need to read the pointer at all, tmp_csa_settings still is
the right value anyway.
Assisted-by: LLM
Fixes: b8456a14e9d2 ("{nl,cfg,mac}80211: implement mesh channel switch userspace API")
Reported-by: syzbot+b59873f5699e941717ca@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b59873f5699e941717ca
Link: https://patch.msgid.link/20260908122838.201719-17-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mesh.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index bed7ac8382505..a35e2d5870b6f 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -1559,7 +1559,6 @@ int ieee80211_mesh_csa_beacon(struct ieee80211_sub_if_data *sdata,
ret = ieee80211_mesh_rebuild_beacon(sdata);
if (ret) {
- tmp_csa_settings = rcu_dereference(ifmsh->csa);
RCU_INIT_POINTER(ifmsh->csa, NULL);
kfree_rcu(tmp_csa_settings, rcu_head);
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 033/398] power: sequencing: Fix build issue with COMPILE_TEST
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (31 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 032/398] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 034/398] arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR Greg Kroah-Hartman
` (369 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Biju Das, Bartosz Golaszewski,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Biju Das <biju.das.jz@bp.renesas.com>
[ Upstream commit 3b54dbd119805361695cb50ca6a875f4c7518b74 ]
The POWER_SEQUENCING_TH1520_GPU driver depends on
(ARCH_THEAD && AUXILIARY_BUS) || COMPILE_TEST. This means when
COMPILE_TEST=y and ARCH_THEAD is not set, the driver can still be
built even though it requires AUXILIARY_BUS, which may not be
selected in that configuration, leading to a build failure.
Fix this by dropping AUXILIARY_BUS from the dependency and instead
selecting it directly, so the dependency is satisfied regardless of
whether COMPILE_TEST or ARCH_THEAD is enabled.
Fixes: 1a7312b93ab0 ("power: sequencing: extend build coverage with COMPILE_TEST=y")
Signed-off-by: Biju Das <biju.das.jz@bp.renesas.com>
Link: https://patch.msgid.link/20260826122742.153643-3-biju.das.jz@bp.renesas.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/power/sequencing/Kconfig | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/power/sequencing/Kconfig b/drivers/power/sequencing/Kconfig
index 280f92beb5d0e..a33b705415c49 100644
--- a/drivers/power/sequencing/Kconfig
+++ b/drivers/power/sequencing/Kconfig
@@ -29,7 +29,8 @@ config POWER_SEQUENCING_QCOM_WCN
config POWER_SEQUENCING_TH1520_GPU
tristate "T-HEAD TH1520 GPU power sequencing driver"
- depends on (ARCH_THEAD && AUXILIARY_BUS) || COMPILE_TEST
+ depends on ARCH_THEAD || COMPILE_TEST
+ select AUXILIARY_BUS
help
Say Y here to enable the power sequencing driver for the TH1520 SoC
GPU. This driver handles the complex clock and reset sequence
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 087/438] wifi: mac80211: dont access the TSF of a down interface
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (85 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 086/438] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 088/438] wifi: mac80211: add HE 6 GHz capability in the scan elems len Greg Kroah-Hartman
` (362 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1c8c45017f784e646b47,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 0b1de9feeb8651f7a3bb53ed7c9006e3b5298c01 ]
The tsf debugfs files call the driver even if the interface
isn't up, tgriggering check-sdata-in-driver warnings.
Reject the access in that case.
Assisted-by: LLM
Fixes: 37a41b4affa3 ("mac80211: add ieee80211_vif param to tsf functions")
Reported-by: syzbot+1c8c45017f784e646b47@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1c8c45017f784e646b47
Link: https://patch.msgid.link/20260908122838.201719-18-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/debugfs_netdev.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/mac80211/debugfs_netdev.c b/net/mac80211/debugfs_netdev.c
index 8346d3eb11430..6aba224936708 100644
--- a/net/mac80211/debugfs_netdev.c
+++ b/net/mac80211/debugfs_netdev.c
@@ -657,6 +657,9 @@ static ssize_t ieee80211_if_fmt_tsf(
struct ieee80211_local *local = sdata->local;
u64 tsf;
+ if (!ieee80211_sdata_running((struct ieee80211_sub_if_data *)sdata))
+ return -ENETDOWN;
+
tsf = drv_get_tsf(local, (struct ieee80211_sub_if_data *)sdata);
return scnprintf(buf, buflen, "0x%016llx\n", (unsigned long long) tsf);
@@ -670,6 +673,9 @@ static ssize_t ieee80211_if_parse_tsf(
int ret;
int tsf_is_delta = 0;
+ if (!ieee80211_sdata_running(sdata))
+ return -ENETDOWN;
+
if (strncmp(buf, "reset", 5) == 0) {
if (local->ops->reset_tsf) {
drv_reset_tsf(local, sdata);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 034/398] arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (32 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 033/398] power: sequencing: Fix build issue with COMPILE_TEST Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 035/398] arm64: dts: renesas: r9a09g056: " Greg Kroah-Hartman
` (368 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ovidiu Panait, Geert Uytterhoeven,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
[ Upstream commit 33da68f61d25ef8411489d06514ff627c1f88152 ]
The GBETH ethernet nodes don't specify a TX scheduling policy, so stmmac
falls back to Strict Priority. In this configuration the queue with the
highest priority gets all the traffic, starving the others under load.
Under sustained UDP TX load with multiple data streams, this starvation
triggers spurious adapter resets due to TX queue timeouts:
iperf3 -c <ip> -i0 -t60 --bind-dev end0 -u -b0 -P4
end0: NETDEV WATCHDOG: CPU: 1: transmit queue 1 timed out 5228 ms
end0: Reset adapter.
Investigation shows that only the highest priority queue is advancing
while the others stall for more than 5 seconds, causing a netdev watchdog
reset.
Switch the TX scheduling policy to Weighted-Round-Robin (WRR) so that
traffic is processed across all queues, eliminating the stalls.
Fixes: 050ee38d0002 ("arm64: dts: renesas: r9a09g057: Add GBETH nodes")
Signed-off-by: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260722085353.136986-2-ovidiu.panait.rb@renesas.com
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit 1ee90b0591630c8db982f13441a56fd9fb07e45b)
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/renesas/r9a09g057.dtsi | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/arch/arm64/boot/dts/renesas/r9a09g057.dtsi b/arch/arm64/boot/dts/renesas/r9a09g057.dtsi
index 100d5cab9b12f..dc41290ed9c5a 100644
--- a/arch/arm64/boot/dts/renesas/r9a09g057.dtsi
+++ b/arch/arm64/boot/dts/renesas/r9a09g057.dtsi
@@ -1160,23 +1160,28 @@ queue3 {
mtl_tx_setup0: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
@@ -1261,23 +1266,28 @@ queue3 {
mtl_tx_setup1: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 088/438] wifi: mac80211: add HE 6 GHz capability in the scan elems len
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (86 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 087/438] wifi: mac80211: dont access the TSF of a down interface Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 089/438] wifi: mac80211: mesh: reset the CSA state when leaving Greg Kroah-Hartman
` (361 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f961b9f94edbc266f1f8,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit cd54bf333f5631d3630bab0a832e9ae648f73515 ]
The HE 6 GHz Band Capability element is in the probe request for
every band if 6 GHz is supported, so add the size to scan_ies_len.
Otherwise, building probe request elements can fail, triggering the
WARN_ON in __ieee80211_start_scan().
Assisted-by: LLM
Fixes: 2ad2274c58ee ("mac80211: Add HE 6GHz capabilities element to probe request")
Reported-by: syzbot+f961b9f94edbc266f1f8@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f961b9f94edbc266f1f8
Link: https://patch.msgid.link/20260908122838.201719-19-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/main.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/mac80211/main.c b/net/mac80211/main.c
index eb1eaaf34612e..8edfef2b57f80 100644
--- a/net/mac80211/main.c
+++ b/net/mac80211/main.c
@@ -1454,6 +1454,10 @@ int ieee80211_register_hw(struct ieee80211_hw *hw)
sizeof(struct ieee80211_he_mcs_nss_supp) +
IEEE80211_HE_PPE_THRES_MAX_LEN;
+ if (local->hw.wiphy->bands[NL80211_BAND_6GHZ])
+ local->scan_ies_len +=
+ 3 + sizeof(struct ieee80211_he_6ghz_capa);
+
if (supp_eht)
local->scan_ies_len +=
3 + sizeof(struct ieee80211_eht_cap_elem) +
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 035/398] arm64: dts: renesas: r9a09g056: Switch GBETH TX queue scheduling to WRR
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (33 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 034/398] arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 036/398] arm64: dts: renesas: r9a09g047: " Greg Kroah-Hartman
` (367 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ovidiu Panait, Geert Uytterhoeven,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
[ Upstream commit 66fcbdbeca0118b8aeac218b33fa18c394513543 ]
The GBETH ethernet nodes don't specify a TX scheduling policy, so stmmac
falls back to Strict Priority. In this configuration the queue with the
highest priority gets all the traffic, starving the others under load.
Under sustained UDP TX load with multiple data streams, this starvation
triggers spurious adapter resets due to TX queue timeouts:
iperf3 -c <ip> -i0 -t60 --bind-dev end0 -u -b0 -P4
end0: NETDEV WATCHDOG: CPU: 1: transmit queue 1 timed out 5228 ms
end0: Reset adapter.
Investigation shows that only the highest priority queue is advancing
while the others stall for more than 5 seconds, causing a netdev watchdog
reset.
Switch the TX scheduling policy to Weighted-Round-Robin (WRR) so that
traffic is processed across all queues, eliminating the stalls.
Fixes: c8c8a57c5b40 ("arm64: dts: renesas: r9a09g056: Add GBETH nodes")
Signed-off-by: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260722085353.136986-3-ovidiu.panait.rb@renesas.com
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/renesas/r9a09g056.dtsi | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/arch/arm64/boot/dts/renesas/r9a09g056.dtsi b/arch/arm64/boot/dts/renesas/r9a09g056.dtsi
index 8871108789060..cde453fd35e24 100644
--- a/arch/arm64/boot/dts/renesas/r9a09g056.dtsi
+++ b/arch/arm64/boot/dts/renesas/r9a09g056.dtsi
@@ -827,23 +827,28 @@ queue3 {
mtl_tx_setup0: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
@@ -928,23 +933,28 @@ queue3 {
mtl_tx_setup1: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 089/438] wifi: mac80211: mesh: reset the CSA state when leaving
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (87 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 088/438] wifi: mac80211: add HE 6 GHz capability in the scan elems len Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 090/438] wifi: mac80211: mesh: release the channel if start fails Greg Kroah-Hartman
` (360 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f5752cd6b94fe38be666,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 860134b3af77970e006feab7e5decb8c84771c7f ]
ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed
in ieee80211_mesh_finish_csa(), i.e. when the channel switch completes.
Leaving the mesh while a switch is still pending therefore leaks it.
Additionally, ifmsh->csa_role and ifmsh->chsw_ttl have their state leak
in this case, so things can get mixed up in addition to the memory
leak.
Refactor the reset and call it in ieee80211_stop_mesh() to fix it all.
Assisted-by: LLM
Reported-by: syzbot+f5752cd6b94fe38be666@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f5752cd6b94fe38be666
Fixes: b8456a14e9d2 ("{nl,cfg,mac}80211: implement mesh channel switch userspace API")
Link: https://patch.msgid.link/20260908122838.201719-20-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mesh.c | 29 ++++++++++++++++++-----------
1 file changed, 18 insertions(+), 11 deletions(-)
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index a35e2d5870b6f..8f88141253758 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -1196,6 +1196,21 @@ int ieee80211_start_mesh(struct ieee80211_sub_if_data *sdata)
return 0;
}
+static void ieee80211_mesh_reset_csa(struct ieee80211_sub_if_data *sdata)
+{
+ struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
+ struct mesh_csa_settings *csa;
+
+ /* Reset the TTL value and Initiator flag */
+ ifmsh->csa_role = IEEE80211_MESH_CSA_ROLE_NONE;
+ ifmsh->chsw_ttl = 0;
+
+ /* Remove the CSA and MCSP elements from the beacon */
+ csa = sdata_dereference(ifmsh->csa, sdata);
+ RCU_INIT_POINTER(ifmsh->csa, NULL);
+ kfree_rcu(csa, rcu_head);
+}
+
void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
{
struct ieee80211_local *local = sdata->local;
@@ -1206,6 +1221,7 @@ void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
/* abort any running channel switch */
sdata->vif.bss_conf.csa_active = false;
+ ieee80211_mesh_reset_csa(sdata);
ieee80211_vif_unblock_queues_csa(sdata);
/* flush STAs and mpaths on this iface */
@@ -1514,19 +1530,10 @@ static void ieee80211_mesh_rx_bcn_presp(struct ieee80211_sub_if_data *sdata,
int ieee80211_mesh_finish_csa(struct ieee80211_sub_if_data *sdata, u64 *changed)
{
- struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
- struct mesh_csa_settings *tmp_csa_settings;
- int ret = 0;
+ int ret;
- /* Reset the TTL value and Initiator flag */
- ifmsh->csa_role = IEEE80211_MESH_CSA_ROLE_NONE;
- ifmsh->chsw_ttl = 0;
+ ieee80211_mesh_reset_csa(sdata);
- /* Remove the CSA and MCSP elements from the beacon */
- tmp_csa_settings = sdata_dereference(ifmsh->csa, sdata);
- RCU_INIT_POINTER(ifmsh->csa, NULL);
- if (tmp_csa_settings)
- kfree_rcu(tmp_csa_settings, rcu_head);
ret = ieee80211_mesh_rebuild_beacon(sdata);
if (ret)
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 036/398] arm64: dts: renesas: r9a09g047: Switch GBETH TX queue scheduling to WRR
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (34 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 035/398] arm64: dts: renesas: r9a09g056: " Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 037/398] IB/iser: reject a remote invalidation of an unregistered direction Greg Kroah-Hartman
` (366 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ovidiu Panait, Geert Uytterhoeven,
Tommaso Merciai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
[ Upstream commit 63016c3a91f2c458ca75869c8c782e899591f22d ]
The GBETH ethernet nodes don't specify a TX scheduling policy, so stmmac
falls back to Strict Priority. In this configuration the queue with the
highest priority gets all the traffic, starving the others under load.
Under sustained UDP TX load with multiple data streams, this starvation
triggers spurious adapter resets due to TX queue timeouts:
iperf3 -c <ip> -i0 -t60 --bind-dev end0 -u -b0 -P4
end0: NETDEV WATCHDOG: CPU: 1: transmit queue 1 timed out 5228 ms
end0: Reset adapter.
Investigation shows that only the highest priority queue is advancing
while the others stall for more than 5 seconds, causing a netdev watchdog
reset.
Switch the TX scheduling policy to Weighted-Round-Robin (WRR) so that
traffic is processed across all queues, eliminating the stalls.
Fixes: 41ffbb1c42d3 ("arm64: dts: renesas: r9a09g047: Add GBETH nodes")
Signed-off-by: Ovidiu Panait <ovidiu.panait.rb@renesas.com>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Tested-by: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
Link: https://patch.msgid.link/20260722085353.136986-4-ovidiu.panait.rb@renesas.com
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/renesas/r9a09g047.dtsi | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/arch/arm64/boot/dts/renesas/r9a09g047.dtsi b/arch/arm64/boot/dts/renesas/r9a09g047.dtsi
index 47d843c790212..603810ed39476 100644
--- a/arch/arm64/boot/dts/renesas/r9a09g047.dtsi
+++ b/arch/arm64/boot/dts/renesas/r9a09g047.dtsi
@@ -973,23 +973,28 @@ queue3 {
mtl_tx_setup0: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
@@ -1073,23 +1078,28 @@ queue3 {
mtl_tx_setup1: tx-queues-config {
snps,tx-queues-to-use = <4>;
+ snps,tx-sched-wrr;
queue0 {
+ snps,weight = <0x10>;
snps,dcb-algorithm;
snps,priority = <0x1>;
};
queue1 {
+ snps,weight = <0x12>;
snps,dcb-algorithm;
snps,priority = <0x2>;
};
queue2 {
+ snps,weight = <0x14>;
snps,dcb-algorithm;
snps,priority = <0x4>;
};
queue3 {
+ snps,weight = <0x18>;
snps,dcb-algorithm;
snps,priority = <0x8>;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 090/438] wifi: mac80211: mesh: release the channel if start fails
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (88 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 089/438] wifi: mac80211: mesh: reset the CSA state when leaving Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 091/438] wifi: mac80211: set up the TX info early to fix failure paths Greg Kroah-Hartman
` (359 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+63a84ea9c0f57d6133fa,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit ae97fff6495a8764bc0ef281cfe5444f701e527f ]
ieee80211_join_mesh() acquires a channel context and then calls
ieee80211_start_mesh(), which can fail. In that case, the chanctx
isn't released then interface removal will attempt to unassign it
after it's removed from the driver, hitting:
wlan0: Failed check-sdata-in-driver check, flags: 0x0
WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx
ieee80211_assign_link_chanctx
__ieee80211_link_release_channel
ieee80211_link_release_channel
ieee80211_teardown_sdata
unregister_netdevice_many_notify
_cfg80211_unregister_wdev
ieee80211_remove_interfaces
ieee80211_unregister_hw
mac80211_hwsim_del_radio
hwsim_exit_net
Correctly release the channel on start failures.
Assisted-by: LLM
Reported-by: syzbot+63a84ea9c0f57d6133fa@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=63a84ea9c0f57d6133fa
Fixes: 2b5e19677592 ("mac80211: cache mesh beacon")
Link: https://patch.msgid.link/20260908122838.201719-21-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index 45f8e3c87884a..8e2ff624a0caa 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -3323,7 +3323,11 @@ static int ieee80211_join_mesh(struct wiphy *wiphy, struct net_device *dev,
if (err)
return err;
- return ieee80211_start_mesh(sdata);
+ err = ieee80211_start_mesh(sdata);
+ if (err)
+ ieee80211_link_release_channel(&sdata->deflink);
+
+ return err;
}
static int ieee80211_leave_mesh(struct wiphy *wiphy, struct net_device *dev)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 037/398] IB/iser: reject a remote invalidation of an unregistered direction
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (35 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 036/398] arm64: dts: renesas: r9a09g047: " Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 038/398] IB/isert: wait for deferred control PDU completions before releasing the connection Greg Kroah-Hartman
` (365 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Max Gurtovoy,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit d85f0f0a7c85756fc992c70d869706f19dac9259 ]
A write command whose data is sent entirely as immediate data is not
registered. iser_reg_mem_fastreg() takes the DMA key path and leaves
rdma_reg[ISER_DIR_OUT].desc at NULL, while iser_dma_map_task_data() has
already set dir[ISER_DIR_OUT].
iser_check_remote_inv() looks at dir[] alone and hands the descriptor to
iser_inv_desc(), which reads desc->sig_protected. A target that answers
such a command with IB_WR_SEND_WITH_INV faults the initiator.
Leaving those commands unregistered is deliberate.
The same function already terminates the connection when a target sends
a remote invalidation the initiator did not ask for. A target that
invalidates a direction that was never registered is in the same class,
so give it the same answer.
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]
CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy)
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: rxe_wq do_work
RIP: 0010:iser_task_rsp+0x6d6/0xec0
Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04
RSP: 0018:ffff88811b008db8 EFLAGS: 00010202
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848
RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020
RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0
R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800
R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0
PKRU: 55555554
Call Trace:
<IRQ>
__ib_process_cq+0xe1/0x390
ib_poll_handler+0x6e/0x200
irq_poll_softirq+0x1df/0x480
? clockevents_program_event+0x2ba/0x860
? __pfx_irq_poll_softirq+0x10/0x10
handle_softirqs+0x18e/0x590
? __pfx_handle_softirqs+0x10/0x10
? __hrtimer_rearm_deferred+0x156/0x450
do_softirq+0x3b/0x60
</IRQ>
<TASK>
__local_bh_enable_ip+0x61/0x70
__alloc_skb+0x732/0x890
? _raw_spin_lock_irqsave+0x85/0xe0
? __pfx___alloc_skb+0x10/0x10
? _raw_read_unlock_irqrestore+0x16/0x50
rxe_init_packet+0x16b/0x4f0
prepare_ack_packet+0xb8/0x830
rxe_receiver+0x499/0x9980
? __pfx_rxe_receiver+0x10/0x10
? rxe_completer+0x29e5/0x38c0
? hrtimer_start_range_ns_common+0x75f/0x1730
? hrtimer_start_range_ns+0xa6/0x2c0
? __pfx__raw_spin_lock_irqsave+0x10/0x10
? __pfx_rxe_receiver+0x10/0x10
do_work+0x144/0x470
process_one_work+0x633/0x1030
? assign_work+0x11d/0x370
worker_thread+0x45b/0xd10
? __pfx_worker_thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc_sigpending+0x15c/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x36e/0x5a0
? __pfx_ret_from_fork+0x10/0x10
? __switch_to+0x572/0xdd0
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
Fixes: 59caaed7a72a ("IB/iser: Support the remote invalidation exception")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260819010804.641772-1-yhlee@isslab.korea.ac.kr
Reviewed-by: Max Gurtovoy <mgurtovoy@nvidia.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/iser/iser_initiator.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/ulp/iser/iser_initiator.c b/drivers/infiniband/ulp/iser/iser_initiator.c
index f5f090dc4f1eb..cf234ddbaaad5 100644
--- a/drivers/infiniband/ulp/iser/iser_initiator.c
+++ b/drivers/infiniband/ulp/iser/iser_initiator.c
@@ -599,11 +599,8 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
iser_dbg("conn %p: remote invalidation for rkey %#x\n",
iser_conn, rkey);
- if (unlikely(!iser_conn->snd_w_inv)) {
- iser_err("conn %p: unexpected remote invalidation, terminating connection\n",
- iser_conn);
- return -EPROTO;
- }
+ if (unlikely(!iser_conn->snd_w_inv))
+ goto bad_inv;
task = iscsi_itt_to_ctask(iser_conn->iscsi_conn, hdr->itt);
if (likely(task)) {
@@ -612,12 +609,16 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
if (iser_task->dir[ISER_DIR_IN]) {
desc = iser_task->rdma_reg[ISER_DIR_IN].desc;
+ if (unlikely(!desc))
+ goto bad_inv;
if (unlikely(iser_inv_desc(desc, rkey)))
return -EINVAL;
}
if (iser_task->dir[ISER_DIR_OUT]) {
desc = iser_task->rdma_reg[ISER_DIR_OUT].desc;
+ if (unlikely(!desc))
+ goto bad_inv;
if (unlikely(iser_inv_desc(desc, rkey)))
return -EINVAL;
}
@@ -628,6 +629,11 @@ static int iser_check_remote_inv(struct iser_conn *iser_conn, struct ib_wc *wc,
}
return 0;
+
+bad_inv:
+ iser_err("conn %p: unexpected remote invalidation, terminating connection\n",
+ iser_conn);
+ return -EPROTO;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 091/438] wifi: mac80211: set up the TX info early to fix failure paths
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (89 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 090/438] wifi: mac80211: mesh: release the channel if start fails Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 092/438] mm: memblock: show all region flags in debugfs Greg Kroah-Hartman
` (358 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 50d3d79dc0743b616afb00d01a626c76758721f7 ]
The previous commit 2c51457d930f ("wifi: mac80211: free ack status
frame on TX header build failure") cleaned up the leak, but still
left the code a bit messy and the failed SKB didn't get reported
to userspace.
Fix this up by initialising skb->cb[] earlier, which allows using
ieee80211_free_txskb() and therefore reports it for the failure
in ieee80211_build_hdr(), and unifies the ieee80211_skb_resize()
failure path with it.
Assisted-by: LLM
Fixes: c3e7724b6bc2 ("mac80211: use ieee80211_free_txskb to fix possible skb leaks")
Link: https://patch.msgid.link/20260908122838.201719-22-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tx.c | 38 ++++++++++++++++++++------------------
1 file changed, 20 insertions(+), 18 deletions(-)
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index a726a697c32d7..e264121208736 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -2974,10 +2974,23 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
*/
skb = skb_share_check(skb, GFP_ATOMIC);
if (unlikely(!skb)) {
- ret = -ENOMEM;
- goto free;
+ /* skb_share_check() already freed the skb */
+ if (info_id)
+ ieee80211_remove_ack_skb(local, info_id);
+ return ERR_PTR(-ENOMEM);
}
+ /* set this up so failure paths can clean up ack skb */
+ info = IEEE80211_SKB_CB(skb);
+ memset(info, 0, sizeof(*info));
+
+ info->flags = info_flags;
+ if (info_id) {
+ info->status_data = info_id;
+ info->status_data_idr = 1;
+ }
+ info->band = band;
+
hdr.frame_control = fc;
hdr.duration_id = 0;
hdr.seq_ctrl = 0;
@@ -3016,10 +3029,8 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
head_need += local->tx_headroom;
head_need = max_t(int, 0, head_need);
if (ieee80211_skb_resize(sdata, skb, head_need, ENCRYPT_DATA)) {
- ieee80211_free_txskb(&local->hw, skb);
- skb = NULL;
ret = -ENOMEM;
- goto free;
+ goto free_txskb;
}
}
@@ -3046,16 +3057,6 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
skb_reset_mac_header(skb);
- info = IEEE80211_SKB_CB(skb);
- memset(info, 0, sizeof(*info));
-
- info->flags = info_flags;
- if (info_id) {
- info->status_data = info_id;
- info->status_data_idr = 1;
- }
- info->band = band;
-
if (likely(!cookie)) {
ctrl_flags |= u32_encode_bits(link_id,
IEEE80211_TX_CTRL_MLO_LINK);
@@ -3079,16 +3080,17 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
pre_conf_link_id, link_id);
#endif
ret = -EINVAL;
- goto free;
+ goto free_txskb;
}
}
info->control.flags = ctrl_flags;
return skb;
+ free_txskb:
+ ieee80211_free_txskb(&local->hw, skb);
+ return ERR_PTR(ret);
free:
- if (info_id)
- ieee80211_remove_ack_skb(local, info_id);
kfree_skb(skb);
return ERR_PTR(ret);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 038/398] IB/isert: wait for deferred control PDU completions before releasing the connection
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (36 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 037/398] IB/iser: reject a remote invalidation of an unregistered direction Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 039/398] RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup Greg Kroah-Hartman
` (364 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit a8fe3dfce8c0d8a76dc3d8486a5bff5feebe156f ]
isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and
ISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns. The work
item then runs isert_completion_put() -> isert_put_cmd(), which reads
isert_conn->conn and takes conn->cmd_lock.
Nothing orders that work item against teardown. isert_wait_conn() queues
isert_release_work, which frees isert_conn, and iscsit_close_connection()
frees the iscsit_conn right after it returns, so the queued work can run
against freed memory.
Count the deferred control PDU completions per connection and let
isert_wait_conn() wait for them before the release work is queued.
ISTATE_SEND_LOGOUTRSP is deliberately not counted: that branch runs
iscsit_logout_post_handler(), which ends up waiting for
conn->conn_wait_comp, and that completion is only sent by
iscsit_close_connection() after it has called iscsit_wait_conn().
Waiting for it here would deadlock. Its wait stays the existing
isert_wait4logout().
The splat below is from a kernel with tracing printk()s and an msleep(200)
injected into isert_do_control_comp() to widen the window:
BUG: KASAN: slab-use-after-free in isert_put_cmd+0x53d/0x620
Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182
CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G B 7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy)
Tainted: [B]=BAD_PAGE
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: isert_comp_wq isert_do_control_comp
Call Trace:
<TASK>
dump_stack_lvl+0x53/0x70
print_report+0xd0/0x630
? __pfx__raw_spin_lock_irqsave+0x10/0x10
? _raw_spin_unlock_irqrestore+0x3e/0x70
? isert_put_cmd+0x53d/0x620
kasan_report+0xce/0x100
? isert_put_cmd+0x53d/0x620
isert_put_cmd+0x53d/0x620
? isert_completion_put+0x305/0x330
? isert_do_control_comp+0x2ef/0x310
process_one_work+0x633/0x1030
? assign_work+0x11d/0x370
worker_thread+0x45b/0xd10
? __pfx_worker_thread+0x10/0x10
? __pfx_worker_thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc_sigpending+0x15c/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x36e/0x5a0
? __pfx_ret_from_fork+0x10/0x10
? __switch_to+0x572/0xdd0
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Allocated by task 48:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
__kasan_kmalloc+0x8f/0xa0
__kmalloc_cache_noprof+0x158/0x370
isert_cma_handler+0x1e3/0x2ae0
cma_cm_event_handler+0x3e/0x240
cma_ib_req_handler+0x17d9/0x4490
cm_process_work+0x41/0x330
cm_work_handler+0x5727/0xc160
process_one_work+0x633/0x1030
worker_thread+0x45b/0xd10
kthread+0x2c6/0x3b0
ret_from_fork+0x36e/0x5a0
ret_from_fork_asm+0x1a/0x30
Freed by task 184:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x43/0x70
kfree+0x121/0x380
iscsit_close_connection+0x7cf/0x1e60
iscsit_take_action_for_connection_exit+0x1b6/0x360
iscsi_target_tx_thread+0x472/0x690
kthread+0x2c6/0x3b0
ret_from_fork+0x36e/0x5a0
ret_from_fork_asm+0x1a/0x30
Fixes: b8d26b3be8b3 ("iser-target: Add iSCSI Extensions for RDMA (iSER) target driver")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260821080620.1694119-1-yhlee@isslab.korea.ac.kr
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/isert/ib_isert.c | 22 ++++++++++++++++++++++
drivers/infiniband/ulp/isert/ib_isert.h | 2 ++
2 files changed, 24 insertions(+)
diff --git a/drivers/infiniband/ulp/isert/ib_isert.c b/drivers/infiniband/ulp/isert/ib_isert.c
index 6483a55170cd1..b3fc753982a38 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.c
+++ b/drivers/infiniband/ulp/isert/ib_isert.c
@@ -21,6 +21,7 @@
#include <target/target_core_fabric.h>
#include <target/iscsi/iscsi_transport.h>
#include <linux/semaphore.h>
+#include <linux/wait_bit.h>
#include "ib_isert.h"
@@ -311,6 +312,7 @@ isert_init_conn(struct isert_conn *isert_conn)
init_completion(&isert_conn->login_req_comp);
init_waitqueue_head(&isert_conn->rem_wait);
kref_init(&isert_conn->kref);
+ atomic_set(&isert_conn->ctrl_comp_cnt, 0);
mutex_init(&isert_conn->mutex);
INIT_WORK(&isert_conn->release_work, isert_release_work);
}
@@ -1697,6 +1699,8 @@ isert_do_control_comp(struct work_struct *work)
struct isert_conn *isert_conn = isert_cmd->conn;
struct ib_device *ib_dev = isert_conn->cm_id->device;
struct iscsit_cmd *cmd = isert_cmd->iscsit_cmd;
+ /* The switch below may free isert_cmd. */
+ bool counted = isert_cmd->ctrl_counted;
isert_dbg("Cmd %p i_state %d\n", isert_cmd, cmd->i_state);
@@ -1718,6 +1722,14 @@ isert_do_control_comp(struct work_struct *work)
dump_stack();
break;
}
+
+ /*
+ * The count is what keeps isert_conn alive, so drop it last. The wait
+ * queue lives in the global hash table, not in isert_conn, so this is
+ * safe even if the waiter has already freed the connection.
+ */
+ if (counted && atomic_dec_and_test(&isert_conn->ctrl_comp_cnt))
+ wake_up_var(&isert_conn->ctrl_comp_cnt);
}
static void
@@ -1761,6 +1773,12 @@ isert_send_done(struct ib_cq *cq, struct ib_wc *wc)
case ISTATE_SEND_TEXTRSP:
isert_unmap_tx_desc(tx_desc, ib_dev);
+ /* Paired with the wait in isert_wait_conn(). */
+ isert_cmd->ctrl_counted =
+ isert_cmd->iscsit_cmd->i_state != ISTATE_SEND_LOGOUTRSP;
+ if (isert_cmd->ctrl_counted)
+ atomic_inc(&isert_conn->ctrl_comp_cnt);
+
INIT_WORK(&isert_cmd->comp_work, isert_do_control_comp);
queue_work(isert_comp_wq, &isert_cmd->comp_work);
return;
@@ -2605,6 +2623,10 @@ static void isert_wait_conn(struct iscsit_conn *conn)
isert_wait4cmds(conn);
isert_wait4logout(isert_conn);
+ /* Paired with the count taken in isert_send_done(). */
+ wait_var_event(&isert_conn->ctrl_comp_cnt,
+ !atomic_read(&isert_conn->ctrl_comp_cnt));
+
queue_work(isert_release_wq, &isert_conn->release_work);
}
diff --git a/drivers/infiniband/ulp/isert/ib_isert.h b/drivers/infiniband/ulp/isert/ib_isert.h
index 0bac5aa66c802..519b17e54bd34 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.h
+++ b/drivers/infiniband/ulp/isert/ib_isert.h
@@ -153,6 +153,7 @@ struct isert_cmd {
struct work_struct comp_work;
struct scatterlist sg;
bool ctx_init_done;
+ bool ctrl_counted;
};
static inline struct isert_cmd *tx_desc_to_cmd(struct iser_tx_desc *desc)
@@ -187,6 +188,7 @@ struct isert_conn {
struct mutex mutex;
struct kref kref;
struct work_struct release_work;
+ atomic_t ctrl_comp_cnt;
bool logout_posted;
bool snd_w_inv;
wait_queue_head_t rem_wait;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 092/438] mm: memblock: show all region flags in debugfs
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (90 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 091/438] wifi: mac80211: set up the TX info early to fix failure paths Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 093/438] scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions Greg Kroah-Hartman
` (357 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Meijing Zhao,
Mike Rapoport (Microsoft), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Meijing Zhao <zhaomeijing@lixiang.com>
[ Upstream commit e2d5b01f878d76bd1142e512a0b979a1d3cd0abf ]
Commit 493f349e38d0 ("memblock: Add flags and nid info in memblock
debugfs") made memblock_debug_show() stop after finding the first set
flag. A memblock region can carry multiple flags, so the remaining flags
are hidden from debugfs.
Walk all bits in the region flags and print every set flag separated by
"|". Keep walking beyond flagname[] so that a set flag without a known
name is reported as UNKNOWN rather than silently ignored.
Fixes: 493f349e38d0 ("memblock: Add flags and nid info in memblock debugfs")
Signed-off-by: Meijing Zhao <zhaomeijing@lixiang.com>
Link: https://patch.msgid.link/20260902075944.3742866-1-zhaomeijing100@gmail.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
mm/memblock.c | 18 +++++++++++-------
1 file changed, 11 insertions(+), 7 deletions(-)
diff --git a/mm/memblock.c b/mm/memblock.c
index 6349c48154f4b..a8d1992ba7a13 100644
--- a/mm/memblock.c
+++ b/mm/memblock.c
@@ -2823,14 +2823,18 @@ static int memblock_debug_show(struct seq_file *m, void *private)
else
seq_printf(m, "%4c ", 'x');
if (reg->flags) {
- for (j = 0; j < count; j++) {
- if (reg->flags & (1U << j)) {
- seq_printf(m, "%s\n", flagname[j]);
- break;
- }
+ unsigned int flags = reg->flags;
+ bool first = true;
+
+ for (j = 0; flags; j++, flags >>= 1) {
+ if (!(flags & 1))
+ continue;
+ if (!first)
+ seq_putc(m, '|');
+ seq_puts(m, j < count ? flagname[j] : "UNKNOWN");
+ first = false;
}
- if (j == count)
- seq_printf(m, "%s\n", "UNKNOWN");
+ seq_putc(m, '\n');
} else {
seq_printf(m, "%s\n", "NONE");
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 039/398] RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (37 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 038/398] IB/isert: wait for deferred control PDU completions before releasing the connection Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 040/398] RDMA/mad: Fix receive buffer leak when PKey enforcement fails Greg Kroah-Hartman
` (363 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linkai Gong, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linkai Gong <gonglinkai@kylinos.cn>
[ Upstream commit 6c368f7baaea63c1c7c28c6df271511f2a1562c9 ]
bnxt_re_init_dcb_wq() ignores a failed allocation. The async DCB
handler later calls queue_work() on the NULL pointer.
Fixes: 51dc5312dcd9 ("RDMA/bnxt_re: Add support to handle DCB_CONFIG_CHANGE event")
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/bnxt_re/main.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/hw/bnxt_re/main.c b/drivers/infiniband/hw/bnxt_re/main.c
index f33e006126fd2..e8a4befd6ca01 100644
--- a/drivers/infiniband/hw/bnxt_re/main.c
+++ b/drivers/infiniband/hw/bnxt_re/main.c
@@ -356,9 +356,13 @@ static int bnxt_re_update_qp1_tos_dscp(struct bnxt_re_dev *rdev)
return bnxt_qplib_modify_qp(&rdev->qplib_res, &qp->qplib_qp);
}
-static void bnxt_re_init_dcb_wq(struct bnxt_re_dev *rdev)
+static int bnxt_re_init_dcb_wq(struct bnxt_re_dev *rdev)
{
rdev->dcb_wq = create_singlethread_workqueue("bnxt_re_dcb_wq");
+ if (!rdev->dcb_wq)
+ return -ENOMEM;
+
+ return 0;
}
static void bnxt_re_uninit_dcb_wq(struct bnxt_re_dev *rdev)
@@ -2340,7 +2344,9 @@ static int bnxt_re_dev_init(struct bnxt_re_dev *rdev, u8 op_type)
bnxt_re_debugfs_add_pdev(rdev);
- bnxt_re_init_dcb_wq(rdev);
+ rc = bnxt_re_init_dcb_wq(rdev);
+ if (rc)
+ goto fail;
bnxt_re_net_register_async_event(rdev);
if (!rdev->is_virtfn)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 093/438] scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (91 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 092/438] mm: memblock: show all region flags in debugfs Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 094/438] scsi: qla2xxx: Fix the ql2xfc2target parameter description Greg Kroah-Hartman
` (356 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Damien Le Moal,
Martin K. Petersen (Oracle), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 264bf9655c3d067d775a46f05eb8c871c488a864 ]
The MODULE_PARM_DESC() lines of use_msix, use_tasklet and read_wwn all
name a parameter zoned, which does not exist, and the use_tasklet one
repeats the use_msix text. modinfo shows three "zoned" entries and no
description for the real parameters.
Name the right parameters and describe use_tasklet.
Fixes: efa1fca45082 ("scsi: pm8001: Remove PM8001_USE_MSIX")
Fixes: 205430290ad0 ("scsi: pm8001: Remove PM8001_USE_TASKLET")
Fixes: 80975adc79dd ("scsi: pm8001: Remove PM8001_READ_VPD")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://patch.msgid.link/20260906170925.2524-1-kmehltretter@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/pm8001/pm8001_init.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/scsi/pm8001/pm8001_init.c b/drivers/scsi/pm8001/pm8001_init.c
index 54b35893261a6..5af81c73a8f87 100644
--- a/drivers/scsi/pm8001/pm8001_init.c
+++ b/drivers/scsi/pm8001/pm8001_init.c
@@ -58,15 +58,15 @@ MODULE_PARM_DESC(link_rate, "Enable link rate.\n"
bool pm8001_use_msix = true;
module_param_named(use_msix, pm8001_use_msix, bool, 0444);
-MODULE_PARM_DESC(zoned, "Use MSIX interrupts. Default: true");
+MODULE_PARM_DESC(use_msix, "Use MSIX interrupts. Default: true");
static bool pm8001_use_tasklet = true;
module_param_named(use_tasklet, pm8001_use_tasklet, bool, 0444);
-MODULE_PARM_DESC(zoned, "Use MSIX interrupts. Default: true");
+MODULE_PARM_DESC(use_tasklet, "Use tasklets for interrupt handling. Default: true");
static bool pm8001_read_wwn = true;
module_param_named(read_wwn, pm8001_read_wwn, bool, 0444);
-MODULE_PARM_DESC(zoned, "Get WWN from the controller. Default: true");
+MODULE_PARM_DESC(read_wwn, "Get WWN from the controller. Default: true");
uint pcs_event_log_severity = 0x03;
module_param(pcs_event_log_severity, int, 0644);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 040/398] RDMA/mad: Fix receive buffer leak when PKey enforcement fails
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (38 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 039/398] RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 041/398] RDMA/irdma: Enforce local fence for IB_WR_REG_MR Greg Kroah-Hartman
` (362 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li RongQing, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li RongQing <lirongqing@baidu.com>
[ Upstream commit 3476c28c9addfa253f505e6bd87f1f5598b961d0 ]
ib_mad_complete_recv() initializes mad_recv_wc->rmpp_list and then runs
ib_mad_enforce_security() before linking recv_buf onto that list. On
failure it calls ib_free_recv_mad(), which only walks rmpp_list and frees
the ib_mad_private of every buffer found there. As the list is still
empty at that point, nothing is freed at all.
The caller cannot clean up either: ib_mad_recv_done() sets recv to NULL
right after ib_mad_complete_recv() returns, assuming the MAD layer took
ownership of the buffer. Every MAD that fails the PKey check therefore
leaks one ib_mad_private (about 300 bytes per IB port MAD, ~2K for OPA),
and a remote node can trigger this repeatedly by sending MADs with a
wrong PKey.
Link recv_buf onto rmpp_list right after the list is initialized, so the
error path has something to free.
Fixes: 47a2b338fe63 ("IB/core: Enforce security on management datagrams")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
Link: https://patch.msgid.link/20260826073216.2367-1-lirongqing@baidu.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/mad.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/core/mad.c b/drivers/infiniband/core/mad.c
index 5150cd53d4435..f7ad35233c2df 100644
--- a/drivers/infiniband/core/mad.c
+++ b/drivers/infiniband/core/mad.c
@@ -2059,6 +2059,8 @@ static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
int ret;
INIT_LIST_HEAD(&mad_recv_wc->rmpp_list);
+ list_add(&mad_recv_wc->recv_buf.list, &mad_recv_wc->rmpp_list);
+
ret = ib_mad_enforce_security(mad_agent_priv,
mad_recv_wc->wc->pkey_index);
if (ret) {
@@ -2067,7 +2069,6 @@ static void ib_mad_complete_recv(struct ib_mad_agent_private *mad_agent_priv,
return;
}
- list_add(&mad_recv_wc->recv_buf.list, &mad_recv_wc->rmpp_list);
if (is_kernel_rmpp_data_response(mad_agent_priv, mad_recv_wc)) {
spin_lock_irqsave(&mad_agent_priv->lock, flags);
mad_send_wr = ib_find_send_mad(mad_agent_priv, mad_recv_wc);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 094/438] scsi: qla2xxx: Fix the ql2xfc2target parameter description
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (92 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 093/438] scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 095/438] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order Greg Kroah-Hartman
` (355 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter,
Martin K. Petersen (Oracle), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 779f202a92ef10a426efc07d0f4267918cb07ca3 ]
The module parameter is ql2xfc2target, but its MODULE_PARM_DESC() names
qla2xfc2target, so modinfo describes a parameter that does not exist and
shows no description for the real one.
Use the parameter name in the description.
Fixes: 877b03795fcf ("scsi: qla2xxx: Add option to disable FC2 Target support")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260906171009.2560-1-kmehltretter@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/qla2xxx/qla_os.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/scsi/qla2xxx/qla_os.c b/drivers/scsi/qla2xxx/qla_os.c
index e0c5732037adf..f2114b386fa0f 100644
--- a/drivers/scsi/qla2xxx/qla_os.c
+++ b/drivers/scsi/qla2xxx/qla_os.c
@@ -352,7 +352,7 @@ MODULE_PARM_DESC(ql2xnvme_queues,
int ql2xfc2target = 1;
module_param(ql2xfc2target, int, 0444);
-MODULE_PARM_DESC(qla2xfc2target,
+MODULE_PARM_DESC(ql2xfc2target,
"Enables FC2 Target support. "
"0 - FC2 Target support is disabled. "
"1 - FC2 Target support is enabled (default).");
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 041/398] RDMA/irdma: Enforce local fence for IB_WR_REG_MR
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (39 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 040/398] RDMA/mad: Fix receive buffer leak when PKey enforcement fails Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 042/398] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted Greg Kroah-Hartman
` (361 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jacob Moroni <jmoroni@google.com>
[ Upstream commit 3fb905f07ea45b31c8f67ba6e4668de46f527e65 ]
Enforce local fence for IB_WR_REG_MR to avoid spurious
FASTREG_VALID_MKEY async events during heavy invalidation
and registration activity.
Commit 69e8e429bca2 ("RDMA/irdma: Enforce local fence for LOCAL_INV WRs")
was very similar, but was not sufficient to prevent all occurrences
of these async events.
Fixes: b48c24c2d710 ("RDMA/irdma: Implement device supported verb APIs")
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Link: https://patch.msgid.link/20260901160014.2026285-1-jmoroni@google.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/irdma/verbs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index 9ada0bc00bd07..40443d77365b4 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -4165,7 +4165,7 @@ static int irdma_post_send(struct ib_qp *ibqp,
stag_info.total_len = iwmr->ibmr.length;
stag_info.reg_addr_pa = *palloc->level1.addr;
stag_info.first_pm_pbl_index = palloc->level1.idx;
- stag_info.local_fence = ib_wr->send_flags & IB_SEND_FENCE;
+ stag_info.local_fence = true;
if (iwmr->npages > IRDMA_MIN_PAGES_PER_FMR)
stag_info.chunk_size = 1;
err = irdma_sc_mr_fast_register(&iwqp->sc_qp, &stag_info,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 095/438] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (93 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 094/438] scsi: qla2xxx: Fix the ql2xfc2target parameter description Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 096/438] dmaengine: pxa: fix double counting of the hw descriptors Greg Kroah-Hartman
` (354 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Bereza, Frank Li, Suraj Gupta,
Vinod Koul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Bereza <alex@bereza.email>
[ Upstream commit cee9c863ee68cb27d66745eb03f60e357f4f8ad2 ]
xilinx_dma_alloc_chan_resources() builds a static ring of hardware
buffer descriptors once and the driver uses this ring throughout the
lifetime of a channel. This requires the allocation order of hardware
buffer descriptors from chan->free_seg_list to stay in sync with the
hardware buffer descriptor ring built at channel allocation time by
returning oldest descriptors to chan->free_seg_list first.
When chan->pending_list is not empty e.g. during
xilinx_dma_terminate_all() the chan->free_seg_list and the order of the
static hardware buffer descriptor ring get out of sync. Descriptors age
in this order: pending -> active -> done. So freeing pending_list first
returns the newest buffer descriptors to the chan->free_seg_list first
and thus breaks the order required by the static hardware buffer
descriptor ring. Then when the channel is reused, after a wrap around of
the free_seg_list the DMA will find a hardware buffer descriptor with a
length field that is still zeroed and stop with something like this:
xilinx-vdma 86000000.dma: Channel 000000003a21d7b8 has errors 10, cdr 6de4c000 tdr 6de4c000
After this no more descriptors are completed and a consumer potentially
blocks and waits forever. The only way to get out of this error state is
to rebuild the static hardware buffer descriptor ring and the
free_seg_list by releasing and re-acquiring the channel.
Fix the order in which hardware buffer descriptors are returned to
free_seg_list to ensure the mentioned requirement holds.
Fixes: 23059408b6a3 ("dmaengine: xilinx_dma: Fix race condition in the driver for multiple descriptor scenario")
Signed-off-by: Alex Bereza <alex@bereza.email>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Suraj Gupta <suraj.gupta2@amd.com>
Link: https://patch.msgid.link/20260817-fix-hw-buf-desc-reuse-v1-1-d79827a844c7@bereza.email
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/xilinx/xilinx_dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/xilinx/xilinx_dma.c b/drivers/dma/xilinx/xilinx_dma.c
index 74ad80d6c5a5f..0e62e523d0ccd 100644
--- a/drivers/dma/xilinx/xilinx_dma.c
+++ b/drivers/dma/xilinx/xilinx_dma.c
@@ -920,9 +920,9 @@ static void xilinx_dma_free_descriptors(struct xilinx_dma_chan *chan)
spin_lock_irqsave(&chan->lock, flags);
- xilinx_dma_free_desc_list(chan, &chan->pending_list);
xilinx_dma_free_desc_list(chan, &chan->done_list);
xilinx_dma_free_desc_list(chan, &chan->active_list);
+ xilinx_dma_free_desc_list(chan, &chan->pending_list);
spin_unlock_irqrestore(&chan->lock, flags);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 042/398] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (40 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 041/398] RDMA/irdma: Enforce local fence for IB_WR_REG_MR Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 043/398] dmaengine: sprd: Fix runtime PM reference leak in probe Greg Kroah-Hartman
` (360 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+d396918a29afb8543e1c,
Quanye Yang, Jack Wang, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Quanye Yang <quanyeyang@proton.me>
[ Upstream commit 2ae16aaa78b5edc6e6d0904c84fd9cdfb762bcda ]
The client borrows shared CQ credits in the ADDR_RESOLVED handler via
ib_cq_pool_get(), before the peer is connected. create_cm() can return
-ERESTARTSYS from wait_event_interruptible_timeout() without destroying
the CM ID. The init_conns() and stop-and-destroy paths then call
destroy_con_cq_qp() while cq is still NULL (no PUT) and only afterwards
rdma_destroy_id().
CMA serializes the handler against rdma_destroy_id() with handler_mutex,
but that does not order the GET against destroy_con_cq_qp(). If
ADDR_RESOLVED has already passed the DESTROYING check, it can take
con_mutex, GET credits, and then lose the con to kfree. Device
unregister later hits WARN_ON(cq->cqe_used) in ib_cq_pool_cleanup().
Set a per-connection flag under con_mutex before CQ/QP teardown so a
racing ADDR_RESOLVED cannot borrow credits after teardown has begun.
Reported-by: syzbot+d396918a29afb8543e1c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=d396918a29afb8543e1c
Fixes: 3b89e92c2a95 ("RDMA/rtrs: Use new shared CQ mechanism")
Signed-off-by: Quanye Yang <quanyeyang@proton.me>
Link: https://patch.msgid.link/20260830-rdma-rtrs-clt-cq-pool-leak-v1-1-b169434fd3df@proton.me
Reviewed-by: Jack Wang <jinpu.wang@cloud.ionos.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/rtrs/rtrs-clt.c | 8 ++++++++
drivers/infiniband/ulp/rtrs/rtrs-clt.h | 2 ++
2 files changed, 10 insertions(+)
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.c b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
index 8fa1d72bd20a4..fea3b17611c50 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt.c
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
@@ -1738,6 +1738,8 @@ static void destroy_con_cq_qp(struct rtrs_clt_con *con)
/*
* Be careful here: destroy_con_cq_qp() can be called even
* create_con_cq_qp() failed, see comments there.
+ * Caller must set con->destroyed under this lock first so a
+ * racing ADDR_RESOLVED cannot ib_cq_pool_get() after we PUT/SKIP.
*/
lockdep_assert_held(&con->con_mutex);
rtrs_cq_qp_destroy(&con->c);
@@ -1772,6 +1774,10 @@ static int rtrs_rdma_addr_resolved(struct rtrs_clt_con *con)
int err;
mutex_lock(&con->con_mutex);
+ if (con->destroyed) {
+ mutex_unlock(&con->con_mutex);
+ return -ECONNABORTED;
+ }
err = create_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
if (err) {
@@ -2202,6 +2208,7 @@ static void rtrs_clt_stop_and_destroy_conns(struct rtrs_clt_path *clt_path)
break;
con = to_clt_con(clt_path->s.con[cid]);
mutex_lock(&con->con_mutex);
+ con->destroyed = true;
destroy_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
destroy_cm(con);
@@ -2368,6 +2375,7 @@ static int init_conns(struct rtrs_clt_path *clt_path)
if (con->c.cm_id) {
stop_cm(con);
mutex_lock(&con->con_mutex);
+ con->destroyed = true;
destroy_con_cq_qp(con);
mutex_unlock(&con->con_mutex);
destroy_cm(con);
diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.h b/drivers/infiniband/ulp/rtrs/rtrs-clt.h
index 0f57759b3080f..e1e7c7adc9470 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt.h
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.h
@@ -75,6 +75,8 @@ struct rtrs_clt_con {
unsigned int cpu;
struct mutex con_mutex;
int cm_err;
+ /* Set under con_mutex before CQ/QP teardown. */
+ bool destroyed;
};
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 096/438] dmaengine: pxa: fix double counting of the hw descriptors
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (94 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 095/438] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 097/438] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA Greg Kroah-Hartman
` (353 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sascha Hauer, Frank Li, Vinod Koul,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sascha Hauer <s.hauer@pengutronix.de>
[ Upstream commit f6504be006aa4bb4bd26285f410a885c17920d65 ]
pxad_alloc_desc() was converted from
kzalloc(struct_size(sw_desc, hw_desc, nb_hw_desc), GFP_NOWAIT)
to kzalloc_flex(), which sets the __counted_by() counter sw_desc->nb_desc
itself - but only where the compiler has __builtin_counted_by_ref(), so
from gcc 15.1 or clang 22.1 on. The loop below it still increments
nb_desc, which makes it come out doubled there and correct elsewhere.
nb_desc is what pxad_free_desc() iterates over and what
set_updater_desc() indexes from, so set it explicitly and drop the
increment. The error path has to lower it to the number of descriptors
allocated so far, otherwise pxad_free_desc() would free entries that were
never allocated.
Fixes: 69050f8d6d075 ("treewide: Replace kmalloc with kmalloc_obj for non-scalar types")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Sascha Hauer <s.hauer@pengutronix.de>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://lore.kernel.org/r/20260817-dmaengine-pxa-v1-1-850c215c1196@pengutronix.de
Link: https://patch.msgid.link/20260817-dmaengine-pxa-v2-1-f42ab0569a48@pengutronix.de
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/pxa_dma.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/pxa_dma.c b/drivers/dma/pxa_dma.c
index fa2ee0b3e09f8..fc43124fefa89 100644
--- a/drivers/dma/pxa_dma.c
+++ b/drivers/dma/pxa_dma.c
@@ -744,6 +744,7 @@ pxad_alloc_desc(struct pxad_chan *chan, unsigned int nb_hw_desc)
sw_desc = kzalloc_flex(*sw_desc, hw_desc, nb_hw_desc, GFP_NOWAIT);
if (!sw_desc)
return NULL;
+ sw_desc->nb_desc = nb_hw_desc;
sw_desc->desc_pool = chan->desc_pool;
for (i = 0; i < nb_hw_desc; i++) {
@@ -752,10 +753,10 @@ pxad_alloc_desc(struct pxad_chan *chan, unsigned int nb_hw_desc)
dev_err(&chan->vc.chan.dev->device,
"%s(): Couldn't allocate the %dth hw_desc from dma_pool %p\n",
__func__, i, sw_desc->desc_pool);
+ sw_desc->nb_desc = i;
goto err;
}
- sw_desc->nb_desc++;
sw_desc->hw_desc[i] = desc;
if (i == 0)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 043/398] dmaengine: sprd: Fix runtime PM reference leak in probe
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (41 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 042/398] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 044/398] wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic Greg Kroah-Hartman
` (359 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Frank Li, Baolin Wang,
Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit a7df136ec529ee49a789c5029bc37b98b0d4bedd ]
pm_runtime_get_sync() increments a device's usage counter even when it
fails. sprd_dma_probe() currently jumps directly to controller clock
cleanup on that error, bypassing both pm_runtime_put_noidle() and
pm_runtime_disable(). This can happen if the preceding unchecked
pm_runtime_set_active() fails and the following runtime-resume attempt
also returns an error.
Enter the existing runtime-PM unwind path instead. This drops the
reference without idling the partially initialized device, disables
runtime PM, and then releases the controller clocks. The success path
and propagated error code are unchanged.
This issue was found by a static analysis checker and confirmed by manual
source review.
Fixes: 9b3b8171f7f4 ("dmaengine: sprd: Add Spreadtrum DMA driver")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Link: https://patch.msgid.link/20260813153149.3953497-1-ruoyuw560@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/sprd-dma.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/dma/sprd-dma.c b/drivers/dma/sprd-dma.c
index 187a090463ced..a740182530200 100644
--- a/drivers/dma/sprd-dma.c
+++ b/drivers/dma/sprd-dma.c
@@ -1212,7 +1212,7 @@ static int sprd_dma_probe(struct platform_device *pdev)
ret = pm_runtime_get_sync(&pdev->dev);
if (ret < 0)
- goto err_rpm;
+ goto err_register;
ret = dma_async_device_register(&sdev->dma_dev);
if (ret < 0) {
@@ -1234,7 +1234,6 @@ static int sprd_dma_probe(struct platform_device *pdev)
err_register:
pm_runtime_put_noidle(&pdev->dev);
pm_runtime_disable(&pdev->dev);
-err_rpm:
sprd_dma_disable(sdev);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 097/438] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (95 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 096/438] dmaengine: pxa: fix double counting of the hw descriptors Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 098/438] RDMA/efa: Keep admin queues alive while IRQ is registered Greg Kroah-Hartman
` (352 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Bereza, Frank Li, Suraj Gupta,
Vinod Koul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Bereza <alex@bereza.email>
[ Upstream commit 7ed1e3070c9b4bbd67d5519e14711038dd53ab13 ]
Using the DMA in cyclic mode modifies the hardware buffer descriptor
chain in xilinx_dma_prep_dma_cyclic so that the last descriptor used by
the cyclic transfer points back to the first descriptor, but it never
restores the original descriptor ring. This breaks using non-cyclic mode
after cyclic mode with an error like:
xilinx-vdma 86000000.dma: Channel 00000000354d5c8d has errors 100, cdr 6de40000 tdr 6de40400
The only way to get out of this error state is to rebuild the hardware
buffer descriptor ring by releasing and re-acquiring the channel.
Fix using non-cyclic mode after cyclic mode by always restoring the
original buffer descriptor ring in the same manner as it is set up by
xilinx_dma_alloc_chan_resources().
Fixes: 23059408b6a3 ("dmaengine: xilinx_dma: Fix race condition in the driver for multiple descriptor scenario")
Signed-off-by: Alex Bereza <alex@bereza.email>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Suraj Gupta <suraj.gupta2@amd.com>
Link: https://patch.msgid.link/20260817-fix-hw-buf-desc-after-cyclic-mode-v1-1-1fe47e701d6c@bereza.email
Link: https://patch.msgid.link/20260818-fix-hw-buf-desc-after-cyclic-mode-v2-1-530ff44c6a81@bereza.email
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/xilinx/xilinx_dma.c | 24 +++++++++++++++++-------
1 file changed, 17 insertions(+), 7 deletions(-)
diff --git a/drivers/dma/xilinx/xilinx_dma.c b/drivers/dma/xilinx/xilinx_dma.c
index 0e62e523d0ccd..12cf1ca3a98a1 100644
--- a/drivers/dma/xilinx/xilinx_dma.c
+++ b/drivers/dma/xilinx/xilinx_dma.c
@@ -756,15 +756,25 @@ xilinx_aximcdma_alloc_tx_segment(struct xilinx_dma_chan *chan)
return segment;
}
-static void xilinx_dma_clean_hw_desc(struct xilinx_axidma_desc_hw *hw)
+static void xilinx_dma_clean_hw_desc(struct xilinx_dma_chan *chan,
+ struct xilinx_axidma_tx_segment *segment)
{
- u32 next_desc = hw->next_desc;
- u32 next_desc_msb = hw->next_desc_msb;
+ dma_addr_t next;
+ u32 i;
- memset(hw, 0, sizeof(struct xilinx_axidma_desc_hw));
+ /*
+ * Restore the buffer descriptor's next descriptor pointer to the value
+ * set up in xilinx_dma_alloc_chan_resources(). Otherwise using the DMA
+ * in cyclic mode leaves the next descriptor pointer altered and
+ * prevents subsequent non-cyclic transfers.
+ */
+ i = segment - chan->seg_v;
+ next = chan->seg_p +
+ sizeof(*chan->seg_v) * ((i + 1) % XILINX_DMA_NUM_DESCS);
- hw->next_desc = next_desc;
- hw->next_desc_msb = next_desc_msb;
+ memset(&segment->hw, 0, sizeof(segment->hw));
+ segment->hw.next_desc = lower_32_bits(next);
+ segment->hw.next_desc_msb = upper_32_bits(next);
}
static void xilinx_mcdma_clean_hw_desc(struct xilinx_aximcdma_desc_hw *hw)
@@ -786,7 +796,7 @@ static void xilinx_mcdma_clean_hw_desc(struct xilinx_aximcdma_desc_hw *hw)
static void xilinx_dma_free_tx_segment(struct xilinx_dma_chan *chan,
struct xilinx_axidma_tx_segment *segment)
{
- xilinx_dma_clean_hw_desc(&segment->hw);
+ xilinx_dma_clean_hw_desc(chan, segment);
list_add_tail(&segment->node, &chan->free_seg_list);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 044/398] wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (42 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 043/398] dmaengine: sprd: Fix runtime PM reference leak in probe Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 045/398] wifi: virt_wifi: free skb when disconnected Greg Kroah-Hartman
` (358 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lachlan Hodges, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lachlan Hodges <lachlan.hodges@morsemicro.com>
[ Upstream commit af72b5946d493cecced27d0951ea37c1d178601e ]
Currently when building the S1G TIM element, we only build the bitmap
control if we have buffered unicast traffic. Since AID 0 sits within
the bitmap control if we have buffered multicast traffic with no
buffered unicast traffic the bitmap control won't be emitted and
dozing stations will be unaware of buffered multicast.
To fix, only exclude the bitmap control byte when we don't have
both buffered unicast and multicast traffic.
Fixes: ee6360945483 ("wifi: mac80211: support block bitmap S1G TIM encoding")
Signed-off-by: Lachlan Hodges <lachlan.hodges@morsemicro.com>
Link: https://patch.msgid.link/20260827054302.254124-1-lachlan.hodges@morsemicro.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tx.c | 41 ++++++++++++++++++++++-------------------
1 file changed, 22 insertions(+), 19 deletions(-)
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index e7df1a0c85911..cd1d814cdb824 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -4954,10 +4954,18 @@ static void ieee80211_beacon_add_tim_pvb(struct ps_data *ps,
*/
static void ieee80211_s1g_beacon_add_tim_pvb(struct ps_data *ps,
struct sk_buff *skb,
- bool mcast_traffic)
+ bool mcast_traffic,
+ bool ucast_traffic)
{
int blk;
+ /*
+ * if no unicast and multicast traffic don't emit a bitmap control
+ * or pvb
+ */
+ if (!mcast_traffic && !ucast_traffic)
+ return;
+
/*
* Emit a bitmap control block with a page slice number of 31 and a
* page index of 0 which indicates as per IEEE80211-2024 9.4.2.5.1
@@ -4966,6 +4974,10 @@ static void ieee80211_s1g_beacon_add_tim_pvb(struct ps_data *ps,
*/
skb_put_u8(skb, mcast_traffic | (31 << 1));
+ /* If there's no unicast traffic we don't need to include a PVB. */
+ if (!ucast_traffic)
+ return;
+
/* Emit an encoded block for each non-zero sub-block */
for (blk = 0; blk < IEEE80211_MAX_SUPPORTED_S1G_TIM_BLOCKS; blk++) {
u8 blk_bmap = 0;
@@ -5047,25 +5059,16 @@ static void __ieee80211_beacon_add_tim(struct ieee80211_sub_if_data *sdata,
ps->dtim_bc_mc = mcast_traffic;
- if (have_bits) {
- if (s1g)
- ieee80211_s1g_beacon_add_tim_pvb(ps, skb,
- mcast_traffic);
- else
- ieee80211_beacon_add_tim_pvb(ps, skb, mcast_traffic);
+ if (s1g) {
+ ieee80211_s1g_beacon_add_tim_pvb(ps, skb, mcast_traffic,
+ have_bits);
+ } else if (have_bits) {
+ ieee80211_beacon_add_tim_pvb(ps, skb, mcast_traffic);
} else {
- /*
- * If there is no buffered unicast traffic for an S1G
- * interface, we can exclude the bitmap control. This is in
- * contrast to other phy types as they do include the bitmap
- * control and pvb even when there is no buffered traffic.
- */
- if (!s1g) {
- /* Bitmap control */
- skb_put_u8(skb, mcast_traffic);
- /* Part Virt Bitmap */
- skb_put_u8(skb, 0);
- }
+ /* Bitmap control */
+ skb_put_u8(skb, mcast_traffic);
+ /* Part Virt Bitmap */
+ skb_put_u8(skb, 0);
}
tim->datalen = skb_tail_pointer(skb) - tim->data;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 098/438] RDMA/efa: Keep admin queues alive while IRQ is registered
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (96 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 097/438] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 099/438] RDMA/efa: Keep EQ resources " Greg Kroah-Hartman
` (351 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Margolin, Leon Romanovsky,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit e08aca85c02ff290f785f07acae758f0daf5f49e ]
The management IRQ handler accesses both the admin completion queue and the
async event queue. The driver registered the IRQ before constructing these
queues and destroyed them before freeing the IRQ, so the handler's lifetime
was not contained by the resources it accesses.
Initialize the queues with interrupts masked, request the IRQ, and then
switch to interrupt mode. On removal, reset the device and free the IRQ
before destroying the queues. Also reset the device before destroying the
queues if IRQ registration fails, because the device already has their DMA
addresses.
Fixes: b7f5e880f377 ("RDMA/efa: Add the efa module")
Link: https://patch.msgid.link/20260907-use-after-free-of-admin-queue-struct-v1-1-dd9d9267fbf4@nvidia.com
Reviewed-by: Michael Margolin <mrgolin@amazon.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/efa/efa_com.c | 4 +---
drivers/infiniband/hw/efa/efa_main.c | 15 +++++++++------
2 files changed, 10 insertions(+), 9 deletions(-)
diff --git a/drivers/infiniband/hw/efa/efa_com.c b/drivers/infiniband/hw/efa/efa_com.c
index 7cc3f4af0bb9d..12ccb6441d13d 100644
--- a/drivers/infiniband/hw/efa/efa_com.c
+++ b/drivers/infiniband/hw/efa/efa_com.c
@@ -786,7 +786,7 @@ int efa_com_admin_init(struct efa_com_dev *edev,
aq->dmadev = edev->dmadev;
aq->efa_dev = edev->efa_dev;
- set_bit(EFA_AQ_STATE_POLLING_BIT, &aq->state);
+ efa_com_set_admin_polling_mode(edev, true);
sema_init(&aq->avail_cmds, aq->depth);
@@ -804,8 +804,6 @@ int efa_com_admin_init(struct efa_com_dev *edev,
if (err)
goto err_destroy_sq;
- efa_com_set_admin_polling_mode(edev, false);
-
err = efa_com_admin_init_aenq(edev, aenq_handlers);
if (err)
goto err_destroy_cq;
diff --git a/drivers/infiniband/hw/efa/efa_main.c b/drivers/infiniband/hw/efa/efa_main.c
index 97da8e828e340..25af30c441929 100644
--- a/drivers/infiniband/hw/efa/efa_main.c
+++ b/drivers/infiniband/hw/efa/efa_main.c
@@ -611,18 +611,21 @@ static struct efa_dev *efa_probe_device(struct pci_dev *pdev)
edev->aq.msix_vector_idx = dev->admin_msix_vector_idx;
edev->aenq.msix_vector_idx = dev->admin_msix_vector_idx;
- err = efa_set_mgmnt_irq(dev);
+ err = efa_com_admin_init(edev, &aenq_handlers);
if (err)
goto err_disable_msix;
- err = efa_com_admin_init(edev, &aenq_handlers);
+ err = efa_set_mgmnt_irq(dev);
if (err)
- goto err_free_mgmnt_irq;
+ goto err_destroy_admin;
+
+ efa_com_set_admin_polling_mode(edev, false);
return dev;
-err_free_mgmnt_irq:
- efa_free_irq(dev, &dev->admin_irq);
+err_destroy_admin:
+ efa_com_dev_reset(edev, EFA_REGS_RESET_INIT_ERR);
+ efa_com_admin_destroy(edev);
err_disable_msix:
efa_disable_msix(dev);
err_reg_read_destroy:
@@ -646,8 +649,8 @@ static void efa_remove_device(struct pci_dev *pdev,
edev = &dev->edev;
efa_com_dev_reset(edev, reset_reason);
- efa_com_admin_destroy(edev);
efa_free_irq(dev, &dev->admin_irq);
+ efa_com_admin_destroy(edev);
efa_disable_msix(dev);
efa_com_mmio_reg_read_destroy(edev);
devm_iounmap(&pdev->dev, edev->reg_bar);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 045/398] wifi: virt_wifi: free skb when disconnected
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (43 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 044/398] wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic Greg Kroah-Hartman
@ 2026-09-23 14:01 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 046/398] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path Greg Kroah-Hartman
` (357 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:01 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mariano Baragiola, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mariano Baragiola <mbaragiola@linux.com>
[ Upstream commit f9edf7cf63b96d2b776fca8d258d3c5256e40c8e ]
When the simulated link is disconnected, virt_wifi_start_xmit() returns
NET_XMIT_DROP without freeing the skb. dev_hard_start_xmit() treats this
return value as consumed, so every packet sent while disconnected leaks its
skb.
Free the skb before returning the drop status.
Fixes: c7cdba31ed8b ("mac80211-next: rtnetlink wifi simulation device")
Signed-off-by: Mariano Baragiola <mbaragiola@linux.com>
Link: https://patch.msgid.link/20260809124947.3590270-1-mbaragiola@linux.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virtual/virt_wifi.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wireless/virtual/virt_wifi.c b/drivers/net/wireless/virtual/virt_wifi.c
index cd6b66242bff2..b976b90c1c2d2 100644
--- a/drivers/net/wireless/virtual/virt_wifi.c
+++ b/drivers/net/wireless/virtual/virt_wifi.c
@@ -432,6 +432,7 @@ static netdev_tx_t virt_wifi_start_xmit(struct sk_buff *skb,
priv->tx_packets++;
if (!priv->is_connected) {
priv->tx_failed++;
+ dev_kfree_skb_any(skb);
return NET_XMIT_DROP;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 099/438] RDMA/efa: Keep EQ resources alive while IRQ is registered
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (97 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 7.2 098/438] RDMA/efa: Keep admin queues alive while IRQ is registered Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 100/438] RDMA/siw: Bound fragmented header copies by the remaining length Greg Kroah-Hartman
` (350 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Margolin, Leon Romanovsky,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit e22a3627b7151754f07f90ea3d1ab6e85f5d93f4 ]
The completion IRQ handler accesses the EQ state and DMA buffer. Its IRQ was
registered before that state was initialized, while teardown released the
buffer before free_irq() synchronized the handler.
Initialize the EQ without arming it, register the IRQ, and then arm it.
Reverse the resource order during teardown by freeing the IRQ before
destroying the EQ.
Fixes: 2a152512a155 ("RDMA/efa: CQ notifications")
Link: https://patch.msgid.link/20260907-use-after-free-of-admin-queue-struct-v1-2-dd9d9267fbf4@nvidia.com
Reviewed-by: Michael Margolin <mrgolin@amazon.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/efa/efa_com.c | 3 +--
drivers/infiniband/hw/efa/efa_com.h | 1 +
drivers/infiniband/hw/efa/efa_main.c | 18 ++++++++++--------
3 files changed, 12 insertions(+), 10 deletions(-)
diff --git a/drivers/infiniband/hw/efa/efa_com.c b/drivers/infiniband/hw/efa/efa_com.c
index 12ccb6441d13d..eed6000fc62df 100644
--- a/drivers/infiniband/hw/efa/efa_com.c
+++ b/drivers/infiniband/hw/efa/efa_com.c
@@ -1192,7 +1192,7 @@ static void efa_com_destroy_eq(struct efa_com_dev *edev,
err);
}
-static void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq)
+void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq)
{
u32 val = 0;
@@ -1281,7 +1281,6 @@ int efa_com_eq_init(struct efa_com_dev *edev, struct efa_com_eq *eeq,
eeq->phase = 1;
eeq->depth = params.depth;
eeq->cb = cb;
- efa_com_arm_eq(edev, eeq);
return 0;
diff --git a/drivers/infiniband/hw/efa/efa_com.h b/drivers/infiniband/hw/efa/efa_com.h
index f8c692b0e092e..d9b3eb0cdf37c 100644
--- a/drivers/infiniband/hw/efa/efa_com.h
+++ b/drivers/infiniband/hw/efa/efa_com.h
@@ -159,6 +159,7 @@ int efa_com_admin_init(struct efa_com_dev *edev,
void efa_com_admin_destroy(struct efa_com_dev *edev);
int efa_com_eq_init(struct efa_com_dev *edev, struct efa_com_eq *eeq,
efa_eqe_handler cb, u16 depth, u8 msix_vec);
+void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq);
void efa_com_eq_destroy(struct efa_com_dev *edev, struct efa_com_eq *eeq);
int efa_com_dev_reset(struct efa_com_dev *edev,
enum efa_regs_reset_reason_types reset_reason);
diff --git a/drivers/infiniband/hw/efa/efa_main.c b/drivers/infiniband/hw/efa/efa_main.c
index 25af30c441929..c2ecd44476d4f 100644
--- a/drivers/infiniband/hw/efa/efa_main.c
+++ b/drivers/infiniband/hw/efa/efa_main.c
@@ -300,28 +300,30 @@ static void efa_set_host_info(struct efa_dev *dev)
static void efa_destroy_eq(struct efa_dev *dev, struct efa_eq *eq)
{
- efa_com_eq_destroy(&dev->edev, &eq->eeq);
efa_free_irq(dev, &eq->irq);
+ efa_com_eq_destroy(&dev->edev, &eq->eeq);
}
static int efa_create_eq(struct efa_dev *dev, struct efa_eq *eq, u32 msix_vec)
{
int err;
- efa_setup_comp_irq(dev, eq, msix_vec);
- err = efa_request_irq(dev, &eq->irq);
+ err = efa_com_eq_init(&dev->edev, &eq->eeq, efa_process_eqe,
+ dev->dev_attr.max_eq_depth, msix_vec);
if (err)
return err;
- err = efa_com_eq_init(&dev->edev, &eq->eeq, efa_process_eqe,
- dev->dev_attr.max_eq_depth, msix_vec);
+ efa_setup_comp_irq(dev, eq, msix_vec);
+ err = efa_request_irq(dev, &eq->irq);
if (err)
- goto err_free_comp_irq;
+ goto err_destroy_eq;
+
+ efa_com_arm_eq(&dev->edev, &eq->eeq);
return 0;
-err_free_comp_irq:
- efa_free_irq(dev, &eq->irq);
+err_destroy_eq:
+ efa_com_eq_destroy(&dev->edev, &eq->eeq);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 046/398] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (44 preceding siblings ...)
2026-09-23 14:01 ` [PATCH 6.18 045/398] wifi: virt_wifi: free skb when disconnected Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 047/398] wifi: brcmfmac: cyw: pass PMKID to firmware if present Greg Kroah-Hartman
` (356 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peng Hao, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peng Hao <flyingpenghao@gmail.com>
[ Upstream commit a3d722190cdef18da4878b5efc27c3c386dda248 ]
mwifiex_pcie_request_irq() registers each MSI-X vector with a per-index
dev_id (&card->msix_ctx[i]). On a request_irq() failure the cleanup loop
"for (j = 0; j < i; j++)" frees msix_entries[j].vector but passes the
failed index's &card->msix_ctx[i] as the dev_id. free_irq() matches on
(irq, dev_id), so it fails to find the action registered with
&card->msix_ctx[j]: the already-requested IRQ j is not freed (leaked) and
free_irq() warns about freeing a non-existent IRQ. Use &card->msix_ctx[j].
Fixes: 99074fc1e67b ("mwifiex: enable pcie MSIx interrupt mode support")
Signed-off-by: Peng Hao <flyingpeng@tencent.com>
Link: https://patch.msgid.link/20260828111531.56723-1-flyingpeng@tencent.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/marvell/mwifiex/pcie.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/marvell/mwifiex/pcie.c b/drivers/net/wireless/marvell/mwifiex/pcie.c
index a760de191fce7..a9425e9a94f45 100644
--- a/drivers/net/wireless/marvell/mwifiex/pcie.c
+++ b/drivers/net/wireless/marvell/mwifiex/pcie.c
@@ -3068,7 +3068,7 @@ static int mwifiex_pcie_request_irq(struct mwifiex_adapter *adapter)
ret);
for (j = 0; j < i; j++)
free_irq(card->msix_entries[j].vector,
- &card->msix_ctx[i]);
+ &card->msix_ctx[j]);
pci_disable_msix(pdev);
} else {
mwifiex_dbg(adapter, MSG, "MSIx enabled!");
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 100/438] RDMA/siw: Bound fragmented header copies by the remaining length
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (98 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 099/438] RDMA/efa: Keep EQ resources " Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 101/438] x86/div64: Fix addition of large constants in mul_u64_add_u64_div_u64() Greg Kroah-Hartman
` (349 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jérémy Jean,
Bernard Metzler, Leon Romanovsky, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
[ Upstream commit 9ff797e516dbc1ecb73701ec4c24055712d44411 ]
siw_get_hdr() can receive an extended DDP/RDMAP header across more than
one TCP callback. The first callback may receive most of the header,
while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead
of the number of missing bytes. This makes the destination move past the
end of the header and overwrite the receive state, including
fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd
value as a copy offset, which creates an OOB write.
Use the number of header bytes already received when calculating the
next copy length.
Fixes: 754209850df8 ("RDMA/siw: Always consume all skbuf data in sk_data_ready() upcall.")
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Link: https://patch.msgid.link/20260908085520.1746329-1-Jeremy.Jean@oss.cyber.gouv.fr
Assisted-by: Codex:gpt-6
Acked-by: Bernard Metzler <bernard.metzler@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_qp_rx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/sw/siw/siw_qp_rx.c b/drivers/infiniband/sw/siw/siw_qp_rx.c
index b566d163c5aab..e5b641c8d694a 100644
--- a/drivers/infiniband/sw/siw/siw_qp_rx.c
+++ b/drivers/infiniband/sw/siw/siw_qp_rx.c
@@ -1079,7 +1079,7 @@ static int siw_get_hdr(struct siw_rx_stream *srx)
if (iwarp_pktinfo[opcode].hdr_len > sizeof(struct iwarp_ctrl_tagged)) {
int hdrlen = iwarp_pktinfo[opcode].hdr_len;
- bytes = min_t(int, hdrlen - MIN_DDP_HDR, srx->skb_new);
+ bytes = min_t(int, hdrlen - srx->fpdu_part_rcvd, srx->skb_new);
skb_copy_bits(skb, srx->skb_offset,
(char *)c_hdr + srx->fpdu_part_rcvd, bytes);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 047/398] wifi: brcmfmac: cyw: pass PMKID to firmware if present
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (45 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 046/398] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 048/398] wifi: libipw: reject too-short beacon and probe responses Greg Kroah-Hartman
` (355 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bogdan Nicolae, Arend van Spriel,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bogdan Nicolae <bogdan.nicolae@gmail.com>
[ Upstream commit e2de8d5eb2984416affdd9559e55f37c7f1bbf47 ]
Zero out auth_status on initialization. Otherwise, garbage will
leak from the stack to the firmware (when ssid is less than 32 bytes
and/or when params->pmkid is set). Then, pass the params->pmkid to the
firmware (without it, the firmware caches a garbage PMKID on successful
authentication and denies a subsequent association request that includes
the PMKID).
Fixes: 66f909308a7c ("wifi: brcmfmac: cyw: support external SAE authentication in station mode")
Signed-off-by: Bogdan Nicolae <bogdan.nicolae@gmail.com>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260807163418.487508-1-bogdan.nicolae@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
index b7472e19dd608..32a6e9ca2a469 100644
--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
@@ -201,7 +201,7 @@ brcmf_cyw_external_auth(struct wiphy *wiphy, struct net_device *dev,
{
struct brcmf_if *ifp;
struct brcmf_pub *drvr;
- struct brcmf_auth_req_status_le auth_status;
+ struct brcmf_auth_req_status_le auth_status = {};
int ret = 0;
brcmf_dbg(TRACE, "Enter\n");
@@ -209,6 +209,9 @@ brcmf_cyw_external_auth(struct wiphy *wiphy, struct net_device *dev,
ifp = netdev_priv(dev);
drvr = ifp->drvr;
if (params->status == WLAN_STATUS_SUCCESS) {
+ if (params->pmkid)
+ memcpy(auth_status.pmkid, params->pmkid,
+ WLAN_PMKID_LEN);
auth_status.flags = cpu_to_le16(BRCMF_EXTAUTH_SUCCESS);
} else {
bphy_err(drvr, "External authentication failed: status=%d\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 101/438] x86/div64: Fix addition of large constants in mul_u64_add_u64_div_u64()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (99 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 100/438] RDMA/siw: Bound fragmented header copies by the remaining length Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 102/438] drm/msm: Fix the separate_gpu_kms parameter description Greg Kroah-Hartman
` (348 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Laight, Borislav Petkov (AMD),
H. Peter Anvin, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Laight <david.laight.linux@gmail.com>
[ Upstream commit f65d38155aef069c897a64643a03db237dd1e0c8 ]
Adding constants over 2^31 fails to compile because the ADD instruction only
supports 32bit signed immediates.
Replace the "irm" constraint with "erm" so that the compiler loads large
constants into a register.
Found by a patch to drivers/iio/frequency/ad9910.c
[ bp: Massage commit message. ]
Fixes: 6480241f31f5 ("lib: add mul_u64_add_u64_div_u64() and mul_u64_u64_div_u64_roundup()")
Signed-off-by: David Laight <david.laight.linux@gmail.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: H. Peter Anvin <hpa@zytor.com>
Link: https://patch.msgid.link/20260803094702.3852-2-david.laight.linux@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/include/asm/div64.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/x86/include/asm/div64.h b/arch/x86/include/asm/div64.h
index 30fd06ede751c..8a2d343f977ec 100644
--- a/arch/x86/include/asm/div64.h
+++ b/arch/x86/include/asm/div64.h
@@ -111,7 +111,7 @@ static inline u64 mul_u64_add_u64_div_u64(u64 rax, u64 mul, u64 add, u64 div)
if (!statically_true(!add))
asm ("addq %[add], %[lo]; adcq $0, %[hi]" :
- [lo] "+r" (rax), [hi] "+r" (rdx) : [add] "irm" (add));
+ [lo] "+r" (rax), [hi] "+r" (rdx) : [add] "erm" (add));
asm ("divq %[div]" : "+a" (rax), "+d" (rdx) : [div] "rm" (div));
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 048/398] wifi: libipw: reject too-short beacon and probe responses
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (46 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 047/398] wifi: brcmfmac: cyw: pass PMKID to firmware if present Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 049/398] wifi: libipw: reject too-short association responses Greg Kroah-Hartman
` (354 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shmulik Cohen, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shmulik Cohen <anuk909@gmail.com>
[ Upstream commit 5ce5721e8cbe3e80db8f43851cc2a2a92485ef4b ]
libipw_process_probe_response() and the libipw_network_init() call it
makes assume the frame contains the full 36-byte beacon and probe
response prefix, but the ipw2100 and ipw2200 receive paths only
establish that a management frame carries the generic 24-byte
three-address header.
libipw_network_init() then computes the information element length as
stats->len - sizeof(*beacon)
stats->len is a u16 and sizeof() has type size_t, so the subtraction is
evaluated as size_t and wraps instead of going negative. Truncating
that to the u16 length parameter of libipw_parse_info_param() yields
65524 for a 24-byte beacon, and the parser then walks the receive
buffer as if it held almost 64 KiB of information elements, reading
past the allocation.
Reject the frame before any fixed field is touched.
Found by an AI-assisted review of length arithmetic in management frame
parsers. Verified with a KUnit case under Generic KASAN on arm64 under
QEMU; I do not have the hardware, so it is not tested on a real device.
Fixes: b453872c35cf ("[NET] ieee80211 subsystem")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Shmulik Cohen <anuk909@gmail.com>
Link: https://patch.msgid.link/20260812190412.18333-2-anuk909@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
index c8841f9b9ad91..2661dac6985e4 100644
--- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
@@ -1421,6 +1421,9 @@ static void libipw_process_probe_response(struct libipw_device
#endif
unsigned long flags;
+ if (stats->len < sizeof(*beacon))
+ return;
+
LIBIPW_DEBUG_SCAN("'%*pE' (%pM): %c%c%c%c %c%c%c%c-%c%c%c%c %c%c%c%c\n",
info_element->len, info_element->data,
beacon->header.addr3,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 102/438] drm/msm: Fix the separate_gpu_kms parameter description
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (100 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 101/438] x86/div64: Fix addition of large constants in mul_u64_add_u64_div_u64() Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 103/438] drm/msm/adreno: Fix the skip_gpu " Greg Kroah-Hartman
` (347 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Rob Clark,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit adf5967331318bcb436fc80069915231ec039352 ]
The module parameter is separate_gpu_kms, but its MODULE_PARM_DESC()
names separate_gpu_drm, so modinfo describes a parameter that does not
exist and shows no description for the real one.
Use the parameter name in the description.
Fixes: 217ed15bd399 ("drm/msm: enable separate binding of GPU and display devices")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Patchwork: https://patchwork.freedesktop.org/patch/751407/
Message-ID: <20260906170347.2427-1-kmehltretter@gmail.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/msm_drv.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/msm/msm_drv.c b/drivers/gpu/drm/msm/msm_drv.c
index 32d5ebea2596f..fa46ab3063e6f 100644
--- a/drivers/gpu/drm/msm/msm_drv.c
+++ b/drivers/gpu/drm/msm/msm_drv.c
@@ -55,7 +55,7 @@ MODULE_PARM_DESC(modeset, "Use kernel modesetting [KMS] (1=on (default), 0=disab
module_param(modeset, bool, 0600);
static bool separate_gpu_kms;
-MODULE_PARM_DESC(separate_gpu_drm, "Use separate DRM device for the GPU (0=single DRM device for both GPU and display (default), 1=two DRM devices)");
+MODULE_PARM_DESC(separate_gpu_kms, "Use separate DRM device for the GPU (0=single DRM device for both GPU and display (default), 1=two DRM devices)");
module_param(separate_gpu_kms, bool, 0400);
DECLARE_FAULT_ATTR(fail_gem_alloc);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 049/398] wifi: libipw: reject too-short association responses
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (47 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 048/398] wifi: libipw: reject too-short beacon and probe responses Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 050/398] IB/IPoIB: Avoid restoring OPER_UP after multicast flush Greg Kroah-Hartman
` (353 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shmulik Cohen, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shmulik Cohen <anuk909@gmail.com>
[ Upstream commit adb7118b7d2cfd7e8213c17d7d2829f353017754 ]
libipw_handle_assoc_resp() reads the capability, status and aid fields
of the 30-byte association response prefix and then computes the
information element length as
stats->len - sizeof(*frame)
stats->len is a u16 and sizeof() has type size_t, so the subtraction is
evaluated as size_t and wraps instead of going negative. Truncating
that to the u16 length parameter of libipw_parse_info_param() turns a
frame shorter than the fixed fields into a length near 64 KiB, and the
parser then reads past the receive buffer.
Both the ipw2100 and ipw2200 management receive paths reach this
function having established only that the frame carries the generic
24-byte three-address header.
Reject the frame before any fixed field is touched.
Found by an AI-assisted review of length arithmetic in management frame
parsers. Verified with a KUnit case under Generic KASAN on arm64 under
QEMU; I do not have the hardware, so it is not tested on a real device.
Fixes: 9e8571affd1c ("[PATCH] ieee80211: Add QoS (WME) support to the ieee80211 subsystem")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Shmulik Cohen <anuk909@gmail.com>
Link: https://patch.msgid.link/20260812190412.18333-3-anuk909@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
index 2661dac6985e4..424349a6935e4 100644
--- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c
@@ -1209,6 +1209,9 @@ static int libipw_handle_assoc_resp(struct libipw_device *ieee, struct libipw_as
struct libipw_network *network = &network_resp;
struct net_device *dev = ieee->dev;
+ if (stats->len < sizeof(*frame))
+ return 1;
+
network->flags = 0;
network->qos_data.active = 0;
network->qos_data.supported = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 103/438] drm/msm/adreno: Fix the skip_gpu parameter description
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (101 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 102/438] drm/msm: Fix the separate_gpu_kms parameter description Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 104/438] dma-buf: Make DMABUF_DEBUG default to y on DEBUG_KERNEL kernels Greg Kroah-Hartman
` (346 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Rob Clark,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 8061ee61b9426fe38350fa9eead2d9c50b03deb6 ]
The module parameter is skip_gpu, but its MODULE_PARM_DESC() names
no_gpu, so modinfo describes a parameter that does not exist and shows
no description for the real one.
Use the parameter name in the description.
Fixes: 3f17991488af ("drm/msm/adreno: Add a modparam to skip GPU")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Patchwork: https://patchwork.freedesktop.org/patch/751406/
Message-ID: <20260906170301.2393-1-kmehltretter@gmail.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/adreno/adreno_device.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/msm/adreno/adreno_device.c b/drivers/gpu/drm/msm/adreno/adreno_device.c
index 7f20320ef66af..05c77fe27e620 100644
--- a/drivers/gpu/drm/msm/adreno/adreno_device.c
+++ b/drivers/gpu/drm/msm/adreno/adreno_device.c
@@ -25,7 +25,7 @@ MODULE_PARM_DESC(disable_acd, "Forcefully disable GPU ACD");
module_param_unsafe(disable_acd, bool, 0400);
static bool skip_gpu;
-MODULE_PARM_DESC(no_gpu, "Disable GPU driver register (0=enable GPU driver register (default), 1=skip GPU driver register");
+MODULE_PARM_DESC(skip_gpu, "Disable GPU driver register (0=enable GPU driver register (default), 1=skip GPU driver register");
module_param(skip_gpu, bool, 0400);
extern const struct adreno_gpulist a2xx_gpulist;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 050/398] IB/IPoIB: Avoid restoring OPER_UP after multicast flush
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (48 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 049/398] wifi: libipw: reject too-short association responses Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 051/398] wifi: cfg80211: dont get the radio mask for netdev-less wdevs Greg Kroah-Hartman
` (352 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ben Davies, Carolina Jubran,
Cosmin Ratiu, Edward Srouji, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Carolina Jubran <cjubran@nvidia.com>
[ Upstream commit 9a141d3dc869d18b2eab35e999f4790a9b84e40f ]
ipoib_ib_dev_flush_light() temporarily clears IPOIB_FLAG_OPER_UP to
prevent multicast joins while ipoib_mcast_dev_flush() is running, and
restores the flag afterwards if it was previously set.
This restore races with ipoib_ib_dev_down(). If the interface is brought
down while the flush is in progress, ipoib_ib_dev_down() clears
IPOIB_FLAG_OPER_UP, but the flush path may set it again after the device
has already gone down.
Since commit 894021a75291 ("IB/ipoib: Make the carrier_on_task race
aware"), ipoib_mcast_carrier_on_task() relies on IPOIB_FLAG_OPER_UP
being cleared to terminate its rtnl_trylock() retry loop. If the flag is
left set after shutdown, the workqueue retries forever, causing teardown
to deadlock when ipoib_ndo_uninit() waits in destroy_workqueue() while
holding RTNL.
Instead of overloading IPOIB_FLAG_OPER_UP to block multicast joins
during a light flush, introduce a dedicated IPOIB_FLAG_MCAST_FLUSH flag.
Use it together with IPOIB_FLAG_OPER_UP to determine whether multicast
joins are allowed, avoiding the race with device shutdown.
Fixes: 344bacca8cd8 ("IB/ipoib: Don't allow MC joins during light MC flush")
Reported-by: Ben Davies <ben.davies@gresearch.co.uk>
Signed-off-by: Carolina Jubran <cjubran@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260902-avoid-rest-oper-up-v1-1-04fcd4916cae@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/ipoib/ipoib.h | 7 +++++++
drivers/infiniband/ulp/ipoib/ipoib_ib.c | 12 +++++++-----
drivers/infiniband/ulp/ipoib/ipoib_multicast.c | 16 ++++++++--------
3 files changed, 22 insertions(+), 13 deletions(-)
diff --git a/drivers/infiniband/ulp/ipoib/ipoib.h b/drivers/infiniband/ulp/ipoib/ipoib.h
index 91f866e3fb8bd..143e03b649021 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib.h
+++ b/drivers/infiniband/ulp/ipoib/ipoib.h
@@ -87,6 +87,7 @@ enum {
IPOIB_FLAG_INITIALIZED = 1,
IPOIB_FLAG_ADMIN_UP = 2,
IPOIB_PKEY_ASSIGNED = 3,
+ IPOIB_FLAG_MCAST_FLUSH = 4,
IPOIB_FLAG_SUBINTERFACE = 5,
IPOIB_STOP_REAPER = 7,
IPOIB_FLAG_ADMIN_CM = 9,
@@ -414,6 +415,12 @@ struct ipoib_dev_priv {
const struct net_device_ops *rn_ops;
};
+static inline bool ipoib_mcast_allowed(struct ipoib_dev_priv *priv)
+{
+ return test_bit(IPOIB_FLAG_OPER_UP, &priv->flags) &&
+ !test_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
+}
+
struct ipoib_ah {
struct net_device *dev;
struct ib_ah *ah;
diff --git a/drivers/infiniband/ulp/ipoib/ipoib_ib.c b/drivers/infiniband/ulp/ipoib/ipoib_ib.c
index 10b0dbda6cd53..8d9aa75b83206 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib_ib.c
+++ b/drivers/infiniband/ulp/ipoib/ipoib_ib.c
@@ -1227,17 +1227,19 @@ static void __ipoib_ib_dev_flush(struct ipoib_dev_priv *priv,
}
if (level == IPOIB_FLUSH_LIGHT) {
- int oper_up;
ipoib_mark_paths_invalid(dev);
- /* Set IPoIB operation as down to prevent races between:
+ /* Set MCAST_FLUSH to prevent races between:
* the flush flow which leaves MCG and on the fly joins
* which can happen during that time. mcast restart task
* should deal with join requests we missed.
+ *
+ * Do not clear OPER_UP for this; restoring it races with
+ * ipoib_ib_dev_down() and can leave OPER_UP set after the
+ * device is down.
*/
- oper_up = test_and_clear_bit(IPOIB_FLAG_OPER_UP, &priv->flags);
+ set_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
ipoib_mcast_dev_flush(dev);
- if (oper_up)
- set_bit(IPOIB_FLAG_OPER_UP, &priv->flags);
+ clear_bit(IPOIB_FLAG_MCAST_FLUSH, &priv->flags);
ipoib_reap_dead_ahs(priv);
}
diff --git a/drivers/infiniband/ulp/ipoib/ipoib_multicast.c b/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
index 8a4ab9ff0a681..4f7639bbc7dc5 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
+++ b/drivers/infiniband/ulp/ipoib/ipoib_multicast.c
@@ -74,7 +74,7 @@ static void __ipoib_mcast_schedule_join_thread(struct ipoib_dev_priv *priv,
struct ipoib_mcast *mcast,
bool delay)
{
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
return;
/*
@@ -469,7 +469,7 @@ static int ipoib_mcast_join(struct net_device *dev, struct ipoib_mcast *mcast)
int ret = 0;
if (!priv->broadcast ||
- !test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ !ipoib_mcast_allowed(priv))
return -EINVAL;
init_completion(&mcast->done);
@@ -555,7 +555,7 @@ void ipoib_mcast_join_task(struct work_struct *work)
unsigned long delay_until = 0;
struct ipoib_mcast *mcast = NULL;
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
return;
if (ib_query_port(priv->ca, priv->port, &port_attr)) {
@@ -577,7 +577,7 @@ void ipoib_mcast_join_task(struct work_struct *work)
netif_addr_unlock_bh(dev);
spin_lock_irq(&priv->lock);
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
goto out;
if (!priv->broadcast) {
@@ -749,7 +749,7 @@ void ipoib_mcast_send(struct net_device *dev, u8 *daddr, struct sk_buff *skb)
spin_lock_irqsave(&priv->lock, flags);
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags) ||
+ if (!ipoib_mcast_allowed(priv) ||
!priv->broadcast ||
!test_bit(IPOIB_MCAST_FLAG_ATTACHED, &priv->broadcast->flags)) {
++dev->stats.tx_dropped;
@@ -871,7 +871,7 @@ void ipoib_mcast_restart_task(struct work_struct *work)
LIST_HEAD(remove_list);
struct ib_sa_mcmember_rec rec;
- if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags))
+ if (!ipoib_mcast_allowed(priv))
/*
* shortcut...on shutdown flush is called next, just
* let it do all the work
@@ -965,9 +965,9 @@ void ipoib_mcast_restart_task(struct work_struct *work)
ipoib_mcast_remove_list(&remove_list);
/*
- * Double check that we are still up
+ * Double check that we are still up and not flushing
*/
- if (test_bit(IPOIB_FLAG_OPER_UP, &priv->flags)) {
+ if (ipoib_mcast_allowed(priv)) {
spin_lock_irq(&priv->lock);
__ipoib_mcast_schedule_join_thread(priv, NULL, 0);
spin_unlock_irq(&priv->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 104/438] dma-buf: Make DMABUF_DEBUG default to y on DEBUG_KERNEL kernels
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (102 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 103/438] drm/msm/adreno: Fix the skip_gpu " Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 20:41 ` Karl Mehltretter
2026-09-23 14:02 ` [PATCH 7.2 105/438] netfilter: nft_nat: fully initialise new_addr in netmap setup Greg Kroah-Hartman
` (345 subsequent siblings)
449 siblings, 1 reply; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter,
Christian König, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 143755bdabaa96776c24f878014608e9cb44f930 ]
Commit 646013f513f3 ("dma-buf: enable DMABUF_DEBUG by default on DEBUG
kernels") changed the default of DMABUF_DEBUG to "y if DEBUG", but no
Kconfig symbol DEBUG exists, so the option has had no default since.
Use DEBUG_KERNEL, the Kconfig symbol for a debug kernel.
Fixes: 646013f513f3 ("dma-buf: enable DMABUF_DEBUG by default on DEBUG kernels")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Christian König <christian.koenig@amd.com>
Link: https://lore.kernel.org/r/20260907020015.24719-1-kmehltretter@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma-buf/Kconfig | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma-buf/Kconfig b/drivers/dma-buf/Kconfig
index 7efc0f0d07126..e4f078a326a41 100644
--- a/drivers/dma-buf/Kconfig
+++ b/drivers/dma-buf/Kconfig
@@ -43,7 +43,7 @@ config UDMABUF
config DMABUF_DEBUG
bool "DMA-BUF debug checks"
depends on DMA_SHARED_BUFFER
- default y if DEBUG
+ default y if DEBUG_KERNEL
help
This option enables additional checks for DMA-BUF importers and
exporters. Specifically it validates that importers do not peek at the
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 051/398] wifi: cfg80211: dont get the radio mask for netdev-less wdevs
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (49 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 050/398] IB/IPoIB: Avoid restoring OPER_UP after multicast flush Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 052/398] wifi: cfg80211: check IP header size in cfg80211_classify8021d() Greg Kroah-Hartman
` (351 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+abff43d2d045e37c0bb2,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit a7783e585360ee05dfe21d3173dbbe985c94f29e ]
cfg80211_calculate_bi_data() calls rdev_get_radio_mask() with
wdev->netdev, which can be NULL and then crashes in mac80211.
To avoid that, invert the order of checks since wdev->netdev
is always valid for beaconing interfaces.
Assisted-by: LLM
Fixes: abb4cfe3661a ("wifi: cfg80211: extend interface combination check for multi-radio")
Reported-by: syzbot+abff43d2d045e37c0bb2@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=abff43d2d045e37c0bb2
Link: https://patch.msgid.link/20260904165614.2056a8b7dc91.I7412c5062d8166ad6c81ee7252cec49dea19a60f@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/util.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
diff --git a/net/wireless/util.c b/net/wireless/util.c
index 918d8f8468bdb..3a60dfca77236 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -2385,16 +2385,15 @@ static void cfg80211_calculate_bi_data(struct wiphy *wiphy, u32 new_beacon_int,
if (wdev->valid_links)
continue;
+ wdev_bi = cfg80211_wdev_bi(wdev);
+ if (!wdev_bi)
+ continue;
+
/* skip wdevs not active on the given wiphy radio */
if (radio_idx >= 0 &&
!(rdev_get_radio_mask(rdev, wdev->netdev) & BIT(radio_idx)))
continue;
- wdev_bi = cfg80211_wdev_bi(wdev);
-
- if (!wdev_bi)
- continue;
-
if (!*beacon_int_gcd) {
*beacon_int_gcd = wdev_bi;
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 105/438] netfilter: nft_nat: fully initialise new_addr in netmap setup
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (103 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 104/438] dma-buf: Make DMABUF_DEBUG default to y on DEBUG_KERNEL kernels Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 106/438] netfilter: nf_tables: fix device name and prefix match in hook lookup Greg Kroah-Hartman
` (344 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Theodor Arsenij Larionov Trichkine,
Pablo Neira Ayuso, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
[ Upstream commit d313499df66159b4b7971d760d16729598ab7e5a ]
nft_nat_setup_netmap() builds the mapped address in an on-stack
union nf_inet_addr. For an IPv4 mapping it writes only the 4-byte .ip
member and the loop runs a single 32-bit iteration, but it then copies
the whole 16-byte union into range->min_addr and range->max_addr, so the
upper 12 bytes reach nf_nat_setup_info() uninitialised.
KMSAN reports an uninit-value in nf_nat_setup_info() reached from
nft_nat_eval(). The IPv6 path fills all 16 bytes and is not affected.
Zero-initialise new_addr.
Fixes: 3ff7ddb1353d ("netfilter: nft_nat: add netmap support")
Signed-off-by: Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nft_nat.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/netfilter/nft_nat.c b/net/netfilter/nft_nat.c
index e32cd9fbc7c2e..cdbd800cac969 100644
--- a/net/netfilter/nft_nat.c
+++ b/net/netfilter/nft_nat.c
@@ -64,8 +64,8 @@ static void nft_nat_setup_netmap(struct nf_nat_range2 *range,
const struct nft_pktinfo *pkt,
const struct nft_nat *priv)
{
+ union nf_inet_addr new_addr = {};
struct sk_buff *skb = pkt->skb;
- union nf_inet_addr new_addr;
__be32 netmask;
int i, len = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 052/398] wifi: cfg80211: check IP header size in cfg80211_classify8021d()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (50 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 051/398] wifi: cfg80211: dont get the radio mask for netdev-less wdevs Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 053/398] soundwire: cadence_master: wait and cancel cdns->work before clock stop Greg Kroah-Hartman
` (350 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+878ddc3962f792e9af59,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 48b2c5c628b09cf36cbeca53e0432fc2a7518be7 ]
A frame that looks like IP can be transmitted, but be too short, so
the DS field is read incorrectly:
BUG: KMSAN: uninit-value in cfg80211_classify8021d+0x99d/0x12b0 net/wireless/util.c:1027
cfg80211_classify8021d+0x99d/0x12b0 net/wireless/util.c:1027
ieee80211_select_queue+0x37a/0x9e0 net/mac80211/wme.c:180
__ieee80211_subif_start_xmit+0x60f/0x1d90 net/mac80211/tx.c:4304
ieee80211_subif_start_xmit+0xa8/0x6d0 net/mac80211/tx.c:4538
...
packet_sendmsg+0x9173/0xa2a0 net/packet/af_packet.c:3108
Use skb_header_pointer() like the MPLS case.
Assisted-by: LLM
Fixes: e31a16d6f64e ("wireless: move some utility functions from mac80211 to cfg80211")
Reported-by: syzbot+878ddc3962f792e9af59@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=878ddc3962f792e9af59
Link: https://patch.msgid.link/20260904165614.5e61a4c80b92.I37d68d3f406cb3b90b32e6943418d66070b65197@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/util.c | 26 ++++++++++++++++++++++----
1 file changed, 22 insertions(+), 4 deletions(-)
diff --git a/net/wireless/util.c b/net/wireless/util.c
index 3a60dfca77236..0254cd5f89f15 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -962,12 +962,30 @@ unsigned int cfg80211_classify8021d(struct sk_buff *skb,
}
switch (skb->protocol) {
- case htons(ETH_P_IP):
- dscp = ipv4_get_dsfield(ip_hdr(skb)) & 0xfc;
+ case htons(ETH_P_IP): {
+ const struct iphdr *iph;
+ struct iphdr _iph;
+
+ iph = skb_header_pointer(skb, sizeof(struct ethhdr),
+ sizeof(*iph), &_iph);
+ if (!iph)
+ return 0;
+
+ dscp = ipv4_get_dsfield(iph) & 0xfc;
break;
- case htons(ETH_P_IPV6):
- dscp = ipv6_get_dsfield(ipv6_hdr(skb)) & 0xfc;
+ }
+ case htons(ETH_P_IPV6): {
+ const struct ipv6hdr *ip6h;
+ struct ipv6hdr _ip6h;
+
+ ip6h = skb_header_pointer(skb, sizeof(struct ethhdr),
+ sizeof(*ip6h), &_ip6h);
+ if (!ip6h)
+ return 0;
+
+ dscp = ipv6_get_dsfield(ip6h) & 0xfc;
break;
+ }
case htons(ETH_P_MPLS_UC):
case htons(ETH_P_MPLS_MC): {
struct mpls_label mpls_tmp, *mpls;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 106/438] netfilter: nf_tables: fix device name and prefix match in hook lookup
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (104 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 105/438] netfilter: nft_nat: fully initialise new_addr in netmap setup Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 107/438] netfilter: nf_nat: unregister and release hooks on error Greg Kroah-Hartman
` (343 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wei Fang, Fernando Fernandez Mancera,
Pablo Neira Ayuso, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fernando Fernandez Mancera <fmancera@suse.de>
[ Upstream commit 444e4c88c9c62a3d823069006563513fe7d5aa66 ]
Currently, a netdev chain or flowtable hooked to a device prefix can be
unintentionally deleted by a control-plane request targeting an exact
device name or even a shorter one due to the usage of min() to calculate
the length to match.
Fix this by making sure an exact device match never matches a prefix and
that both the target and the candidate have the same length during
delete operation. The add and update paths retain the existing overlap
matching to prevent a single device from matching multiple hooks.
Reported-by: Wei Fang <void0red@gmail.com>
Closes: https://lore.kernel.org/netfilter-devel/CANE+tVrDeNCHQVmsqkV2ozeBqyE3GtRDMhZgsg1bhw10yGNTRQ@mail.gmail.com/
Fixes: 6d07a289504a ("netfilter: nf_tables: Support wildcard netdev hook specs")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_tables_api.c | 22 +++++++++++++---------
1 file changed, 13 insertions(+), 9 deletions(-)
diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
index 63003a3b8babe..245fe7b2f6734 100644
--- a/net/netfilter/nf_tables_api.c
+++ b/net/netfilter/nf_tables_api.c
@@ -2435,11 +2435,14 @@ static struct nft_hook *nft_netdev_hook_alloc(struct net *net,
}
static struct nft_hook *nft_hook_list_find(struct list_head *hook_list,
- const struct nft_hook *this)
+ const struct nft_hook *this,
+ bool strict)
{
struct nft_hook *hook;
list_for_each_entry(hook, hook_list, list) {
+ if (strict && hook->ifnamelen != this->ifnamelen)
+ continue;
if (!strncmp(hook->ifname, this->ifname,
min(hook->ifnamelen, this->ifnamelen))) {
if (hook->flags & NFT_HOOK_REMOVE)
@@ -2481,7 +2484,7 @@ static int nf_tables_parse_netdev_hooks(struct net *net,
err = PTR_ERR(hook);
goto err_hook;
}
- if (nft_hook_list_find(hook_list, hook)) {
+ if (nft_hook_list_find(hook_list, hook, false)) {
NL_SET_BAD_ATTR(extack, tmp);
nft_netdev_hook_free(hook);
err = -EEXIST;
@@ -2938,7 +2941,7 @@ static int nf_tables_updchain(struct nft_ctx *ctx, u8 genmask, u8 policy,
ops->hook = basechain->ops.hook;
}
- if (nft_hook_list_find(&basechain->hook_list, h)) {
+ if (nft_hook_list_find(&basechain->hook_list, h, false)) {
list_del(&h->list);
nft_netdev_hook_free(h);
continue;
@@ -2951,7 +2954,8 @@ static int nf_tables_updchain(struct nft_ctx *ctx, u8 genmask, u8 policy,
!nft_trans_chain_update(trans))
continue;
- if (nft_hook_list_find(&nft_trans_chain_hooks(trans), h)) {
+ if (nft_hook_list_find(&nft_trans_chain_hooks(trans),
+ h, false)) {
nft_chain_release_hook(&hook);
return -EEXIST;
}
@@ -3252,7 +3256,7 @@ static int nft_delchain_hook(struct nft_ctx *ctx,
return err;
list_for_each_entry(this, &chain_hook.list, list) {
- hook = nft_hook_list_find(&basechain->hook_list, this);
+ hook = nft_hook_list_find(&basechain->hook_list, this, true);
if (!hook) {
err = -ENOENT;
goto err_chain_del_hook;
@@ -9031,7 +9035,7 @@ static int nft_register_flowtable_net_hooks(struct net *net,
if (!nft_is_active_next(net, ft))
continue;
- if (nft_hook_list_find(&ft->hook_list, hook)) {
+ if (nft_hook_list_find(&ft->hook_list, hook, false)) {
err = -EEXIST;
goto err_unregister_net_hooks;
}
@@ -9108,7 +9112,7 @@ static int nft_flowtable_update(struct nft_ctx *ctx, const struct nlmsghdr *nlh,
return err;
list_for_each_entry_safe(hook, next, &flowtable_hook.list, list) {
- if (nft_hook_list_find(&flowtable->hook_list, hook)) {
+ if (nft_hook_list_find(&flowtable->hook_list, hook, false)) {
list_del(&hook->list);
nft_netdev_hook_free(hook);
continue;
@@ -9121,7 +9125,7 @@ static int nft_flowtable_update(struct nft_ctx *ctx, const struct nlmsghdr *nlh,
!nft_trans_flowtable_update(trans))
continue;
- if (nft_hook_list_find(&nft_trans_flowtable_hooks(trans), hook)) {
+ if (nft_hook_list_find(&nft_trans_flowtable_hooks(trans), hook, false)) {
err = -EEXIST;
goto err_flowtable_update_hook;
}
@@ -9341,7 +9345,7 @@ static int nft_delflowtable_hook(struct nft_ctx *ctx,
return err;
list_for_each_entry(this, &flowtable_hook.list, list) {
- hook = nft_hook_list_find(&flowtable->hook_list, this);
+ hook = nft_hook_list_find(&flowtable->hook_list, this, true);
if (!hook) {
err = -ENOENT;
goto err_flowtable_del_hook;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 053/398] soundwire: cadence_master: wait and cancel cdns->work before clock stop
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (51 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 052/398] wifi: cfg80211: check IP header size in cfg80211_classify8021d() Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 054/398] MIPS: Octeon: apply USB FDT fixups also when USB is modular Greg Kroah-Hartman
` (349 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bard Liao, David Lin, Shuming Fan,
Pierre-Louis Bossart, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bard Liao <yung-chuan.liao@linux.intel.com>
[ Upstream commit aba7b41faeecb7692458095ce6fafc341fe0b80e ]
A peripheral event could happen during the clock stop process. We need
to wait for the event be handled before stopping the bus clock.
Otherwise, we will get the IO transfer timed out issue.
Fixes: af4cc917826f ("soundwire: cadence: mask Slave interrupt before stopping clock")
Signed-off-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: David Lin <david.lin@intel.com>
Reviewed-by: Shuming Fan <shumingf@realtek.com>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260901031019.233254-1-yung-chuan.liao@linux.intel.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soundwire/cadence_master.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/soundwire/cadence_master.c b/drivers/soundwire/cadence_master.c
index d7a0a14ad9626..9c7296afd711a 100644
--- a/drivers/soundwire/cadence_master.c
+++ b/drivers/soundwire/cadence_master.c
@@ -1702,6 +1702,13 @@ int sdw_cdns_clock_stop(struct sdw_cdns *cdns, bool block_wake)
return 0;
}
+ /*
+ * wait for any in-flight peripheral event handling to complete before stopping the clock.
+ * No need to disable peripheral interrupts before canceling the work, as the peripheral
+ * interrupts are already masked before the work is scheduled.
+ */
+ cancel_work_sync(&cdns->work);
+
/*
* Before entering clock stop we mask the Slave
* interrupts. This helps avoid having to deal with e.g. a
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 107/438] netfilter: nf_nat: unregister and release hooks on error
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (105 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 106/438] netfilter: nf_tables: fix device name and prefix match in hook lookup Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 108/438] netfilter: flowtable: hold reference on ct until flow is released Greg Kroah-Hartman
` (342 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit cbdd39ce42530a193c56beb206a3356cb6d01016 ]
If nf_hook_entries_insert_raw() fails, the NAT hooks get never released,
resulting in a memleak.
Postpone setting nat_proto_net->nat_hook_ops when the hooks are
registered to simplify the error path to decide whether the nat hooks
need unwinding.
Fixes: 1cd472bf036c ("netfilter: nf_nat: add nat hook register functions to nf_nat")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_nat_core.c | 46 ++++++++++++++++++++++++-------------
1 file changed, 30 insertions(+), 16 deletions(-)
diff --git a/net/netfilter/nf_nat_core.c b/net/netfilter/nf_nat_core.c
index 63ff6b4d5d214..be021d8ecc41a 100644
--- a/net/netfilter/nf_nat_core.c
+++ b/net/netfilter/nf_nat_core.c
@@ -1230,31 +1230,45 @@ int nf_nat_register_fn(struct net *net, u8 pf, const struct nf_hook_ops *ops,
}
ret = nf_register_net_hooks(net, nat_ops, ops_count);
- if (ret < 0) {
- mutex_unlock(&nf_nat_proto_mutex);
- for (i = 0; i < ops_count; i++) {
- priv = nat_ops[i].priv;
- kfree_rcu(priv, rcu_head);
- }
- kfree_rcu(nat_ops, rcu);
- return ret;
- }
-
- nat_proto_net->nat_hook_ops = nat_ops;
+ if (ret < 0)
+ goto err_free_hooks;
+ } else {
+ nat_ops = nat_proto_net->nat_hook_ops;
}
- nat_ops = nat_proto_net->nat_hook_ops;
priv = nat_ops[hooknum].priv;
if (WARN_ON_ONCE(!priv)) {
- mutex_unlock(&nf_nat_proto_mutex);
- return -EOPNOTSUPP;
+ ret = -EOPNOTSUPP;
+ goto err_unregister_hooks;
}
ret = nf_hook_entries_insert_raw(&priv->entries, ops);
- if (ret == 0)
- nat_proto_net->users++;
+ if (ret)
+ goto err_unregister_hooks;
+
+ if (!nat_proto_net->nat_hook_ops)
+ nat_proto_net->nat_hook_ops = nat_ops;
+
+ nat_proto_net->users++;
mutex_unlock(&nf_nat_proto_mutex);
+
+ return 0;
+
+err_unregister_hooks:
+ if (nat_proto_net->nat_hook_ops) {
+ mutex_unlock(&nf_nat_proto_mutex);
+ return ret;
+ }
+ nf_unregister_net_hooks(net, nat_ops, ops_count);
+err_free_hooks:
+ mutex_unlock(&nf_nat_proto_mutex);
+ for (i = 0; i < ops_count; i++) {
+ priv = nat_ops[i].priv;
+ kfree_rcu(priv, rcu_head);
+ }
+ kfree_rcu(nat_ops, rcu);
+
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 054/398] MIPS: Octeon: apply USB FDT fixups also when USB is modular
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (52 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 053/398] soundwire: cadence_master: wait and cancel cdns->work before clock stop Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 055/398] dma-coherent: report a failed reserved memory assignment Greg Kroah-Hartman
` (348 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Orgad Shaneh, Thomas Bogendoerfer,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Orgad Shaneh <orgads@gmail.com>
[ Upstream commit 126f16e0a1b353c2ba5c7e2c8626cfa865934f9f ]
The uctl/usbn device-tree fixups in octeon_prune_device_tree() - which
set the board's USB reference-clock frequency and type from
__cvmx_helper_board_usb_get_clock_type() - are guarded by
"#ifdef CONFIG_USB", which is false when USB is built as a module. The
fixups then silently disappear and octeon-hcd sees whatever default the
DTS carries (12MHz crystal in octeon_3xxx.dts), leaving the PHY dead or
the bus erroring on boards with a different reference clock.
Use IS_ENABLED() so USB=m gets the same fixups as USB=y.
Fixes: 7fd57ab9d9cf ("MIPS: Octeon: Fix compile error when USB is not enabled.")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Orgad Shaneh <orgads@gmail.com>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/cavium-octeon/octeon-platform.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/mips/cavium-octeon/octeon-platform.c b/arch/mips/cavium-octeon/octeon-platform.c
index 47677b5d7ed00..f53c98372e0be 100644
--- a/arch/mips/cavium-octeon/octeon-platform.c
+++ b/arch/mips/cavium-octeon/octeon-platform.c
@@ -18,7 +18,7 @@
#include <asm/octeon/octeon.h>
#include <asm/octeon/cvmx-helper-board.h>
-#ifdef CONFIG_USB
+#if IS_ENABLED(CONFIG_USB)
#include <linux/usb/ehci_def.h>
#include <linux/usb/ehci_pdriver.h>
#include <linux/usb/ohci_pdriver.h>
@@ -1080,7 +1080,7 @@ int __init octeon_prune_device_tree(void)
;
}
-#ifdef CONFIG_USB
+#if IS_ENABLED(CONFIG_USB)
/* OHCI/UHCI USB */
alias_prop = fdt_getprop(initial_boot_params, aliases,
"uctl", NULL);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 108/438] netfilter: flowtable: hold reference on ct until flow is released
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (106 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 107/438] netfilter: nf_nat: unregister and release hooks on error Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 109/438] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations Greg Kroah-Hartman
` (341 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d ]
nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe
semantics also allow to refer to the wrong conntrack from the flowtable
datapath. Hold reference on ct until flow is released after rcu grace
period.
Add rcu_barrier() on module exit path, to ensure pending flow entries
are release before module goes away.
Fixes: 0ff90b6c2034 ("netfilter: nf_flow_offload: fix use-after-free and a resource leak")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_flow_table_core.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/net/netfilter/nf_flow_table_core.c b/net/netfilter/nf_flow_table_core.c
index 8b1165f2b5a49..254063fca0780 100644
--- a/net/netfilter/nf_flow_table_core.c
+++ b/net/netfilter/nf_flow_table_core.c
@@ -258,6 +258,14 @@ static void flow_offload_route_release(struct flow_offload *flow)
nft_flow_dst_release(flow, FLOW_OFFLOAD_DIR_REPLY);
}
+static void flow_offload_free_rcu(struct rcu_head *rcu_head)
+{
+ struct flow_offload *flow = container_of(rcu_head, struct flow_offload, rcu_head);
+
+ nf_ct_put(flow->ct);
+ kfree(flow);
+}
+
void flow_offload_free(struct flow_offload *flow)
{
switch (flow->type) {
@@ -267,8 +275,7 @@ void flow_offload_free(struct flow_offload *flow)
default:
break;
}
- nf_ct_put(flow->ct);
- kfree_rcu(flow, rcu_head);
+ call_rcu(&flow->rcu_head, flow_offload_free_rcu);
}
EXPORT_SYMBOL_GPL(flow_offload_free);
@@ -852,6 +859,7 @@ static int __init nf_flow_table_module_init(void)
static void __exit nf_flow_table_module_exit(void)
{
+ rcu_barrier();
nf_flow_table_offload_exit();
unregister_pernet_subsys(&nf_flow_table_net_ops);
kmem_cache_destroy(flow_offload_cachep);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 055/398] dma-coherent: report a failed reserved memory assignment
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (53 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 054/398] MIPS: Octeon: apply USB FDT fixups also when USB is modular Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 056/398] dmaengine: Fix device kref underflow in dma_chan_put() Greg Kroah-Hartman
` (347 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Marek Szyprowski,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
[ Upstream commit 504981db4f69bdd28054fb98c96a3a67f7248dde ]
rmem_dma_device_init() drops the return value of
dma_assign_coherent_memory() and always reports success. That call fails
with -EBUSY when the device already has a coherent pool, and the file
allows only "*one* such region of memory" per device.
of_reserved_mem_device_init_by_idx() reads the zero as success. It logs
"assigned reserved memory node" for a region that was not assigned and
records the pairing, so of_reserved_mem_device_release() later runs
rmem_dma_device_release() for it. That clears dev->dma_mem without
looking at which region it was called for, dropping the pool the device
did get and leaving it on ordinary memory.
dma_declare_coherent_memory() checks the same call and releases the
memory on failure, and rmem_swiotlb_device_init() propagates its own
errors. Return the error here as well, so a device tree that assigns two
pools to one device fails the probe instead of half working.
Fixes: 7bfa5ab6fa1b ("drivers: dma-coherent: add initialization from device tree")
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Link: https://lore.kernel.org/r/20260905074727.108029-1-donggeunyoo.kernel@gmail.com
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/dma/coherent.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/kernel/dma/coherent.c b/kernel/dma/coherent.c
index 77c8d9487a9ab..87f2f02e921a6 100644
--- a/kernel/dma/coherent.c
+++ b/kernel/dma/coherent.c
@@ -351,8 +351,7 @@ static int rmem_dma_device_init(struct reserved_mem *rmem, struct device *dev)
min_not_zero(dev->coherent_dma_mask, dev->bus_dma_limit))
dev_warn(dev, "reserved memory is beyond device's set DMA address range\n");
- dma_assign_coherent_memory(dev, mem);
- return 0;
+ return dma_assign_coherent_memory(dev, mem);
}
static void rmem_dma_device_release(struct reserved_mem *rmem,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 109/438] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (107 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 108/438] netfilter: flowtable: hold reference on ct until flow is released Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 110/438] arm64: hibernate: clone only the linear map that exists at runtime Greg Kroah-Hartman
` (340 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shouping Wang, Robin Murphy,
Will Deacon, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shouping Wang <allen.wang@hj-micro.com>
[ Upstream commit 49daa3d668b69a5454b5aba0078848a479f79f1c ]
When MXP_MULTIPLE_DTM_EN is TRUE, each DTM will monitor at most
two device ports. In this case, {wp_dev_sel2, wp_dev_sel} will
only use values 2'b00 and 2'b01 per DTM.
Previously the setting allowed values beyond the supported range
per DTM, which could cause each DTM to select invalid ports when
MXP_MULTIPLE_DTM_EN is TRUE.
Fix this by only setting CMN_DTM_WPn_CONFIG_WP_DEV_SEL2 when
!multi_dtm.
Fixes: 60d1504070c2 ("perf/arm-cmn: Support new IP features")
Signed-off-by: Shouping Wang <allen.wang@hj-micro.com>
Reviewed-by: Robin Murphy <robin.murphy@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/perf/arm-cmn.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/perf/arm-cmn.c b/drivers/perf/arm-cmn.c
index 6e5cc4086a9e2..7e75903811710 100644
--- a/drivers/perf/arm-cmn.c
+++ b/drivers/perf/arm-cmn.c
@@ -1393,13 +1393,14 @@ static void arm_cmn_claim_wp_idx(struct arm_cmn_dtm *dtm,
static u32 arm_cmn_wp_config(struct perf_event *event, int wp_idx)
{
+ struct arm_cmn *cmn = to_cmn(event->pmu);
u32 config;
u32 dev = CMN_EVENT_WP_DEV_SEL(event);
u32 chn = CMN_EVENT_WP_CHN_SEL(event);
u32 grp = CMN_EVENT_WP_GRP(event);
u32 exc = CMN_EVENT_WP_EXCLUSIVE(event);
u32 combine = CMN_EVENT_WP_COMBINE(event);
- bool is_cmn600 = to_cmn(event->pmu)->part == PART_CMN600;
+ bool is_cmn600 = cmn->part == PART_CMN600;
/* CMN-600 supports only primary and secondary matching groups */
if (is_cmn600)
@@ -1407,8 +1408,11 @@ static u32 arm_cmn_wp_config(struct perf_event *event, int wp_idx)
config = FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL, dev) |
FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_CHN_SEL, chn) |
- FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_GRP, grp) |
- FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL2, dev >> 1);
+ FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_GRP, grp);
+
+ if (!cmn->multi_dtm)
+ config |= FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL2, dev >> 1);
+
if (exc)
config |= is_cmn600 ? CMN600_WPn_CONFIG_WP_EXCLUSIVE :
CMN_DTM_WPn_CONFIG_WP_EXCLUSIVE;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 056/398] dmaengine: Fix device kref underflow in dma_chan_put()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (54 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 055/398] dma-coherent: report a failed reserved memory assignment Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 057/398] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() Greg Kroah-Hartman
` (346 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit 44dab659064eb5c10adb0306510eebe848ed592d ]
dma_chan_get() takes chan->device->ref only on the slow path:
/* no kref on fast path */
if (chan->client_count) {
__module_get(owner);
chan->client_count++;
return 0;
}
if (!try_module_get(owner))
return -ENODEV;
if (!dma_device_get(chan->device)) { // calls kref_get_unless_zero()
dma_chan_put() drops the ref unconditionally, so every fast-path
get/put pair drops one extra device reference.
The bug fires when two conditions hold together: a non-private
provider has a persistent client holding chan->client_count > 0
and another client cycles dmaengine_get()/dmaengine_put().
When the kref hits zero, the subsequent dma_find_channel() returns
NULL even though the provider module is still loaded.
Fix this by dropping device->ref only on the last put, matching the
single slow-path get.
Fixes: 8ad342a86359 ("dmaengine: Add reference counting to dma_device struct")
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-2-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index e6d9d338a60a8..07eb4a7437c3c 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -515,7 +515,9 @@ static void dma_chan_put(struct dma_chan *chan)
chan->route_data = NULL;
}
- dma_device_put(chan->device);
+ /* This channel is not in use anymore, drop the device ref */
+ if (!chan->client_count)
+ dma_device_put(chan->device);
module_put(dma_chan_to_owner(chan));
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 110/438] arm64: hibernate: clone only the linear map that exists at runtime
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (108 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 109/438] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 111/438] arm64: mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentation Greg Kroah-Hartman
` (339 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Breno Leitao, Ard Biesheuvel,
Will Deacon, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Breno Leitao <leitao@debian.org>
[ Upstream commit e4a6f57d22e079e23fafac51057fad534160b269 ]
This is similar to commit 1537e55728ec2 ("arm64: trans_pgd: clone only
the linear map that exists at runtime"), but in a different place.
swsusp_arch_resume() clones the kernel linear map with
trans_pgd_create_copy(..., PAGE_OFFSET, PAGE_END). PAGE_OFFSET comes
from the compile-time VA_BITS, so a CONFIG_ARM64_VA_BITS_52 kernel
booting on hardware without LPA2 -- vabits_actual is 48 and the fifth
level is folded -- hands the walk a 3.9PB window while its linear map
only spans the top 128TB.
On a VA_BITS_52 4k kernel with CONFIG_KASAN_GENERIC in a 4GB VM, I see:
swapper/0: page allocation failure: order:0, mode:0x920(GFP_ATOMIC|__GFP_ZERO)
hibernate_page_alloc+0x10/0x1c
swsusp_arch_resume+0x70/0x320
hibernation_restore+0xa4/0x138
software_resume+0x15c/0x270
PM: hibernation: Failed to load image, recovering.
PM: hibernation: resume failed (-12)
Fix it by copying the linear map that is the actual one, not the
compiled one.
Fixes: a6bbf5d4d9d1 ("arm64: mm: Add definitions to support 5 levels of paging")
Signed-off-by: Breno Leitao <leitao@debian.org>
Reviewed-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kernel/hibernate.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c
index 7bf1174277772..424291c547f02 100644
--- a/arch/arm64/kernel/hibernate.c
+++ b/arch/arm64/kernel/hibernate.c
@@ -423,8 +423,8 @@ int __nocfi swsusp_arch_resume(void)
* Create a second copy of just the linear map, and use this when
* restoring.
*/
- rc = trans_pgd_create_copy(&trans_info, &tmp_pg_dir, PAGE_OFFSET,
- PAGE_END);
+ rc = trans_pgd_create_copy(&trans_info, &tmp_pg_dir,
+ _PAGE_OFFSET(vabits_actual), PAGE_END);
if (rc)
return rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 057/398] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (55 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 056/398] dmaengine: Fix device kref underflow in dma_chan_put() Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 058/398] dmaengine: wait for RCU readers before releasing dma_device Greg Kroah-Hartman
` (345 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit e873c74132f0c5f1452816cd9bb26208f0bba1e1 ]
When dma_device_put() drops the last reference on chan->device->ref,
dma_device_release() runs and may free the dma_device along with its
channels.
dma_chan_put() then still reads chan->device->owner via
dma_chan_to_owner() for the trailing module_put(). KASAN catches it:
slab-use-after-free in dma_chan_put+0x3e6/0x4c0
Read of size 8 by task insmod/6319
Freed by task 6319:
kfree+0x225/0x470
dma_chan_put+0x395/0x4c0
dmaengine_put+0xf8/0x160
Cache the module owner in dma_chan_put() before the put so the trailing
module_put() does not need chan->device.
Fixes: 8ad342a86359 ("dmaengine: Add reference counting to dma_device struct")
Suggested-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260518-dmaengine-kref-fix-v1-1-4d6125048fb7@amd.com
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-3-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index 07eb4a7437c3c..cb4a81715ded1 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -495,10 +495,13 @@ static int dma_chan_get(struct dma_chan *chan)
*/
static void dma_chan_put(struct dma_chan *chan)
{
+ struct module *owner;
+
/* This channel is not in use, bail out */
if (!chan->client_count)
return;
+ owner = dma_chan_to_owner(chan);
chan->client_count--;
/* This channel is not in use anymore, free it */
@@ -518,7 +521,7 @@ static void dma_chan_put(struct dma_chan *chan)
/* This channel is not in use anymore, drop the device ref */
if (!chan->client_count)
dma_device_put(chan->device);
- module_put(dma_chan_to_owner(chan));
+ module_put(owner);
}
enum dma_status dma_sync_wait(struct dma_chan *chan, dma_cookie_t cookie)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 111/438] arm64: mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (109 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 110/438] arm64: hibernate: clone only the linear map that exists at runtime Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 112/438] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr Greg Kroah-Hartman
` (338 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yury Khrustalev, Will Deacon,
Mark Rutland, Catalin Marinas, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Catalin Marinas <catalin.marinas@arm.com>
[ Upstream commit fdb9ebc7fb7788b8371fbef6c17dc5c8291e1429 ]
PTRACE_{PEEK,POKE}MTETAGS return -EIO rather than -EOPNOTSUPP (as
documented) when no tags are copied from/to a mapping without PROT_MTE.
This has been the behaviour since the interface was introduced, though
the original intent was to distinguish between address not being
accessible and mapped as untagged.
Update the documentation to match the implementation (de-facto ABI).
Since -EOPNOTSUPP was never returned, change the error assignment to
-EIO as well to avoid confusion.
Fixes: df9d7a22dd21 ("arm64: mte: Add Memory Tagging Extension documentation")
Fixes: 18ddbaa02b7a ("arm64: mte: ptrace: Add PTRACE_{PEEK,POKE}MTETAGS support")
Reported-by: Yury Khrustalev <yury.khrustalev@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/arch/arm64/memory-tagging-extension.rst | 5 ++---
arch/arm64/kernel/mte.c | 2 +-
2 files changed, 3 insertions(+), 4 deletions(-)
diff --git a/Documentation/arch/arm64/memory-tagging-extension.rst b/Documentation/arch/arm64/memory-tagging-extension.rst
index e6fe428f0e2a4..1d32fc5df1838 100644
--- a/Documentation/arch/arm64/memory-tagging-extension.rst
+++ b/Documentation/arch/arm64/memory-tagging-extension.rst
@@ -208,11 +208,10 @@ will use the corresponding aligned address.
tracer's space cannot be accessed or does not have valid tags.
- ``-EPERM`` - the specified process cannot be traced.
- ``-EIO`` - the tracee's address range cannot be accessed (e.g. invalid
- address) and no tags copied. ``iov_len`` not updated.
+ address) or does not have valid tags (not mapped with the ``PROT_MTE``
+ flag) and no tags copied. ``iov_len`` not updated.
- ``-EFAULT`` - fault on accessing the tracer's memory (``struct iovec``
or ``iov_base`` buffer) and no tags copied. ``iov_len`` not updated.
-- ``-EOPNOTSUPP`` - the tracee's address does not have valid tags (never
- mapped with the ``PROT_MTE`` flag). ``iov_len`` not updated.
**Note**: There are no transient errors for the requests above, so user
programs should not retry in case of a non-zero system call return.
diff --git a/arch/arm64/kernel/mte.c b/arch/arm64/kernel/mte.c
index 1a9aad6ef22a0..31f5c6b0510e7 100644
--- a/arch/arm64/kernel/mte.c
+++ b/arch/arm64/kernel/mte.c
@@ -476,7 +476,7 @@ static int __access_remote_tags(struct mm_struct *mm, unsigned long addr,
* was never mapped with PROT_MTE.
*/
if (!(vma->vm_flags & VM_MTE)) {
- err = -EOPNOTSUPP;
+ err = -EIO;
put_page(page);
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 058/398] dmaengine: wait for RCU readers before releasing dma_device
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (56 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 057/398] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 059/398] wifi: cfg80211: dont free driver-owned scan requests Greg Kroah-Hartman
` (344 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Frank Li, Logan Gunthorpe,
Shivank Garg, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivank Garg <shivankg@amd.com>
[ Upstream commit dc750422170a563c7a81f6e49d36bb02c62ae37f ]
dma_issue_pending_all() walks the dma_device_list with
list_for_each_entry_rcu() under rcu_read_lock(). dma_device_release()
unlinks the device with list_del_rcu() and then calls
device->device_release() (which in many drivers, such as plx_dma.c,
directly calls kfree()).
Because there is no grace period between unlinking the device and
freeing it, concurrent RCU readers in dma_issue_pending_all() can
access the device after it has been freed.
The lockless walk originally relied on clients holding a dmaengine
reference to pin the provider module, and therefore the device, for as
long as they might traverse the list. Commit 8ad342a86359 ("dmaengine:
Add reference counting to dma_device struct") decoupled the dma_device
lifetime from the module reference, so the device can now be released
while a reader is still walking the list.
Add synchronize_rcu() before the device is freed, so RCU readers are
guaranteed to have finished. Keep it unconditional: providers that do
not implement device_release() free the device themselves once
dma_async_device_unregister() returns. This call will delay for a grace
period with dma_list_mutex held, which is safe and only teardown path is
delayed.
Fixes: 2ba05622b8b1 ("dmaengine: provide a common 'issue_pending_all' implementation")
Suggested-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260526-dmaengine-kref-fix-v2-0-3df60afac01d@amd.com
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Logan Gunthorpe <logang@deltatee.com>
Signed-off-by: Shivank Garg <shivankg@amd.com>
Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-4-d4a4ee47d927@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dmaengine.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
index cb4a81715ded1..fa2019d51918c 100644
--- a/drivers/dma/dmaengine.c
+++ b/drivers/dma/dmaengine.c
@@ -428,6 +428,7 @@ static void dma_device_release(struct kref *ref)
list_del_rcu(&device->global_node);
dma_channel_rebalance();
+ synchronize_rcu();
if (device->device_release)
device->device_release(device);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 112/438] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (110 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 111/438] arm64: mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentation Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 113/438] smb: client: validate absolute native symlink targets before NT fixups Greg Kroah-Hartman
` (337 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Thadeu Lima de Souza Cascardo, Melissa Wen, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
[ Upstream commit 9eb1a393c89a79c4210230d23e7d88d239c61d7b ]
When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not
set, a drm_pending_vblank_event will be allocated. If later, there is an
allocation failure or another failure at setup_out_fence(), that event
will not have base.fence set and it will not be released at
complete_signaling().
Release the event and set crtc_state->event to NULL just like in the
DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at
drm_event_reserve_init(). That is, prepare_signaling() releases the
event and there is nothing to be done at complete_signaling(). Use
drm_event_cancel_free() as that will also undo drm_event_reserve_init()
in case it has been called.
Reported-by: sashiko-bot@kernel.org
Closes: https://sashiko.dev/#/patchset/20260727-drm_crtc_atomic_commit_leak-v1-1-23d9948a9d7c@igalia.com?part=1
Fixes: 92c715fca907 ("drm/atomic: Fix double free in drm_atomic_state_default_clear")
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Reviewed-by: Melissa Wen <mwen@igalia.com>
Signed-off-by: Melissa Wen <mwen@igalia.com>
Link: https://patch.msgid.link/20260826-drm_pending_vblank_event_leak-v4-1-f8de8b996b9d@igalia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/drm_atomic_uapi.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/drm_atomic_uapi.c b/drivers/gpu/drm/drm_atomic_uapi.c
index 7b951af5ab320..66b591b39a513 100644
--- a/drivers/gpu/drm/drm_atomic_uapi.c
+++ b/drivers/gpu/drm/drm_atomic_uapi.c
@@ -1461,10 +1461,12 @@ static int prepare_signaling(struct drm_device *dev,
struct dma_fence *fence;
struct drm_out_fence_state *f;
+ ret = -ENOMEM;
+
f = krealloc(*fence_state, sizeof(**fence_state) *
(*num_fences + 1), GFP_KERNEL);
if (!f)
- return -ENOMEM;
+ goto err_free_event;
memset(&f[*num_fences], 0, sizeof(*f));
@@ -1473,12 +1475,12 @@ static int prepare_signaling(struct drm_device *dev,
fence = drm_crtc_create_fence(crtc);
if (!fence)
- return -ENOMEM;
+ goto err_free_event;
ret = setup_out_fence(&f[(*num_fences)++], fence);
if (ret) {
dma_fence_put(fence);
- return ret;
+ goto err_free_event;
}
crtc_state->event->base.fence = fence;
@@ -1534,6 +1536,11 @@ static int prepare_signaling(struct drm_device *dev,
}
return 0;
+
+err_free_event:
+ drm_event_cancel_free(dev, &crtc_state->event->base);
+ crtc_state->event = NULL;
+ return ret;
}
static void complete_signaling(struct drm_device *dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 059/398] wifi: cfg80211: dont free driver-owned scan requests
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (57 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 058/398] dmaengine: wait for RCU readers before releasing dma_device Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 060/398] wifi: cfg80211: only group hidden BSSes with beacon entries Greg Kroah-Hartman
` (343 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+189dcafc06865d38178d,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit dab68a74e90b8e07f08ed9deaa5884857a3cfe89 ]
When an interface goes down while a scan is running, cfg80211 completes
the scan towards userspace and frees the scan request. However, the
driver can be convinced that it owns the request, since the cancellation
is (intended to be) asynchronous.
The WARN_ON() in the netdev notifier was meant to catch this, but it's
not actually avoidable, so it triggers and we get a UAF in scan_done().
There doesn't seem to be a great way around it, so just track that the
driver is still convinced it owns the request, and then just free it on
completion if it was already cancelled. Also remove the warnings since
they can trigger in the intended architecture.
Assisted-by: LLM
Fixes: 4a58e7c38443 ("cfg80211: don't "leak" uncompleted scans")
Reported-by: syzbot+189dcafc06865d38178d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=189dcafc06865d38178d
Link: https://patch.msgid.link/20260904165614.375e543228b1.I03cbb5a54cb02d6bba5034286af1ed73aba134d1@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/core.c | 11 +++++------
net/wireless/core.h | 10 ++++++++++
net/wireless/rdev-ops.h | 3 +++
net/wireless/scan.c | 31 +++++++++++++++++++++++++++++--
4 files changed, 47 insertions(+), 8 deletions(-)
diff --git a/net/wireless/core.c b/net/wireless/core.c
index b565f777e5561..55abf5a203338 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -241,9 +241,8 @@ void cfg80211_stop_p2p_device(struct cfg80211_registered_device *rdev,
rdev->opencount--;
if (rdev->scan_req && rdev->scan_req->req.wdev == wdev) {
- if (WARN_ON(!rdev->scan_req->notified &&
- (!rdev->int_scan_req ||
- !rdev->int_scan_req->notified)))
+ if (!rdev->scan_req->notified &&
+ (!rdev->int_scan_req || !rdev->int_scan_req->notified))
rdev->scan_req->info.aborted = true;
___cfg80211_scan_done(rdev, false);
}
@@ -1660,9 +1659,9 @@ static int cfg80211_netdev_notifier_call(struct notifier_block *nb,
wiphy_lock(&rdev->wiphy);
cfg80211_update_iface_num(rdev, wdev->iftype, -1);
if (rdev->scan_req && rdev->scan_req->req.wdev == wdev) {
- if (WARN_ON(!rdev->scan_req->notified &&
- (!rdev->int_scan_req ||
- !rdev->int_scan_req->notified)))
+ if (!rdev->scan_req->notified &&
+ (!rdev->int_scan_req ||
+ !rdev->int_scan_req->notified))
rdev->scan_req->info.aborted = true;
___cfg80211_scan_done(rdev, false);
}
diff --git a/net/wireless/core.h b/net/wireless/core.h
index 1086aa1a44f42..d7ac3145fd1ae 100644
--- a/net/wireless/core.h
+++ b/net/wireless/core.h
@@ -24,6 +24,16 @@
struct cfg80211_scan_request_int {
struct cfg80211_scan_info info;
bool notified;
+ /*
+ * set while the request is handed to the driver, i.e. between
+ * rdev_scan() and cfg80211_scan_done()
+ */
+ bool driver_owns;
+ /*
+ * set when cfg80211 is done with the request but the driver still
+ * owns it, so that cfg80211_scan_done() knows to just free it
+ */
+ bool stale;
/* must be last - variable members */
struct cfg80211_scan_request req;
};
diff --git a/net/wireless/rdev-ops.h b/net/wireless/rdev-ops.h
index f4c06282b2e15..bc99458b6ed71 100644
--- a/net/wireless/rdev-ops.h
+++ b/net/wireless/rdev-ops.h
@@ -464,7 +464,10 @@ static inline int rdev_scan(struct cfg80211_registered_device *rdev,
return -EINVAL;
trace_rdev_scan(&rdev->wiphy, request);
+ request->driver_owns = true;
ret = rdev->ops->scan(&rdev->wiphy, &request->req);
+ if (ret)
+ request->driver_owns = false;
trace_rdev_return_int(&rdev->wiphy, ret);
return ret;
}
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 9648e24181fb0..69f2f5e539af2 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -1115,6 +1115,21 @@ int cfg80211_scan(struct cfg80211_registered_device *rdev)
return 0;
}
+/*
+ * Release the scan request, but free it only if the driver is also done,
+ * e.g. mac80211 may cancel it asynchronously and still use it.
+ */
+static void cfg80211_put_scan_req(struct cfg80211_scan_request_int *req)
+{
+ if (!req)
+ return;
+
+ if (req->driver_owns)
+ req->stale = true;
+ else
+ kfree(req);
+}
+
void ___cfg80211_scan_done(struct cfg80211_registered_device *rdev,
bool send_message)
{
@@ -1174,10 +1189,10 @@ void ___cfg80211_scan_done(struct cfg80211_registered_device *rdev,
dev_put(wdev->netdev);
- kfree(rdev->int_scan_req);
+ cfg80211_put_scan_req(rdev->int_scan_req);
rdev->int_scan_req = NULL;
- kfree(rdev->scan_req);
+ cfg80211_put_scan_req(rdev->scan_req);
rdev->scan_req = NULL;
if (!send_message)
@@ -1200,6 +1215,18 @@ void cfg80211_scan_done(struct cfg80211_scan_request *request,
struct cfg80211_scan_info old_info = intreq->info;
trace_cfg80211_scan_done(intreq, info);
+
+ intreq->driver_owns = false;
+
+ if (intreq->stale) {
+ /*
+ * The scan is already completed as far as we're concerned,
+ * it was just kept around for the driver - done now, free it.
+ */
+ kfree(intreq);
+ return;
+ }
+
WARN_ON(intreq != rdev->scan_req &&
intreq != rdev->int_scan_req);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 113/438] smb: client: validate absolute native symlink targets before NT fixups
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (111 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 112/438] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 114/438] keys: fix lost wakeup when reaping a dead key type Greg Kroah-Hartman
` (336 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jérémy Jean, Namjae Jeon,
Paulo Alcantara, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
[ Upstream commit 23c240d9509e15f72e4112fc95f0160ab32ec430 ]
With symlinkroot unset, an absolute target is copied without conversion
to an NT drive path. Later code still assumes an NT prefix is present
when modifying the target and calculating the print name length.
For "/ab", this causes two failures: sym[5] and path[5] are written
past their allocations, and plen -= 2 * poff subtracts an assumed
8-byte prefix from a 6-byte UTF-16 target, wrapping u16 plen to 65534.
That underflow causes another overflow: memcpy() copies 65534 bytes
into a 24-byte buffer. A user with write access to a mounted share
can trigger these bugs with default settings.
Validate the NT drive prefix, including an ASCII drive letter, before
accessing fixed offsets or subtracting the prefix length.
Fixes: 3363da82e02f ("smb: client: fix native SMB symlink traversal")
Assisted-by: Codex:gpt-5
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/client/reparse.c | 24 +++++++++++++++++-------
1 file changed, 17 insertions(+), 7 deletions(-)
diff --git a/fs/smb/client/reparse.c b/fs/smb/client/reparse.c
index 8a1b9e8be5ba7..9e31fce7e0a52 100644
--- a/fs/smb/client/reparse.c
+++ b/fs/smb/client/reparse.c
@@ -3,6 +3,7 @@
* Copyright (c) 2024 Paulo Alcantara <pc@manguebit.com>
*/
+#include <linux/ctype.h>
#include <linux/fs.h>
#include <linux/stat.h>
#include <linux/slab.h>
@@ -159,15 +160,24 @@ static int create_native_symlink(const unsigned int xid, struct inode *inode,
convert_delimiter(sym, sep);
/*
- * For absolute NT symlinks it is required to pass also leading
- * backslash and to not mangle NT object prefix "\\??\\" and not to
- * mangle colon in drive letter. But cifs_convert_path_to_utf16()
- * removes leading backslash and replaces '?' and ':'. So temporary
- * mask these characters in NT object prefix by '_' and then change
- * them back.
+ * Absolute NT symlinks must retain the leading backslash, "\\??\\"
+ * prefix and drive-letter colon. cifs_convert_path_to_utf16() strips
+ * the leading backslash and maps '?' and ':', so temporarily mask
+ * these characters with '_' and restore them after conversion.
+ *
+ * When symlinkroot is unset, sym comes directly from the caller.
+ * Validate the complete "\\??\\X:" prefix before using fixed offsets
+ * or subtracting the NT prefix length below. Require an ASCII drive
+ * letter so the prefix occupies six characters in UTF-16 too.
*/
- if (!(sbflags & CIFS_MOUNT_POSIX_PATHS) && symname[0] == '/')
+ if (!(sbflags & CIFS_MOUNT_POSIX_PATHS) && symname[0] == '/') {
+ if (!strstarts(sym, "\\??\\") || !isascii(sym[4]) ||
+ !isalpha(sym[4]) || sym[5] != ':') {
+ rc = -EINVAL;
+ goto out;
+ }
sym[0] = sym[1] = sym[2] = sym[5] = '_';
+ }
/*
* On a POSIX paths mount the symlink target is stored verbatim, so
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 060/398] wifi: cfg80211: only group hidden BSSes with beacon entries
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (58 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 059/398] wifi: cfg80211: dont free driver-owned scan requests Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 061/398] wifi: cfg80211: dont filter by BSS type when removing stale entries Greg Kroah-Hartman
` (342 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1a797e1c81be78a2ace7,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 068843ed0902c552a13860c5ec6b2ca65b57a065 ]
When a probe response for an unknown BSS comes in, __cfg80211_bss_update()
looks for an existing entry with the same BSSID and a hidden (zero-length
or NUL-filled) SSID, and if it finds one it groups them, using the beacon
IEs from the existing entry.
But that could find another entry without a beacon, if it was also from a
probe response (with SSID), so there's a group without beacon elements.
If a beacon with a hidden SSID for that BSSID arrives later,
cfg80211_combine_bsses() goes looking for the probe response entries that
belong to it - i.e. entries with the same BSSID and channel that have no
beacon IEs - and finds those two. They are already grouped with each
other, so it hits its
WARN_ON_ONCE(bss->pub.hidden_beacon_bss)
WARN_ON_ONCE(!list_empty(&bss->hidden_list))
which are there because an entry without beacon elements is not supposed
to be part of a group yet.
Only combine entries when a beacon was already received, ones that are
kept separate will be combined when a beacon arrives.
Assisted-by: LLM
Fixes: 4593c4cbe1c9 ("cfg80211: fix BSS list hidden SSID lookup")
Reported-by: syzbot+1a797e1c81be78a2ace7@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1a797e1c81be78a2ace7
Link: https://patch.msgid.link/20260904165614.bcfa64715745.Iad740347c86de56d4ff4f96a95f3c3afc47c42de@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/scan.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 69f2f5e539af2..4f3e37dd71495 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -2050,6 +2050,13 @@ __cfg80211_bss_update(struct cfg80211_registered_device *rdev,
if (!hidden)
hidden = rb_find_bss(rdev, tmp,
BSS_CMP_HIDE_NUL);
+ /*
+ * Only group with an entry with beacon data, otherwise
+ * beacon data can never be filled/updated.
+ */
+ if (hidden &&
+ !rcu_access_pointer(hidden->pub.beacon_ies))
+ hidden = NULL;
if (hidden) {
new->pub.hidden_beacon_bss = &hidden->pub;
list_add(&new->hidden_list,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 114/438] keys: fix lost wakeup when reaping a dead key type
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (112 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 113/438] smb: client: validate absolute native symlink targets before NT fixups Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 115/438] neighbour: Add missing RCU annotation for neightbl_dump_info() Greg Kroah-Hartman
` (335 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Jarkko Sakkinen,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 2725ab3f5ad1c5f375c7c9fee4af02a9b138f701 ]
clear_bit() is atomic with respect to the word it modifies, but it is
an unordered operation: it implies no memory barrier on either side
(Documentation/atomic_bitops.txt).
key_garbage_collector() clears KEY_GC_REAPING_KEYTYPE with clear_bit()
and calls wake_up_bit() after reaping a dead key type. wake_up_bit()
uses a lockless waitqueue check and requires a full barrier after the
clear.
The existing smp_mb() is before clear_bit(), so nothing orders the clear
against that check. The GC can see an empty waitqueue while
unregister_key_type() still sees the bit set. The final wakeup is then
lost, leaving module unload stuck in wait_on_bit().
Use clear_and_wake_up_bit(). Its clear_bit_unlock() has RELEASE
semantics, so the completed GC work stays ordered before the clear, and
its smp_mb__after_atomic() orders the clear before the waitqueue check.
Fixes: 0c061b5707ab ("KEYS: Correctly destroy key payloads when their keytype is removed")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://lore.kernel.org/r/20260821025327.61488-1-kmehltretter@gmail.com
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/keys/gc.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/security/keys/gc.c b/security/keys/gc.c
index 748e83818a760..eda445f815d47 100644
--- a/security/keys/gc.c
+++ b/security/keys/gc.c
@@ -318,9 +318,7 @@ static void key_garbage_collector(struct work_struct *work)
if (unlikely(gc_state & KEY_GC_REAPING_DEAD_3)) {
kdebug("dead wake");
- smp_mb();
- clear_bit(KEY_GC_REAPING_KEYTYPE, &key_gc_flags);
- wake_up_bit(&key_gc_flags, KEY_GC_REAPING_KEYTYPE);
+ clear_and_wake_up_bit(KEY_GC_REAPING_KEYTYPE, &key_gc_flags);
}
if (gc_state & KEY_GC_REAP_AGAIN)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 061/398] wifi: cfg80211: dont filter by BSS type when removing stale entries
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (59 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 060/398] wifi: cfg80211: only group hidden BSSes with beacon entries Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 062/398] wifi: mac80211: dont start a ROC while scanning Greg Kroah-Hartman
` (341 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+dc6f4dce0d707900cdea,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit b377e1000d963e7182a987082b4b06580bd7ac84 ]
When an assoc AP switches to a channel that already has a BSS entry,
cfg80211_update_assoc_bss_entry() removes that entry before rehashing
the real one, since the two would otherwise collide in the BSS rbtree.
The lookup for that entry also required it to match the connection's BSS
type, so an entry advertising e.g. the IBSS capability bit was left in
place, and the following cfg80211_rehash_bss() then ran into it:
WARN_ON(!cmp)
Changing the type shouldn't really happen, but can be triggered by a
rogue AP/device, so drop the check and remove any entries matching
the comparison.
Assisted-by: LLM
Fixes: 0afd425b1b64 ("cfg80211: fix duplicated scan entries after channel switch")
Reported-by: syzbot+dc6f4dce0d707900cdea@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dc6f4dce0d707900cdea
Link: https://patch.msgid.link/20260904165614.1f05dae1c546.Ib52d57b57caa912efee020f9d4a033a5160617ce@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/scan.c | 5 -----
1 file changed, 5 deletions(-)
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index 4f3e37dd71495..29e150b4511f2 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -3491,11 +3491,6 @@ void cfg80211_update_assoc_bss_entry(struct wireless_dev *wdev,
cbss->pub.channel = chan;
list_for_each_entry(bss, &rdev->bss_list, list) {
- if (!cfg80211_bss_type_match(bss->pub.capability,
- bss->pub.channel->band,
- wdev->conn_bss_type))
- continue;
-
if (bss == cbss)
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 115/438] neighbour: Add missing RCU annotation for neightbl_dump_info().
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (113 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 114/438] keys: fix lost wakeup when reaping a dead key type Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 116/438] neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS Greg Kroah-Hartman
` (334 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 764dcebb033764633700a036c7351a7c6350eec6 ]
neightbl_dump_info() fetches the first non-default neigh_parms
with list_next_entry(&tbl->parms, ...) and iterates through the
list with list_for_each_entry_from_rcu().
However, list_next_entry() does not use RCU helper.
Let's use list_for_each_entry_rcu() and skip the default parms.
Fixes: 4ae34be50064 ("neighbour: Convert RTM_GETNEIGHTBL to RCU.")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260909233143.2401847-2-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 1349c0eedb642..49dd7df149ef3 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2611,11 +2611,14 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
break;
nidx = 0;
- p = list_next_entry(&tbl->parms, list);
- list_for_each_entry_from_rcu(p, &tbl->parms_list, list) {
+
+ list_for_each_entry_rcu(p, &tbl->parms_list, list) {
if (!net_eq(neigh_parms_net(p), net))
continue;
+ if (!p->dev)
+ continue;
+
if (nidx < neigh_skip)
goto next;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 062/398] wifi: mac80211: dont start a ROC while scanning
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (60 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 061/398] wifi: cfg80211: dont filter by BSS type when removing stale entries Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 063/398] wifi: mac80211: dont warn when an IBSS has no channel to scan Greg Kroah-Hartman
` (340 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+c3a167b5615df4ccd7fb,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 733f0fde95392ed5f61a4e36aee661ea8d0e8581 ]
The ROC work can be pending when a scan starts (which requires
ROC list to be empty, but that's possible), and then a new ROC
can be added to the list and the work will pick it up.
Avoid starting that ROC if a scan made it between things, as
otherwise we'll hit a warning later:
WARNING: net/mac80211/offchannel.c:404 at ieee80211_start_next_roc+0x256/0x2d0
Workqueue: events_unbound cfg80211_wiphy_work
Call Trace:
__ieee80211_scan_completed+0x4fd/0xe40 net/mac80211/scan.c:537
ieee80211_scan_work+0x472/0x1ff0 net/mac80211/scan.c:1193
cfg80211_wiphy_work+0x410/0x570 net/wireless/core.c:513
Assisted-by: LLM
Fixes: aaa016ccd5df ("mac80211: rewrite remain-on-channel logic")
Reported-by: syzbot+c3a167b5615df4ccd7fb@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c3a167b5615df4ccd7fb
Link: https://patch.msgid.link/20260904165722.f9d5b150edd8.I61bc9de8c8d089096ad695213b9c85c7df38c3bd@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/offchannel.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/mac80211/offchannel.c b/net/mac80211/offchannel.c
index ae82533e3c025..0c98bdcd54ab8 100644
--- a/net/mac80211/offchannel.c
+++ b/net/mac80211/offchannel.c
@@ -462,6 +462,13 @@ static void __ieee80211_roc_work(struct ieee80211_local *local)
return;
if (!roc->started) {
+ /*
+ * The work can be started by a previous ROC work, but a scan
+ * can get between things; scan finish will retrigger us.
+ */
+ if (local->scanning)
+ return;
+
WARN_ON(!local->emulate_chanctx);
_ieee80211_start_next_roc(local);
} else {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 116/438] neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (114 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 115/438] neighbour: Add missing RCU annotation for neightbl_dump_info() Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 117/438] neighbour: Dont render blackhole_netdev via RTM_GETNEIGHTBL Greg Kroah-Hartman
` (333 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 6d79b223ec44ada58ad37db42f539b60985a7722 ]
NDTPA_INTERVAL_PROBE_TIME_MS sets .type and .min but misses
.validation_type, so no validation is applied:
# ynl --family rt-neigh --do setneightbl \
--json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 0}}'
# ynl --family rt-neigh --dump getneightbl --output-json | \
jq '.[] | select(.name == "arp_cache" and has("config"))
| .parms["interval-probe-time-ms"]'
0
Moreover, nla_get_msecs() uses msecs_to_jiffies(), and u64 is
silently cast to u32, so a larger value can bypass the min check:
e.g. 4294967296 == 0x100000000
# ynl --family rt-neigh --do setneightbl \
--json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 4294967296}}'
# ynl --family rt-neigh --dump getneightbl --output-json | \
jq '.[] | select(.name == "arp_cache" and has("config"))
| .parms["interval-probe-time-ms"]'
0
msecs_to_jiffies() returns MAX_JIFFY_OFFSET if the value is
larger than INT_MAX. Also, INT_MAX ms overflows int NEIGH_VAR()
when HZ > 1000 (Alpha, MIPS), and passing a negative integer to
queue_delayed_work(unsigned long delay) causes sign extension,
which wraps around the expiry time to the past, resulting in it
being handled as 0 delay in the timer wheel.
Let's use NLA_POLICY_FULL_RANGE() and limit the max to 1 day.
The same max check is applied to sysctl as well.
Note that this controls the probe interval for NTF_MANAGED
entries, so the max of 1 day is unlikely to break any
deployments.
Fixes: 211da42eaa45 ("net, neigh: introduce interval_probe_time_ms for periodic probe")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260909233143.2401847-3-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/netlink/specs/rt-neigh.yaml | 3 +++
Documentation/networking/ip-sysctl.rst | 2 +-
net/core/neighbour.c | 17 +++++++++++++----
3 files changed, 17 insertions(+), 5 deletions(-)
diff --git a/Documentation/netlink/specs/rt-neigh.yaml b/Documentation/netlink/specs/rt-neigh.yaml
index 0f46ef3135905..c8e55c98d5649 100644
--- a/Documentation/netlink/specs/rt-neigh.yaml
+++ b/Documentation/netlink/specs/rt-neigh.yaml
@@ -341,6 +341,9 @@ attribute-sets:
-
name: interval-probe-time-ms
type: u64
+ checks:
+ min: 1
+ max: 86400000
operations:
enum-model: directional
diff --git a/Documentation/networking/ip-sysctl.rst b/Documentation/networking/ip-sysctl.rst
index 208f46967ee59..b05829e44d8fc 100644
--- a/Documentation/networking/ip-sysctl.rst
+++ b/Documentation/networking/ip-sysctl.rst
@@ -248,7 +248,7 @@ neigh/default/unres_qlen - INTEGER
neigh/default/interval_probe_time_ms - INTEGER
The probe interval for neighbor entries with NTF_MANAGED flag,
- the min value is 1.
+ the min value is 1, and the max value is 86400000 (1 day).
Default: 5000
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 49dd7df149ef3..0db78a0dfb516 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2359,6 +2359,13 @@ static const struct nla_policy nl_neightbl_policy[NDTA_MAX+1] = {
[NDTA_PARMS] = { .type = NLA_NESTED },
};
+#define NTBL_PARM_MS_MAX (24 * 60 * 60 * MSEC_PER_SEC)
+
+static const struct netlink_range_validation nl_ntbl_parm_ms_range = {
+ .min = 1,
+ .max = NTBL_PARM_MS_MAX,
+};
+
static const struct nla_policy nl_ntbl_parm_policy[NDTPA_MAX+1] = {
[NDTPA_IFINDEX] = { .type = NLA_U32 },
[NDTPA_QUEUE_LEN] = { .type = NLA_U32 },
@@ -2375,7 +2382,8 @@ static const struct nla_policy nl_ntbl_parm_policy[NDTPA_MAX+1] = {
[NDTPA_ANYCAST_DELAY] = { .type = NLA_U64 },
[NDTPA_PROXY_DELAY] = { .type = NLA_U64 },
[NDTPA_LOCKTIME] = { .type = NLA_U64 },
- [NDTPA_INTERVAL_PROBE_TIME_MS] = { .type = NLA_U64, .min = 1 },
+ [NDTPA_INTERVAL_PROBE_TIME_MS] = NLA_POLICY_FULL_RANGE(NLA_U64,
+ &nl_ntbl_parm_ms_range),
};
static int neightbl_set(struct sk_buff *skb, struct nlmsghdr *nlh,
@@ -3672,12 +3680,13 @@ static int neigh_proc_dointvec_ms_jiffies_positive(const struct ctl_table *ctl,
void *buffer, size_t *lenp, loff_t *ppos)
{
struct ctl_table tmp = *ctl;
- int ret;
+ int ret, min, max;
- int min = msecs_to_jiffies(1);
+ min = msecs_to_jiffies(1);
+ max = msecs_to_jiffies(NTBL_PARM_MS_MAX);
tmp.extra1 = &min;
- tmp.extra2 = NULL;
+ tmp.extra2 = &max;
ret = proc_dointvec_ms_jiffies_minmax(&tmp, write, buffer, lenp, ppos);
neigh_proc_update(ctl, write);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 063/398] wifi: mac80211: dont warn when an IBSS has no channel to scan
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (61 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 062/398] wifi: mac80211: dont start a ROC while scanning Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 064/398] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces Greg Kroah-Hartman
` (339 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1634c5399e29d8b66789,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit a7491b7efbd9136b120a12ed72af9c12121dd134 ]
ieee80211_request_ibss_scan() warns when regulatory leaves no
allowed channel, but that can happen as the regdomain can change
while IBSS is operating, and it can continue to operate briefly
during the 60s grace period until it's shut down.
Just remove the warning in this case.
Assisted-by: LLM
Fixes: 34bcf7150241 ("mac80211: fix ibss scanning")
Reported-by: syzbot+1634c5399e29d8b66789@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1634c5399e29d8b66789
Link: https://patch.msgid.link/20260904165722.fe380c27fef4.I0e8bee2e12a40d240851a4bc724d47753af46159@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/scan.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/mac80211/scan.c b/net/mac80211/scan.c
index 1e06a465b49e3..1101e98f186de 100644
--- a/net/mac80211/scan.c
+++ b/net/mac80211/scan.c
@@ -1238,7 +1238,7 @@ int ieee80211_request_ibss_scan(struct ieee80211_sub_if_data *sdata,
}
}
- if (WARN_ON_ONCE(n_ch == 0))
+ if (n_ch == 0)
return -EINVAL;
local->int_scan_req->n_channels = n_ch;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 117/438] neighbour: Dont render blackhole_netdev via RTM_GETNEIGHTBL.
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (115 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 116/438] neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 118/438] neighbour: Skip default parms when resumed in neightbl_dump_info() Greg Kroah-Hartman
` (332 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 7b430fcfc972f61b09cc19ca95997586af4a147d ]
The cited commits started to initialise blackhole_netdev with
neigh_parms_alloc().
This is visible in init_net as the ifindex==0 entries via
RTM_GETNEIGHTBL:
# ynl --family rt-neigh --dump getneightbl --output-json \
| jq '.[] | select(.parms.ifindex == 0)
| {name: .name, ifindex: .parms.ifindex}'
{
"name": "arp_cache",
"ifindex": 0
}
{
"name": "ndisc_cache",
"ifindex": 0
}
For RTM_SETNEIGHTBL, ifindex being 0 means wildcard.
Let's skip blackhole_netdev's parms in neightbl_dump_info().
Note that lookup_neigh_parms() does not need the same change
because the default parms is always the first entry and matches
with ifindex == 0.
Fixes: e5f80fcf869a ("ipv6: give an IPv6 dev to blackhole_netdev")
Fixes: 22600596b675 ("ipv4: give an IPv4 dev to blackhole_netdev")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260909233143.2401847-4-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 0db78a0dfb516..02bf940ce00af 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2624,7 +2624,7 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
if (!net_eq(neigh_parms_net(p), net))
continue;
- if (!p->dev)
+ if (!p->dev || p->dev == blackhole_netdev)
continue;
if (nidx < neigh_skip)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 064/398] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (62 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 063/398] wifi: mac80211: dont warn when an IBSS has no channel to scan Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 065/398] wifi: mac80211: suppress chanctx warning for debugfs reset Greg Kroah-Hartman
` (338 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f1ba58d6b55abd13239e,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 362bd5bce29ed0f6fd3d39a7065567777d70606e ]
AP_VLAN interfaces are purely virtual, so don't try to offload
TC setup to drivers. We can't really use the AP interface either
since we may not know it all the time, and it could technically
even change.
Just reject the TC offload so things get done in software.
Assisted-by: LLM
Fixes: 61587f1556fe ("wifi: mac80211: add support for letting drivers register tc offload support")
Reported-by: syzbot+f1ba58d6b55abd13239e@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f1ba58d6b55abd13239e
Link: https://patch.msgid.link/20260904165722.726cc076cecb.Iccfd88b13635425e850ce031376eb60a4ce5f4f8@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 499126317a914..82eff9e867c1f 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -896,6 +896,9 @@ static int ieee80211_netdev_setup_tc(struct net_device *dev,
struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
struct ieee80211_local *local = sdata->local;
+ if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
+ return -EOPNOTSUPP;
+
return drv_net_setup_tc(local, sdata, dev, type, type_data);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 118/438] neighbour: Skip default parms when resumed in neightbl_dump_info().
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (116 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 117/438] neighbour: Dont render blackhole_netdev via RTM_GETNEIGHTBL Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 119/438] ALSA: bcd2000: Fix race between rawmidi and disconnect Greg Kroah-Hartman
` (331 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 979aabdad8dd03394467ee484a1a70f3d40b19ba ]
neightbl_dump_info() calls neightbl_fill_info() in each loop
to render the default parms.
If there are many devices and neightbl_fill_param_info() failed,
neightbl_fill_info() is called again when the dump resumes:
# ynl --family rt-neigh --dump getneightbl --output-json |
jq '.[] | {name: .name, ifindex: .parms.ifindex}'
...
{
"name": "ndisc_cache",
"ifindex": null
}
...
{
"name": "ndisc_cache",
"ifindex": 6
}
{
"name": "ndisc_cache",
"ifindex": null
}
{
"name": "ndisc_cache",
"ifindex": 5
}
Let's skip neightbl_fill_info() if it is already called in
neightbl_dump_info().
Note that we cannot use !neigh_skip instead of !default_skip
because default_skip == 1 && neigh_skip == 0 could be true
if the first neightbl_fill_param_info() fails.
Also, nidx must be cleared at the end of each table loop;
otherwise, if neightbl_fill_info() for a subsequent table
fails, the leftover nidx from the previous table would be
saved in cb->args[1], resulting in erroneously skipping parms
of the subsequent table in the next dump.
Fixes: c7fb64db001f ("[NETLINK]: Neighbour table configuration and statistics via rtnetlink")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260909233143.2401847-5-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 02bf940ce00af..7448320f7ad52 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2587,9 +2587,10 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
{
const struct nlmsghdr *nlh = cb->nlh;
struct net *net = sock_net(skb->sk);
+ int default_skip = cb->args[2];
+ int neigh_skip = cb->args[1];
int family, tidx, nidx = 0;
int tbl_skip = cb->args[0];
- int neigh_skip = cb->args[1];
struct neigh_table *tbl;
if (cb->strict_check) {
@@ -2613,12 +2614,13 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
if (tidx < tbl_skip || (family && tbl->family != family))
continue;
- if (neightbl_fill_info(skb, tbl, NETLINK_CB(cb->skb).portid,
+ if (!default_skip &&
+ neightbl_fill_info(skb, tbl, NETLINK_CB(cb->skb).portid,
nlh->nlmsg_seq, RTM_NEWNEIGHTBL,
NLM_F_MULTI) < 0)
break;
- nidx = 0;
+ default_skip = 1;
list_for_each_entry_rcu(p, &tbl->parms_list, list) {
if (!net_eq(neigh_parms_net(p), net))
@@ -2641,12 +2643,15 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
}
neigh_skip = 0;
+ nidx = 0;
+ default_skip = 0;
}
out:
rcu_read_unlock();
cb->args[0] = tidx;
cb->args[1] = nidx;
+ cb->args[2] = default_skip;
return skb->len;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 065/398] wifi: mac80211: suppress chanctx warning for debugfs reset
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (63 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 064/398] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 066/398] wifi: mac80211: abort chanswitch when leaving a mesh Greg Kroah-Hartman
` (337 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+56a1a45a9a2c04d425ff,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit bf29d085e0eba92388518719d044f4702a8c6644 ]
Before suspend all the channel contexts should removed, so the
warning makes sense and should be there, but during reset the
same code is called without first removing. Limit the check to
the real suspend case.
Assisted-by: LLM
Fixes: 12e7f517029d ("mac80211: cleanup generic suspend/resume procedures")
Reported-by: syzbot+56a1a45a9a2c04d425ff@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=56a1a45a9a2c04d425ff
Link: https://patch.msgid.link/20260904165722.fe46395e310b.Ic4aaa95bd9d0ceb6a3cd7d84c425afee7d7d3dd7@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 2 +-
net/mac80211/debugfs.c | 2 +-
net/mac80211/ieee80211_i.h | 2 +-
net/mac80211/pm.c | 8 +++++---
4 files changed, 8 insertions(+), 6 deletions(-)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index 72c9d5aceae58..f6e8352665c1a 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -3094,7 +3094,7 @@ static int ieee80211_set_txq_params(struct wiphy *wiphy,
static int ieee80211_suspend(struct wiphy *wiphy,
struct cfg80211_wowlan *wowlan)
{
- return __ieee80211_suspend(wiphy_priv(wiphy), wowlan);
+ return __ieee80211_suspend(wiphy_priv(wiphy), wowlan, false);
}
static int ieee80211_resume(struct wiphy *wiphy)
diff --git a/net/mac80211/debugfs.c b/net/mac80211/debugfs.c
index 687a66cd49433..14ce2ea105939 100644
--- a/net/mac80211/debugfs.c
+++ b/net/mac80211/debugfs.c
@@ -409,7 +409,7 @@ static ssize_t reset_write(struct file *file, const char __user *user_buf,
rtnl_lock();
wiphy_lock(local->hw.wiphy);
- __ieee80211_suspend(&local->hw, NULL);
+ __ieee80211_suspend(&local->hw, NULL, true);
ret = __ieee80211_resume(&local->hw);
wiphy_unlock(local->hw.wiphy);
diff --git a/net/mac80211/ieee80211_i.h b/net/mac80211/ieee80211_i.h
index b0e64cf346e2b..3f5fd978cb51d 100644
--- a/net/mac80211/ieee80211_i.h
+++ b/net/mac80211/ieee80211_i.h
@@ -2365,7 +2365,7 @@ int ieee80211_reconfig(struct ieee80211_local *local);
void ieee80211_stop_device(struct ieee80211_local *local, bool suspend);
int __ieee80211_suspend(struct ieee80211_hw *hw,
- struct cfg80211_wowlan *wowlan);
+ struct cfg80211_wowlan *wowlan, bool reset);
static inline int __ieee80211_resume(struct ieee80211_hw *hw)
{
diff --git a/net/mac80211/pm.c b/net/mac80211/pm.c
index 5a508d99e84f7..f63676c448536 100644
--- a/net/mac80211/pm.c
+++ b/net/mac80211/pm.c
@@ -18,7 +18,8 @@ static void ieee80211_sched_scan_cancel(struct ieee80211_local *local)
cfg80211_sched_scan_stopped_locked(local->hw.wiphy, 0);
}
-int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan)
+int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan,
+ bool reset)
{
struct ieee80211_local *local = hw_to_local(hw);
struct ieee80211_sub_if_data *sdata;
@@ -166,9 +167,10 @@ int __ieee80211_suspend(struct ieee80211_hw *hw, struct cfg80211_wowlan *wowlan)
/*
* We disconnected on all interfaces before suspend, all channel
- * contexts should be released.
+ * contexts should be released, but on 'reset' debugfs that's
+ * not true so don't check there.
*/
- WARN_ON(!list_empty(&local->chanctx_list));
+ WARN_ON(!reset && !list_empty(&local->chanctx_list));
/* stop hardware - this must stop RX */
ieee80211_stop_device(local, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 119/438] ALSA: bcd2000: Fix race between rawmidi and disconnect
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (117 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 118/438] neighbour: Skip default parms when resumed in neightbl_dump_info() Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 120/438] ntfs: use dynamic MFT tail reservation Greg Kroah-Hartman
` (330 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 221253723dc58bb901c3f27a7659823e63fc598c ]
Although we tried to fix the potential UAF issues at USB disconnect on
bcd2000 driver, there is still an overlooked case -- namely, when a
rawmidi trigger callback has been already running at USB disconnect
handling, the in-flight function (e.g. bcd2000_midi_send()) could
still access the URB, because the previous URB NULL-check & clearance
was considered only for the URB complete callbacks, but not about the
parallel rawmidi operations.
For addressing the race, this patch introduced a new spinlock that
covers each rawmidi operation as well as the rawmidi handling in the
complete callback. The URB is cleared with the lock, so it guarantees
that the pending rawmidi task already finished or a NULL check is
effective.
Fixes: 459d3a64766f ("ALSA: bcd2000: clear the URB pointers on disconnect")
Link: https://patch.msgid.link/20260910155227.996210-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/bcd2000/bcd2000.c | 33 ++++++++++++++++++++++++++-------
1 file changed, 26 insertions(+), 7 deletions(-)
diff --git a/sound/usb/bcd2000/bcd2000.c b/sound/usb/bcd2000/bcd2000.c
index c5c542d17ccc1..2bd49bf827489 100644
--- a/sound/usb/bcd2000/bcd2000.c
+++ b/sound/usb/bcd2000/bcd2000.c
@@ -43,6 +43,7 @@ struct bcd2000 {
struct usb_interface *intf;
int card_index;
+ spinlock_t midi_lock;
int midi_out_active;
struct snd_rawmidi *rmidi;
struct snd_rawmidi_substream *midi_receive_substream;
@@ -90,6 +91,8 @@ static void bcd2000_midi_input_trigger(struct snd_rawmidi_substream *substream,
int up)
{
struct bcd2000 *bcd2k = substream->rmidi->private_data;
+
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
bcd2k->midi_receive_substream = up ? substream : NULL;
}
@@ -195,6 +198,8 @@ static void bcd2000_midi_output_trigger(struct snd_rawmidi_substream *substream,
{
struct bcd2000 *bcd2k = substream->rmidi->private_data;
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
+
if (up) {
bcd2k->midi_out_substream = substream;
/* check if there is data userspace wants to send */
@@ -219,6 +224,7 @@ static void bcd2000_output_complete(struct urb *urb)
return;
/* check if there is more data userspace wants to send */
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
bcd2000_midi_send(bcd2k);
}
@@ -234,6 +240,8 @@ static void bcd2000_input_complete(struct urb *urb)
if (!bcd2k || urb->status == -ESHUTDOWN)
return;
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
+
if (urb->actual_length > 0)
bcd2000_midi_handle_input(bcd2k, urb->transfer_buffer,
urb->actual_length);
@@ -348,16 +356,26 @@ static int bcd2000_init_midi(struct bcd2000 *bcd2k)
return 0;
}
+static void bcd2000_midi_free(struct bcd2000 *bcd2k,
+ struct urb **urb_p)
+{
+ struct urb *urb = *urb_p;
+
+ if (!urb)
+ return;
+
+ usb_poison_urb(urb);
+ scoped_guard(spinlock_irq, &bcd2k->midi_lock)
+ *urb_p = NULL;
+
+ usb_free_urb(urb);
+}
+
static void bcd2000_free_usb_related_resources(struct bcd2000 *bcd2k,
struct usb_interface *interface)
{
- usb_poison_urb(bcd2k->midi_out_urb);
- usb_poison_urb(bcd2k->midi_in_urb);
-
- usb_free_urb(bcd2k->midi_out_urb);
- usb_free_urb(bcd2k->midi_in_urb);
- bcd2k->midi_out_urb = NULL;
- bcd2k->midi_in_urb = NULL;
+ bcd2000_midi_free(bcd2k, &bcd2k->midi_out_urb);
+ bcd2000_midi_free(bcd2k, &bcd2k->midi_in_urb);
if (bcd2k->intf) {
usb_set_intfdata(bcd2k->intf, NULL);
@@ -393,6 +411,7 @@ static int bcd2000_probe(struct usb_interface *interface,
bcd2k->card = card;
bcd2k->card_index = card_index;
bcd2k->intf = interface;
+ spin_lock_init(&bcd2k->midi_lock);
snd_card_set_dev(card, &interface->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 066/398] wifi: mac80211: abort chanswitch when leaving a mesh
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (64 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 065/398] wifi: mac80211: suppress chanctx warning for debugfs reset Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 067/398] wifi: mac80211: reset state when starting AP fails Greg Kroah-Hartman
` (336 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+81cd9dc1596563141d19,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit ac7472a24bd433b81c06582835dd1d5547c10da9 ]
The code in ieee80211_stop_mesh() leaves CSA active, but leaving
the mesh released the channel context, so the CSA finalize work
crashes:
Oops: general protection fault, probably for non-canonical address
0xdffffc0000000003
KASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f]
RIP: 0010:ieee80211_put_srates_elem+0x42/0x640 net/mac80211/util.c:3272
Call Trace:
ieee80211_mesh_build_beacon+0xa83/0x1b50 net/mac80211/mesh.c:1093
ieee80211_mesh_rebuild_beacon+0xc7/0x170 net/mac80211/mesh.c:1147
ieee80211_mesh_finish_csa+0x131/0x210 net/mac80211/mesh.c:1542
ieee80211_set_after_csa_beacon net/mac80211/cfg.c:4085 [inline]
__ieee80211_csa_finalize net/mac80211/cfg.c:4133 [inline]
ieee80211_csa_finalize+0x633/0x1150 net/mac80211/cfg.c:4155
cfg80211_wiphy_work+0x2ab/0x450 net/wireless/core.c:438
Abort the channel switch properly.
Assisted-by: LLM
Fixes: b8456a14e9d2 ("{nl,cfg,mac}80211: implement mesh channel switch userspace API")
Reported-by: syzbot+81cd9dc1596563141d19@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=81cd9dc1596563141d19
Link: https://patch.msgid.link/20260904165722.d0b87eee08aa.I80550d6127e0bb26efb49a5fbe95be1aef1cd0cb@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mesh.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index 4b0eebd5c7cf8..04b3ac4525035 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -1223,6 +1223,10 @@ void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
netif_carrier_off(sdata->dev);
+ /* abort any running channel switch */
+ sdata->vif.bss_conf.csa_active = false;
+ ieee80211_vif_unblock_queues_csa(sdata);
+
/* flush STAs and mpaths on this iface */
sta_info_flush(sdata, -1);
ieee80211_free_keys(sdata, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 120/438] ntfs: use dynamic MFT tail reservation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (118 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 119/438] ALSA: bcd2000: Fix race between rawmidi and disconnect Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 121/438] ntfs: repack $MFT/$ATTRIBUTE LIST Greg Kroah-Hartman
` (329 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hyunchul Lee, Namjae Jeon,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 6d8c197c9992659a65525a07de4368c8401fdda7 ]
The ntfs MFT allocator historically treated records below 64 as a
permanent extension area and stopped searching for $MFT extent records
after record 400. Windows and ntfs3 do not maintain that on-disk
layout, so an NTFS volume can have free MFT records while ntfs returns
-ENOSPC when $MFT:$DATA needs another mapping-pairs extent.
Use record 24 as the first normal record and maintain an in-memory tail
reserve of up to four initialized records. Normal allocations skip the
reserve, while $MFT metadata extent allocations consume it. When a new
tail is initialized, allocate at least two records and reserve the
following records to avoid recursive allocation during MFT extension.
Existing free runs can seed the reserve on volumes mounted without one.
For $MFT/$DATA, constrain an extent record to a record whose byte offset
is below the new extent lowest VCN byte offset. This preserves bootstrap
reachability without an arbitrary record 400 limit. If no safe record is
available, validate and use reserved records 15, 12, 13, and 14 as
bootstrap candidates while keeping their MFT bitmap entries in use.
This allows existing Windows volumes to extend $MFT using their actual
free records and prevents normal file allocation from consuming
the metadata reserve.
Fixes: 115380f9a2f9 ("ntfs: update mft operations")
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs/attrib.c | 11 +-
fs/ntfs/mft.c | 420 +++++++++++++++++++++++++++++++++++++----------
fs/ntfs/mft.h | 2 +-
fs/ntfs/namei.c | 2 +-
fs/ntfs/volume.h | 6 +
5 files changed, 349 insertions(+), 92 deletions(-)
diff --git a/fs/ntfs/attrib.c b/fs/ntfs/attrib.c
index 918ff4db75f73..f50685ec2fb34 100644
--- a/fs/ntfs/attrib.c
+++ b/fs/ntfs/attrib.c
@@ -2912,7 +2912,7 @@ int ntfs_attr_add(struct ntfs_inode *ni, __le32 type,
attr_ni = NULL;
/* Allocate new extent. */
- err = ntfs_mft_record_alloc(ni->vol, 0, &attr_ni, ni, NULL);
+ err = ntfs_mft_record_alloc(ni->vol, 0, &attr_ni, ni, NULL, -1);
if (err) {
ntfs_error(sb, "Failed to allocate extent record");
goto err_out;
@@ -3545,7 +3545,7 @@ int ntfs_attr_record_move_away(struct ntfs_attr_search_ctx *ctx, int extra)
* new extent and move attribute to it.
*/
ni = NULL;
- err = ntfs_mft_record_alloc(base_ni->vol, 0, &ni, base_ni, NULL);
+ err = ntfs_mft_record_alloc(base_ni->vol, 0, &ni, base_ni, NULL, -1);
if (err) {
ntfs_error(sb, "Couldn't allocate MFT record, err : %d", err);
return err;
@@ -3971,7 +3971,10 @@ int ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni, s64 from_vcn)
unsigned int de_cnt = 0;
/* Allocate new mft record. */
- err = ntfs_mft_record_alloc(ni->vol, 0, &ext_ni, base_ni, NULL);
+ err = ntfs_mft_record_alloc(ni->vol, 0, &ext_ni, base_ni, NULL,
+ base_ni->mft_no == FILE_MFT &&
+ ni->type == AT_DATA &&
+ ni->name == AT_UNNAMED ? stop_vcn : -1);
if (err) {
ntfs_error(sb, "Failed to allocate extent record");
goto put_err_out;
@@ -4831,7 +4834,7 @@ static int ntfs_resident_attr_resize(struct ntfs_inode *attr_ni, const s64 newsi
}
/* Allocate new mft record. */
- err = ntfs_mft_record_alloc(base_ni->vol, 0, &ext_ni, base_ni, NULL);
+ err = ntfs_mft_record_alloc(base_ni->vol, 0, &ext_ni, base_ni, NULL, -1);
if (err) {
ntfs_error(sb, "Couldn't allocate MFT record");
goto put_err_out;
diff --git a/fs/ntfs/mft.c b/fs/ntfs/mft.c
index 3ad739179c7a1..5fae9ad03858e 100644
--- a/fs/ntfs/mft.c
+++ b/fs/ntfs/mft.c
@@ -841,12 +841,126 @@ static bool ntfs_may_write_mft_record(struct ntfs_volume *vol, const u64 mft_no,
static const char *es = " Leaving inconsistent metadata. Unmount and run chkdsk.";
-#define RESERVED_MFT_RECORDS 64
+#define FIRST_NORMAL_MFT_RECORD 24
+#define MFT_RECORD_RESERVE 4
/*
- * ntfs_mft_bitmap_find_and_alloc_free_rec_nolock - see name
+ * Records 12-15 are marked in use by Windows but normally have no name
+ * and no links. Keep them as the last bootstrap option when a volume
+ * mounted without an in-memory tail reserve needs its first $MFT metadata
+ * extent.
+ */
+static bool mft_reserved_is_free(struct ntfs_volume *vol,
+ struct ntfs_inode *mft_ni, s64 mft_no)
+{
+ struct attr_record *a;
+ struct mft_record *m;
+ struct folio *folio;
+ void *mapped;
+ pgoff_t index = NTFS_MFT_NR_TO_PIDX(vol, mft_no);
+ unsigned int ofs = NTFS_MFT_NR_TO_POFS(vol, mft_no);
+ u32 attrs_offset, bytes_in_use;
+ bool available = false, have_std = false;
+ int i;
+
+ for (i = 0; i < mft_ni->nr_extents; i++) {
+ if (mft_ni->ext.extent_ntfs_inos[i] &&
+ mft_ni->ext.extent_ntfs_inos[i]->mft_no == mft_no)
+ return false;
+ }
+ m = kmalloc(vol->mft_record_size, GFP_NOFS);
+ if (!m)
+ return false;
+
+ folio = read_mapping_folio(vol->mft_ino->i_mapping, index, NULL);
+ if (IS_ERR(folio))
+ goto free_m;
+
+ folio_lock(folio);
+ mapped = kmap_local_folio(folio, 0);
+ memcpy(m, (u8 *)mapped + ofs, vol->mft_record_size);
+ kunmap_local(mapped);
+ folio_unlock(folio);
+ folio_put(folio);
+ if (post_read_mst_fixup((struct ntfs_record *)m, vol->mft_record_size))
+ goto free_m;
+
+ if (!ntfs_is_mft_record(m->magic) ||
+ !(m->flags & MFT_RECORD_IN_USE) || m->base_mft_record ||
+ m->link_count)
+ goto out;
+
+ attrs_offset = le16_to_cpu(m->attrs_offset);
+ bytes_in_use = le32_to_cpu(m->bytes_in_use);
+ if (attrs_offset > bytes_in_use || bytes_in_use > vol->mft_record_size ||
+ bytes_in_use - attrs_offset < sizeof(a->type))
+ goto out;
+
+ for (a = (struct attr_record *)((u8 *)m + attrs_offset);
+ (u8 *)a + sizeof(a->type) <= (u8 *)m + bytes_in_use;) {
+ u32 len;
+
+ if (a->type == AT_END) {
+ if ((u8 *)a + sizeof(a->type) + sizeof(a->length) >
+ (u8 *)m + bytes_in_use)
+ break;
+ /* Also accept a record emptied by an earlier bootstrap. */
+ available = have_std ||
+ (u8 *)a == (u8 *)m + attrs_offset;
+ break;
+ }
+ if (a->type == AT_FILE_NAME)
+ break;
+ len = le32_to_cpu(a->length);
+ if (len < offsetof(struct attr_record, data) ||
+ (u8 *)a + len > (u8 *)m + bytes_in_use)
+ break;
+ if (a->type == AT_STANDARD_INFORMATION) {
+ u32 value_len, value_ofs;
+
+ if (have_std || a->non_resident ||
+ len < offsetof(struct attr_record,
+ data.resident.reserved) + 1)
+ break;
+ value_len = le32_to_cpu(a->data.resident.value_length);
+ value_ofs = le16_to_cpu(a->data.resident.value_offset);
+ if (value_ofs > len || value_len > len - value_ofs)
+ break;
+ have_std = true;
+ }
+ a = (struct attr_record *)((u8 *)a + len);
+ }
+out:
+ kfree(m);
+ return available;
+free_m:
+ kfree(m);
+ return false;
+}
+
+static s64 mft_reserve_end(const u8 *buf, s64 buf_start, s64 buf_end,
+ s64 start, s64 pass_end, s64 initialized_mft_records)
+{
+ s64 end = start + 1;
+ s64 limit = min_t(s64, start + MFT_RECORD_RESERVE, pass_end);
+
+ if (limit > initialized_mft_records)
+ limit = initialized_mft_records;
+ if (limit > buf_end)
+ limit = buf_end;
+ while (end < limit &&
+ !(buf[(end - buf_start) >> 3] &
+ (1 << ((end - buf_start) & 7))))
+ end++;
+ return end;
+}
+
+/*
+ * mft_bitmap_alloc_free_rec - find and allocate a free MFT record
* @vol: volume on which to search for a free mft record
* @base_ni: open base inode if allocating an extent mft record or NULL
+ * @max_mft_no: first record which must not be allocated, or -1
+ * @new_reserve_end: if not NULL, end of a free run starting after the result
*
* Search for a free mft record in the mft bitmap attribute on the ntfs volume
* @vol.
@@ -862,10 +976,12 @@ static const char *es = " Leaving inconsistent metadata. Unmount and run chkds
*
* Locking: Caller must hold vol->mftbmp_lock for writing.
*/
-static s64 ntfs_mft_bitmap_find_and_alloc_free_rec_nolock(struct ntfs_volume *vol,
- struct ntfs_inode *base_ni)
+static s64 mft_bitmap_alloc_free_rec(struct ntfs_volume *vol,
+ struct ntfs_inode *base_ni,
+ s64 max_mft_no, s64 *new_reserve_end)
{
s64 pass_end, ll, data_pos, pass_start, ofs, bit;
+ s64 initialized_mft_records;
unsigned long flags;
struct address_space *mftbmp_mapping;
u8 *buf = NULL, *byte;
@@ -882,30 +998,36 @@ static s64 ntfs_mft_bitmap_find_and_alloc_free_rec_nolock(struct ntfs_volume *vo
read_lock_irqsave(&NTFS_I(vol->mft_ino)->size_lock, flags);
pass_end = NTFS_I(vol->mft_ino)->allocated_size >>
vol->mft_record_size_bits;
+ initialized_mft_records = NTFS_I(vol->mft_ino)->initialized_size >>
+ vol->mft_record_size_bits;
read_unlock_irqrestore(&NTFS_I(vol->mft_ino)->size_lock, flags);
read_lock_irqsave(&NTFS_I(vol->mftbmp_ino)->size_lock, flags);
ll = NTFS_I(vol->mftbmp_ino)->initialized_size << 3;
read_unlock_irqrestore(&NTFS_I(vol->mftbmp_ino)->size_lock, flags);
if (pass_end > ll)
pass_end = ll;
- pass = 1;
- if (!base_ni)
- data_pos = vol->mft_data_pos;
- else
- data_pos = base_ni->mft_no + 1;
- if (data_pos < RESERVED_MFT_RECORDS)
- data_pos = RESERVED_MFT_RECORDS;
- if (data_pos >= pass_end) {
- data_pos = RESERVED_MFT_RECORDS;
+ if (max_mft_no >= 0 && pass_end > max_mft_no)
+ pass_end = max_mft_no;
+ if (base_ni && base_ni->mft_no == FILE_MFT) {
+ data_pos = FILE_first_user;
pass = 2;
- /* This happens on a freshly formatted volume. */
if (data_pos >= pass_end)
return -ENOSPC;
- }
-
- if (base_ni && base_ni->mft_no == FILE_MFT) {
- data_pos = 0;
- pass = 2;
+ } else {
+ pass = 1;
+ if (!base_ni)
+ data_pos = vol->mft_data_pos;
+ else
+ data_pos = base_ni->mft_no + 1;
+ if (data_pos < FIRST_NORMAL_MFT_RECORD)
+ data_pos = FIRST_NORMAL_MFT_RECORD;
+ if (data_pos >= pass_end) {
+ data_pos = FIRST_NORMAL_MFT_RECORD;
+ pass = 2;
+ /* This happens on a freshly formatted volume. */
+ if (data_pos >= pass_end)
+ return -ENOSPC;
+ }
}
pass_start = data_pos;
@@ -940,38 +1062,28 @@ static s64 ntfs_mft_bitmap_find_and_alloc_free_rec_nolock(struct ntfs_volume *vo
size, data_pos, bit);
for (; bit < size && data_pos + bit < pass_end;
bit &= ~7ull, bit += 8) {
- /*
- * If we're extending $MFT and running out of the first
- * mft record (base record) then give up searching since
- * no guarantee that the found record will be accessible.
- */
- if (base_ni && base_ni->mft_no == FILE_MFT && bit > 400) {
- folio_unlock(folio);
- kunmap_local(buf);
- folio_put(folio);
- return -ENOSPC;
- }
-
byte = buf + (bit >> 3);
if (*byte == 0xff)
continue;
- b = ffz((unsigned long)*byte);
- if (b < 8 && b >= (bit & 7)) {
+ b = bit & 7;
+ for (; b < 8; b++) {
+ if (*byte & (1 << b))
+ continue;
ll = data_pos + (bit & ~7ull) + b;
+ if (ll >= pass_end)
+ break;
+ /* Keep the dynamic tail reserve for $MFT metadata. */
+ if ((!base_ni || base_ni->mft_no != FILE_MFT) &&
+ ll >= vol->mft_record_reserve_pos &&
+ ll < vol->mft_record_reserve_end)
+ continue;
if (unlikely(ll >= (1ll << 32))) {
folio_unlock(folio);
kunmap_local(buf);
folio_put(folio);
return -ENOSPC;
}
- *byte |= 1 << b;
- folio_mark_dirty(folio);
- folio_unlock(folio);
- kunmap_local(buf);
- folio_put(folio);
- ntfs_debug("Done. (Found and allocated mft record 0x%llx.)",
- ll);
- return ll;
+ goto found;
}
}
ntfs_debug("After inner for loop: size 0x%x, data_pos 0x%llx, bit 0x%llx",
@@ -994,7 +1106,8 @@ static s64 ntfs_mft_bitmap_find_and_alloc_free_rec_nolock(struct ntfs_volume *vo
* part of the zone which we omitted earlier.
*/
pass_end = pass_start;
- data_pos = pass_start = RESERVED_MFT_RECORDS;
+ data_pos = FIRST_NORMAL_MFT_RECORD;
+ pass_start = FIRST_NORMAL_MFT_RECORD;
ntfs_debug("pass %i, pass_start 0x%llx, pass_end 0x%llx.",
pass, pass_start, pass_end);
if (data_pos >= pass_end)
@@ -1004,6 +1117,18 @@ static s64 ntfs_mft_bitmap_find_and_alloc_free_rec_nolock(struct ntfs_volume *vo
/* No free mft records in currently initialized mft bitmap. */
ntfs_debug("Done. (No free mft records left in currently initialized mft bitmap.)");
return -ENOSPC;
+found:
+ if (new_reserve_end)
+ *new_reserve_end = mft_reserve_end(buf, data_pos,
+ data_pos + size, ll, pass_end,
+ initialized_mft_records);
+ *byte |= 1 << b;
+ folio_mark_dirty(folio);
+ folio_unlock(folio);
+ kunmap_local(buf);
+ folio_put(folio);
+ ntfs_debug("Done. (Found and allocated mft record 0x%llx.)", ll);
+ return ll;
}
static int ntfs_mft_attr_extend(struct ntfs_inode *ni)
@@ -1471,8 +1596,9 @@ static int ntfs_mft_bitmap_extend_initialized_nolock(struct ntfs_volume *vol)
* @vol: volume on which to extend the mft data attribute
*
* Extend the mft data attribute on the ntfs volume @vol by 16 mft records
- * worth of clusters or if not enough space for this by one mft record worth
- * of clusters.
+ * worth of clusters or if not enough space for this by two mft records worth
+ * of clusters. Keeping at least two new records breaks the recursion between
+ * extending $MFT and allocating a record for a new $MFT attribute extent.
*
* Note: Only changes allocated_size, i.e. does not touch initialized_size or
* data_size.
@@ -1526,10 +1652,8 @@ static int ntfs_mft_data_extend_allocation_nolock(struct ntfs_volume *vol)
}
lcn = rl->lcn + rl->length;
ntfs_debug("Last lcn of mft data attribute is 0x%llx.", lcn);
- /* Minimum allocation is one mft record worth of clusters. */
- min_nr = NTFS_B_TO_CLU(vol, vol->mft_record_size);
- if (!min_nr)
- min_nr = 1;
+ /* Keep room for the allocating record and at least one MFT reserve. */
+ min_nr = DIV_ROUND_UP_ULL((u64)vol->mft_record_size * 2, vol->cluster_size);
/* Want to allocate 16 mft records worth of clusters. */
nr = vol->mft_record_size << 4 >> vol->cluster_size_bits;
if (!nr)
@@ -1928,6 +2052,7 @@ static int ntfs_mft_record_format(const struct ntfs_volume *vol, const s64 mft_n
* @ni: [OUT] on success, set to the allocated ntfs inode
* @base_ni: [IN] open base inode if allocating an extent mft record or NULL
* @ni_mrec: [OUT] on successful return this is the mapped mft record
+ * @mft_data_vcn: [IN] lowest VCN of a new $MFT/$DATA extent, or -1
*
* Allocate an mft record in $MFT/$DATA of an open ntfs volume @vol.
*
@@ -1955,30 +2080,23 @@ static int ntfs_mft_record_format(const struct ntfs_volume *vol, const s64 mft_n
* optimize this we start scanning at the place specified by @base_ni or if
* @base_ni is NULL we start where we last stopped and we perform wrap around
* when we reach the end. Note, we do not try to allocate mft records below
- * number 64 because numbers 0 to 15 are the defined system files anyway and 16
- * to 64 are special in that they are used for storing extension mft records
- * for the $DATA attribute of $MFT. This is required to avoid the possibility
- * of creating a runlist with a circular dependency which once written to disk
- * can never be read in again. Windows will only use records 16 to 24 for
- * normal files if the volume is completely out of space. We never use them
- * which means that when the volume is really out of space we cannot create any
- * more files while Windows can still create up to 8 small files. We can start
- * doing this at some later time, it does not matter much for now.
+ * number 24 because numbers 0 to 15 are the defined system files and records
+ * 16 to 23 are kept for metadata compatibility. Records reserved dynamically
+ * at the initialized MFT tail are skipped by normal allocation and consumed by
+ * $MFT metadata extent allocation.
*
* When scanning the mft bitmap, we only search up to the last allocated mft
- * record. If there are no free records left in the range 64 to number of
+ * record. If there are no free records left in the range 24 to number of
* allocated mft records, then we extend the $MFT/$DATA attribute in order to
* create free mft records. We extend the allocated size of $MFT/$DATA by 16
* records at a time or one cluster, if cluster size is above 16kiB. If there
- * is not sufficient space to do this, we try to extend by a single mft record
- * or one cluster, if cluster size is above the mft record size.
+ * is not sufficient space to do this, we try to extend by two mft records or
+ * one cluster, if a cluster already contains at least two mft records.
*
- * No matter how many mft records we allocate, we initialize only the first
- * allocated mft record, incrementing mft data size and initialized size
- * accordingly, open an struct ntfs_inode for it and return it to the caller, unless
- * there are less than 64 mft records, in which case we allocate and initialize
- * mft records until we reach record 64 which we consider as the first free mft
- * record for use by normal files.
+ * When extending the initialized MFT tail, we also initialize up to four
+ * additional records and reserve them in memory for future $MFT metadata
+ * extents. If there are less than 24 mft records, records are initialized
+ * until record 24, which is the first record used for normal files.
*
* If during any stage we overflow the initialized data in the mft bitmap, we
* extend the initialized size (and data size) by 8 bytes, allocating another
@@ -2014,9 +2132,12 @@ static int ntfs_mft_record_format(const struct ntfs_volume *vol, const s64 mft_n
*/
int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
struct ntfs_inode **ni, struct ntfs_inode *base_ni,
- struct mft_record **ni_mrec)
+ struct mft_record **ni_mrec, const s64 mft_data_vcn)
{
s64 ll, bit, old_data_initialized, old_data_size;
+ s64 max_mft_no = -1, reserve_start = -1, reserve_end = -1;
+ s64 candidate_reserve_end = -1;
+ s64 *reserve_endp;
unsigned long flags;
struct folio *folio;
struct ntfs_inode *mft_ni, *mftbmp_ni;
@@ -2027,7 +2148,9 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
unsigned int ofs;
int err;
__le16 seq_no, usn;
- bool record_formatted = false;
+ bool record_formatted = false, from_reserve = false, tail_alloc = false;
+ bool reserve_created = false;
+ bool forced_reserved_record = false;
unsigned int memalloc_flags;
if (base_ni && *ni)
@@ -2036,6 +2159,21 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
/* @mode and @base_ni are mutually exclusive. */
if (mode && base_ni)
return -EINVAL;
+ if (mft_data_vcn >= 0 &&
+ (!base_ni || base_ni->mft_no != FILE_MFT))
+ return -EINVAL;
+ if (mft_data_vcn >= 0) {
+ u64 vbo;
+
+ if ((u64)mft_data_vcn > (U64_MAX >> vol->cluster_size_bits))
+ return -EOVERFLOW;
+ vbo = (u64)mft_data_vcn << vol->cluster_size_bits;
+ /*
+ * The whole extent record must be reachable without this
+ * extent, including when an MFT record spans multiple clusters.
+ */
+ max_mft_no = vbo >> vol->mft_record_size_bits;
+ }
if (base_ni)
ntfs_debug("Entering (allocating an extent mft record for base mft record 0x%llx).",
@@ -2050,10 +2188,39 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
mutex_lock(&mft_ni->mrec_lock);
mftbmp_ni = NTFS_I(vol->mftbmp_ino);
search_free_rec:
+ from_reserve = false;
+ reserve_created = false;
+ candidate_reserve_end = -1;
if (!base_ni || base_ni->mft_no != FILE_MFT)
down_write(&vol->mftbmp_lock);
- bit = ntfs_mft_bitmap_find_and_alloc_free_rec_nolock(vol, base_ni);
+ if (base_ni && base_ni->mft_no == FILE_MFT &&
+ vol->mft_record_reserve_pos < vol->mft_record_reserve_end &&
+ (max_mft_no < 0 || vol->mft_record_reserve_pos < max_mft_no)) {
+ bit = vol->mft_record_reserve_pos;
+ err = ntfs_bitmap_set_bit(vol->mftbmp_ino, bit);
+ if (unlikely(err)) {
+ ntfs_error(vol->sb,
+ "Failed to allocate reserved MFT record 0x%llx.",
+ bit);
+ goto err_out;
+ }
+ vol->mft_record_reserve_pos++;
+ from_reserve = true;
+ ntfs_debug("Allocated MFT metadata record 0x%llx from tail reserve.",
+ bit);
+ goto have_alloc_rec;
+ }
+ reserve_endp = vol->mft_record_reserve_pos >=
+ vol->mft_record_reserve_end ? &candidate_reserve_end : NULL;
+ bit = mft_bitmap_alloc_free_rec(vol, base_ni, max_mft_no, reserve_endp);
if (bit >= 0) {
+ if (candidate_reserve_end > bit + 1) {
+ vol->mft_record_reserve_pos = bit + 1;
+ vol->mft_record_reserve_end = candidate_reserve_end;
+ reserve_created = true;
+ ntfs_debug("Reserved free MFT records [0x%llx, 0x%llx) for metadata.",
+ bit + 1, candidate_reserve_end);
+ }
ntfs_debug("Found and allocated free record (#1), bit 0x%llx.",
(long long)bit);
goto have_alloc_rec;
@@ -2068,6 +2235,24 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
}
if (base_ni && base_ni->mft_no == FILE_MFT) {
+ static const u8 bootstrap_records[] = {
+ FILE_reserved15, FILE_reserved12, FILE_reserved13,
+ FILE_reserved14,
+ };
+ int i;
+
+ for (i = 0; i < ARRAY_SIZE(bootstrap_records); i++) {
+ if (max_mft_no >= 0 && bootstrap_records[i] >= max_mft_no)
+ continue;
+ if (!mft_reserved_is_free(vol, mft_ni,
+ bootstrap_records[i]))
+ continue;
+ bit = bootstrap_records[i];
+ forced_reserved_record = true;
+ ntfs_debug("Using reserved MFT record %lld to bootstrap metadata extension.",
+ bit);
+ goto have_alloc_rec;
+ }
memalloc_nofs_restore(memalloc_flags);
return bit;
}
@@ -2087,10 +2272,10 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
old_data_initialized = mftbmp_ni->initialized_size;
read_unlock_irqrestore(&mftbmp_ni->size_lock, flags);
if (old_data_initialized << 3 > ll &&
- old_data_initialized > RESERVED_MFT_RECORDS / 8) {
+ old_data_initialized << 3 > FIRST_NORMAL_MFT_RECORD) {
bit = ll;
- if (bit < RESERVED_MFT_RECORDS)
- bit = RESERVED_MFT_RECORDS;
+ if (bit < FIRST_NORMAL_MFT_RECORD)
+ bit = FIRST_NORMAL_MFT_RECORD;
if (unlikely(bit >= (1ll << 32)))
goto max_err_out;
ntfs_debug("Found free record (#2), bit 0x%llx.",
@@ -2176,6 +2361,11 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
read_lock_irqsave(&mft_ni->size_lock, flags);
old_data_initialized = mft_ni->initialized_size;
read_unlock_irqrestore(&mft_ni->size_lock, flags);
+ tail_alloc = (!base_ni || base_ni->mft_no != FILE_MFT) &&
+ bit >= (old_data_initialized >> vol->mft_record_size_bits) &&
+ vol->mft_record_reserve_pos >= vol->mft_record_reserve_end;
+ if (tail_alloc)
+ ll = (bit + 2) << vol->mft_record_size_bits;
if (ll <= old_data_initialized) {
ntfs_debug("Allocated mft record already initialized.");
goto mft_rec_already_initialized;
@@ -2208,6 +2398,29 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
mft_ni->initialized_size);
}
read_unlock_irqrestore(&mft_ni->size_lock, flags);
+ if (tail_alloc) {
+ s64 bitmap_records;
+
+ read_lock_irqsave(&mft_ni->size_lock, flags);
+ reserve_end = mft_ni->allocated_size >>
+ vol->mft_record_size_bits;
+ read_unlock_irqrestore(&mft_ni->size_lock, flags);
+ read_lock_irqsave(&mftbmp_ni->size_lock, flags);
+ bitmap_records = mftbmp_ni->initialized_size << 3;
+ read_unlock_irqrestore(&mftbmp_ni->size_lock, flags);
+ if (reserve_end > bitmap_records)
+ reserve_end = bitmap_records;
+ if (reserve_end > bit + 1 + MFT_RECORD_RESERVE)
+ reserve_end = bit + 1 + MFT_RECORD_RESERVE;
+ reserve_start = bit + 1;
+ if (reserve_end > reserve_start) {
+ ll = reserve_end << vol->mft_record_size_bits;
+ } else {
+ reserve_start = -1;
+ reserve_end = -1;
+ ll = (bit + 1) << vol->mft_record_size_bits;
+ }
+ }
} else if (ll > mft_ni->allocated_size) {
err = -ENOSPC;
goto undo_mftbmp_alloc_nolock;
@@ -2276,6 +2489,12 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
mark_mft_record_dirty(ctx->ntfs_ino);
ntfs_attr_put_search_ctx(ctx);
unmap_mft_record(mft_ni);
+ if (reserve_start >= 0 && reserve_end > reserve_start) {
+ vol->mft_record_reserve_pos = reserve_start;
+ vol->mft_record_reserve_end = reserve_end;
+ ntfs_debug("Reserved MFT records [0x%llx, 0x%llx) for metadata.",
+ reserve_start, reserve_end);
+ }
read_lock_irqsave(&mft_ni->size_lock, flags);
ntfs_debug("Status of mft data after mft record initialization: allocated_size 0x%llx, data_size 0x%llx, initialized_size 0x%llx.",
mft_ni->allocated_size, i_size_read(vol->mft_ino),
@@ -2315,8 +2534,8 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
/* If we just formatted the mft record no need to do it again. */
if (!record_formatted) {
/* Sanity check that the mft record is really not in use. */
- if (ntfs_is_file_record(m->magic) &&
- (m->flags & MFT_RECORD_IN_USE)) {
+ if (!forced_reserved_record && ntfs_is_file_record(m->magic) &&
+ (m->flags & MFT_RECORD_IN_USE)) {
ntfs_warning(vol->sb,
"Mft record 0x%llx was marked free in mft bitmap but is marked used itself. Unmount and run chkdsk.",
bit);
@@ -2389,9 +2608,13 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
ntfs_error(vol->sb, "Failed to map allocated extent mft record 0x%llx.",
bit);
err = PTR_ERR(m_tmp);
- /* Set the mft record itself not in use. */
- m->flags &= cpu_to_le16(
- ~le16_to_cpu(MFT_RECORD_IN_USE));
+ if (forced_reserved_record) {
+ m->base_mft_record = 0;
+ m->flags |= MFT_RECORD_IN_USE;
+ } else {
+ /* Set the mft record itself not in use. */
+ m->flags &= cpu_to_le16(~le16_to_cpu(MFT_RECORD_IN_USE));
+ }
/* Make sure the mft record is written out to disk. */
ntfs_mft_mark_dirty(folio);
folio_unlock(folio);
@@ -2464,7 +2687,8 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
(*ni)->mft_no = bit;
if (ni_mrec)
*ni_mrec = (*ni)->mrec;
- ntfs_dec_free_mft_records(vol, 1);
+ if (!forced_reserved_record)
+ ntfs_dec_free_mft_records(vol, 1);
return 0;
undo_data_init:
write_lock_irqsave(&mft_ni->size_lock, flags);
@@ -2476,10 +2700,13 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
if (!base_ni || base_ni->mft_no != FILE_MFT)
down_write(&vol->mftbmp_lock);
undo_mftbmp_alloc_nolock:
- if (ntfs_bitmap_clear_bit(vol->mftbmp_ino, bit)) {
+ if (!forced_reserved_record && ntfs_bitmap_clear_bit(vol->mftbmp_ino, bit)) {
ntfs_error(vol->sb, "Failed to clear bit in mft bitmap.%s", es);
NVolSetErrors(vol);
}
+ if ((from_reserve || reserve_created) &&
+ vol->mft_record_reserve_pos == bit + 1)
+ vol->mft_record_reserve_pos = bit;
if (!base_ni || base_ni->mft_no != FILE_MFT)
up_write(&vol->mftbmp_lock);
err_out:
@@ -2515,9 +2742,11 @@ int ntfs_mft_record_free(struct ntfs_volume *vol, struct ntfs_inode *ni)
int err;
u16 seq_no;
__le16 old_seq_no;
+ __le64 old_base_mft_record;
struct mft_record *ni_mrec;
unsigned int memalloc_flags;
struct ntfs_inode *base_ni;
+ bool keep_reserved;
if (!vol || !ni)
return -EINVAL;
@@ -2530,9 +2759,23 @@ int ntfs_mft_record_free(struct ntfs_volume *vol, struct ntfs_inode *ni)
/* Cache the mft reference for later. */
mft_no = ni->mft_no;
-
- /* Mark the mft record as not in use. */
- ni_mrec->flags &= ~MFT_RECORD_IN_USE;
+ if (likely(ni->nr_extents >= 0))
+ base_ni = ni;
+ else
+ base_ni = ni->ext.base_ntfs_ino;
+ keep_reserved = mft_no >= FILE_reserved12 &&
+ mft_no <= FILE_reserved15 &&
+ base_ni->mft_no == FILE_MFT;
+
+ old_base_mft_record = ni_mrec->base_mft_record;
+ if (keep_reserved) {
+ /* Restore the special, unnamed form used by reserved records. */
+ ni_mrec->base_mft_record = 0;
+ ni_mrec->flags |= MFT_RECORD_IN_USE;
+ } else {
+ /* Mark the mft record as not in use. */
+ ni_mrec->flags &= ~MFT_RECORD_IN_USE;
+ }
/* Increment the sequence number, skipping zero, if it is not zero. */
old_seq_no = ni_mrec->sequence_number;
@@ -2561,16 +2804,20 @@ int ntfs_mft_record_free(struct ntfs_volume *vol, struct ntfs_inode *ni)
if (err)
goto sync_rollback;
- if (likely(ni->nr_extents >= 0))
- base_ni = ni;
- else
- base_ni = ni->ext.base_ntfs_ino;
+ if (keep_reserved) {
+ unmap_mft_record(ni);
+ return 0;
+ }
/* Clear the bit in the $MFT/$BITMAP corresponding to this record. */
memalloc_flags = memalloc_nofs_save();
if (base_ni->mft_no != FILE_MFT)
down_write(&vol->mftbmp_lock);
err = ntfs_bitmap_clear_bit(vol->mftbmp_ino, mft_no);
+ if (!err && base_ni->mft_no == FILE_MFT &&
+ mft_no + 1 == vol->mft_record_reserve_pos &&
+ mft_no < vol->mft_record_reserve_end)
+ vol->mft_record_reserve_pos = mft_no;
if (base_ni->mft_no != FILE_MFT)
up_write(&vol->mftbmp_lock);
memalloc_nofs_restore(memalloc_flags);
@@ -2596,6 +2843,7 @@ int ntfs_mft_record_free(struct ntfs_volume *vol, struct ntfs_inode *ni)
"Eeek! Rollback failed in %s. Leaving inconsistent metadata!\n", __func__);
ni_mrec->flags |= MFT_RECORD_IN_USE;
ni_mrec->sequence_number = old_seq_no;
+ ni_mrec->base_mft_record = old_base_mft_record;
NInoSetDirty(ni);
write_mft_record(ni, ni_mrec, 0);
unmap_mft_record(ni);
diff --git a/fs/ntfs/mft.h b/fs/ntfs/mft.h
index 75a51a98d0f6e..ed5c1d595c0d3 100644
--- a/fs/ntfs/mft.h
+++ b/fs/ntfs/mft.h
@@ -78,7 +78,7 @@ static inline int write_mft_record(struct ntfs_inode *ni, struct mft_record *m,
int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
struct ntfs_inode **ni, struct ntfs_inode *base_ni,
- struct mft_record **ni_mrec);
+ struct mft_record **ni_mrec, const s64 mft_data_vcn);
int ntfs_mft_record_free(struct ntfs_volume *vol, struct ntfs_inode *ni);
int ntfs_mft_records_write(const struct ntfs_volume *vol, const u64 mref,
const s64 count, struct mft_record *b);
diff --git a/fs/ntfs/namei.c b/fs/ntfs/namei.c
index 96045face63f9..dfd05e604f9c1 100644
--- a/fs/ntfs/namei.c
+++ b/fs/ntfs/namei.c
@@ -480,7 +480,7 @@ static struct ntfs_inode *__ntfs_create(struct mnt_idmap *idmap, struct inode *d
mark_inode_dirty(dir);
err = ntfs_mft_record_alloc(dir_ni->vol, mode, &ni, NULL,
- &ni_mrec);
+ &ni_mrec, -1);
if (err) {
iput(vi);
return ERR_PTR(err);
diff --git a/fs/ntfs/volume.h b/fs/ntfs/volume.h
index 65fd3908af261..2b60d14fc7ef5 100644
--- a/fs/ntfs/volume.h
+++ b/fs/ntfs/volume.h
@@ -55,6 +55,10 @@
* @attrdef_size: Size of the attribute definition table in bytes.
* @attrdef: Table of attribute definitions. Obtained from FILE_AttrDef.
* @mft_data_pos: Mft record number at which to allocate the next mft record.
+ * @mft_record_reserve_pos: First record in the in-memory MFT metadata reserve
+ * (protected by mftbmp_lock).
+ * @mft_record_reserve_end: First record beyond the MFT metadata reserve
+ * (protected by mftbmp_lock).
* @mft_zone_start: First cluster of the mft zone.
* @mft_zone_end: First cluster beyond the mft zone.
* @mft_zone_pos: Current position in the mft zone.
@@ -119,6 +123,8 @@ struct ntfs_volume {
s32 attrdef_size;
struct attr_def *attrdef;
s64 mft_data_pos;
+ s64 mft_record_reserve_pos;
+ s64 mft_record_reserve_end;
s64 mft_zone_start;
s64 mft_zone_end;
s64 mft_zone_pos;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 067/398] wifi: mac80211: reset state when starting AP fails
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (65 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 066/398] wifi: mac80211: abort chanswitch when leaving a mesh Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 068/398] wifi: cfg80211: restore netns_immutable on failures Greg Kroah-Hartman
` (335 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+ca7a2759caaa6cd4e3db,
syzbot+c4686c3eb8b64032618f, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 3f28551d0241254a75626d868041c6340285088b ]
ieee80211_start_ap() can set enable_beacon (and beacon_int) and fail
later, leaving it set forever. Scanning can then attempt to restore
beaconing on such an interface, leading to:
Oops: divide error: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:mac80211_hwsim_link_info_changed+0xca7/0xf00
Call Trace:
drv_link_info_changed+0x413/0x860 net/mac80211/driver-ops.c:495
ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427
ieee80211_offchannel_return+0x381/0x580 net/mac80211/offchannel.c:160
__ieee80211_scan_completed+0x993/0xe30 net/mac80211/scan.c:519
ieee80211_scan_work+0x472/0x2010 net/mac80211/scan.c:1193
cfg80211_wiphy_work+0x2b7/0x550 net/wireless/core.c:538
in hwsim. Also, cfg80211 then allows changing the interface type,
and the off-channel path getgs confused about beaconing as well,
leading to another warning:
WARNING: net/mac80211/driver-ops.c:468 at drv_link_info_changed+0x583/0x880
ieee80211_link_info_change_notify+0x24b/0x3c0 net/mac80211/main.c:427
ieee80211_offchannel_stop_vifs+0x328/0x5c0 net/mac80211/offchannel.c:122
ieee80211_start_sw_scan net/mac80211/scan.c:583 [inline]
__ieee80211_start_scan+0xfb6/0x1af0 net/mac80211/scan.c:882
Reset the state on failures to always have it correct.
Assisted-by: LLM
Fixes: d6a83228823f ("mac80211: track enable_beacon explicitly")
Reported-by: syzbot+ca7a2759caaa6cd4e3db@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=ca7a2759caaa6cd4e3db
Reported-by: syzbot+c4686c3eb8b64032618f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c4686c3eb8b64032618f
Link: https://patch.msgid.link/20260904165722.9629429a5221.I7f599412bfe12a09d41ea4901be9ad165d07d133@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index f6e8352665c1a..84e27d8a75ef1 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -1717,6 +1717,9 @@ static int ieee80211_start_ap(struct wiphy *wiphy, struct net_device *dev,
return 0;
error:
+ link_conf->enable_beacon = false;
+ link_conf->beacon_int = prev_beacon_int;
+ sdata->vif.cfg.ssid_len = 0;
ieee80211_link_release_channel(link);
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 121/438] ntfs: repack $MFT/$ATTRIBUTE LIST
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (119 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 120/438] ntfs: use dynamic MFT tail reservation Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 122/438] ntfs: account for MFT records added during allocation Greg Kroah-Hartman
` (328 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hyunchul Lee, Namjae Jeon,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit b1d732e62a5b3942546e4edaab8976258e779287 ]
Repack the non-resident $MFT/$ATTRIBUTE_LIST into a contiguous run
when its mapping pairs no longer fit in the base MFT record. Propagate
allocation and writeback errors, and check synchronous replacement writes.
Fixes: 495e90fa3348 ("ntfs: update attrib operations")
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs/attrib.c | 47 ++++++++---
fs/ntfs/attrlist.c | 202 ++++++++++++++++++++++++++++++++++++++++++---
fs/ntfs/inode.c | 10 ++-
3 files changed, 236 insertions(+), 23 deletions(-)
diff --git a/fs/ntfs/attrib.c b/fs/ntfs/attrib.c
index f50685ec2fb34..34c4044b59af2 100644
--- a/fs/ntfs/attrib.c
+++ b/fs/ntfs/attrib.c
@@ -3839,13 +3839,13 @@ int ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni, s64 from_vcn)
*/
if (ni->type == AT_ATTRIBUTE_LIST) {
ntfs_attr_put_search_ctx(ctx);
- if (ntfs_inode_free_space(base_ni, mp_size -
- cur_max_mp_size)) {
- ntfs_debug("Attribute list is too big. Defragment the volume\n");
- return -ENOSPC;
- }
- if (ntfs_attrlist_update(base_ni))
- return -EIO;
+ err = ntfs_inode_free_space(base_ni, mp_size -
+ cur_max_mp_size);
+ if (err)
+ return err;
+ err = ntfs_attrlist_update(base_ni);
+ if (err)
+ return err;
goto retry;
}
@@ -4517,13 +4517,39 @@ static int ntfs_non_resident_attr_expand(struct ntfs_inode *ni, const s64 newsiz
ntfs_bytes_to_cluster(vol, ni->allocated_size),
first_free_vcn -
ntfs_bytes_to_cluster(vol, ni->allocated_size),
- lcn_seek_from, DATA_ZONE, false, false, false);
+ lcn_seek_from, DATA_ZONE, false,
+ ni->type == AT_ATTRIBUTE_LIST, false);
if (IS_ERR(rl)) {
ntfs_debug("Cluster allocation failed (%lld)",
(long long)first_free_vcn -
ntfs_bytes_to_cluster(vol, ni->allocated_size));
return PTR_ERR(rl);
}
+ /*
+ * A contiguous ATTRIBUTE_LIST allocation keeps its mapping
+ * pairs small enough to fit in the base MFT record. The
+ * allocator can return a short run when contiguity was
+ * requested, so discard it and retry normally if necessary.
+ */
+ if (ni->type == AT_ATTRIBUTE_LIST &&
+ (rl->vcn != ntfs_bytes_to_cluster(vol,
+ ni->allocated_size) ||
+ rl->length != first_free_vcn -
+ ntfs_bytes_to_cluster(vol, ni->allocated_size) ||
+ rl[1].length)) {
+ ntfs_cluster_free_from_rl(vol, rl);
+ kvfree(rl);
+ rl = ntfs_cluster_alloc(vol,
+ ntfs_bytes_to_cluster(vol,
+ ni->allocated_size),
+ first_free_vcn -
+ ntfs_bytes_to_cluster(vol,
+ ni->allocated_size),
+ lcn_seek_from, DATA_ZONE, false,
+ false, false);
+ if (IS_ERR(rl))
+ return PTR_ERR(rl);
+ }
}
if (!NInoCompressed(ni)) {
@@ -4916,7 +4942,8 @@ int ntfs_attr_expand(struct ntfs_inode *ni, const s64 newsize, const s64 preallo
ntfs_debug("Entering for inode 0x%llx, attr 0x%x, size %lld\n",
(unsigned long long)ni->mft_no, ni->type, newsize);
- if (ni->data_size == newsize) {
+ if (ni->data_size == newsize &&
+ (!prealloc_size || prealloc_size <= ni->allocated_size)) {
ntfs_debug("Size is already ok\n");
return 0;
}
@@ -4931,7 +4958,7 @@ int ntfs_attr_expand(struct ntfs_inode *ni, const s64 newsize, const s64 preallo
}
if (NInoNonResident(ni)) {
- if (newsize > ni->data_size)
+ if (newsize > ni->data_size || prealloc_size > ni->allocated_size)
err = ntfs_non_resident_attr_expand(ni, newsize, prealloc_size,
NVolDisableSparse(ni->vol) ?
HOLES_NO : HOLES_OK, true);
diff --git a/fs/ntfs/attrlist.c b/fs/ntfs/attrlist.c
index be3086d343381..4e60f7e930102 100644
--- a/fs/ntfs/attrlist.c
+++ b/fs/ntfs/attrlist.c
@@ -12,6 +12,9 @@
#include "mft.h"
#include "attrib.h"
#include "attrlist.h"
+#include "lcnalloc.h"
+
+#define NTFS_MAX_ATTR_LIST_SIZE (256 * 1024)
/*
* ntfs_attrlist_need - check whether inode need attribute list
@@ -51,11 +54,151 @@ int ntfs_attrlist_need(struct ntfs_inode *ni)
return 0;
}
+/*
+ * Repack the $MFT/$ATTRIBUTE_LIST data into one run.
+ *
+ * The mapping pairs for an $ATTRIBUTE_LIST must remain in the base MFT
+ * record. Once that record has no room left, extending a fragmented list
+ * can require one more mapping-pairs byte than the record can hold. There
+ * is no attribute that can legally be moved out in that state: $STANDARD_
+ * INFORMATION, $ATTRIBUTE_LIST, and the first $MFT/$DATA extent all have to
+ * stay in the base record. Move the list data to one contiguous run. The
+ * caller supplies the minimum allocation size so a recovery can use the
+ * smallest useful run while normal updates can still request the maximum
+ * legal list size as a reserve.
+ */
+static int ntfs_attrlist_repack(struct inode *attr_vi,
+ struct ntfs_inode *attr_ni, s64 min_alloc_size)
+{
+ struct ntfs_volume *vol = attr_ni->vol;
+ struct runlist_element *old_rl, *new_rl;
+ u8 *data = NULL;
+ s64 data_size, alloc_size, nr_clusters, written;
+ s64 old_alloc_size;
+ size_t old_rl_count, new_rl_count;
+ unsigned long flags;
+ int err, restore_err;
+
+ if (attr_ni->mft_no != FILE_MFT || !NInoNonResident(attr_ni) ||
+ min_alloc_size < 0)
+ return -EINVAL;
+
+ err = ntfs_attr_map_whole_runlist(attr_ni);
+ if (err)
+ return err;
+
+ data_size = attr_ni->data_size;
+ if (data_size < 0)
+ return -EIO;
+
+ if (data_size) {
+ data = kvmalloc(data_size, GFP_NOFS);
+ if (!data)
+ return -ENOMEM;
+
+ written = ntfs_inode_attr_pread(attr_vi, 0, data_size, data);
+ if (written != data_size) {
+ err = written < 0 ? (int)written : -EIO;
+ goto out_free_data;
+ }
+ }
+
+ old_alloc_size = attr_ni->allocated_size;
+ alloc_size = max_t(s64, old_alloc_size, min_alloc_size);
+ nr_clusters = ntfs_bytes_to_cluster(vol,
+ alloc_size + vol->cluster_size - 1);
+ if (nr_clusters <= 0) {
+ err = -EFBIG;
+ goto out_free_data;
+ }
+
+ /* A single run keeps the mapping pairs at the minimum size. */
+ new_rl = ntfs_cluster_alloc(vol, 0, nr_clusters, -1, DATA_ZONE,
+ true, true, false);
+ if (IS_ERR(new_rl)) {
+ err = PTR_ERR(new_rl);
+ goto out_free_data;
+ }
+
+ new_rl_count = 0;
+ if (new_rl->vcn == 0 && new_rl->length == nr_clusters &&
+ !new_rl[1].length)
+ new_rl_count = 2;
+
+ if (new_rl_count != 2) {
+ ntfs_cluster_free_from_rl(vol, new_rl);
+ kvfree(new_rl);
+ err = -ENOSPC;
+ goto out_free_data;
+ }
+
+ old_rl = attr_ni->runlist.rl;
+ old_rl_count = attr_ni->runlist.count;
+ down_write(&attr_ni->runlist.lock);
+ attr_ni->runlist.rl = new_rl;
+ attr_ni->runlist.count = new_rl_count;
+ up_write(&attr_ni->runlist.lock);
+
+ write_lock_irqsave(&attr_ni->size_lock, flags);
+ attr_ni->allocated_size = ntfs_cluster_to_bytes(vol, nr_clusters);
+ write_unlock_irqrestore(&attr_ni->size_lock, flags);
+
+ /* Populate the replacement extent before publishing its mapping pairs. */
+ if (data_size) {
+ written = ntfs_inode_attr_pwrite(attr_vi, 0, data_size, data, true);
+ if (written != data_size) {
+ err = written < 0 ? (int)written : -EIO;
+ goto restore_old_runlist;
+ }
+ }
+
+ err = ntfs_attr_update_mapping_pairs(attr_ni, 0);
+ if (err)
+ goto restore_old_runlist;
+
+ /* The new mapping is now authoritative; release the old data runs. */
+ if (ntfs_cluster_free_from_rl(vol, old_rl)) {
+ ntfs_error(vol->sb,
+ "Failed to free old ATTRIBUTE_LIST extent: inode %#llx",
+ (long long)attr_ni->mft_no);
+ NVolSetErrors(vol);
+ }
+ kvfree(old_rl);
+ kvfree(data);
+ return 0;
+
+restore_old_runlist:
+ down_write(&attr_ni->runlist.lock);
+ attr_ni->runlist.rl = old_rl;
+ attr_ni->runlist.count = old_rl_count;
+ up_write(&attr_ni->runlist.lock);
+
+ write_lock_irqsave(&attr_ni->size_lock, flags);
+ attr_ni->allocated_size = old_alloc_size;
+ write_unlock_irqrestore(&attr_ni->size_lock, flags);
+
+ restore_err = ntfs_attr_update_mapping_pairs(attr_ni, 0);
+ if (restore_err) {
+ ntfs_error(vol->sb, "Failed to restore ATTRIBUTE_LIST mapping pairs (%d)",
+ restore_err);
+ NVolSetErrors(vol);
+ }
+
+ ntfs_cluster_free_from_rl(vol, new_rl);
+ kvfree(new_rl);
+ err = err ? err : restore_err;
+
+out_free_data:
+ kvfree(data);
+ return err;
+}
+
int ntfs_attrlist_update(struct ntfs_inode *base_ni)
{
struct inode *attr_vi;
struct ntfs_inode *attr_ni;
- int err;
+ s64 written;
+ int err, retry_err;
/*
* generic_shutdown_super() clears SB_ACTIVE before evicting cached
@@ -74,21 +217,55 @@ int ntfs_attrlist_update(struct ntfs_inode *base_ni)
attr_ni = NTFS_I(attr_vi);
err = ntfs_attr_truncate_i(attr_ni, base_ni->attr_list_size, HOLES_NO);
- if (err == -ENOSPC && attr_ni->mft_no == FILE_MFT) {
- err = ntfs_attr_truncate(attr_ni, 0);
- if (err || ntfs_attr_truncate_i(attr_ni, base_ni->attr_list_size, HOLES_NO) != 0) {
+ if (err == -ENOSPC && attr_ni->mft_no == FILE_MFT &&
+ NInoNonResident(attr_ni)) {
+ retry_err = ntfs_attrlist_repack(attr_vi, attr_ni,
+ base_ni->attr_list_size);
+ if (retry_err) {
+ ntfs_error(base_ni->vol->sb, "Failed to repack attribute list");
iput(attr_vi);
+ return retry_err;
+ }
+
+ retry_err = ntfs_attr_truncate_i(attr_ni, base_ni->attr_list_size,
+ HOLES_NO);
+ if (retry_err) {
ntfs_error(base_ni->vol->sb,
- "Failed to truncate attribute list of inode %#llx",
- (long long)base_ni->mft_no);
- return -EIO;
+ "Failed to resize attribute list after repack");
+ iput(attr_vi);
+ return retry_err;
}
} else if (err) {
iput(attr_vi);
ntfs_error(base_ni->vol->sb,
"Failed to truncate attribute list of inode %#llx",
(long long)base_ni->mft_no);
- return -EIO;
+ return err;
+ }
+
+ /*
+ * Reserve the maximum legal list size while the MFT metadata area is
+ * still easy to allocate contiguously. This prevents a later list entry
+ * from needing another mapping-pairs byte in the full base MFT record.
+ * Failure to obtain the optional reserve must not reject the current
+ * metadata update; the repack retry above remains available if needed.
+ */
+ if (base_ni->mft_no == FILE_MFT && NInoNonResident(attr_ni) &&
+ attr_ni->allocated_size < NTFS_MAX_ATTR_LIST_SIZE) {
+ retry_err = ntfs_attr_expand(attr_ni, base_ni->attr_list_size,
+ NTFS_MAX_ATTR_LIST_SIZE);
+ if (retry_err == -ENOSPC) {
+ retry_err = ntfs_attrlist_repack(attr_vi, attr_ni,
+ NTFS_MAX_ATTR_LIST_SIZE);
+ if (retry_err == -ENOSPC)
+ retry_err = 0;
+ }
+ if (retry_err) {
+ ntfs_error(base_ni->vol->sb,
+ "Failed to reserve attribute list space");
+ iput(attr_vi);
+ return retry_err;
+ }
}
i_size_write(attr_vi, base_ni->attr_list_size);
@@ -96,14 +273,15 @@ int ntfs_attrlist_update(struct ntfs_inode *base_ni)
if (NInoNonResident(attr_ni) && !NInoAttrListNonResident(base_ni))
NInoSetAttrListNonResident(base_ni);
- if (ntfs_inode_attr_pwrite(attr_vi, 0, base_ni->attr_list_size,
- base_ni->attr_list, false) !=
- base_ni->attr_list_size) {
+ written = ntfs_inode_attr_pwrite(attr_vi, 0, base_ni->attr_list_size,
+ base_ni->attr_list, false);
+ if (written != base_ni->attr_list_size) {
+ err = written < 0 ? (int)written : -EIO;
iput(attr_vi);
ntfs_error(base_ni->vol->sb,
"Failed to write attribute list of inode %#llx",
(long long)base_ni->mft_no);
- return -EIO;
+ return err;
}
NInoSetAttrListDirty(base_ni);
diff --git a/fs/ntfs/inode.c b/fs/ntfs/inode.c
index f40f35afcda9a..cc5818d50e3e8 100644
--- a/fs/ntfs/inode.c
+++ b/fs/ntfs/inode.c
@@ -3745,6 +3745,7 @@ static s64 __ntfs_inode_non_resident_attr_pwrite(struct inode *vi,
u64 rl_length = 0;
s64 vcn;
struct runlist_element *rl;
+ int bio_err;
lcn_count = max_t(s64, 1, ntfs_bytes_to_cluster(vol, attr_len));
vcn = ntfs_pidx_to_cluster(vol, folio->index);
@@ -3788,8 +3789,15 @@ static s64 __ntfs_inode_non_resident_attr_pwrite(struct inode *vi,
goto err_unlock_folio;
}
- submit_bio_wait(bio);
+ bio_err = submit_bio_wait(bio);
bio_put(bio);
+ if (bio_err) {
+ ntfs_error(vi->i_sb,
+ "Synchronous attribute write failed (%d)",
+ bio_err);
+ ret = bio_err;
+ goto err_unlock_folio;
+ }
vcn += rl_length;
offset += length;
} while (lcn_count != 0);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 068/398] wifi: cfg80211: restore netns_immutable on failures
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (66 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 067/398] wifi: mac80211: reset state when starting AP fails Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 069/398] wifi: cfg80211: undo netns switch if renaming the wiphy fails Greg Kroah-Hartman
` (334 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit eeee52cfd1d639774c9812e8890631404a057dd2 ]
Switching a wiphy's netns has to clear netns_immutable before moving
interfaces, but then if any of the interfaces fails to move, it gets
netns_immutable cleared forever. Then userspace can move it by itself,
breaking the assumption that they all move together.
Fix the order here and always reset netns_immutable after attempting
the move.
Assisted-by: LLM
Fixes: 463d018323851 ("cfg80211: make aware of net namespaces")
Link: https://patch.msgid.link/20260904170220.7ea88157dcbc.Id868585a790be8b9ece9b39b0db464a5963faaf3@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/wireless/core.c b/net/wireless/core.c
index 55abf5a203338..3c11f35f957db 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -164,9 +164,9 @@ int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
continue;
wdev->netdev->netns_immutable = false;
err = dev_change_net_namespace(wdev->netdev, net, "wlan%d");
+ wdev->netdev->netns_immutable = true;
if (err)
break;
- wdev->netdev->netns_immutable = true;
}
if (err) {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 122/438] ntfs: account for MFT records added during allocation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (120 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 121/438] ntfs: repack $MFT/$ATTRIBUTE LIST Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 123/438] ntfs: protect runlist updates with the runlist lock Greg Kroah-Hartman
` (327 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hyunchul Lee, Namjae Jeon,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 631946431ddc66a472c5cc629cd654e62dfa1f88 ]
When no free MFT record is available in the initialized $MFT/$BITMAP,
ntfs_mft_record_alloc() extends $MFT/$DATA and formats the requested record
together with a dynamically sized tail reserve. Those records become
visible through the $MFT file size before charging the requested record to
the free-record counter.
Account for all newly visible records before releasing the MFT allocation
lock, then subtract the one record being allocated. Keep MFT counter
updates independent of the asynchronous free-cluster scan and update the
counter when a record is successfully cleared in the MFT bitmap.
Store the clamped result of the MFT bitmap scan and keep statfs from
exposing an invalid cached count if an accounting error occurs.
Fixes: 115380f9a2f9 ("ntfs: update mft operations")
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs/mft.c | 11 ++++++++---
fs/ntfs/super.c | 12 +++++++++---
fs/ntfs/volume.h | 6 ------
3 files changed, 17 insertions(+), 12 deletions(-)
diff --git a/fs/ntfs/mft.c b/fs/ntfs/mft.c
index 5fae9ad03858e..ed3aa4c423e81 100644
--- a/fs/ntfs/mft.c
+++ b/fs/ntfs/mft.c
@@ -1539,7 +1539,6 @@ static int ntfs_mft_bitmap_extend_initialized_nolock(struct ntfs_volume *vol)
ret = ntfs_attr_set(mftbmp_ni, old_initialized_size, 8, 0);
if (likely(!ret)) {
ntfs_debug("Done. (Wrote eight initialized bytes to mft bitmap.");
- ntfs_inc_free_mft_records(vol, 8 * 8);
return 0;
}
ntfs_error(vol->sb, "Failed to write to mft bitmap.");
@@ -2135,6 +2134,7 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
struct mft_record **ni_mrec, const s64 mft_data_vcn)
{
s64 ll, bit, old_data_initialized, old_data_size;
+ s64 nr_new_mft_records = 0;
s64 max_mft_no = -1, reserve_start = -1, reserve_end = -1;
s64 candidate_reserve_end = -1;
s64 *reserve_endp;
@@ -2501,8 +2501,13 @@ int ntfs_mft_record_alloc(struct ntfs_volume *vol, const int mode,
mft_ni->initialized_size);
WARN_ON(i_size_read(vol->mft_ino) > mft_ni->allocated_size);
WARN_ON(mft_ni->initialized_size > i_size_read(vol->mft_ino));
+ nr_new_mft_records = (i_size_read(vol->mft_ino) - old_data_size) >>
+ vol->mft_record_size_bits;
read_unlock_irqrestore(&mft_ni->size_lock, flags);
mft_rec_already_initialized:
+ /* Account for newly visible MFT records before dropping the lock. */
+ if (nr_new_mft_records > 0)
+ ntfs_inc_free_mft_records(vol, nr_new_mft_records);
/*
* We can finally drop the mft bitmap lock as the mft data attribute
* has been fully updated. The only disparity left is that the
@@ -2814,6 +2819,8 @@ int ntfs_mft_record_free(struct ntfs_volume *vol, struct ntfs_inode *ni)
if (base_ni->mft_no != FILE_MFT)
down_write(&vol->mftbmp_lock);
err = ntfs_bitmap_clear_bit(vol->mftbmp_ino, mft_no);
+ if (!err)
+ ntfs_inc_free_mft_records(vol, 1);
if (!err && base_ni->mft_no == FILE_MFT &&
mft_no + 1 == vol->mft_record_reserve_pos &&
mft_no < vol->mft_record_reserve_end)
@@ -2823,9 +2830,7 @@ int ntfs_mft_record_free(struct ntfs_volume *vol, struct ntfs_inode *ni)
memalloc_nofs_restore(memalloc_flags);
if (err)
goto bitmap_rollback;
-
unmap_mft_record(ni);
- ntfs_inc_free_mft_records(vol, 1);
return 0;
/* Rollback what we did... */
diff --git a/fs/ntfs/super.c b/fs/ntfs/super.c
index 63aa83ff77f5d..b5371d269f747 100644
--- a/fs/ntfs/super.c
+++ b/fs/ntfs/super.c
@@ -2064,8 +2064,7 @@ static unsigned long __get_nr_free_mft_records(struct ntfs_volume *vol,
/* If errors occurred we may well have gone below zero, fix this. */
if (nr_free < 0)
nr_free = 0;
- else
- atomic64_set(&vol->free_mft_records, nr_free);
+ atomic64_set(&vol->free_mft_records, nr_free);
ntfs_debug("Exiting.");
return nr_free;
@@ -2131,7 +2130,14 @@ static int ntfs_statfs(struct dentry *dentry, struct kstatfs *sfs)
read_unlock_irqrestore(&mft_ni->size_lock, flags);
/* Free inodes in fs (based on current total count). */
- sfs->f_ffree = atomic64_read(&vol->free_mft_records);
+ size = atomic64_read(&vol->free_mft_records);
+ if (unlikely(size < 0 || size > (s64)sfs->f_files))
+ ntfs_warning(vol->sb, "Invalid free MFT record count %lld.", size);
+ if (size < 0)
+ size = 0;
+ else if (size > (s64)sfs->f_files)
+ size = sfs->f_files;
+ sfs->f_ffree = size;
/*
* File system id. This is extremely *nix flavour dependent and even
diff --git a/fs/ntfs/volume.h b/fs/ntfs/volume.h
index 2b60d14fc7ef5..bc85a95922458 100644
--- a/fs/ntfs/volume.h
+++ b/fs/ntfs/volume.h
@@ -258,17 +258,11 @@ static inline void ntfs_dec_free_clusters(struct ntfs_volume *vol, s64 nr)
static inline void ntfs_inc_free_mft_records(struct ntfs_volume *vol, s64 nr)
{
- if (!NVolFreeClusterKnown(vol))
- return;
-
atomic64_add(nr, &vol->free_mft_records);
}
static inline void ntfs_dec_free_mft_records(struct ntfs_volume *vol, s64 nr)
{
- if (!NVolFreeClusterKnown(vol))
- return;
-
atomic64_sub(nr, &vol->free_mft_records);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 069/398] wifi: cfg80211: undo netns switch if renaming the wiphy fails
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (67 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 068/398] wifi: cfg80211: restore netns_immutable on failures Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 070/398] wifi: mac80211: unlist vifs when their netdev is unregistered Greg Kroah-Hartman
` (333 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+3515319a302224e081b4,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit a41bd1938a9bfe226d444172a7e20e4bd5097960 ]
Once all the interfaces have been moved, cfg80211_switch_netns()
moves the wiphy itself by setting its network namespace and then
renaming it, which makes sysfs move it. The rename can fail (but
only on allocation failures), leaving things mixed up and hitting
the warning there.
Ignoring it isn't great, undo the move and let the change fail
in this case. If undo fails then WARN, then things would again
be stuck in two different network namespaces.
Assisted-by: LLM
Reported-by: syzbot+3515319a302224e081b4@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=3515319a302224e081b4
Fixes: 463d018323851 ("cfg80211: make aware of net namespaces")
Link: https://patch.msgid.link/20260904170220.7966cc705e33.Ib398351113bbd3cab85302467060cab378564421@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/core.c | 88 +++++++++++++++++++++++++--------------------
1 file changed, 50 insertions(+), 38 deletions(-)
diff --git a/net/wireless/core.c b/net/wireless/core.c
index 3c11f35f957db..c38a737171569 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -150,9 +150,25 @@ int cfg80211_dev_rename(struct cfg80211_registered_device *rdev,
return 0;
}
+static int cfg80211_switch_wdev_netns(struct wireless_dev *wdev,
+ struct net *net)
+{
+ int err;
+
+ if (!wdev->netdev)
+ return 0;
+
+ wdev->netdev->netns_immutable = false;
+ err = dev_change_net_namespace(wdev->netdev, net, "wlan%d");
+ wdev->netdev->netns_immutable = true;
+
+ return err;
+}
+
int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
struct net *net)
{
+ struct net *old_net = wiphy_net(&rdev->wiphy);
struct wireless_dev *wdev;
int err = 0;
@@ -160,58 +176,54 @@ int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
return -EOPNOTSUPP;
list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
- if (!wdev->netdev)
- continue;
- wdev->netdev->netns_immutable = false;
- err = dev_change_net_namespace(wdev->netdev, net, "wlan%d");
- wdev->netdev->netns_immutable = true;
+ err = cfg80211_switch_wdev_netns(wdev, net);
if (err)
- break;
+ goto undo;
}
- if (err) {
- /* failed -- clean up to old netns */
- net = wiphy_net(&rdev->wiphy);
-
- list_for_each_entry_continue_reverse(wdev,
- &rdev->wiphy.wdev_list,
- list) {
+ scoped_guard(wiphy, &rdev->wiphy) {
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
if (!wdev->netdev)
continue;
- wdev->netdev->netns_immutable = false;
- err = dev_change_net_namespace(wdev->netdev, net,
- "wlan%d");
- WARN_ON(err);
- wdev->netdev->netns_immutable = true;
+ nl80211_notify_iface(rdev, wdev,
+ NL80211_CMD_DEL_INTERFACE);
}
- return err;
- }
+ nl80211_notify_wiphy(rdev, NL80211_CMD_DEL_WIPHY);
- guard(wiphy)(&rdev->wiphy);
+ wiphy_net_set(&rdev->wiphy, net);
- list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
- if (!wdev->netdev)
- continue;
- nl80211_notify_iface(rdev, wdev, NL80211_CMD_DEL_INTERFACE);
- }
-
- nl80211_notify_wiphy(rdev, NL80211_CMD_DEL_WIPHY);
+ /* this only fails on allocation failure */
+ err = device_rename(&rdev->wiphy.dev,
+ dev_name(&rdev->wiphy.dev));
+ if (err)
+ wiphy_net_set(&rdev->wiphy, old_net);
- wiphy_net_set(&rdev->wiphy, net);
+ nl80211_notify_wiphy(rdev, NL80211_CMD_NEW_WIPHY);
- err = device_rename(&rdev->wiphy.dev, dev_name(&rdev->wiphy.dev));
- WARN_ON(err);
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ if (!wdev->netdev)
+ continue;
+ nl80211_notify_iface(rdev, wdev,
+ NL80211_CMD_NEW_INTERFACE);
+ }
+ }
- nl80211_notify_wiphy(rdev, NL80211_CMD_NEW_WIPHY);
+ if (!err)
+ return 0;
- list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
- if (!wdev->netdev)
- continue;
- nl80211_notify_iface(rdev, wdev, NL80211_CMD_NEW_INTERFACE);
- }
+ /* set to the last one to undo all of them */
+ wdev = list_entry(&rdev->wiphy.wdev_list, typeof(*wdev), list);
+undo:
+ /*
+ * Move back everything, if this fails again (allocation failures)
+ * then things get stuck in different network namespaces.
+ */
+ list_for_each_entry_continue_reverse(wdev, &rdev->wiphy.wdev_list,
+ list)
+ WARN_ON(cfg80211_switch_wdev_netns(wdev, old_net));
- return 0;
+ return err;
}
static void cfg80211_rfkill_poll(struct rfkill *rfkill, void *data)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 123/438] ntfs: protect runlist updates with the runlist lock
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (121 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 122/438] ntfs: account for MFT records added during allocation Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 124/438] ntfs: propagate folio errors Greg Kroah-Hartman
` (326 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hyunchul Lee, Namjae Jeon,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 91709ba5d6d709b2b663287b7e871e2c6b480502 ]
ntfs_non_resident_attr_shrink() calls runlist helpers that require the
runlist write lock, but did not hold it while freeing clusters and
truncating the runlist. Serialize those operations and the resident
conversion with the runlist lock.
ntfs_attr_map_cluster() can merge a newly allocated run before updating
mapping pairs. If the update fails, free the clusters and restore both
the in-memory runlist and on-disk mapping pairs from a saved runlist.
Mark the volume in error if either rollback step fails.
Fixes: 495e90fa3348 ("ntfs: update attrib operations")
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs/attrib.c | 205 +++++++++++++++++++++++++++++++++++----------
fs/ntfs/attrib.h | 9 ++
fs/ntfs/attrlist.c | 46 ++++++----
fs/ntfs/attrlist.h | 2 +
fs/ntfs/compress.c | 2 +-
fs/ntfs/file.c | 3 +-
fs/ntfs/inode.c | 2 +-
fs/ntfs/mft.c | 13 +--
8 files changed, 216 insertions(+), 66 deletions(-)
diff --git a/fs/ntfs/attrib.c b/fs/ntfs/attrib.c
index 34c4044b59af2..b10ef76c98f33 100644
--- a/fs/ntfs/attrib.c
+++ b/fs/ntfs/attrib.c
@@ -3569,7 +3569,8 @@ int ntfs_attr_record_move_away(struct ntfs_attr_search_ctx *ctx, int extra)
* update allocated and compressed size.
*/
static int ntfs_attr_update_meta(struct attr_record *a, struct ntfs_inode *ni,
- struct mft_record *m, struct ntfs_attr_search_ctx *ctx)
+ struct mft_record *m, struct ntfs_attr_search_ctx *ctx,
+ struct ntfs_inode *locked_ni, bool defer_attrlist)
{
int sparse, err = 0;
struct ntfs_inode *base_ni;
@@ -3605,6 +3606,8 @@ static int ntfs_attr_update_meta(struct attr_record *a, struct ntfs_inode *ni,
le16_to_cpu(a->data.non_resident.mapping_pairs_offset) == 8) &&
!(le32_to_cpu(m->bytes_allocated) - le32_to_cpu(m->bytes_in_use))) {
+ if (defer_attrlist)
+ return -ENOSPC;
if (!NInoAttrList(base_ni)) {
err = ntfs_inode_add_attrlist(base_ni);
if (err)
@@ -3618,7 +3621,7 @@ static int ntfs_attr_update_meta(struct attr_record *a, struct ntfs_inode *ni,
goto out;
}
- err = ntfs_attrlist_update(base_ni);
+ err = ntfs_attrlist_update_locked(base_ni, locked_ni);
if (err)
goto out;
err = -EAGAIN;
@@ -3698,6 +3701,8 @@ static int ntfs_attr_update_meta(struct attr_record *a, struct ntfs_inode *ni,
* ntfs_attr_update_mapping_pairs - update mapping pairs for ntfs attribute
* @ni: non-resident ntfs inode for which we need update
* @from_vcn: update runlist starting this VCN
+ * @locked_ni: inode whose runlist write lock is already held
+ * @defer_attrlist: return -ENOSPC instead of updating an attribute list
*
* Build mapping pairs from @na->rl and write them to the disk. Also, this
* function updates sparse bit, allocated and compressed size (allocates/frees
@@ -3707,7 +3712,10 @@ static int ntfs_attr_update_meta(struct attr_record *a, struct ntfs_inode *ni,
* call to this function. Vice-versa @na->compressed_size will be calculated and
* set to correct value during this function.
*/
-int ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni, s64 from_vcn)
+static int __ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni,
+ s64 from_vcn,
+ struct ntfs_inode *locked_ni,
+ bool defer_attrlist)
{
struct ntfs_attr_search_ctx *ctx;
struct ntfs_inode *base_ni;
@@ -3799,7 +3807,8 @@ int ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni, s64 from_vcn)
continue;
}
- err = ntfs_attr_update_meta(a, ni, m, ctx);
+ err = ntfs_attr_update_meta(a, ni, m, ctx, locked_ni,
+ defer_attrlist);
if (err < 0) {
if (err == -EAGAIN) {
ntfs_attr_put_search_ctx(ctx);
@@ -3839,11 +3848,17 @@ int ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni, s64 from_vcn)
*/
if (ni->type == AT_ATTRIBUTE_LIST) {
ntfs_attr_put_search_ctx(ctx);
+ ctx = NULL;
+ if (locked_ni == ni || defer_attrlist) {
+ err = -ENOSPC;
+ goto put_err_out;
+ }
err = ntfs_inode_free_space(base_ni, mp_size -
cur_max_mp_size);
if (err)
return err;
- err = ntfs_attrlist_update(base_ni);
+ err = ntfs_attrlist_update_locked(
+ base_ni, locked_ni);
if (err)
return err;
goto retry;
@@ -3851,6 +3866,10 @@ int ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni, s64 from_vcn)
/* Add attribute list if it isn't present, and retry. */
if (!NInoAttrList(base_ni)) {
+ if (defer_attrlist) {
+ err = -ENOSPC;
+ goto put_err_out;
+ }
ntfs_attr_put_search_ctx(ctx);
if (ntfs_inode_add_attrlist(base_ni)) {
ntfs_error(sb, "Can not add attrlist");
@@ -3878,13 +3897,21 @@ int ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni, s64 from_vcn)
}
}
+ if (defer_attrlist &&
+ (ctx->ntfs_ino->nr_extents == -1 ||
+ NInoAttrList(ctx->ntfs_ino)) &&
+ ctx->attr->type != AT_ATTRIBUTE_LIST) {
+ err = -ENOSPC;
+ goto put_err_out;
+ }
+
/* Update lowest vcn. */
a->data.non_resident.lowest_vcn = cpu_to_le64(stop_vcn);
mark_mft_record_dirty(ctx->ntfs_ino);
if ((ctx->ntfs_ino->nr_extents == -1 || NInoAttrList(ctx->ntfs_ino)) &&
ctx->attr->type != AT_ATTRIBUTE_LIST) {
ctx->al_entry->lowest_vcn = cpu_to_le64(stop_vcn);
- err = ntfs_attrlist_update(base_ni);
+ err = ntfs_attrlist_update_locked(base_ni, locked_ni);
if (err)
goto put_err_out;
}
@@ -4059,6 +4086,19 @@ int ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni, s64 from_vcn)
return err;
}
+int ntfs_attr_update_mapping_pairs_locked(struct ntfs_inode *ni,
+ s64 from_vcn,
+ struct ntfs_inode *locked_ni)
+{
+ return __ntfs_attr_update_mapping_pairs(ni, from_vcn, locked_ni,
+ false);
+}
+
+int ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni, s64 from_vcn)
+{
+ return ntfs_attr_update_mapping_pairs_locked(ni, from_vcn, NULL);
+}
+
/*
* ntfs_attr_make_resident - convert a non-resident to a resident attribute
* @ni: open ntfs attribute to make resident
@@ -4192,7 +4232,9 @@ static int ntfs_attr_make_resident(struct ntfs_inode *ni, struct ntfs_attr_searc
*
* Reduce the size of a non-resident, open ntfs attribute @na to @newsize bytes.
*/
-static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni, const s64 newsize)
+static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni,
+ const s64 newsize,
+ struct ntfs_inode *locked_ni)
{
struct ntfs_volume *vol;
struct ntfs_attr_search_ctx *ctx;
@@ -4200,6 +4242,7 @@ static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni, const s64 newsiz
s64 nr_freed_clusters;
int err;
struct ntfs_inode *base_ni;
+ bool runlist_locked = locked_ni == ni;
ntfs_debug("Inode 0x%llx attr 0x%x new size %lld\n",
(unsigned long long)ni->mft_no, ni->type, (long long)newsize);
@@ -4245,18 +4288,24 @@ static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni, const s64 newsiz
* clusters if there is a change.
*/
if (ntfs_bytes_to_cluster(vol, ni->allocated_size) != first_free_vcn) {
- struct ntfs_attr_search_ctx *ctx;
+ /*
+ * ntfs_cluster_free() and ntfs_rl_truncate_nolock()
+ * both require this lock.
+ */
+ if (!runlist_locked)
+ down_write(&ni->runlist.lock);
err = ntfs_attr_map_whole_runlist(ni);
if (err) {
ntfs_debug("Eeek! ntfs_attr_map_whole_runlist failed.\n");
- return err;
+ goto unlock_runlist;
}
ctx = ntfs_attr_get_search_ctx(ni, NULL);
if (!ctx) {
ntfs_error(vol->sb, "%s: Failed to get search context", __func__);
- return -ENOMEM;
+ err = -ENOMEM;
+ goto unlock_runlist;
}
/* Deallocate all clusters starting with the first free one. */
@@ -4264,7 +4313,8 @@ static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni, const s64 newsiz
if (nr_freed_clusters < 0) {
ntfs_debug("Eeek! Freeing of clusters failed. Aborting...\n");
ntfs_attr_put_search_ctx(ctx);
- return (int)nr_freed_clusters;
+ err = (int)nr_freed_clusters;
+ goto unlock_runlist;
}
ntfs_attr_put_search_ctx(ctx);
@@ -4277,7 +4327,8 @@ static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni, const s64 newsiz
kvfree(ni->runlist.rl);
ni->runlist.rl = NULL;
ntfs_error(vol->sb, "Eeek! Run list truncation failed.\n");
- return -EIO;
+ err = -EIO;
+ goto unlock_runlist;
}
/* Prepare to mapping pairs update. */
@@ -4293,11 +4344,13 @@ static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni, const s64 newsiz
VFS_I(base_ni)->i_blocks = ni->allocated_size >> 9;
/* Write mapping pairs for new runlist. */
- err = ntfs_attr_update_mapping_pairs(ni, 0 /*first_free_vcn*/);
+ err = ntfs_attr_update_mapping_pairs_locked(ni, 0, ni);
if (err) {
ntfs_debug("Eeek! Mapping pairs update failed. Leaving inconstant metadata. Run chkdsk.\n");
- return err;
+ goto unlock_runlist;
}
+ if (!runlist_locked)
+ up_write(&ni->runlist.lock);
}
/* Get the first attribute record. */
@@ -4339,7 +4392,11 @@ static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni, const s64 newsiz
/* If the attribute now has zero size, make it resident. */
if (!newsize && !NInoEncrypted(ni) && !NInoCompressed(ni)) {
+ if (!runlist_locked)
+ down_write(&ni->runlist.lock);
err = ntfs_attr_make_resident(ni, ctx);
+ if (!runlist_locked)
+ up_write(&ni->runlist.lock);
if (err) {
/* If couldn't make resident, just continue. */
if (err != -EPERM)
@@ -4356,6 +4413,11 @@ static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni, const s64 newsiz
put_err_out:
ntfs_attr_put_search_ctx(ctx);
return err;
+
+unlock_runlist:
+ if (!runlist_locked)
+ up_write(&ni->runlist.lock);
+ return err;
}
/*
@@ -4364,13 +4426,14 @@ static int ntfs_non_resident_attr_shrink(struct ntfs_inode *ni, const s64 newsiz
* @prealloc_size: preallocation size (in bytes) to which to expand the attribute
* @newsize: new size (in bytes) to which to expand the attribute
* @holes: how to create a hole if expanding
- * @need_lock: whether mrec lock is needed or not
+ * @locked_ni: inode whose runlist lock is already held
*
* Expand the size of a non-resident, open ntfs attribute @na to @newsize bytes,
* by allocating new clusters.
*/
static int ntfs_non_resident_attr_expand(struct ntfs_inode *ni, const s64 newsize,
- const s64 prealloc_size, unsigned int holes, bool need_lock)
+ const s64 prealloc_size, unsigned int holes,
+ struct ntfs_inode *locked_ni)
{
s64 lcn_seek_from;
s64 first_free_vcn;
@@ -4568,7 +4631,8 @@ static int ntfs_non_resident_attr_expand(struct ntfs_inode *ni, const s64 newsiz
/* Prepare to mapping pairs update. */
ni->allocated_size = ntfs_cluster_to_bytes(vol, first_free_vcn);
- err = ntfs_attr_update_mapping_pairs(ni, 0);
+ err = ntfs_attr_update_mapping_pairs_locked(
+ ni, 0, locked_ni);
if (err) {
ntfs_debug("Mapping pairs update failed");
goto rollback;
@@ -4612,11 +4676,11 @@ static int ntfs_non_resident_attr_expand(struct ntfs_inode *ni, const s64 newsiz
ntfs_debug("Leaking clusters");
/* Now, truncate the runlist itself. */
- if (need_lock)
+ if (ni != locked_ni)
down_write(&ni->runlist.lock);
err2 = ntfs_rl_truncate_nolock(vol, &ni->runlist,
ntfs_bytes_to_cluster(vol, org_alloc_size));
- if (need_lock)
+ if (ni != locked_ni)
up_write(&ni->runlist.lock);
if (err2) {
/*
@@ -4630,11 +4694,11 @@ static int ntfs_non_resident_attr_expand(struct ntfs_inode *ni, const s64 newsiz
/* Prepare to mapping pairs update. */
ni->allocated_size = org_alloc_size;
/* Restore mapping pairs. */
- if (need_lock)
+ if (ni != locked_ni)
down_read(&ni->runlist.lock);
- if (ntfs_attr_update_mapping_pairs(ni, 0))
+ if (__ntfs_attr_update_mapping_pairs(ni, 0, locked_ni, true))
ntfs_error(sb, "Failed to restore old mapping pairs");
- if (need_lock)
+ if (ni != locked_ni)
up_read(&ni->runlist.lock);
if (NInoSparse(ni) || NInoCompressed(ni)) {
@@ -4739,7 +4803,8 @@ static int ntfs_resident_attr_resize(struct ntfs_inode *attr_ni, const s64 newsi
mark_mft_record_dirty(ctx->ntfs_ino);
ntfs_attr_put_search_ctx(ctx);
/* Resize non-resident attribute */
- return ntfs_non_resident_attr_expand(attr_ni, newsize, prealloc_size, holes, true);
+ return ntfs_non_resident_attr_expand(
+ attr_ni, newsize, prealloc_size, holes, NULL);
} else if (err != -ENOSPC && err != -EPERM) {
ntfs_error(sb, "Failed to make attribute non-resident");
goto put_err_out;
@@ -4914,13 +4979,14 @@ int __ntfs_attr_truncate_vfs(struct ntfs_inode *ni, const s64 newsize,
if (NInoNonResident(ni)) {
if (newsize > i_size) {
down_write(&ni->runlist.lock);
- err = ntfs_non_resident_attr_expand(ni, newsize, 0,
- NVolDisableSparse(ni->vol) ?
- HOLES_NO : HOLES_OK,
- false);
+ err = ntfs_non_resident_attr_expand(
+ ni, newsize, 0,
+ NVolDisableSparse(ni->vol) ?
+ HOLES_NO : HOLES_OK, ni);
up_write(&ni->runlist.lock);
} else
- err = ntfs_non_resident_attr_shrink(ni, newsize);
+ err = ntfs_non_resident_attr_shrink(
+ ni, newsize, NULL);
} else
err = ntfs_resident_attr_resize(ni, newsize, 0,
NVolDisableSparse(ni->vol) ?
@@ -4929,7 +4995,9 @@ int __ntfs_attr_truncate_vfs(struct ntfs_inode *ni, const s64 newsize,
return err;
}
-int ntfs_attr_expand(struct ntfs_inode *ni, const s64 newsize, const s64 prealloc_size)
+int ntfs_attr_expand_locked(struct ntfs_inode *ni, const s64 newsize,
+ const s64 prealloc_size,
+ struct ntfs_inode *locked_ni)
{
int err = 0;
@@ -4959,9 +5027,10 @@ int ntfs_attr_expand(struct ntfs_inode *ni, const s64 newsize, const s64 preallo
if (NInoNonResident(ni)) {
if (newsize > ni->data_size || prealloc_size > ni->allocated_size)
- err = ntfs_non_resident_attr_expand(ni, newsize, prealloc_size,
- NVolDisableSparse(ni->vol) ?
- HOLES_NO : HOLES_OK, true);
+ err = ntfs_non_resident_attr_expand(
+ ni, newsize, prealloc_size,
+ NVolDisableSparse(ni->vol) ?
+ HOLES_NO : HOLES_OK, locked_ni);
} else
err = ntfs_resident_attr_resize(ni, newsize, prealloc_size,
NVolDisableSparse(ni->vol) ?
@@ -4972,6 +5041,12 @@ int ntfs_attr_expand(struct ntfs_inode *ni, const s64 newsize, const s64 preallo
return err;
}
+int ntfs_attr_expand(struct ntfs_inode *ni, const s64 newsize,
+ const s64 prealloc_size)
+{
+ return ntfs_attr_expand_locked(ni, newsize, prealloc_size, NULL);
+}
+
/*
* ntfs_attr_truncate_i - resize an ntfs attribute
* @ni: open ntfs inode to resize
@@ -4984,7 +5059,9 @@ int ntfs_attr_expand(struct ntfs_inode *ni, const s64 newsize, const s64 preallo
* newly allocated space is marked as not initialised and no real allocation
* on disk is performed.
*/
-int ntfs_attr_truncate_i(struct ntfs_inode *ni, const s64 newsize, unsigned int holes)
+int ntfs_attr_truncate_i_locked(struct ntfs_inode *ni, const s64 newsize,
+ unsigned int holes,
+ struct ntfs_inode *locked_ni)
{
int err;
@@ -5018,15 +5095,23 @@ int ntfs_attr_truncate_i(struct ntfs_inode *ni, const s64 newsize, unsigned int
if (NInoNonResident(ni)) {
if (newsize > ni->data_size)
- err = ntfs_non_resident_attr_expand(ni, newsize, 0, holes, true);
+ err = ntfs_non_resident_attr_expand(
+ ni, newsize, 0, holes, locked_ni);
else
- err = ntfs_non_resident_attr_shrink(ni, newsize);
+ err = ntfs_non_resident_attr_shrink(
+ ni, newsize, locked_ni);
} else
err = ntfs_resident_attr_resize(ni, newsize, 0, holes);
ntfs_debug("Return status %d\n", err);
return err;
}
+int ntfs_attr_truncate_i(struct ntfs_inode *ni, const s64 newsize,
+ unsigned int holes)
+{
+ return ntfs_attr_truncate_i_locked(ni, newsize, holes, NULL);
+}
+
/*
* Resize an attribute, creating a hole if relevant
*/
@@ -5044,10 +5129,11 @@ int ntfs_attr_map_cluster(struct ntfs_inode *ni, s64 vcn_start, s64 *lcn_start,
struct ntfs_volume *vol = ni->vol;
struct ntfs_attr_search_ctx *ctx;
struct runlist_element *rl, *rlc;
+ struct runlist_element *old_rl = NULL;
s64 vcn = vcn_start, lcn, clu_count;
s64 lcn_seek_from = -1;
int err = 0;
- size_t new_rl_count;
+ size_t new_rl_count, old_rl_count;
err = ntfs_attr_map_whole_runlist(ni);
if (err)
@@ -5140,6 +5226,19 @@ int ntfs_attr_map_cluster(struct ntfs_inode *ni, s64 vcn_start, s64 *lcn_start,
WARN_ON(rlc->vcn != vcn);
lcn = rlc->lcn;
clu_count = rlc->length;
+ old_rl_count = ni->runlist.count;
+ old_rl = kmemdup(ni->runlist.rl,
+ old_rl_count * sizeof(*old_rl), GFP_NOFS);
+ if (!old_rl) {
+ err = -ENOMEM;
+ if (ntfs_cluster_free_from_rl(vol, rlc)) {
+ ntfs_error(vol->sb,
+ "Failed to free cluster allocation after runlist backup failure.");
+ NVolSetErrors(vol);
+ }
+ kvfree(rlc);
+ goto out;
+ }
rl = ntfs_runlists_merge(&ni->runlist, rlc, 0, &new_rl_count);
if (IS_ERR(rl)) {
@@ -5163,15 +5262,32 @@ int ntfs_attr_map_cluster(struct ntfs_inode *ni, s64 vcn_start, s64 *lcn_start,
if (update_mp) {
ntfs_attr_reinit_search_ctx(ctx);
- err = ntfs_attr_update_mapping_pairs(ni, 0);
+ err = ntfs_attr_update_mapping_pairs_locked(ni, 0, ni);
if (err) {
int err2;
err2 = ntfs_cluster_free(ni, vcn, clu_count, ctx);
- if (err2 < 0)
+ if (err2 < 0 || err2 != clu_count) {
ntfs_error(vol->sb,
- "Failed to free cluster allocation. Leaving inconstant metadata.\n");
- goto out;
+ "Failed to free cluster allocation. Leaving inconsistent metadata.\n");
+ NVolSetErrors(vol);
+ goto out;
+ }
+
+ /*
+ * Restore the runlist before repairing the on-disk
+ * mapping pairs.
+ */
+ kvfree(ni->runlist.rl);
+ ni->runlist.rl = old_rl;
+ ni->runlist.count = old_rl_count;
+ old_rl = NULL;
+ if (ntfs_attr_update_mapping_pairs_locked(
+ ni, 0, ni)) {
+ ntfs_error(vol->sb,
+ "Failed to restore mapping pairs after allocation rollback.\n");
+ NVolSetErrors(vol);
+ }
}
} else {
VFS_I(ni)->i_blocks += clu_count << (vol->cluster_size_bits - 9);
@@ -5183,6 +5299,7 @@ int ntfs_attr_map_cluster(struct ntfs_inode *ni, s64 vcn_start, s64 *lcn_start,
*lcn_count = clu_count;
*balloc = true;
out:
+ kvfree(old_rl);
ntfs_attr_put_search_ctx(ctx);
return err;
}
@@ -5420,7 +5537,7 @@ int ntfs_non_resident_attr_insert_range(struct ntfs_inode *ni, s64 start_vcn, s6
ni->data_size += ntfs_cluster_to_bytes(vol, len);
if (ntfs_cluster_to_bytes(vol, start_vcn) < ni->initialized_size)
ni->initialized_size += ntfs_cluster_to_bytes(vol, len);
- ret = ntfs_attr_update_mapping_pairs(ni, 0);
+ ret = ntfs_attr_update_mapping_pairs_locked(ni, 0, ni);
up_write(&ni->runlist.lock);
if (ret)
return ret;
@@ -5505,7 +5622,7 @@ int ntfs_non_resident_attr_collapse_range(struct ntfs_inode *ni, s64 start_vcn,
}
if (ni->allocated_size > 0) {
- ret = ntfs_attr_update_mapping_pairs(ni, 0);
+ ret = ntfs_attr_update_mapping_pairs_locked(ni, 0, ni);
if (ret) {
up_write(&ni->runlist.lock);
goto out_rl;
@@ -5583,7 +5700,7 @@ int ntfs_non_resident_attr_punch_hole(struct ntfs_inode *ni, s64 start_vcn, s64
ni->runlist.rl = rl;
ni->runlist.count = new_rl_count;
- ret = ntfs_attr_update_mapping_pairs(ni, 0);
+ ret = ntfs_attr_update_mapping_pairs_locked(ni, 0, ni);
up_write(&ni->runlist.lock);
if (ret) {
kvfree(punch_rl);
@@ -5759,7 +5876,7 @@ int ntfs_attr_fallocate(struct ntfs_inode *ni, loff_t start, loff_t byte_len, bo
if (NInoRunlistDirty(ni)) {
mutex_lock_nested(&ni->mrec_lock, NTFS_INODE_MUTEX_NORMAL);
down_write(&ni->runlist.lock);
- err = ntfs_attr_update_mapping_pairs(ni, 0);
+ err = ntfs_attr_update_mapping_pairs_locked(ni, 0, ni);
if (err)
ntfs_error(ni->vol->sb, "Updating mapping pairs failed");
else
diff --git a/fs/ntfs/attrib.h b/fs/ntfs/attrib.h
index e2224fbfaabe9..6b4fa9f576401 100644
--- a/fs/ntfs/attrib.h
+++ b/fs/ntfs/attrib.h
@@ -112,7 +112,13 @@ int ntfs_non_resident_attr_punch_hole(struct ntfs_inode *ni, s64 start_vcn, s64
int __ntfs_attr_truncate_vfs(struct ntfs_inode *ni, const s64 newsize,
const s64 i_size);
int ntfs_attr_expand(struct ntfs_inode *ni, const s64 newsize, const s64 prealloc_size);
+int ntfs_attr_expand_locked(struct ntfs_inode *ni, const s64 newsize,
+ const s64 prealloc_size,
+ struct ntfs_inode *locked_ni);
int ntfs_attr_truncate_i(struct ntfs_inode *ni, const s64 newsize, unsigned int holes);
+int ntfs_attr_truncate_i_locked(struct ntfs_inode *ni, const s64 newsize,
+ unsigned int holes,
+ struct ntfs_inode *locked_ni);
int ntfs_attr_truncate(struct ntfs_inode *ni, const s64 newsize);
int ntfs_attr_rm(struct ntfs_inode *ni);
int ntfs_attr_exist(struct ntfs_inode *ni, const __le32 type, __le16 *name,
@@ -133,6 +139,9 @@ int ntfs_resident_attr_record_add(struct ntfs_inode *ni, __le32 type,
__le16 *name, u8 name_len, u8 *val, u32 size,
__le16 flags);
int ntfs_attr_update_mapping_pairs(struct ntfs_inode *ni, s64 from_vcn);
+int ntfs_attr_update_mapping_pairs_locked(struct ntfs_inode *ni,
+ s64 from_vcn,
+ struct ntfs_inode *locked_ni);
struct runlist_element *ntfs_attr_vcn_to_rl(struct ntfs_inode *ni, s64 vcn, s64 *lcn);
/*
diff --git a/fs/ntfs/attrlist.c b/fs/ntfs/attrlist.c
index 4e60f7e930102..bb191953dcb1b 100644
--- a/fs/ntfs/attrlist.c
+++ b/fs/ntfs/attrlist.c
@@ -68,7 +68,8 @@ int ntfs_attrlist_need(struct ntfs_inode *ni)
* legal list size as a reserve.
*/
static int ntfs_attrlist_repack(struct inode *attr_vi,
- struct ntfs_inode *attr_ni, s64 min_alloc_size)
+ struct ntfs_inode *attr_ni, s64 min_alloc_size,
+ struct ntfs_inode *locked_ni)
{
struct ntfs_volume *vol = attr_ni->vol;
struct runlist_element *old_rl, *new_rl;
@@ -78,10 +79,12 @@ static int ntfs_attrlist_repack(struct inode *attr_vi,
size_t old_rl_count, new_rl_count;
unsigned long flags;
int err, restore_err;
-
if (attr_ni->mft_no != FILE_MFT || !NInoNonResident(attr_ni) ||
min_alloc_size < 0)
return -EINVAL;
+ /* The buffered I/O below can reacquire the attribute runlist lock. */
+ if (attr_ni == locked_ni)
+ return -ENOSPC;
err = ntfs_attr_map_whole_runlist(attr_ni);
if (err)
@@ -131,7 +134,6 @@ static int ntfs_attrlist_repack(struct inode *attr_vi,
err = -ENOSPC;
goto out_free_data;
}
-
old_rl = attr_ni->runlist.rl;
old_rl_count = attr_ni->runlist.count;
down_write(&attr_ni->runlist.lock);
@@ -152,7 +154,7 @@ static int ntfs_attrlist_repack(struct inode *attr_vi,
}
}
- err = ntfs_attr_update_mapping_pairs(attr_ni, 0);
+ err = ntfs_attr_update_mapping_pairs_locked(attr_ni, 0, locked_ni);
if (err)
goto restore_old_runlist;
@@ -177,7 +179,8 @@ static int ntfs_attrlist_repack(struct inode *attr_vi,
attr_ni->allocated_size = old_alloc_size;
write_unlock_irqrestore(&attr_ni->size_lock, flags);
- restore_err = ntfs_attr_update_mapping_pairs(attr_ni, 0);
+ restore_err = ntfs_attr_update_mapping_pairs_locked(
+ attr_ni, 0, locked_ni);
if (restore_err) {
ntfs_error(vol->sb, "Failed to restore ATTRIBUTE_LIST mapping pairs (%d)",
restore_err);
@@ -193,7 +196,8 @@ static int ntfs_attrlist_repack(struct inode *attr_vi,
return err;
}
-int ntfs_attrlist_update(struct ntfs_inode *base_ni)
+int ntfs_attrlist_update_locked(struct ntfs_inode *base_ni,
+ struct ntfs_inode *locked_ni)
{
struct inode *attr_vi;
struct ntfs_inode *attr_ni;
@@ -215,20 +219,27 @@ int ntfs_attrlist_update(struct ntfs_inode *base_ni)
return err;
}
attr_ni = NTFS_I(attr_vi);
+ /* Truncation and page-cache writes can reacquire this runlist lock. */
+ if (attr_ni == locked_ni) {
+ iput(attr_vi);
+ return -ENOSPC;
+ }
- err = ntfs_attr_truncate_i(attr_ni, base_ni->attr_list_size, HOLES_NO);
+ err = ntfs_attr_truncate_i_locked(
+ attr_ni, base_ni->attr_list_size, HOLES_NO, locked_ni);
if (err == -ENOSPC && attr_ni->mft_no == FILE_MFT &&
NInoNonResident(attr_ni)) {
retry_err = ntfs_attrlist_repack(attr_vi, attr_ni,
- base_ni->attr_list_size);
+ base_ni->attr_list_size, locked_ni);
if (retry_err) {
ntfs_error(base_ni->vol->sb, "Failed to repack attribute list");
iput(attr_vi);
return retry_err;
}
- retry_err = ntfs_attr_truncate_i(attr_ni, base_ni->attr_list_size,
- HOLES_NO);
+ retry_err = ntfs_attr_truncate_i_locked(
+ attr_ni, base_ni->attr_list_size,
+ HOLES_NO, locked_ni);
if (retry_err) {
ntfs_error(base_ni->vol->sb,
"Failed to resize attribute list after repack");
@@ -252,11 +263,13 @@ int ntfs_attrlist_update(struct ntfs_inode *base_ni)
*/
if (base_ni->mft_no == FILE_MFT && NInoNonResident(attr_ni) &&
attr_ni->allocated_size < NTFS_MAX_ATTR_LIST_SIZE) {
- retry_err = ntfs_attr_expand(attr_ni, base_ni->attr_list_size,
- NTFS_MAX_ATTR_LIST_SIZE);
+ retry_err = ntfs_attr_expand_locked(
+ attr_ni, base_ni->attr_list_size,
+ NTFS_MAX_ATTR_LIST_SIZE, locked_ni);
if (retry_err == -ENOSPC) {
- retry_err = ntfs_attrlist_repack(attr_vi, attr_ni,
- NTFS_MAX_ATTR_LIST_SIZE);
+ retry_err = ntfs_attrlist_repack(
+ attr_vi, attr_ni,
+ NTFS_MAX_ATTR_LIST_SIZE, locked_ni);
if (retry_err == -ENOSPC)
retry_err = 0;
}
@@ -289,6 +302,11 @@ int ntfs_attrlist_update(struct ntfs_inode *base_ni)
return 0;
}
+int ntfs_attrlist_update(struct ntfs_inode *base_ni)
+{
+ return ntfs_attrlist_update_locked(base_ni, NULL);
+}
+
/*
* ntfs_attrlist_entry_add - add an attribute list attribute entry
* @ni: opened ntfs inode, which contains that attribute
diff --git a/fs/ntfs/attrlist.h b/fs/ntfs/attrlist.h
index 1892a3934d3ab..10cc2cc8e2081 100644
--- a/fs/ntfs/attrlist.h
+++ b/fs/ntfs/attrlist.h
@@ -16,5 +16,7 @@ int ntfs_attrlist_need(struct ntfs_inode *ni);
int ntfs_attrlist_entry_add(struct ntfs_inode *ni, struct attr_record *attr);
int ntfs_attrlist_entry_rm(struct ntfs_attr_search_ctx *ctx);
int ntfs_attrlist_update(struct ntfs_inode *base_ni);
+int ntfs_attrlist_update_locked(struct ntfs_inode *base_ni,
+ struct ntfs_inode *locked_ni);
#endif /* defined _NTFS_ATTRLIST_H */
diff --git a/fs/ntfs/compress.c b/fs/ntfs/compress.c
index 4ea1a6bfb3eb7..89a151901b9de 100644
--- a/fs/ntfs/compress.c
+++ b/fs/ntfs/compress.c
@@ -1390,7 +1390,7 @@ static int ntfs_write_cb(struct ntfs_inode *ni, loff_t pos, struct page **pages,
ni->runlist.count = new_rl_count;
ni->runlist.rl = rl;
- err = ntfs_attr_update_mapping_pairs(ni, 0);
+ err = ntfs_attr_update_mapping_pairs_locked(ni, 0, ni);
up_write(&ni->runlist.lock);
if (err) {
err = -EIO;
diff --git a/fs/ntfs/file.c b/fs/ntfs/file.c
index 7c1cf27bcaad8..8f682dbe51eaf 100644
--- a/fs/ntfs/file.c
+++ b/fs/ntfs/file.c
@@ -111,7 +111,8 @@ static int ntfs_trim_prealloc(struct inode *vi)
ntfs_error(vol->sb, "Preallocated block rollback failed");
} else {
ni->allocated_size = ntfs_cluster_to_bytes(vol, vcn_tr);
- err = ntfs_attr_update_mapping_pairs(ni, 0);
+ err = ntfs_attr_update_mapping_pairs_locked(
+ ni, 0, ni);
if (err)
ntfs_error(vol->sb,
"Failed to rollback mapping pairs for prealloc");
diff --git a/fs/ntfs/inode.c b/fs/ntfs/inode.c
index cc5818d50e3e8..560f1dd1fba39 100644
--- a/fs/ntfs/inode.c
+++ b/fs/ntfs/inode.c
@@ -2772,7 +2772,7 @@ int __ntfs_write_inode(struct inode *vi, int sync)
if (NInoNonResident(ni) && NInoRunlistDirty(ni)) {
down_write(&ni->runlist.lock);
- err = ntfs_attr_update_mapping_pairs(ni, 0);
+ err = ntfs_attr_update_mapping_pairs_locked(ni, 0, ni);
if (!err)
NInoClearRunlistDirty(ni);
up_write(&ni->runlist.lock);
diff --git a/fs/ntfs/mft.c b/fs/ntfs/mft.c
index ed3aa4c423e81..60f10bb0004fd 100644
--- a/fs/ntfs/mft.c
+++ b/fs/ntfs/mft.c
@@ -1131,7 +1131,8 @@ static s64 mft_bitmap_alloc_free_rec(struct ntfs_volume *vol,
return ll;
}
-static int ntfs_mft_attr_extend(struct ntfs_inode *ni)
+static int ntfs_mft_attr_extend(struct ntfs_inode *ni,
+ struct ntfs_inode *locked_ni)
{
int ret = 0;
struct ntfs_inode *base_ni;
@@ -1152,7 +1153,7 @@ static int ntfs_mft_attr_extend(struct ntfs_inode *ni)
}
}
- ret = ntfs_attr_update_mapping_pairs(ni, 0);
+ ret = ntfs_attr_update_mapping_pairs_locked(ni, 0, locked_ni);
if (ret)
pr_err("MP update failed\n");
@@ -1340,7 +1341,7 @@ static int ntfs_mft_bitmap_extend_allocation_nolock(struct ntfs_volume *vol)
ret = ntfs_attr_record_resize(ctx->mrec, a, mp_size +
le16_to_cpu(a->data.non_resident.mapping_pairs_offset));
if (unlikely(ret)) {
- ret = ntfs_mft_attr_extend(mftbmp_ni);
+ ret = ntfs_mft_attr_extend(mftbmp_ni, mftbmp_ni);
if (!ret)
goto extended_ok;
if (ret != -EAGAIN)
@@ -1451,7 +1452,9 @@ static int ntfs_mft_bitmap_extend_allocation_nolock(struct ntfs_volume *vol)
NVolSetErrors(vol);
}
mark_mft_record_dirty(ctx->ntfs_ino);
- } else if (status.mp_extended && ntfs_attr_update_mapping_pairs(mftbmp_ni, 0)) {
+ } else if (status.mp_extended &&
+ ntfs_attr_update_mapping_pairs_locked(mftbmp_ni, 0,
+ mftbmp_ni)) {
ntfs_error(vol->sb, "Failed to restore mapping pairs.%s", es);
NVolSetErrors(vol);
}
@@ -1776,7 +1779,7 @@ static int ntfs_mft_data_extend_allocation_nolock(struct ntfs_volume *vol)
ret = ntfs_attr_record_resize(ctx->mrec, a, mp_size +
le16_to_cpu(a->data.non_resident.mapping_pairs_offset));
if (unlikely(ret)) {
- ret = ntfs_mft_attr_extend(mft_ni);
+ ret = ntfs_mft_attr_extend(mft_ni, NULL);
if (!ret)
goto extended_ok;
if (ret != -EAGAIN)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 070/398] wifi: mac80211: unlist vifs when their netdev is unregistered
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (68 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 069/398] wifi: cfg80211: undo netns switch if renaming the wiphy fails Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 071/398] wifi: cfg80211: get the wiphy out of a dying network namespace Greg Kroah-Hartman
` (332 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit eee2efd82867b623982ac51925b5a1812a74c50d ]
mac80211 only removes vifs from the local->interfaces list when
an interface is removed via ieee80211_if_remove(), before it
unregisters the netdev. However, it's possible for a netdev to
be unregistered without going through that: When the netns that
holds the wiphy is destroyed, the wiphy is supposed to move to
the init_ns, but that can run into allocation failures.
Then, mac80211 has an interface listed that doesn't exist, and
will eventually hit
BUG: failure at net/wireless/core.h:141/wiphy_to_rdev()!
...
_cfg80211_unregister_wdev+0x24/0x36a [cfg80211]
cfg80211_unregister_wdev+0x15/0x1d [cfg80211]
ieee80211_remove_interfaces+0x1ff/0x257 [mac80211]
ieee80211_unregister_hw+0x73/0x1d1 [mac80211]
mac80211_hwsim_del_radio+0x114/0x166 [mac80211_hwsim]
Remove the interface from the list in ->ndo_uninit if it's still
around to avoid this.
Assisted-by: LLM
Fixes: 463d018323851 ("cfg80211: make aware of net namespaces")
Link: https://patch.msgid.link/20260904170220.038ad73e6c04.I990abca78483e058746b6f42b4796717c3028164@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 26 +++++++++++++++++++++++++-
1 file changed, 25 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 82eff9e867c1f..3da26d4d75fc3 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -885,9 +885,33 @@ static void ieee80211_teardown_sdata(struct ieee80211_sub_if_data *sdata)
ieee80211_link_stop(&sdata->deflink);
}
+/*
+ * The netdev can be unregistered without mac80211 doing it, e.g. by the netdev
+ * core when cfg80211 couldn't move it out of a network namespace that's being
+ * destroyed. Drop it from the interface list either way.
+ */
+static void ieee80211_unlist_sdata(struct ieee80211_sub_if_data *sdata)
+{
+ struct ieee80211_local *local = sdata->local;
+ struct ieee80211_sub_if_data *iter;
+
+ ASSERT_RTNL();
+
+ list_for_each_entry(iter, &local->interfaces, list) {
+ if (iter != sdata)
+ continue;
+ guard(mutex)(&local->iflist_mtx);
+ list_del_rcu(&sdata->list);
+ return;
+ }
+}
+
static void ieee80211_uninit(struct net_device *dev)
{
- ieee80211_teardown_sdata(IEEE80211_DEV_TO_SUB_IF(dev));
+ struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
+
+ ieee80211_unlist_sdata(sdata);
+ ieee80211_teardown_sdata(sdata);
}
static int ieee80211_netdev_setup_tc(struct net_device *dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 124/438] ntfs: propagate folio errors
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (122 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 123/438] ntfs: protect runlist updates with the runlist lock Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 176/398] eth: fbnic: ring the doorbell if a burst ends in a drop Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 125/438] ntfs: ignore interrupted inode reads as corruption Greg Kroah-Hartman
` (325 subsequent siblings)
449 siblings, 1 reply; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hyunchul Lee, Namjae Jeon,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 1923eeffa63edeff427d76fc302bc5eb835771ce ]
Return the error from __filemap_get_folio() instead of replacing it
with -ENOMEM.
Fixes: af0db57d4293 ("ntfs: update inode operations")
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs/inode.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/ntfs/inode.c b/fs/ntfs/inode.c
index 560f1dd1fba39..b6e161d51dce2 100644
--- a/fs/ntfs/inode.c
+++ b/fs/ntfs/inode.c
@@ -3713,7 +3713,7 @@ static s64 __ntfs_inode_non_resident_attr_pwrite(struct inode *vi,
FGP_CREAT | FGP_LOCK,
mapping_gfp_mask(mapping));
if (IS_ERR(folio)) {
- ret = -ENOMEM;
+ ret = PTR_ERR(folio);
break;
}
} else {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 071/398] wifi: cfg80211: get the wiphy out of a dying network namespace
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (69 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 070/398] wifi: mac80211: unlist vifs when their netdev is unregistered Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 072/398] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping Greg Kroah-Hartman
` (331 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+c5f8a81e794d4a4f2014,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 4635b1a1c1d693178a537446a6e09963f0fdae52 ]
When a network namespace is destroyed, cfg80211_pernet_exit() moves any
wiphy back to the initial namespace, and just warns if that fails. But
moving an interface can fail (due to allocation failures), and then the
wiphy is left behind with a garbage netns pointer:
Kernel mode fault at addr 0x30
genlmsg_multicast_netns.constprop.0+0x46/0xcf [cfg80211]
nl80211_notify_wiphy+0xcd/0xe8 [cfg80211]
wiphy_unregister+0x169/0x3fc [cfg80211]
Note that commit debac3a20dec ("net: Remove conflicting altnames for
dying netns in __dev_change_net_namespace().") fixed another path
that could reach it without allocation failures.
Remove interfaces that cannot be moved instead of failing the switch,
so that the wiphy always ends up in the initial namespace. In this
case the netdev core will unregister the interfaces anyway.
Assisted-by: LLM
Reported-by: syzbot+c5f8a81e794d4a4f2014@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c5f8a81e794d4a4f2014
Fixes: 463d018323851 ("cfg80211: make aware of net namespaces")
Link: https://patch.msgid.link/20260904170220.7f3edc6d9992.I5e57921011244d3d8ef14d89e738aa19a5d972a0@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/core.c | 37 +++++++++++++++++++++++++------------
1 file changed, 25 insertions(+), 12 deletions(-)
diff --git a/net/wireless/core.c b/net/wireless/core.c
index c38a737171569..01e44ba4eddd1 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -165,20 +165,24 @@ static int cfg80211_switch_wdev_netns(struct wireless_dev *wdev,
return err;
}
-int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
- struct net *net)
+static int __cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
+ struct net *net, bool force)
{
struct net *old_net = wiphy_net(&rdev->wiphy);
- struct wireless_dev *wdev;
+ struct wireless_dev *wdev, *tmp;
int err = 0;
- if (!(rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK))
- return -EOPNOTSUPP;
-
- list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ list_for_each_entry_safe(wdev, tmp, &rdev->wiphy.wdev_list, list) {
err = cfg80211_switch_wdev_netns(wdev, net);
- if (err)
+ if (!err)
+ continue;
+ if (!force)
goto undo;
+ /* remove interfaces that fail to allow wiphy switching */
+ dev_close(wdev->netdev);
+ scoped_guard(wiphy, &rdev->wiphy)
+ cfg80211_unregister_wdev(wdev);
+ err = 0;
}
scoped_guard(wiphy, &rdev->wiphy) {
@@ -196,7 +200,7 @@ int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
/* this only fails on allocation failure */
err = device_rename(&rdev->wiphy.dev,
dev_name(&rdev->wiphy.dev));
- if (err)
+ if (err && !force)
wiphy_net_set(&rdev->wiphy, old_net);
nl80211_notify_wiphy(rdev, NL80211_CMD_NEW_WIPHY);
@@ -209,8 +213,8 @@ int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
}
}
- if (!err)
- return 0;
+ if (!err || force)
+ return err;
/* set to the last one to undo all of them */
wdev = list_entry(&rdev->wiphy.wdev_list, typeof(*wdev), list);
@@ -226,6 +230,15 @@ int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
return err;
}
+int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
+ struct net *net)
+{
+ if (!(rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK))
+ return -EOPNOTSUPP;
+
+ return __cfg80211_switch_netns(rdev, net, false);
+}
+
static void cfg80211_rfkill_poll(struct rfkill *rfkill, void *data)
{
struct cfg80211_registered_device *rdev = data;
@@ -1764,7 +1777,7 @@ static void __net_exit cfg80211_pernet_exit(struct net *net)
rtnl_lock();
for_each_rdev(rdev) {
if (net_eq(wiphy_net(&rdev->wiphy), net))
- WARN_ON(cfg80211_switch_netns(rdev, &init_net));
+ WARN_ON(__cfg80211_switch_netns(rdev, &init_net, true));
}
rtnl_unlock();
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 125/438] ntfs: ignore interrupted inode reads as corruption
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (123 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 124/438] ntfs: propagate folio errors Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 126/438] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow Greg Kroah-Hartman
` (324 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hyunchul Lee, Namjae Jeon,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 8c5dc7587fdd45f957af81a9adc1e16863f300fc ]
Do not mark the volume in error or report an inode as corrupt when
reading it was interrupted by a signal. -EINTR and -ERESTARTSYS indicate
a transient read failure rather than on-disk NTFS corruption.
Fixes: 115380f9a2f9 ("ntfs: update mft operations")
Reviewed-by: Hyunchul Lee <hyc.lee@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs/inode.c | 21 +++++++++++++--------
fs/ntfs/mft.c | 3 ++-
2 files changed, 15 insertions(+), 9 deletions(-)
diff --git a/fs/ntfs/inode.c b/fs/ntfs/inode.c
index b6e161d51dce2..cfb753be4f6b1 100644
--- a/fs/ntfs/inode.c
+++ b/fs/ntfs/inode.c
@@ -1232,7 +1232,8 @@ static int ntfs_read_locked_inode(struct inode *vi)
if (m)
unmap_mft_record(ni);
err_out:
- if (err != -EOPNOTSUPP && err != -ENOMEM && vol_err == true) {
+ if (err != -EOPNOTSUPP && err != -ENOMEM &&
+ err != -EINTR && err != -ERESTARTSYS && vol_err == true) {
ntfs_error(vol->sb,
"Failed with error code %i. Marking corrupt inode 0x%llx as bad. Run chkdsk.",
err, ni->mft_no);
@@ -1458,12 +1459,13 @@ static int ntfs_read_locked_attr_inode(struct inode *base_vi, struct inode *vi)
ntfs_attr_put_search_ctx(ctx);
unmap_mft_record(base_ni);
err_out:
- if (err != -ENOENT)
+ if (err != -ENOENT && err != -EINTR && err != -ERESTARTSYS)
ntfs_error(vol->sb,
"Failed with error code %i while reading attribute inode (mft_no 0x%llx, type 0x%x, name_len %i). Marking corrupt inode and base inode 0x%llx as bad. Run chkdsk.",
err, ni->mft_no, ni->type, ni->name_len,
base_ni->mft_no);
- if (err != -ENOENT && err != -ENOMEM)
+ if (err != -ENOENT && err != -ENOMEM &&
+ err != -EINTR && err != -ERESTARTSYS)
NVolSetErrors(vol);
return err;
}
@@ -1667,8 +1669,9 @@ static int ntfs_read_locked_index_inode(struct inode *base_vi, struct inode *vi)
/* Get the index bitmap attribute inode. */
bvi = ntfs_attr_iget(base_vi, AT_BITMAP, ni->name, ni->name_len);
if (IS_ERR(bvi)) {
- ntfs_error(vi->i_sb, "Failed to get bitmap attribute.");
err = PTR_ERR(bvi);
+ if (err != -EINTR && err != -ERESTARTSYS)
+ ntfs_error(vi->i_sb, "Failed to get bitmap attribute.");
goto unm_err_out;
}
bni = NTFS_I(bvi);
@@ -1712,10 +1715,12 @@ static int ntfs_read_locked_index_inode(struct inode *base_vi, struct inode *vi)
if (m)
unmap_mft_record(base_ni);
err_out:
- ntfs_error(vi->i_sb,
- "Failed with error code %i while reading index inode (mft_no 0x%llx, name_len %i.",
- err, ni->mft_no, ni->name_len);
- if (err != -EOPNOTSUPP && err != -ENOMEM)
+ if (err != -EINTR && err != -ERESTARTSYS)
+ ntfs_error(vi->i_sb,
+ "Failed with error code %i while reading index inode (mft_no 0x%llx, name_len %i.",
+ err, ni->mft_no, ni->name_len);
+ if (err != -EOPNOTSUPP && err != -ENOMEM &&
+ err != -EINTR && err != -ERESTARTSYS)
NVolSetErrors(vol);
return err;
}
diff --git a/fs/ntfs/mft.c b/fs/ntfs/mft.c
index 60f10bb0004fd..8dcbc93a8ccac 100644
--- a/fs/ntfs/mft.c
+++ b/fs/ntfs/mft.c
@@ -213,7 +213,8 @@ struct mft_record *map_mft_record(struct ntfs_inode *ni)
return m;
atomic_dec(&ni->count);
- ntfs_error(ni->vol->sb, "Failed with error code %lu.", -PTR_ERR(m));
+ if (PTR_ERR(m) != -EINTR && PTR_ERR(m) != -ERESTARTSYS)
+ ntfs_error(ni->vol->sb, "Failed with error code %lu.", -PTR_ERR(m));
return m;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 072/398] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (70 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 071/398] wifi: cfg80211: get the wiphy out of a dying network namespace Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 073/398] wifi: mac80211: dont allow injecting frames wider than the chanctx Greg Kroah-Hartman
` (330 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b4aa2b672b18f1d4dc5f,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 87840d4a3a21b1c19b867a80e16ba69dff284de2 ]
The code checks ->started for frames coming from wmediumd, but the
radio can be stopped after the check and before frame delivery,
causing mac80211 to hit the WARN_ON(!local->started).
Expand the mutex for this case and synchronise against it when the
radio is stopped to avoid being able to hit the warning with hwsim.
Drop the error print that would've complicated the error path, it
only triggers for allocation failures (already noisy) and malformed
frames anyway.
Assisted-by: LLM
Fixes: 7882513bacb1 ("mac80211_hwsim driver support userspace frame tx/rx")
Reported-by: syzbot+b4aa2b672b18f1d4dc5f@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b4aa2b672b18f1d4dc5f
Link: https://patch.msgid.link/20260904170140.5f69a10d606b.I4a7921d00643f69e439c7a3b221d104f66a3dcdc@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virtual/mac80211_hwsim.c | 39 ++++++++++++-------
1 file changed, 24 insertions(+), 15 deletions(-)
diff --git a/drivers/net/wireless/virtual/mac80211_hwsim.c b/drivers/net/wireless/virtual/mac80211_hwsim.c
index 90caa4290dc45..484198766efda 100644
--- a/drivers/net/wireless/virtual/mac80211_hwsim.c
+++ b/drivers/net/wireless/virtual/mac80211_hwsim.c
@@ -2162,7 +2162,12 @@ static void mac80211_hwsim_stop(struct ieee80211_hw *hw, bool suspend)
struct sk_buff *skb;
int i;
- data->started = false;
+ /*
+ * Serialise against wmediumd userspace, so no more frames
+ * can be handed to mac80211 after this returns.
+ */
+ scoped_guard(mutex, &data->mutex)
+ data->started = false;
for (i = 0; i < ARRAY_SIZE(data->link_data); i++)
hrtimer_cancel(&data->link_data[i].beacon_timer);
@@ -6136,12 +6141,12 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
if (frame_data_len < sizeof(struct ieee80211_hdr_3addr) ||
frame_data_len > IEEE80211_MAX_DATA_LEN)
- goto err;
+ goto out;
/* Allocate new skb here */
skb = alloc_skb(frame_data_len, GFP_KERNEL);
if (skb == NULL)
- goto err;
+ goto out;
/* Copy the data */
skb_put_data(skb, frame_data, frame_data_len);
@@ -6166,10 +6171,17 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
goto out;
}
+ /*
+ * Serialise against mac80211_hwsim_stop() - mac80211 doesn't allow
+ * frames reported while the HW is down, hence the ->started check
+ * must be under mutex.
+ */
+ mutex_lock(&data2->mutex);
+
/* check if radio is configured properly */
if ((data2->idle && !data2->tmp_chan) || !data2->started)
- goto out;
+ goto out_unlock;
/* A frame is received from user space */
memset(&rx_status, 0, sizeof(rx_status));
@@ -6185,22 +6197,18 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
iter_data.channel = ieee80211_get_channel(data2->hw->wiphy,
rx_status.freq);
if (!iter_data.channel)
- goto out;
+ goto out_unlock;
rx_status.band = iter_data.channel->band;
- mutex_lock(&data2->mutex);
if (!hwsim_chans_compat(iter_data.channel, channel)) {
ieee80211_iterate_active_interfaces_atomic(
data2->hw, IEEE80211_IFACE_ITER_NORMAL,
mac80211_hwsim_tx_iter, &iter_data);
- if (!iter_data.receive) {
- mutex_unlock(&data2->mutex);
- goto out;
- }
+ if (!iter_data.receive)
+ goto out_unlock;
}
- mutex_unlock(&data2->mutex);
} else if (!channel) {
- goto out;
+ goto out_unlock;
} else {
rx_status.freq = channel->center_freq;
rx_status.band = channel->band;
@@ -6208,7 +6216,7 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
rx_status.rate_idx = nla_get_u32(info->attrs[HWSIM_ATTR_RX_RATE]);
if (rx_status.rate_idx >= data2->hw->wiphy->bands[rx_status.band]->n_bitrates)
- goto out;
+ goto out_unlock;
rx_status.signal = nla_get_u32(info->attrs[HWSIM_ATTR_SIGNAL]);
hdr = (void *)skb->data;
@@ -6218,10 +6226,11 @@ static int hwsim_cloned_frame_received_nl(struct sk_buff *skb_2,
rx_status.boottime_ns = ktime_get_boottime_ns();
mac80211_hwsim_rx(data2, &rx_status, skb);
+ mutex_unlock(&data2->mutex);
return 0;
-err:
- pr_debug("mac80211_hwsim: error occurred in %s\n", __func__);
+out_unlock:
+ mutex_unlock(&data2->mutex);
out:
dev_kfree_skb(skb);
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 126/438] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (124 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 125/438] ntfs: ignore interrupted inode reads as corruption Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 127/438] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting Greg Kroah-Hartman
` (323 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam,
AngeloGioacchino Del Regno, Vinod Koul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
[ Upstream commit de7f29a1fe1dc2864d8a47f8c39d508442cae167 ]
When trying to calculate a PLL rate for target display resolutions
above 2560x1440, 24bpp, 30Hz, the pixel clock value will be more
than 32-bits long but the division to finally calculate the digital
clock divider is being done with div_u64(), which expects a 32bit
unsigned divisor.
Fix the overflow by using div64_u64() instead.
Fixes: 9d9ff3d2a4a5 ("phy: mediatek: hdmi: mt8195: fix wrong pll calculus")
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Link: https://patch.msgid.link/20260911074015.9994-2-angelogioacchino.delregno@collabora.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
index 1426a2db984d5..e6ee8e0800222 100644
--- a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
+++ b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
@@ -290,7 +290,7 @@ static int mtk_hdmi_pll_calc(struct mtk_hdmi_phy *hdmi_phy, struct clk_hw *hw,
posdiv2 = 1;
/* Digital clk divider, max /32 */
- digital_div = div_u64(ns_hdmipll_ck, posdiv1 * posdiv2 * pixel_clk);
+ digital_div = div64_u64(ns_hdmipll_ck, posdiv1 * posdiv2 * pixel_clk);
if (!(digital_div <= 32 && digital_div >= 1))
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 073/398] wifi: mac80211: dont allow injecting frames wider than the chanctx
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (71 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 072/398] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 074/398] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown Greg Kroah-Hartman
` (329 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+435fdb053cf98bfa5778,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit e14bf37bb2b3853012ff160131d1c6233f7a9cc9 ]
Frames injected on a monitor interface can carry a radiotap
field requesting a bandwidth, which mac80211 passes down to
the driver regardless of the the actual operational bandwidth.
If the bandwidth requested is too wide, that triggers a warning
in hwsim:
WARN_ON(hwsim_get_chanwidth(bw) > hwsim_get_chanwidth(confbw))
Drop such frames entirely instead since they cannot be sent.
Assisted-by: LLM
Fixes: 646e76bb5daf ("mac80211: parse VHT info in injected frames")
Reported-by: syzbot+435fdb053cf98bfa5778@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=435fdb053cf98bfa5778
Link: https://patch.msgid.link/20260908122838.201719-13-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/mac80211.h | 5 ++++-
net/mac80211/iface.c | 2 +-
net/mac80211/tx.c | 28 ++++++++++++++++++++++++++--
3 files changed, 31 insertions(+), 4 deletions(-)
diff --git a/include/net/mac80211.h b/include/net/mac80211.h
index ac2546b121385..d19b95d3c3a49 100644
--- a/include/net/mac80211.h
+++ b/include/net/mac80211.h
@@ -7309,11 +7309,14 @@ bool ieee80211_tx_prepare_skb(struct ieee80211_hw *hw,
*
* @skb: packet injected by userspace
* @dev: the &struct device of this 802.11 device
+ * @chandef: the channel definition the frame will be transmitted on, or
+ * %NULL to skip the bandwidth checks
*
* Return: %true if the radiotap header was parsed, %false otherwise
*/
bool ieee80211_parse_tx_radiotap(struct sk_buff *skb,
- struct net_device *dev);
+ struct net_device *dev,
+ const struct cfg80211_chan_def *chandef);
/**
* struct ieee80211_noa_data - holds temporary data for tracking P2P NoA state
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 3da26d4d75fc3..0c739af80f1ee 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -952,7 +952,7 @@ static u16 ieee80211_monitor_select_queue(struct net_device *dev,
/* reset flags and info before parsing radiotap header */
memset(info, 0, sizeof(*info));
- if (!ieee80211_parse_tx_radiotap(skb, dev))
+ if (!ieee80211_parse_tx_radiotap(skb, dev, NULL))
return 0; /* doesn't matter, frame will be dropped */
len_rthdr = ieee80211_get_radiotap_len(skb->data);
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index cd1d814cdb824..4258dcea36f0b 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -2084,8 +2084,29 @@ static bool ieee80211_validate_radiotap_len(struct sk_buff *skb)
return true;
}
+static bool ieee80211_rate_bw_usable(u16 rate_flags,
+ const struct cfg80211_chan_def *chandef)
+{
+ int width;
+
+ if (!chandef)
+ return true;
+
+ if (rate_flags & IEEE80211_TX_RC_160_MHZ_WIDTH)
+ width = 160;
+ else if (rate_flags & IEEE80211_TX_RC_80_MHZ_WIDTH)
+ width = 80;
+ else if (rate_flags & IEEE80211_TX_RC_40_MHZ_WIDTH)
+ width = 40;
+ else
+ return true;
+
+ return width <= cfg80211_chandef_get_width(chandef);
+}
+
bool ieee80211_parse_tx_radiotap(struct sk_buff *skb,
- struct net_device *dev)
+ struct net_device *dev,
+ const struct cfg80211_chan_def *chandef)
{
struct ieee80211_local *local = wdev_priv(dev->ieee80211_ptr);
struct ieee80211_radiotap_iterator iterator;
@@ -2259,6 +2280,9 @@ bool ieee80211_parse_tx_radiotap(struct sk_buff *skb,
struct ieee80211_supported_band *sband =
local->hw.wiphy->bands[info->band];
+ if (!ieee80211_rate_bw_usable(rate_flags, chandef))
+ return false;
+
info->control.flags |= IEEE80211_TX_CTRL_RATE_INJECT;
for (i = 0; i < IEEE80211_TX_MAX_RATES; i++) {
@@ -2448,7 +2472,7 @@ netdev_tx_t ieee80211_monitor_start_xmit(struct sk_buff *skb,
* selected chandef above to accurately set injection rates and
* retransmissions.
*/
- if (!ieee80211_parse_tx_radiotap(skb, dev))
+ if (!ieee80211_parse_tx_radiotap(skb, dev, chandef))
goto fail_rcu;
/* remove the injection radiotap header */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 127/438] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (125 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 126/438] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 128/438] ALSA: pcm: set timer->private_data before registering the PCM timer Greg Kroah-Hartman
` (322 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam,
AngeloGioacchino Del Regno, Vinod Koul, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
[ Upstream commit 486a70ef848264dcf9a57f0bb0452848db9537de ]
The comment in the mtk_phy_tmds_clk_ratio() function clearly and
correctly explains that the TMDS ratio has to be 1/10 for data
rates under 3.4Gbps, and 1/40 over that.
Unfortunately though, the TXC_DIV register setting was wrong, as
in value 3 means to divide by 8 and, in order to achieve the in
spec 1/40 (tmds) data rate, this has to divide by 4 instead!
Add definitions for the TXC_DIV register values clearly explaining
the meanings (DIV2, DIV4, DIV8), and program the correct, DIV 4,
value to the register in mtk_phy_tmds_clk_ratio().
This fixes out of spec clocking and, with this change, SoCs using
the MT8195 class HDMI PHYs can now successfully be configured to
output 3840x2160@60Hz over HDMI.
Fixes: 45810d486bb4 ("phy: mediatek: add support for phy-mtk-hdmi-mt8195")
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Link: https://patch.msgid.link/20260911074015.9994-3-angelogioacchino.delregno@collabora.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c | 2 +-
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h | 3 +++
2 files changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
index e6ee8e0800222..a4bc1268946d8 100644
--- a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
+++ b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
@@ -36,7 +36,7 @@ mtk_phy_tmds_clk_ratio(struct mtk_hdmi_phy *hdmi_phy, bool enable)
* clock bit ratio 1:40, under 3.4Gbps, clock bit ratio 1:10
*/
if (enable)
- mtk_phy_update_field(regs + HDMI20_CLK_CFG, REG_TXC_DIV, 3);
+ mtk_phy_update_field(regs + HDMI20_CLK_CFG, REG_TXC_DIV, VAL_TXC_DIV4);
else
mtk_phy_clear_bits(regs + HDMI20_CLK_CFG, REG_TXC_DIV);
}
diff --git a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h
index e26caaf4d104c..58800d7659ca0 100644
--- a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h
+++ b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h
@@ -17,6 +17,9 @@
#define HDMI20_CLK_CFG 0x70
#define REG_TXC_DIV GENMASK(31, 30)
+#define VAL_TXC_DIV2 1
+#define VAL_TXC_DIV4 2
+#define VAL_TXC_DIV8 3
#define HDMI_1_CFG_0 0x00
#define RG_HDMITX21_DRV_IBIAS_CLK GENMASK(10, 5)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 074/398] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (72 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 073/398] wifi: mac80211: dont allow injecting frames wider than the chanctx Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 075/398] wifi: mac80211: require a peer station for TDLS setup confirm Greg Kroah-Hartman
` (328 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+de3ee5362db09487ea37,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 4504f3960dc4501c73be9f99eabda2e26e9db41e ]
On ifup, AP_VLAN interfaces get crypto_tx_tailroom_needed_cnt from
the AP interface, but it's never decremented again unless the AP is
also brought down. Thus, bringing the same AP_VLAN up again will
increment the counter again and eventually hit the sanity check:
WARN_ON_ONCE(sdata->crypto_tx_tailroom_needed_cnt !=
master->crypto_tx_tailroom_needed_cnt);
Reset it on ifdown to avoid that.
Assisted-by: LLM
Fixes: f9dca80b98ca ("mac80211: fix AP_VLAN crypto tailroom calculation")
Reported-by: syzbot+de3ee5362db09487ea37@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=de3ee5362db09487ea37
Link: https://patch.msgid.link/20260908122838.201719-14-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/iface.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/mac80211/iface.c b/net/mac80211/iface.c
index 0c739af80f1ee..22ffae46f7cb7 100644
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -609,6 +609,8 @@ static void ieee80211_do_stop(struct ieee80211_sub_if_data *sdata, bool going_do
RCU_INIT_POINTER(sdata->vif.bss_conf.chanctx_conf, NULL);
/* see comment in the default case below */
ieee80211_free_keys(sdata, true);
+ /* increased by AP value on ifup, so reset on ifdown */
+ sdata->crypto_tx_tailroom_needed_cnt = 0;
/* no need to tell driver */
break;
case NL80211_IFTYPE_MONITOR:
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 128/438] ALSA: pcm: set timer->private_data before registering the PCM timer
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (126 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 127/438] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 129/438] drm/msm/dp: skip PUSH_IDLE when the link was never enabled Greg Kroah-Hartman
` (321 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+19da64013c46df87f971,
Nguyen Ngoc Thang, Takashi Iwai, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
[ Upstream commit 1e713f9bb2ac583521f06b0eb4e22440b1e3d078 ]
snd_pcm_timer_init() calls snd_device_register() to link the new
struct snd_timer into the global timer list while it still carries
hw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop),
and only afterwards sets timer->private_data = substream.
Once the timer is on the list under register_mutex, a concurrent
reader can already reach it through the same mutex and invoke these
callbacks. /proc/asound/timers does this via c_resolution(), and
snd_timer_open()+snd_timer_start() reach start()/stop() the same way.
All three dereference timer->private_data, which for this brief
window is NULL, giving a NULL-pointer dereference:
substream = timer->private_data;
return substream->runtime ? ... // substream is NULL
Move the private_data/private_free assignment before
snd_device_register() so the timer is never visible on the list
without its private_data set. On the snd_device_register() failure
path, private_free() (snd_pcm_timer_free()) can now run, but it only
does substream->timer = NULL, which is already NULL at that point
since substream->timer is set to the new timer just once, after a
successful registration -- so the failure path stays safe.
Reported-by: syzbot+19da64013c46df87f971@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=19da64013c46df87f971
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
Link: https://patch.msgid.link/20260913134446.114724-1-ngocthang2710.1999@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/core/pcm_timer.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/sound/core/pcm_timer.c b/sound/core/pcm_timer.c
index ab0e5bd70f8fa..18bedd66435dc 100644
--- a/sound/core/pcm_timer.c
+++ b/sound/core/pcm_timer.c
@@ -111,12 +111,15 @@ void snd_pcm_timer_init(struct snd_pcm_substream *substream)
snd_pcm_direction_name(substream->stream),
tid.card, tid.device, tid.subdevice);
timer->hw = snd_pcm_timer;
+ /* Set before registering: a concurrent reader can invoke our hw
+ * callbacks as soon as the timer is on the global list.
+ */
+ timer->private_data = substream;
+ timer->private_free = snd_pcm_timer_free;
if (snd_device_register(timer->card, timer) < 0) {
snd_device_free(timer->card, timer);
return;
}
- timer->private_data = substream;
- timer->private_free = snd_pcm_timer_free;
substream->timer = timer;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 075/398] wifi: mac80211: require a peer station for TDLS setup confirm
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (73 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 074/398] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 076/398] wifi: mac80211: dont allow link changes when iface is down Greg Kroah-Hartman
` (327 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+e55106f8389651870be0,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 038e1d126304fd25d507fd4e671232df57bd1799 ]
It's nonsense for the setup confirm to go to station that
doesn't even exist, and it hits a warning when building
the frame:
WARN_ON_ONCE(!sta || !ap_sta)
Only accept WLAN_TDLS_SETUP_CONFIRM when the station is
already there as a TDLS station. Need to copy the call
to ieee80211_tdls_prep_mgmt_packet() since the existing
WLAN_TDLS_DISCOVERY_REQUEST already falls through to it.
Assisted-by: LLM
Fixes: 6f7eaa47e1de ("mac80211: add TDLS QoS param IE on setup-confirm")
Reported-by: syzbot+e55106f8389651870be0@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e55106f8389651870be0
Link: https://patch.msgid.link/20260908122838.201719-15-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tdls.c | 19 ++++++++++++++++++-
1 file changed, 18 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/tdls.c b/net/mac80211/tdls.c
index 1536cd71878c7..1dde37ad8bb20 100644
--- a/net/mac80211/tdls.c
+++ b/net/mac80211/tdls.c
@@ -1285,6 +1285,24 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
peer_capability, initiator,
extra_ies, extra_ies_len);
break;
+ case WLAN_TDLS_SETUP_CONFIRM: {
+ struct sta_info *sta;
+
+ sta = sta_info_get(sdata, peer);
+ if (!sta || !sta->sta.tdls) {
+ ret = -ENOLINK;
+ break;
+ }
+
+ ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
+ link_id, action_code,
+ dialog_token,
+ status_code,
+ peer_capability,
+ initiator, extra_ies,
+ extra_ies_len, 0, NULL);
+ break;
+ }
case WLAN_TDLS_DISCOVERY_REQUEST:
/*
* Protect the discovery so we can hear the TDLS discovery
@@ -1293,7 +1311,6 @@ int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
*/
drv_mgd_protect_tdls_discover(sdata->local, sdata, link_id);
fallthrough;
- case WLAN_TDLS_SETUP_CONFIRM:
case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
/* no special handling */
ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 129/438] drm/msm/dp: skip PUSH_IDLE when the link was never enabled
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (127 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 128/438] ALSA: pcm: set timer->private_data before registering the PCM timer Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 130/438] drm/msm/dp: fix link bandwidth check when wide bus is enabled Greg Kroah-Hartman
` (320 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jesse Casco, Dmitry Baryshkov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jesse Casco <jesse.casco@gmail.com>
[ Upstream commit e249a6e2a130c08bb4d8b0a55cbe29754307e5c9 ]
msm_dp_display_atomic_enable() returns early when link training fails,
leaving ->power_on false and the main link down.
msm_dp_display_atomic_disable() nevertheless writes DP_STATE_CTRL_PUSH_IDLE
and waits for an idle-pattern completion that cannot arrive, so every failed
enable is followed by "PUSH_IDLE pattern timedout".
Every other step of the teardown is already gated on that flag:
msm_dp_display_disable(), called from .atomic_post_disable(), returns early
on !power_on. The PUSH_IDLE write is the only one that is not, so the
controller's runtime-PM reference is then dropped without the link having
been taken down.
On glymur (Snapdragon X2 Elite) the consequence is not a warning. The SoC
does not survive it: TrustZone force-stops the SOCCP and ADSP remote
processors and the machine resets silently about 50 ms later, with no oops
and no panic. On an ASUS Zenbook A16 (UX3607OA), whose eDP panel does not
currently train, this reproduces without any compositor or GPU involvement:
# eDP enable has already failed with "Failed link training (rc=-104)"
echo 1 > /sys/class/graphics/fb0/blank
[535.645455] === marker ===
[535.694833] qcom_q6v5_pas d00000.remoteproc: fatal error received: \
sys_m_smsm.c:512:TZ force stop
[535.694875] remoteproc remoteproc0: crash detected in soccp: type fatal error
[535.728857] qcom_q6v5_pas 6800000.remoteproc: fatal error received: \
sys_m_smsm.c:783:err fatal notification received from TZ
<SoC reset>
Gate the PUSH_IDLE write on ->power_on so the disable path is consistent
with the rest of the teardown. With this applied the same sequence is
harmless and the machine stays up; without it, it resets every time.
The unconditional write dates back to the original DP driver
(c943b4948b58 ("drm/msm/dp: add displayPort driver support")), but the
surrounding code has been restructured several times since, so no Fixes:
tag is offered.
Note that the eDP link-training failure that exposes this on the A16 is a
separate problem in the glymur eDP PHY and is reported separately; this
change is about not damaging the machine when training fails, for whatever
reason.
Tested on ASUS Zenbook A16 (UX3607OA), Snapdragon X2 Elite Extreme, on
linux-next next-20260803 and next-20260807. The machine has since been
running next-20260807 with this patch as its daily driver.
Assisted-by: Anthropic:Claude-Opus-5
Signed-off-by: Jesse Casco <jesse.casco@gmail.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/745167/
Link: https://lore.kernel.org/r/20260808171325.133041-1-jesse.casco@gmail.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dp/dp_display.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/drivers/gpu/drm/msm/dp/dp_display.c b/drivers/gpu/drm/msm/dp/dp_display.c
index 79e2b171e269a..a2f799cf50f63 100644
--- a/drivers/gpu/drm/msm/dp/dp_display.c
+++ b/drivers/gpu/drm/msm/dp/dp_display.c
@@ -1412,6 +1412,20 @@ void msm_dp_bridge_atomic_disable(struct drm_bridge *drm_bridge,
msm_dp_display = container_of(dp, struct msm_dp_display_private, msm_dp_display);
+ /*
+ * If .atomic_enable() bailed out - link training failure is the common
+ * case - the mainlink was never brought up and ->power_on stayed false.
+ * Driving the PUSH_IDLE pattern into a controller that was never
+ * enabled times out, and .atomic_post_disable() then drops the
+ * controller's runtime-PM reference without tearing the PHY back down,
+ * because msm_dp_display_disable() returns early on !power_on. On
+ * glymur (Snapdragon X2 Elite) that combination is answered by a
+ * TrustZone-level SOCCP/ADSP force-stop and a silent SoC reset.
+ * There is nothing to push idle, so leave it alone.
+ */
+ if (!dp->power_on)
+ return;
+
msm_dp_ctrl_push_idle(msm_dp_display->ctrl);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 076/398] wifi: mac80211: dont allow link changes when iface is down
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (74 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 075/398] wifi: mac80211: require a peer station for TDLS setup confirm Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 077/398] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set Greg Kroah-Hartman
` (326 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+582469b3a9ef5f13606b,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 370872d30349d81dec519e15ea2949fd63511cf7 ]
ieee80211_set_active_links() only checks that the interface is running in
the inner __ieee80211_set_active_links(), after drv_can_activate_links()
was already called, so using active_links on an interface that's down
triggers the check-sdata-in-driver warning.
Add the missing check in the debugfs file.
Assisted-by: LLM
Fixes: 3d9011029227 ("wifi: mac80211: implement link switching")
Reported-by: syzbot+582469b3a9ef5f13606b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=582469b3a9ef5f13606b
Link: https://patch.msgid.link/20260908122838.201719-16-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/debugfs_netdev.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/mac80211/debugfs_netdev.c b/net/mac80211/debugfs_netdev.c
index 30a5a978a678c..ba241567ac7e0 100644
--- a/net/mac80211/debugfs_netdev.c
+++ b/net/mac80211/debugfs_netdev.c
@@ -728,6 +728,9 @@ static ssize_t ieee80211_if_parse_active_links(struct ieee80211_sub_if_data *sda
if (kstrtou16(buf, 0, &active_links) || !active_links)
return -EINVAL;
+ if (!ieee80211_sdata_running(sdata))
+ return -ENETDOWN;
+
return ieee80211_set_active_links(&sdata->vif, active_links) ?: buflen;
}
IEEE80211_IF_FILE_RW(active_links);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 130/438] drm/msm/dp: fix link bandwidth check when wide bus is enabled
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (128 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 129/438] drm/msm/dp: skip PUSH_IDLE when the link was never enabled Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 131/438] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask Greg Kroah-Hartman
` (319 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, William Bright, Dmitry Baryshkov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: William Bright <william.bright@imd-tec.com>
[ Upstream commit 58995b11dfb7dda095d23f22fa4dc79b923b5adf ]
msm_dp_display_mode_valid() halves the pixel clock when either YUV420 or
wide bus is in use, then uses that halved value both for the controller
pixel clock limit and for the DP link bandwidth check.
Only YUV420 halves the data crossing the link. Wide bus widens the
internal DPU to DP interface to two pixels per clock, halving the
controller clock. Every pixel is still transmitted, so the link
bandwidth requirement remains.
As a result, modes needing up to twice the available link bandwidth pass
validation. On the IMDT QCS8550 SBC (rev5 with CYPD6125), where DP runs
over USB-C alt mode where only two lanes are available, 3840x2160@60 was
accepted despite needing 9.6 Gbps against the 8.64 Gbps the link can
carry.
Use a separate link pixel clock that is only halved for YUV420 for the
bandwidth calculation, leaving the wide bus halving to apply solely to
the controller pixel clock limit. With this, 4k@60 is correctly rejected
and 4k@30 selected instead.
Fixes: df9cf852ca30 ("drm/msm/dp: account for widebus and yuv420 during mode validation")
Assisted-by: Claude:claude-opus-5
Signed-off-by: William Bright <william.bright@imd-tec.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/746145/
Link: https://lore.kernel.org/r/20260812-msm-dp-link-bw-v1-1-b0e3ce1190be@imd-tec.com
[DB: dropped useless comment]
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dp/dp_display.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/msm/dp/dp_display.c b/drivers/gpu/drm/msm/dp/dp_display.c
index a2f799cf50f63..22eade11c6150 100644
--- a/drivers/gpu/drm/msm/dp/dp_display.c
+++ b/drivers/gpu/drm/msm/dp/dp_display.c
@@ -698,6 +698,7 @@ enum drm_mode_status msm_dp_bridge_mode_valid(struct drm_bridge *bridge,
u32 mode_rate_khz = 0, supported_rate_khz = 0, mode_bpp = 0;
struct msm_dp *dp;
int mode_pclk_khz = mode->clock;
+ int link_pclk_khz;
bool is_yuv_420;
dp = to_dp_bridge(bridge)->msm_dp_display;
@@ -719,6 +720,8 @@ enum drm_mode_status msm_dp_bridge_mode_valid(struct drm_bridge *bridge,
if (is_yuv_420 && !msm_dp_display->panel->vsc_sdp_supported)
return MODE_NO_420;
+ link_pclk_khz = is_yuv_420 ? mode_pclk_khz / 2 : mode_pclk_khz;
+
if (is_yuv_420 || msm_dp_display->wide_bus_supported)
mode_pclk_khz /= 2;
@@ -730,9 +733,9 @@ enum drm_mode_status msm_dp_bridge_mode_valid(struct drm_bridge *bridge,
mode_bpp = default_bpp;
mode_bpp = msm_dp_panel_get_mode_bpp(msm_dp_display->panel,
- mode_bpp, mode_pclk_khz);
+ mode_bpp, link_pclk_khz);
- mode_rate_khz = mode_pclk_khz * mode_bpp;
+ mode_rate_khz = link_pclk_khz * mode_bpp;
supported_rate_khz = link_info->num_lanes * link_info->rate * 8;
if (mode_rate_khz > supported_rate_khz)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 077/398] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (75 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 076/398] wifi: mac80211: dont allow link changes when iface is down Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 078/398] wifi: mac80211: dont access the TSF of a down interface Greg Kroah-Hartman
` (325 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b59873f5699e941717ca,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit b481e64e4498e2c053d5954f546ee02338f6ab63 ]
In the error path of ieee80211_mesh_csa_beacon() the settings that were
just assigned are read back with rcu_dereference(), which lockdep then
complains about.
There's no need to read the pointer at all, tmp_csa_settings still is
the right value anyway.
Assisted-by: LLM
Fixes: b8456a14e9d2 ("{nl,cfg,mac}80211: implement mesh channel switch userspace API")
Reported-by: syzbot+b59873f5699e941717ca@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b59873f5699e941717ca
Link: https://patch.msgid.link/20260908122838.201719-17-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mesh.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index 04b3ac4525035..a6c90cbb0baad 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -1575,7 +1575,6 @@ int ieee80211_mesh_csa_beacon(struct ieee80211_sub_if_data *sdata,
ret = ieee80211_mesh_rebuild_beacon(sdata);
if (ret) {
- tmp_csa_settings = rcu_dereference(ifmsh->csa);
RCU_INIT_POINTER(ifmsh->csa, NULL);
kfree_rcu(tmp_csa_settings, rcu_head);
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 131/438] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (129 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 130/438] drm/msm/dp: fix link bandwidth check when wide bus is enabled Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 132/438] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map Greg Kroah-Hartman
` (318 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Fitzgerald <rf@opensource.cirrus.com>
[ Upstream commit 4d855d747521505b54457c96bc73577bf74b2374 ]
Rename the ch_mask member of snd_soc_dai_link_ch_map to cpu_ch_mask,
as that is what it is used for.
The CPU and codec channel masks are not necessarily the same, and are
quite likely different. SoundWire and I2S/TDM both support assigning
different sample slots to each codec, so for example channel 0 on each
codec could map to different channels at the CPU. So it's quite normal
that the channel mask at the CPU end is different for each codec, but
the codec channel masks are the same for each codec.
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260910114500.1586637-2-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 6b382bdfe26a ("ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc.h | 2 +-
sound/soc/sdw_utils/soc_sdw_utils.c | 2 +-
sound/soc/soc-pcm.c | 2 +-
3 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/include/sound/soc.h b/include/sound/soc.h
index 10ad80f930c2e..300ce20fc7b70 100644
--- a/include/sound/soc.h
+++ b/include/sound/soc.h
@@ -698,7 +698,7 @@ struct snd_soc_dai_link_component {
struct snd_soc_dai_link_ch_map {
unsigned int cpu;
unsigned int codec;
- unsigned int ch_mask;
+ unsigned int cpu_ch_mask;
};
struct snd_soc_dai_link {
diff --git a/sound/soc/sdw_utils/soc_sdw_utils.c b/sound/soc/sdw_utils/soc_sdw_utils.c
index d8db8fc5313ee..ce2a9c28fe1a5 100644
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -1541,7 +1541,7 @@ int asoc_sdw_hw_params(struct snd_pcm_substream *substream,
* ASoC will set the corresponding channel numbers for each cpu dai.
*/
for_each_link_ch_maps(rtd->dai_link, i, ch_maps)
- ch_maps->ch_mask = ch_mask << (i * step);
+ ch_maps->cpu_ch_mask = ch_mask << (i * step);
return 0;
}
diff --git a/sound/soc/soc-pcm.c b/sound/soc/soc-pcm.c
index 0e49290a8c903..cb64ced211494 100644
--- a/sound/soc/soc-pcm.c
+++ b/sound/soc/soc-pcm.c
@@ -1264,7 +1264,7 @@ static int __soc_pcm_hw_params(struct snd_pcm_substream *substream,
*/
for_each_rtd_ch_maps(rtd, j, ch_maps)
if (ch_maps->cpu == i)
- ch_mask |= ch_maps->ch_mask;
+ ch_mask |= ch_maps->cpu_ch_mask;
/* fixup cpu channel number */
if (ch_mask)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 078/398] wifi: mac80211: dont access the TSF of a down interface
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (76 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 077/398] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 079/398] wifi: mac80211: add HE 6 GHz capability in the scan elems len Greg Kroah-Hartman
` (324 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+1c8c45017f784e646b47,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 0b1de9feeb8651f7a3bb53ed7c9006e3b5298c01 ]
The tsf debugfs files call the driver even if the interface
isn't up, tgriggering check-sdata-in-driver warnings.
Reject the access in that case.
Assisted-by: LLM
Fixes: 37a41b4affa3 ("mac80211: add ieee80211_vif param to tsf functions")
Reported-by: syzbot+1c8c45017f784e646b47@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1c8c45017f784e646b47
Link: https://patch.msgid.link/20260908122838.201719-18-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/debugfs_netdev.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/mac80211/debugfs_netdev.c b/net/mac80211/debugfs_netdev.c
index ba241567ac7e0..a7045787cb225 100644
--- a/net/mac80211/debugfs_netdev.c
+++ b/net/mac80211/debugfs_netdev.c
@@ -656,6 +656,9 @@ static ssize_t ieee80211_if_fmt_tsf(
struct ieee80211_local *local = sdata->local;
u64 tsf;
+ if (!ieee80211_sdata_running((struct ieee80211_sub_if_data *)sdata))
+ return -ENETDOWN;
+
tsf = drv_get_tsf(local, (struct ieee80211_sub_if_data *)sdata);
return scnprintf(buf, buflen, "0x%016llx\n", (unsigned long long) tsf);
@@ -669,6 +672,9 @@ static ssize_t ieee80211_if_parse_tsf(
int ret;
int tsf_is_delta = 0;
+ if (!ieee80211_sdata_running(sdata))
+ return -ENETDOWN;
+
if (strncmp(buf, "reset", 5) == 0) {
if (local->ops->reset_tsf) {
drv_reset_tsf(local, sdata);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 132/438] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (130 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 131/438] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 133/438] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params Greg Kroah-Hartman
` (317 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Fitzgerald <rf@opensource.cirrus.com>
[ Upstream commit 88b14c0d0bab5c0f3e7c641f274e3c70210c0e36 ]
Add a codec_ch_mask member to snd_soc_dai_link_ch_map.
The CPU and codec channel masks are not necessarily the same, and are
quite likely different. SoundWire and I2S/TDM both support assigning
different sample slots to each codec, so for example channel 0 on each
codec could map to different channels at the CPU.
It is also possible for one TX channel to map to multiple RX channels.
So it isn't _always_ safe to assume that the total number of set bits
in the CPU ch_mask is the same as the total number of enabled channels
on the codec.
For example consider this mapping on a capture stream:
CPU0 CODEC0 cpu_ch_mask = 0x03
CPU1 CODEC0 cpu_ch_mask = 0x03
This could be either four TX channels on the codec split across two
receiving CPUs, or two TX channels on the codec duplicated to two CPUs.
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260910114500.1586637-3-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 6b382bdfe26a ("ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc.h | 1 +
1 file changed, 1 insertion(+)
diff --git a/include/sound/soc.h b/include/sound/soc.h
index 300ce20fc7b70..1d2772758fb69 100644
--- a/include/sound/soc.h
+++ b/include/sound/soc.h
@@ -699,6 +699,7 @@ struct snd_soc_dai_link_ch_map {
unsigned int cpu;
unsigned int codec;
unsigned int cpu_ch_mask;
+ unsigned int codec_ch_mask;
};
struct snd_soc_dai_link {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 079/398] wifi: mac80211: add HE 6 GHz capability in the scan elems len
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (77 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 078/398] wifi: mac80211: dont access the TSF of a down interface Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 080/398] wifi: mac80211: mesh: reset the CSA state when leaving Greg Kroah-Hartman
` (323 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f961b9f94edbc266f1f8,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit cd54bf333f5631d3630bab0a832e9ae648f73515 ]
The HE 6 GHz Band Capability element is in the probe request for
every band if 6 GHz is supported, so add the size to scan_ies_len.
Otherwise, building probe request elements can fail, triggering the
WARN_ON in __ieee80211_start_scan().
Assisted-by: LLM
Fixes: 2ad2274c58ee ("mac80211: Add HE 6GHz capabilities element to probe request")
Reported-by: syzbot+f961b9f94edbc266f1f8@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f961b9f94edbc266f1f8
Link: https://patch.msgid.link/20260908122838.201719-19-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/main.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/net/mac80211/main.c b/net/mac80211/main.c
index 655a8aec77386..cf1d4a031af31 100644
--- a/net/mac80211/main.c
+++ b/net/mac80211/main.c
@@ -1431,6 +1431,10 @@ int ieee80211_register_hw(struct ieee80211_hw *hw)
sizeof(struct ieee80211_he_mcs_nss_supp) +
IEEE80211_HE_PPE_THRES_MAX_LEN;
+ if (local->hw.wiphy->bands[NL80211_BAND_6GHZ])
+ local->scan_ies_len +=
+ 3 + sizeof(struct ieee80211_he_6ghz_capa);
+
if (supp_eht)
local->scan_ies_len +=
3 + sizeof(struct ieee80211_eht_cap_elem) +
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 133/438] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (131 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 132/438] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 134/438] spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register Greg Kroah-Hartman
` (316 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Fitzgerald <rf@opensource.cirrus.com>
[ Upstream commit 6b382bdfe26a2232091bf743e454e6794295783e ]
In __soc_pcm_hw_params() if there is a snd_soc_dai_link_ch_map with
non-zero codec_ch_mask, use that channel mask to restrict which channels
are enabled on the codec. But only if there isn't a TDM mask.
It is possible that a snd_soc_dai_link_ch_map could include the same codec
multiple times on different CPUs so the for_each_rtd_ch_maps() loop
accumulates the channel masks for all entries of that codec.
If a TDM mask was also set, it takes priority and is used instead of any
possible snd_soc_dai_link_ch_map entries. (They cannot be ANDed together
because the bit positions are indicating different things: TDM is a bit
for each TDM slot, codec_ch_mask is a bit for each codec channel.)
This fixes a problem of incorrect TX channels enabled on the codec when
multiple codecs are aggregated on a single capture link. For example:
- Two CPUs with six 4-channel codecs.
- The machine driver chooses to assign one channel from each codec to
one channel on the CPU
- But the codec hw_params() would be passed a channel count of 6, which
(a) is more channels than the codec has and (b) allows enabling channels
that should not be driving the audio bus.
Fixes: ac950278b087 ("ASoC: add N cpus to M codecs dai link support")
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260910114500.1586637-4-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/soc-pcm.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
diff --git a/sound/soc/soc-pcm.c b/sound/soc/soc-pcm.c
index cb64ced211494..3137c091bdb88 100644
--- a/sound/soc/soc-pcm.c
+++ b/sound/soc/soc-pcm.c
@@ -1206,7 +1206,9 @@ static int __soc_pcm_hw_params(struct snd_pcm_substream *substream,
goto out;
for_each_rtd_codec_dais(rtd, i, codec_dai) {
- unsigned int tdm_mask = snd_soc_dai_tdm_mask_get(codec_dai, substream->stream);
+ unsigned int ch_mask = snd_soc_dai_tdm_mask_get(codec_dai, substream->stream);
+ struct snd_soc_dai_link_ch_map *ch_maps;
+ int j;
/*
* Skip CODECs which don't support the current stream type,
@@ -1228,9 +1230,15 @@ static int __soc_pcm_hw_params(struct snd_pcm_substream *substream,
/* copy params for each codec */
tmp_params = *params;
- /* fixup params based on TDM slot masks */
- if (tdm_mask)
- soc_pcm_codec_params_fixup(&tmp_params, tdm_mask);
+ /* fixup params based on TDM or ch_map masks */
+ if (!ch_mask) {
+ for_each_rtd_ch_maps(rtd, j, ch_maps)
+ if (ch_maps->codec == i)
+ ch_mask |= ch_maps->codec_ch_mask;
+ }
+
+ if (ch_mask)
+ soc_pcm_codec_params_fixup(&tmp_params, ch_mask);
ret = snd_soc_dai_hw_params(codec_dai, substream,
&tmp_params);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 080/398] wifi: mac80211: mesh: reset the CSA state when leaving
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (78 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 079/398] wifi: mac80211: add HE 6 GHz capability in the scan elems len Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 081/398] wifi: mac80211: mesh: release the channel if start fails Greg Kroah-Hartman
` (322 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+f5752cd6b94fe38be666,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 860134b3af77970e006feab7e5decb8c84771c7f ]
ifmsh->csa is allocated in ieee80211_mesh_csa_beacon() and only freed
in ieee80211_mesh_finish_csa(), i.e. when the channel switch completes.
Leaving the mesh while a switch is still pending therefore leaks it.
Additionally, ifmsh->csa_role and ifmsh->chsw_ttl have their state leak
in this case, so things can get mixed up in addition to the memory
leak.
Refactor the reset and call it in ieee80211_stop_mesh() to fix it all.
Assisted-by: LLM
Reported-by: syzbot+f5752cd6b94fe38be666@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f5752cd6b94fe38be666
Fixes: b8456a14e9d2 ("{nl,cfg,mac}80211: implement mesh channel switch userspace API")
Link: https://patch.msgid.link/20260908122838.201719-20-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mesh.c | 29 ++++++++++++++++++-----------
1 file changed, 18 insertions(+), 11 deletions(-)
diff --git a/net/mac80211/mesh.c b/net/mac80211/mesh.c
index a6c90cbb0baad..a18b8b2260012 100644
--- a/net/mac80211/mesh.c
+++ b/net/mac80211/mesh.c
@@ -1215,6 +1215,21 @@ int ieee80211_start_mesh(struct ieee80211_sub_if_data *sdata)
return 0;
}
+static void ieee80211_mesh_reset_csa(struct ieee80211_sub_if_data *sdata)
+{
+ struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
+ struct mesh_csa_settings *csa;
+
+ /* Reset the TTL value and Initiator flag */
+ ifmsh->csa_role = IEEE80211_MESH_CSA_ROLE_NONE;
+ ifmsh->chsw_ttl = 0;
+
+ /* Remove the CSA and MCSP elements from the beacon */
+ csa = sdata_dereference(ifmsh->csa, sdata);
+ RCU_INIT_POINTER(ifmsh->csa, NULL);
+ kfree_rcu(csa, rcu_head);
+}
+
void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
{
struct ieee80211_local *local = sdata->local;
@@ -1225,6 +1240,7 @@ void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
/* abort any running channel switch */
sdata->vif.bss_conf.csa_active = false;
+ ieee80211_mesh_reset_csa(sdata);
ieee80211_vif_unblock_queues_csa(sdata);
/* flush STAs and mpaths on this iface */
@@ -1529,19 +1545,10 @@ static void ieee80211_mesh_rx_bcn_presp(struct ieee80211_sub_if_data *sdata,
int ieee80211_mesh_finish_csa(struct ieee80211_sub_if_data *sdata, u64 *changed)
{
- struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
- struct mesh_csa_settings *tmp_csa_settings;
- int ret = 0;
+ int ret;
- /* Reset the TTL value and Initiator flag */
- ifmsh->csa_role = IEEE80211_MESH_CSA_ROLE_NONE;
- ifmsh->chsw_ttl = 0;
+ ieee80211_mesh_reset_csa(sdata);
- /* Remove the CSA and MCSP elements from the beacon */
- tmp_csa_settings = sdata_dereference(ifmsh->csa, sdata);
- RCU_INIT_POINTER(ifmsh->csa, NULL);
- if (tmp_csa_settings)
- kfree_rcu(tmp_csa_settings, rcu_head);
ret = ieee80211_mesh_rebuild_beacon(sdata);
if (ret)
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 134/438] spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (132 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 133/438] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 135/438] Input: trackpoint - fix the inertia attribute name in the ABI document Greg Kroah-Hartman
` (315 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gabor Juhos, Md Sadre Alam,
Mark Brown, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gabor Juhos <j4g8y7@gmail.com>
[ Upstream commit 930a7312c946bf4731721cadd82bb9a2ada496ca ]
The description of commit bfb34eced559 ("mtd: rawnand: qcom: avoid writing
to obsolete register") says this:
"QPIC_EBI2_ECC_BUF_CFG register got obsolete from QPIC V2.0 onwards.
Avoid writing this register if QPIC version is V2.0 or newer."
Although the referenced commit is related to the 'qcom-nandc' driver,
however the hardware supported by the current driver is also based on
QPIC v2.0 so we should avoid writing that register here as well.
Remove the register writing code to avoid undefined behaviour.
Fixes: 7304d1909080 ("spi: spi-qpic: add driver for QCOM SPI NAND flash Interface")
Signed-off-by: Gabor Juhos <j4g8y7@gmail.com>
Reviewed-by: Md Sadre Alam <md.alam@oss.qualcomm.com>
Link: https://patch.msgid.link/20260909-qpic-snand-avoid-ebi2-reg-write-v1-1-9b1b1466cc75@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-qpic-snand.c | 4 ----
1 file changed, 4 deletions(-)
diff --git a/drivers/spi/spi-qpic-snand.c b/drivers/spi/spi-qpic-snand.c
index b6c58d9cfe143..8388c637eee00 100644
--- a/drivers/spi/spi-qpic-snand.c
+++ b/drivers/spi/spi-qpic-snand.c
@@ -740,8 +740,6 @@ static int qcom_spi_read_cw_raw(struct qcom_nand_controller *snandc, u8 *data_bu
qcom_write_reg_dma(snandc, &snandc->regs->addr0, NAND_ADDR0, 2, 0);
qcom_write_reg_dma(snandc, &snandc->regs->cfg0, NAND_DEV0_CFG0, 3, 0);
- qcom_write_reg_dma(snandc, &snandc->regs->ecc_buf_cfg, NAND_EBI2_ECC_BUF_CFG, 1, 0);
-
qcom_write_reg_dma(snandc, &snandc->regs->erased_cw_detect_cfg_clr,
NAND_ERASED_CW_DETECT_CFG, 1, 0);
qcom_write_reg_dma(snandc, &snandc->regs->erased_cw_detect_cfg_set,
@@ -1008,8 +1006,6 @@ static void qcom_spi_config_page_write(struct qcom_nand_controller *snandc)
{
qcom_write_reg_dma(snandc, &snandc->regs->addr0, NAND_ADDR0, 2, 0);
qcom_write_reg_dma(snandc, &snandc->regs->cfg0, NAND_DEV0_CFG0, 3, 0);
- qcom_write_reg_dma(snandc, &snandc->regs->ecc_buf_cfg, NAND_EBI2_ECC_BUF_CFG,
- 1, NAND_BAM_NEXT_SGL);
}
static void qcom_spi_config_cw_write(struct qcom_nand_controller *snandc)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 081/398] wifi: mac80211: mesh: release the channel if start fails
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (79 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 080/398] wifi: mac80211: mesh: reset the CSA state when leaving Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 082/398] wifi: mac80211: set up the TX info early to fix failure paths Greg Kroah-Hartman
` (321 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+63a84ea9c0f57d6133fa,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit ae97fff6495a8764bc0ef281cfe5444f701e527f ]
ieee80211_join_mesh() acquires a channel context and then calls
ieee80211_start_mesh(), which can fail. In that case, the chanctx
isn't released then interface removal will attempt to unassign it
after it's removed from the driver, hitting:
wlan0: Failed check-sdata-in-driver check, flags: 0x0
WARNING: net/mac80211/driver-ops.c:366 at drv_unassign_vif_chanctx
ieee80211_assign_link_chanctx
__ieee80211_link_release_channel
ieee80211_link_release_channel
ieee80211_teardown_sdata
unregister_netdevice_many_notify
_cfg80211_unregister_wdev
ieee80211_remove_interfaces
ieee80211_unregister_hw
mac80211_hwsim_del_radio
hwsim_exit_net
Correctly release the channel on start failures.
Assisted-by: LLM
Reported-by: syzbot+63a84ea9c0f57d6133fa@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=63a84ea9c0f57d6133fa
Fixes: 2b5e19677592 ("mac80211: cache mesh beacon")
Link: https://patch.msgid.link/20260908122838.201719-21-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/cfg.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
index 84e27d8a75ef1..2116485377c7e 100644
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -2941,7 +2941,11 @@ static int ieee80211_join_mesh(struct wiphy *wiphy, struct net_device *dev,
if (err)
return err;
- return ieee80211_start_mesh(sdata);
+ err = ieee80211_start_mesh(sdata);
+ if (err)
+ ieee80211_link_release_channel(&sdata->deflink);
+
+ return err;
}
static int ieee80211_leave_mesh(struct wiphy *wiphy, struct net_device *dev)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 135/438] Input: trackpoint - fix the inertia attribute name in the ABI document
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (133 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 134/438] spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 136/438] objtool: Validate disassembler headers in libopcodes probe Greg Kroah-Hartman
` (314 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Dmitry Torokhov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 45b0037899704caf9078be2be4de69361ca7d933 ]
The attribute is created as "inertia" (TRACKPOINT_INT_ATTR(inertia, ...)
in drivers/input/mouse/trackpoint.c); the ABI file spells the path
"intertia". The description below it already says inertia.
Fix the spelling.
Fixes: aebb47d4e7a9 ("Input: trackpoint: document sysfs interface")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260905102038.42882-1-kmehltretter@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/ABI/testing/sysfs-devices-platform-trackpoint | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Documentation/ABI/testing/sysfs-devices-platform-trackpoint b/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
index df11901a6b3df..7954434b0434a 100644
--- a/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
+++ b/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
@@ -5,7 +5,7 @@ Contact: linux-input@vger.kernel.org
Description:
(RW) Trackpoint sensitivity.
-What: /sys/devices/platform/i8042/.../intertia
+What: /sys/devices/platform/i8042/.../inertia
Date: Aug, 2005
KernelVersion: 2.6.14
Contact: linux-input@vger.kernel.org
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 082/398] wifi: mac80211: set up the TX info early to fix failure paths
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (80 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 081/398] wifi: mac80211: mesh: release the channel if start fails Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 083/398] mm: memblock: show all region flags in debugfs Greg Kroah-Hartman
` (320 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 50d3d79dc0743b616afb00d01a626c76758721f7 ]
The previous commit 2c51457d930f ("wifi: mac80211: free ack status
frame on TX header build failure") cleaned up the leak, but still
left the code a bit messy and the failed SKB didn't get reported
to userspace.
Fix this up by initialising skb->cb[] earlier, which allows using
ieee80211_free_txskb() and therefore reports it for the failure
in ieee80211_build_hdr(), and unifies the ieee80211_skb_resize()
failure path with it.
Assisted-by: LLM
Fixes: c3e7724b6bc2 ("mac80211: use ieee80211_free_txskb to fix possible skb leaks")
Link: https://patch.msgid.link/20260908122838.201719-22-johannes@sipsolutions.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tx.c | 38 ++++++++++++++++++++------------------
1 file changed, 20 insertions(+), 18 deletions(-)
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index 4258dcea36f0b..931846f45c2e1 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -2926,10 +2926,23 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
*/
skb = skb_share_check(skb, GFP_ATOMIC);
if (unlikely(!skb)) {
- ret = -ENOMEM;
- goto free;
+ /* skb_share_check() already freed the skb */
+ if (info_id)
+ ieee80211_remove_ack_skb(local, info_id);
+ return ERR_PTR(-ENOMEM);
}
+ /* set this up so failure paths can clean up ack skb */
+ info = IEEE80211_SKB_CB(skb);
+ memset(info, 0, sizeof(*info));
+
+ info->flags = info_flags;
+ if (info_id) {
+ info->status_data = info_id;
+ info->status_data_idr = 1;
+ }
+ info->band = band;
+
hdr.frame_control = fc;
hdr.duration_id = 0;
hdr.seq_ctrl = 0;
@@ -2968,10 +2981,8 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
head_need += local->tx_headroom;
head_need = max_t(int, 0, head_need);
if (ieee80211_skb_resize(sdata, skb, head_need, ENCRYPT_DATA)) {
- ieee80211_free_txskb(&local->hw, skb);
- skb = NULL;
ret = -ENOMEM;
- goto free;
+ goto free_txskb;
}
}
@@ -2998,16 +3009,6 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
skb_reset_mac_header(skb);
- info = IEEE80211_SKB_CB(skb);
- memset(info, 0, sizeof(*info));
-
- info->flags = info_flags;
- if (info_id) {
- info->status_data = info_id;
- info->status_data_idr = 1;
- }
- info->band = band;
-
if (likely(!cookie)) {
ctrl_flags |= u32_encode_bits(link_id,
IEEE80211_TX_CTRL_MLO_LINK);
@@ -3031,16 +3032,17 @@ static struct sk_buff *ieee80211_build_hdr(struct ieee80211_sub_if_data *sdata,
pre_conf_link_id, link_id);
#endif
ret = -EINVAL;
- goto free;
+ goto free_txskb;
}
}
info->control.flags = ctrl_flags;
return skb;
+ free_txskb:
+ ieee80211_free_txskb(&local->hw, skb);
+ return ERR_PTR(ret);
free:
- if (info_id)
- ieee80211_remove_ack_skb(local, info_id);
kfree_skb(skb);
return ERR_PTR(ret);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 136/438] objtool: Validate disassembler headers in libopcodes probe
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (134 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 135/438] Input: trackpoint - fix the inertia attribute name in the ABI document Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 137/438] gpio: virtuser: skip free_irq when no IRQ is installed Greg Kroah-Hartman
` (313 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alice Ryhl, Ulises Mendez Martinez,
Josh Poimboeuf, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ulises Mendez Martinez <umendez@google.com>
[ Upstream commit 7e61560628d17ea6b1d8ee370f6d42694cff8758 ]
commit 3f2de814c059 ("objtool: Fix libopcodes linking with static libraries")
tested for libopcodes availability by linking a test snippet with a forward
declaration of disassemble_init_for_target().
However, testing symbol linkage with an extern declaration only verifies
the presence of the library (.so/.a) and bypasses checking for development
headers (binutils-dev). On systems where libopcodes is present without
development headers installed, the probe succeeds, enabling BUILD_DISAS.
Subsequent compilation of objtool then fails:
fatal error: 'bfd.h' file not found
113 | #include <bfd.h>
Additionally, the probe invokes $(HOSTCC) without $(HOSTCFLAGS), ignoring
any sysroot or include flags specified for the host compiler.
Fix this by including <bfd.h> and <dis-asm.h> directly in the test snippet,
passing $(HOSTCFLAGS) so host compiler options are respected, and defining
PACKAGE="objtool" to satisfy the configuration check in <bfd.h>.
Fixes: 3f2de814c059 ("objtool: Fix libopcodes linking with static libraries")
Fixes: 436326bc525d ("objtool: fix build failure due to missing libopcodes check")
Reported-by: Alice Ryhl <aliceryhl@google.com>
Assisted-by: Antigravity:Gemini-Next
Signed-off-by: Ulises Mendez Martinez <umendez@google.com>
Link: https://patch.msgid.link/20260904150710.2997558-1-umendez@google.com
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/objtool/Makefile | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/tools/objtool/Makefile b/tools/objtool/Makefile
index a4484fd22a96d..4cc2e756af840 100644
--- a/tools/objtool/Makefile
+++ b/tools/objtool/Makefile
@@ -89,9 +89,11 @@ LIBOPCODES_LIBS := $(shell \
"-lopcodes -lbfd" \
"-lopcodes -lbfd -liberty" \
"-lopcodes -lbfd -liberty -lz"; do \
- echo 'extern void disassemble_init_for_target(void *);' \
- 'int main(void) { disassemble_init_for_target(0); return 0; }' | \
- $(HOSTCC) -xc - -o /dev/null $$libs 2>/dev/null && \
+ printf '%s\n' \
+ '$(pound)include <bfd.h>' \
+ '$(pound)include <dis-asm.h>' \
+ 'int main(void) { disassemble_init_for_target(0); return 0; }' | \
+ $(HOSTCC) $(HOSTCFLAGS) -DPACKAGE='"objtool"' -xc - -o /dev/null $$libs 2>/dev/null && \
echo "$$libs" && break; \
done)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 083/398] mm: memblock: show all region flags in debugfs
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (81 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 082/398] wifi: mac80211: set up the TX info early to fix failure paths Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 084/398] scsi: qla2xxx: Fix the ql2xfc2target parameter description Greg Kroah-Hartman
` (319 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Meijing Zhao,
Mike Rapoport (Microsoft), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Meijing Zhao <zhaomeijing@lixiang.com>
[ Upstream commit e2d5b01f878d76bd1142e512a0b979a1d3cd0abf ]
Commit 493f349e38d0 ("memblock: Add flags and nid info in memblock
debugfs") made memblock_debug_show() stop after finding the first set
flag. A memblock region can carry multiple flags, so the remaining flags
are hidden from debugfs.
Walk all bits in the region flags and print every set flag separated by
"|". Keep walking beyond flagname[] so that a set flag without a known
name is reported as UNKNOWN rather than silently ignored.
Fixes: 493f349e38d0 ("memblock: Add flags and nid info in memblock debugfs")
Signed-off-by: Meijing Zhao <zhaomeijing@lixiang.com>
Link: https://patch.msgid.link/20260902075944.3742866-1-zhaomeijing100@gmail.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
mm/memblock.c | 18 +++++++++++-------
1 file changed, 11 insertions(+), 7 deletions(-)
diff --git a/mm/memblock.c b/mm/memblock.c
index 757258d68425a..e2f15bbc274b5 100644
--- a/mm/memblock.c
+++ b/mm/memblock.c
@@ -2727,14 +2727,18 @@ static int memblock_debug_show(struct seq_file *m, void *private)
else
seq_printf(m, "%4c ", 'x');
if (reg->flags) {
- for (j = 0; j < count; j++) {
- if (reg->flags & (1U << j)) {
- seq_printf(m, "%s\n", flagname[j]);
- break;
- }
+ unsigned int flags = reg->flags;
+ bool first = true;
+
+ for (j = 0; flags; j++, flags >>= 1) {
+ if (!(flags & 1))
+ continue;
+ if (!first)
+ seq_putc(m, '|');
+ seq_puts(m, j < count ? flagname[j] : "UNKNOWN");
+ first = false;
}
- if (j == count)
- seq_printf(m, "%s\n", "UNKNOWN");
+ seq_putc(m, '\n');
} else {
seq_printf(m, "%s\n", "NONE");
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 137/438] gpio: virtuser: skip free_irq when no IRQ is installed
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (135 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 136/438] objtool: Validate disassembler headers in libopcodes probe Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 138/438] ALSA: usb: 6fire: Avoid embedded URBs Greg Kroah-Hartman
` (312 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Linus Walleij,
Bartosz Golaszewski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
[ Upstream commit 50fd0ada8d37587223001600933270b59cb30e19 ]
Disabling interrupt monitoring uses atomic_xchg() to clear the stored IRQ.
When monitoring is already disabled, atomic_xchg() returns 0. It must not
be passed to free_irq().
The bug is reproducible on an x86_64 QEMU guest with
CONFIG_GPIO_VIRTUSER=y and CONFIG_GPIO_SIM=y. Configure a live
gpio-virtuser device through configfs. Its input lookup must refer to a
live gpio-sim bank, such as key gpio-sim-test with offset 0. The
consumer's dev_name attribute is shown as <dev> below; then run:
echo 0 > /sys/kernel/debug/gpio-virtuser/<dev>/gpiod:input:0/interrupts
On an unpatched kernel, this reaches gpio_virtuser_interrupts_set() with
ld->irq still at its initial value 0, and free_irq() reports:
Trying to free already-free IRQ 0
The same reproducer completes without the warning on the patched kernel.
Fixes: 91581c4b3f29 ("gpio: virtuser: new virtual testing driver for the GPIO API")
Assisted-by: LLM
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260914051537.15320-1-runyu.xiao@seu.edu.cn
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpio/gpio-virtuser.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/gpio/gpio-virtuser.c b/drivers/gpio/gpio-virtuser.c
index 7d0d366be37a4..d5876c19cfefa 100644
--- a/drivers/gpio/gpio-virtuser.c
+++ b/drivers/gpio/gpio-virtuser.c
@@ -692,7 +692,8 @@ static int gpio_virtuser_interrupts_set(void *data, u64 val)
atomic_set(&ld->irq, irq);
} else {
irq = atomic_xchg(&ld->irq, 0);
- free_irq(irq, ld);
+ if (irq)
+ free_irq(irq, ld);
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 084/398] scsi: qla2xxx: Fix the ql2xfc2target parameter description
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (82 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 083/398] mm: memblock: show all region flags in debugfs Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 085/398] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order Greg Kroah-Hartman
` (318 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter,
Martin K. Petersen (Oracle), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 779f202a92ef10a426efc07d0f4267918cb07ca3 ]
The module parameter is ql2xfc2target, but its MODULE_PARM_DESC() names
qla2xfc2target, so modinfo describes a parameter that does not exist and
shows no description for the real one.
Use the parameter name in the description.
Fixes: 877b03795fcf ("scsi: qla2xxx: Add option to disable FC2 Target support")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260906171009.2560-1-kmehltretter@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/qla2xxx/qla_os.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/scsi/qla2xxx/qla_os.c b/drivers/scsi/qla2xxx/qla_os.c
index 3e148e4e94593..07ccfe0226c5e 100644
--- a/drivers/scsi/qla2xxx/qla_os.c
+++ b/drivers/scsi/qla2xxx/qla_os.c
@@ -351,7 +351,7 @@ MODULE_PARM_DESC(ql2xnvme_queues,
int ql2xfc2target = 1;
module_param(ql2xfc2target, int, 0444);
-MODULE_PARM_DESC(qla2xfc2target,
+MODULE_PARM_DESC(ql2xfc2target,
"Enables FC2 Target support. "
"0 - FC2 Target support is disabled. "
"1 - FC2 Target support is enabled (default).");
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 138/438] ALSA: usb: 6fire: Avoid embedded URBs
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (136 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 137/438] gpio: virtuser: skip free_irq when no IRQ is installed Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 139/438] ALSA: 6fire: fix OOB write from device-reported iso length Greg Kroah-Hartman
` (311 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 9fe49dbc023e82dfaee7b245997d820d01742a9a ]
The USB 6fire driver uses URBs embedded in different structs for PCM,
MIDI and communication, and this is basically a buggy implementation
nowadays; since a URB is managed with a refcount, this may lead to a
UAF when the URB is released asynchronously.
For addressing the problem, this patch converts those embedded URBs to
ones that are properly allocated via usb_alloc_urb(). The
pcm_urb.packets[] is gone, as it's allocated by usb_alloc_urb(), hence
it's found in urb.iso_frame_desc[] instead.
The conversions are rather straightforward; each embedded struct urb
is changed to a pointer, and its callers are updated accordingly.
The resource for those structs are released in the common destructor
functions (usb6fire_comm_free(), etc), which are called at both the
init error path and the disconnect.
No functional changes, only compile-tested.
Link: https://lore.kernel.org/20260903130757.0668310a.michal.pecio@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260903160458.1938392-4-tiwai@suse.de
Stable-dep-of: 1589afe2d099 ("ALSA: 6fire: fix OOB write from device-reported iso length")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/6fire/comm.c | 42 +++++++++-----
sound/usb/6fire/comm.h | 2 +-
sound/usb/6fire/midi.c | 43 +++++++++-----
sound/usb/6fire/midi.h | 2 +-
sound/usb/6fire/pcm.c | 128 ++++++++++++++++++++++++-----------------
sound/usb/6fire/pcm.h | 5 +-
6 files changed, 136 insertions(+), 86 deletions(-)
diff --git a/sound/usb/6fire/comm.c b/sound/usb/6fire/comm.c
index d3b7cab856997..510d310824e91 100644
--- a/sound/usb/6fire/comm.c
+++ b/sound/usb/6fire/comm.c
@@ -21,7 +21,6 @@ enum {
static void usb6fire_comm_init_urb(struct comm_runtime *rt, struct urb *urb,
u8 *buffer, void *context, void(*handler)(struct urb *urb))
{
- usb_init_urb(urb);
urb->transfer_buffer = buffer;
urb->pipe = usb_sndintpipe(rt->chip->dev, COMM_EP);
urb->complete = handler;
@@ -142,6 +141,19 @@ static int usb6fire_comm_write16(struct comm_runtime *rt, u8 request,
return ret;
}
+static void usb6fire_comm_free(struct comm_runtime *rt)
+{
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->comm = NULL;
+
+ usb_free_urb(rt->receiver);
+ kfree(rt->receiver_buffer);
+ kfree(rt);
+}
+
int usb6fire_comm_init(struct sfire_chip *chip)
{
struct comm_runtime *rt = kzalloc_obj(struct comm_runtime);
@@ -153,14 +165,18 @@ int usb6fire_comm_init(struct sfire_chip *chip)
rt->receiver_buffer = kzalloc(COMM_RECEIVER_BUFSIZE, GFP_KERNEL);
if (!rt->receiver_buffer) {
- kfree(rt);
- return -ENOMEM;
+ ret = -ENOMEM;
+ goto error;
}
- urb = &rt->receiver;
+ urb = usb_alloc_urb(0, GFP_KERNEL);
+ if (!urb) {
+ ret = -ENOMEM;
+ goto error;
+ }
+ rt->receiver = urb;
rt->serial = 1;
rt->chip = chip;
- usb_init_urb(urb);
rt->init_urb = usb6fire_comm_init_urb;
rt->write8 = usb6fire_comm_write8;
rt->write16 = usb6fire_comm_write16;
@@ -175,13 +191,15 @@ int usb6fire_comm_init(struct sfire_chip *chip)
urb->interval = 1;
ret = usb_submit_urb(urb, GFP_KERNEL);
if (ret < 0) {
- kfree(rt->receiver_buffer);
- kfree(rt);
dev_err(&chip->dev->dev, "cannot create comm data receiver.");
- return ret;
+ goto error;
}
chip->comm = rt;
return 0;
+
+ error:
+ usb6fire_comm_free(rt);
+ return ret;
}
void usb6fire_comm_abort(struct sfire_chip *chip)
@@ -189,14 +207,10 @@ void usb6fire_comm_abort(struct sfire_chip *chip)
struct comm_runtime *rt = chip->comm;
if (rt)
- usb_poison_urb(&rt->receiver);
+ usb_poison_urb(rt->receiver);
}
void usb6fire_comm_destroy(struct sfire_chip *chip)
{
- struct comm_runtime *rt = chip->comm;
-
- kfree(rt->receiver_buffer);
- kfree(rt);
- chip->comm = NULL;
+ usb6fire_comm_free(chip->comm);
}
diff --git a/sound/usb/6fire/comm.h b/sound/usb/6fire/comm.h
index 2447d7ecf1798..89976f510f6c2 100644
--- a/sound/usb/6fire/comm.h
+++ b/sound/usb/6fire/comm.h
@@ -19,7 +19,7 @@ enum /* settings for comm */
struct comm_runtime {
struct sfire_chip *chip;
- struct urb receiver;
+ struct urb *receiver;
u8 *receiver_buffer;
u8 serial; /* urb serial */
diff --git a/sound/usb/6fire/midi.c b/sound/usb/6fire/midi.c
index 6b0bb096f27a1..279b449936e75 100644
--- a/sound/usb/6fire/midi.c
+++ b/sound/usb/6fire/midi.c
@@ -66,7 +66,7 @@ static void usb6fire_midi_out_trigger(
struct snd_rawmidi_substream *alsa_sub, int up)
{
struct midi_runtime *rt = alsa_sub->rmidi->private_data;
- struct urb *urb = &rt->out_urb;
+ struct urb *urb = rt->out_urb;
__s8 ret;
guard(spinlock_irqsave)(&rt->out_lock);
@@ -137,6 +137,19 @@ static const struct snd_rawmidi_ops in_ops = {
.trigger = usb6fire_midi_in_trigger
};
+static void usb6fire_midi_free(struct midi_runtime *rt)
+{
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->midi = NULL;
+
+ usb_free_urb(rt->out_urb);
+ kfree(rt->out_buffer);
+ kfree(rt);
+}
+
int usb6fire_midi_init(struct sfire_chip *chip)
{
int ret;
@@ -148,8 +161,14 @@ int usb6fire_midi_init(struct sfire_chip *chip)
rt->out_buffer = kzalloc(MIDI_BUFSIZE, GFP_KERNEL);
if (!rt->out_buffer) {
- kfree(rt);
- return -ENOMEM;
+ ret = -ENOMEM;
+ goto error;
+ }
+
+ rt->out_urb = usb_alloc_urb(0, GFP_KERNEL);
+ if (!rt->out_urb) {
+ ret = -ENOMEM;
+ goto error;
}
rt->chip = chip;
@@ -160,15 +179,13 @@ int usb6fire_midi_init(struct sfire_chip *chip)
spin_lock_init(&rt->in_lock);
spin_lock_init(&rt->out_lock);
- comm_rt->init_urb(comm_rt, &rt->out_urb, rt->out_buffer, rt,
+ comm_rt->init_urb(comm_rt, rt->out_urb, rt->out_buffer, rt,
usb6fire_midi_out_handler);
ret = snd_rawmidi_new(chip->card, "6FireUSB", 0, 1, 1, &rt->instance);
if (ret < 0) {
- kfree(rt->out_buffer);
- kfree(rt);
dev_err(&chip->dev->dev, "unable to create midi.\n");
- return ret;
+ goto error;
}
rt->instance->private_data = rt;
strscpy(rt->instance->name, "DMX6FireUSB MIDI");
@@ -182,6 +199,10 @@ int usb6fire_midi_init(struct sfire_chip *chip)
chip->midi = rt;
return 0;
+
+ error:
+ usb6fire_midi_free(rt);
+ return ret;
}
void usb6fire_midi_abort(struct sfire_chip *chip)
@@ -189,14 +210,10 @@ void usb6fire_midi_abort(struct sfire_chip *chip)
struct midi_runtime *rt = chip->midi;
if (rt)
- usb_poison_urb(&rt->out_urb);
+ usb_poison_urb(rt->out_urb);
}
void usb6fire_midi_destroy(struct sfire_chip *chip)
{
- struct midi_runtime *rt = chip->midi;
-
- kfree(rt->out_buffer);
- kfree(rt);
- chip->midi = NULL;
+ usb6fire_midi_free(chip->midi);
}
diff --git a/sound/usb/6fire/midi.h b/sound/usb/6fire/midi.h
index 47640c845903b..8716ab8a863ae 100644
--- a/sound/usb/6fire/midi.h
+++ b/sound/usb/6fire/midi.h
@@ -22,7 +22,7 @@ struct midi_runtime {
spinlock_t in_lock;
spinlock_t out_lock;
struct snd_rawmidi_substream *out;
- struct urb out_urb;
+ struct urb *out_urb;
u8 out_serial; /* serial number of out packet */
u8 *out_buffer;
int buffer_offset;
diff --git a/sound/usb/6fire/pcm.c b/sound/usb/6fire/pcm.c
index d2e274b731fe5..21789db6657d3 100644
--- a/sound/usb/6fire/pcm.c
+++ b/sound/usb/6fire/pcm.c
@@ -138,8 +138,8 @@ static void usb6fire_pcm_stream_stop(struct pcm_runtime *rt)
rt->stream_state = STREAM_STOPPING;
for (i = 0; i < PCM_N_URBS; i++) {
- usb_kill_urb(&rt->in_urbs[i].instance);
- usb_kill_urb(&rt->out_urbs[i].instance);
+ usb_kill_urb(rt->in_urbs[i].instance);
+ usb_kill_urb(rt->out_urbs[i].instance);
}
ctrl_rt->usb_streaming = false;
ctrl_rt->update_streaming(ctrl_rt);
@@ -161,13 +161,13 @@ static int usb6fire_pcm_stream_start(struct pcm_runtime *rt)
rt->stream_state = STREAM_STARTING;
for (i = 0; i < PCM_N_URBS; i++) {
for (k = 0; k < PCM_N_PACKETS_PER_URB; k++) {
- packet = &rt->in_urbs[i].packets[k];
+ packet = &rt->in_urbs[i].instance->iso_frame_desc[k];
packet->offset = k * rt->in_packet_size;
packet->length = rt->in_packet_size;
packet->actual_length = 0;
packet->status = 0;
}
- ret = usb_submit_urb(&rt->in_urbs[i].instance,
+ ret = usb_submit_urb(rt->in_urbs[i].instance,
GFP_ATOMIC);
if (ret) {
usb6fire_pcm_stream_stop(rt);
@@ -197,6 +197,7 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
unsigned int total_length = 0;
struct pcm_runtime *rt = snd_pcm_substream_chip(sub->instance);
struct snd_pcm_runtime *alsa_rt = sub->instance->runtime;
+ struct usb_iso_packet_descriptor *isoc;
u32 *src = NULL;
u32 *dest = (u32 *) (alsa_rt->dma_area + sub->dma_off
* (alsa_rt->frame_bits >> 3));
@@ -207,8 +208,9 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
/* at least 4 header bytes for valid packet.
* after that: 32 bits per sample for analog channels */
- if (urb->packets[i].actual_length > 4)
- frame_count = (urb->packets[i].actual_length - 4)
+ isoc = &urb->instance->iso_frame_desc[i];
+ if (isoc->actual_length > 4)
+ frame_count = (isoc->actual_length - 4)
/ (rt->in_n_analog << 2);
else
frame_count = 0;
@@ -220,7 +222,7 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
else
return;
src++; /* skip leading 4 bytes of every packet */
- total_length += urb->packets[i].length;
+ total_length += isoc->length;
for (frame = 0; frame < frame_count; frame++) {
memcpy(dest, src, bytes_per_frame);
dest += alsa_rt->channels;
@@ -244,6 +246,7 @@ static void usb6fire_pcm_playback(struct pcm_substream *sub,
int frame_count;
struct pcm_runtime *rt = snd_pcm_substream_chip(sub->instance);
struct snd_pcm_runtime *alsa_rt = sub->instance->runtime;
+ struct usb_iso_packet_descriptor *isoc;
u32 *src = (u32 *) (alsa_rt->dma_area + sub->dma_off
* (alsa_rt->frame_bits >> 3));
u32 *src_end = (u32 *) (alsa_rt->dma_area + alsa_rt->buffer_size
@@ -263,8 +266,9 @@ static void usb6fire_pcm_playback(struct pcm_substream *sub,
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
/* at least 4 header bytes for valid packet.
* after that: 32 bits per sample for analog channels */
- if (urb->packets[i].length > 4)
- frame_count = (urb->packets[i].length - 4)
+ isoc = &urb->instance->iso_frame_desc[i];
+ if (isoc->length > 4)
+ frame_count = (isoc->length - 4)
/ (rt->out_n_analog << 2);
else
frame_count = 0;
@@ -289,6 +293,7 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
struct pcm_urb *out_urb = in_urb->peer;
struct pcm_runtime *rt = in_urb->chip->pcm;
struct pcm_substream *sub;
+ struct usb_iso_packet_descriptor *isoc_out, *isoc_in;
bool period_elapsed;
int total_length = 0;
int frame_count;
@@ -299,11 +304,13 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
if (usb_urb->status || rt->panic || rt->stream_state == STREAM_STOPPING)
return;
- for (i = 0; i < PCM_N_PACKETS_PER_URB; i++)
- if (in_urb->packets[i].status) {
+ for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ isoc_in = &in_urb->instance->iso_frame_desc[i];
+ if (isoc_in->status) {
rt->panic = true;
return;
}
+ }
if (rt->stream_state == STREAM_DISABLED) {
dev_err(&rt->chip->dev->dev,
@@ -328,12 +335,13 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup out urb structure */
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
- out_urb->packets[i].offset = total_length;
- out_urb->packets[i].length = (in_urb->packets[i].actual_length
- - 4) / (rt->in_n_analog << 2)
+ isoc_out = &out_urb->instance->iso_frame_desc[i];
+ isoc_in = &in_urb->instance->iso_frame_desc[i];
+ isoc_out->offset = total_length;
+ isoc_out->length = (isoc_in->actual_length - 4) / (rt->in_n_analog << 2)
* (rt->out_n_analog << 2) + 4;
- out_urb->packets[i].status = 0;
- total_length += out_urb->packets[i].length;
+ isoc_out->status = 0;
+ total_length += isoc_out->length;
}
memset(out_urb->buffer, 0, total_length);
@@ -354,9 +362,10 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup the 4th byte of each sample (0x40 for analog channels) */
dest = out_urb->buffer;
- for (i = 0; i < PCM_N_PACKETS_PER_URB; i++)
- if (out_urb->packets[i].length >= 4) {
- frame_count = (out_urb->packets[i].length - 4)
+ for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ isoc_out = &out_urb->instance->iso_frame_desc[i];
+ if (isoc_out->length >= 4) {
+ frame_count = (isoc_out->length - 4)
/ (rt->out_n_analog << 2);
*(dest++) = 0xaa;
*(dest++) = 0xaa;
@@ -370,8 +379,10 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
*(dest++) = 0x40;
}
}
- usb_submit_urb(&out_urb->instance, GFP_ATOMIC);
- usb_submit_urb(&in_urb->instance, GFP_ATOMIC);
+ }
+
+ usb_submit_urb(out_urb->instance, GFP_ATOMIC);
+ usb_submit_urb(in_urb->instance, GFP_ATOMIC);
}
static void usb6fire_pcm_out_urb_handler(struct urb *usb_urb)
@@ -534,22 +545,25 @@ static const struct snd_pcm_ops pcm_ops = {
.pointer = usb6fire_pcm_pointer,
};
-static void usb6fire_pcm_init_urb(struct pcm_urb *urb,
- struct sfire_chip *chip, bool in, int ep,
- void (*handler)(struct urb *))
+static int usb6fire_pcm_init_urb(struct pcm_urb *urb,
+ struct sfire_chip *chip, bool in, int ep,
+ void (*handler)(struct urb *))
{
urb->chip = chip;
- usb_init_urb(&urb->instance);
- urb->instance.transfer_buffer = urb->buffer;
- urb->instance.transfer_buffer_length =
+ urb->instance = usb_alloc_urb(PCM_N_PACKETS_PER_URB, GFP_KERNEL);
+ if (!urb->instance)
+ return -ENOMEM;
+ urb->instance->transfer_buffer = urb->buffer;
+ urb->instance->transfer_buffer_length =
PCM_N_PACKETS_PER_URB * PCM_MAX_PACKET_SIZE;
- urb->instance.dev = chip->dev;
- urb->instance.pipe = in ? usb_rcvisocpipe(chip->dev, ep)
+ urb->instance->dev = chip->dev;
+ urb->instance->pipe = in ? usb_rcvisocpipe(chip->dev, ep)
: usb_sndisocpipe(chip->dev, ep);
- urb->instance.interval = 1;
- urb->instance.complete = handler;
- urb->instance.context = urb;
- urb->instance.number_of_packets = PCM_N_PACKETS_PER_URB;
+ urb->instance->interval = 1;
+ urb->instance->complete = handler;
+ urb->instance->context = urb;
+ urb->instance->number_of_packets = PCM_N_PACKETS_PER_URB;
+ return 0;
}
static int usb6fire_pcm_buffers_init(struct pcm_runtime *rt)
@@ -571,14 +585,23 @@ static int usb6fire_pcm_buffers_init(struct pcm_runtime *rt)
return 0;
}
-static void usb6fire_pcm_buffers_destroy(struct pcm_runtime *rt)
+static void usb6fire_pcm_free(struct pcm_runtime *rt)
{
int i;
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->pcm = NULL;
+
for (i = 0; i < PCM_N_URBS; i++) {
+ usb_free_urb(rt->out_urbs[i].instance);
kfree(rt->out_urbs[i].buffer);
+ usb_free_urb(rt->in_urbs[i].instance);
kfree(rt->in_urbs[i].buffer);
}
+ kfree(rt);
}
int usb6fire_pcm_init(struct sfire_chip *chip)
@@ -593,11 +616,8 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
return -ENOMEM;
ret = usb6fire_pcm_buffers_init(rt);
- if (ret) {
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
- return ret;
- }
+ if (ret)
+ goto error;
rt->chip = chip;
rt->stream_state = STREAM_DISABLED;
@@ -609,10 +629,14 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
spin_lock_init(&rt->capture.lock);
for (i = 0; i < PCM_N_URBS; i++) {
- usb6fire_pcm_init_urb(&rt->in_urbs[i], chip, true, IN_EP,
- usb6fire_pcm_in_urb_handler);
- usb6fire_pcm_init_urb(&rt->out_urbs[i], chip, false, OUT_EP,
- usb6fire_pcm_out_urb_handler);
+ ret = usb6fire_pcm_init_urb(&rt->in_urbs[i], chip, true, IN_EP,
+ usb6fire_pcm_in_urb_handler);
+ if (ret < 0)
+ goto error;
+ ret = usb6fire_pcm_init_urb(&rt->out_urbs[i], chip, false, OUT_EP,
+ usb6fire_pcm_out_urb_handler);
+ if (ret < 0)
+ goto error;
rt->in_urbs[i].peer = &rt->out_urbs[i];
rt->out_urbs[i].peer = &rt->in_urbs[i];
@@ -620,10 +644,8 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
ret = snd_pcm_new(chip->card, "DMX6FireUSB", 0, 1, 1, &pcm);
if (ret < 0) {
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
dev_err(&chip->dev->dev, "cannot create pcm instance.\n");
- return ret;
+ goto error;
}
pcm->private_data = rt;
@@ -636,6 +658,10 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
chip->pcm = rt;
return 0;
+
+ error:
+ usb6fire_pcm_free(rt);
+ return ret;
}
void usb6fire_pcm_abort(struct sfire_chip *chip)
@@ -653,8 +679,8 @@ void usb6fire_pcm_abort(struct sfire_chip *chip)
snd_pcm_stop_xrun(rt->capture.instance);
for (i = 0; i < PCM_N_URBS; i++) {
- usb_poison_urb(&rt->in_urbs[i].instance);
- usb_poison_urb(&rt->out_urbs[i].instance);
+ usb_poison_urb(rt->in_urbs[i].instance);
+ usb_poison_urb(rt->out_urbs[i].instance);
}
}
@@ -662,9 +688,5 @@ void usb6fire_pcm_abort(struct sfire_chip *chip)
void usb6fire_pcm_destroy(struct sfire_chip *chip)
{
- struct pcm_runtime *rt = chip->pcm;
-
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
- chip->pcm = NULL;
+ usb6fire_pcm_free(chip->pcm);
}
diff --git a/sound/usb/6fire/pcm.h b/sound/usb/6fire/pcm.h
index 5a092dfd69f5a..b586fe220fd11 100644
--- a/sound/usb/6fire/pcm.h
+++ b/sound/usb/6fire/pcm.h
@@ -24,10 +24,7 @@ enum /* settings for pcm */
struct pcm_urb {
struct sfire_chip *chip;
- /* BEGIN DO NOT SEPARATE */
- struct urb instance;
- struct usb_iso_packet_descriptor packets[PCM_N_PACKETS_PER_URB];
- /* END DO NOT SEPARATE */
+ struct urb *instance;
u8 *buffer;
struct pcm_urb *peer;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 085/398] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (83 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 084/398] scsi: qla2xxx: Fix the ql2xfc2target parameter description Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 086/398] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA Greg Kroah-Hartman
` (317 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Bereza, Frank Li, Suraj Gupta,
Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Bereza <alex@bereza.email>
[ Upstream commit cee9c863ee68cb27d66745eb03f60e357f4f8ad2 ]
xilinx_dma_alloc_chan_resources() builds a static ring of hardware
buffer descriptors once and the driver uses this ring throughout the
lifetime of a channel. This requires the allocation order of hardware
buffer descriptors from chan->free_seg_list to stay in sync with the
hardware buffer descriptor ring built at channel allocation time by
returning oldest descriptors to chan->free_seg_list first.
When chan->pending_list is not empty e.g. during
xilinx_dma_terminate_all() the chan->free_seg_list and the order of the
static hardware buffer descriptor ring get out of sync. Descriptors age
in this order: pending -> active -> done. So freeing pending_list first
returns the newest buffer descriptors to the chan->free_seg_list first
and thus breaks the order required by the static hardware buffer
descriptor ring. Then when the channel is reused, after a wrap around of
the free_seg_list the DMA will find a hardware buffer descriptor with a
length field that is still zeroed and stop with something like this:
xilinx-vdma 86000000.dma: Channel 000000003a21d7b8 has errors 10, cdr 6de4c000 tdr 6de4c000
After this no more descriptors are completed and a consumer potentially
blocks and waits forever. The only way to get out of this error state is
to rebuild the static hardware buffer descriptor ring and the
free_seg_list by releasing and re-acquiring the channel.
Fix the order in which hardware buffer descriptors are returned to
free_seg_list to ensure the mentioned requirement holds.
Fixes: 23059408b6a3 ("dmaengine: xilinx_dma: Fix race condition in the driver for multiple descriptor scenario")
Signed-off-by: Alex Bereza <alex@bereza.email>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Suraj Gupta <suraj.gupta2@amd.com>
Link: https://patch.msgid.link/20260817-fix-hw-buf-desc-reuse-v1-1-d79827a844c7@bereza.email
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/xilinx/xilinx_dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/xilinx/xilinx_dma.c b/drivers/dma/xilinx/xilinx_dma.c
index 30e3db94ddf07..4ccf519d39610 100644
--- a/drivers/dma/xilinx/xilinx_dma.c
+++ b/drivers/dma/xilinx/xilinx_dma.c
@@ -918,9 +918,9 @@ static void xilinx_dma_free_descriptors(struct xilinx_dma_chan *chan)
spin_lock_irqsave(&chan->lock, flags);
- xilinx_dma_free_desc_list(chan, &chan->pending_list);
xilinx_dma_free_desc_list(chan, &chan->done_list);
xilinx_dma_free_desc_list(chan, &chan->active_list);
+ xilinx_dma_free_desc_list(chan, &chan->pending_list);
spin_unlock_irqrestore(&chan->lock, flags);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 139/438] ALSA: 6fire: fix OOB write from device-reported iso length
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (137 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 138/438] ALSA: usb: 6fire: Avoid embedded URBs Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 140/438] ksmbd: fix malformed procfs status output Greg Kroah-Hartman
` (310 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+855929c2df672879, Xiang Mei,
Takashi Iwai, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit 1589afe2d099d3e817873bc474676968d7080410 ]
usb6fire_pcm_in_urb_handler() sizes each outgoing isochronous packet as
(actual_length - 4) / (in_n_analog << 2) * (out_n_analog << 2) + 4, where
actual_length is the unsigned length the device reported for the matching
IN packet. A packet completed with status 0 and actual_length < 4 wraps
the subtraction to 0x7fffffec; a zero-length isochronous packet is legal
on the bus, and the preceding loop rejects only non-zero status. The sum
reaches memset() on out_urb->buffer, a 4832-byte object from
kcalloc(PCM_MAX_PACKET_SIZE, PCM_N_PACKETS_PER_URB).
Even without the wrap the result is out of bounds: at 88.2/96 kHz the
4-in/6-out scaling turns a full 420-byte IN packet into 628, so eight
packets span 5024 bytes of that buffer. usb_submit_urb() rejects an
over-long descriptor only after the memset() and the
usb6fire_pcm_playback() copy of user PCM data have run.
Guard the subtraction as the sibling usb6fire_pcm_capture() already does,
and limit the frame count to what fits in rt->out_packet_size, the OUT
endpoint's wMaxPacketSize. This bounds total_length by the buffer size
while keeping each packet length aligned to a whole output frame.
BUG: KASAN: out-of-bounds in usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)
Write of size 18446744073709551456 at addr ffff88802a3d0000 by task vhci_rx/5018
Call Trace:
dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)
print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)
kasan_report (mm/kasan/report.c:595)
kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200)
__asan_memset (mm/kasan/shadow.c:84)
usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)
__usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107 drivers/usb/usbip/vhci_rx.c:242)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
Allocated by task 10:
__kmalloc_cache_noprof (mm/slub.c:5563)
usb6fire_pcm_init (sound/usb/6fire/pcm.c:560 sound/usb/6fire/pcm.c:595)
usb6fire_chip_probe (sound/usb/6fire/chip.c:133)
usb_probe_interface (drivers/usb/core/driver.c:399)
The buggy address belongs to the object at ffff88802a3d0000
which belongs to the cache kmalloc-8k of size 8192
The buggy address is located 0 bytes inside of
4832-byte region [ffff88802a3d0000, ffff88802a3d12e0)
Kernel panic - not syncing: Fatal exception in interrupt
Fixes: c6d43ba816d1 ("ALSA: usb/6fire - Driver for TerraTec DMX 6Fire USB")
Reported-by: co+855929c2df672879@bugs.sh
Closes: https://lore.kernel.org/all/gisnub8aWGLbyZLcDCSc7zWsHonMWGcyRgt5%40bugs.sh/
Assisted-by: LLM
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Link: https://patch.msgid.link/20260914074324.3590843-1-xmei5@asu.edu
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/6fire/pcm.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/sound/usb/6fire/pcm.c b/sound/usb/6fire/pcm.c
index 21789db6657d3..0285d79ace0fc 100644
--- a/sound/usb/6fire/pcm.c
+++ b/sound/usb/6fire/pcm.c
@@ -335,11 +335,19 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup out urb structure */
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ unsigned int frames = 0;
+
isoc_out = &out_urb->instance->iso_frame_desc[i];
isoc_in = &in_urb->instance->iso_frame_desc[i];
+ if (isoc_in->actual_length > 4)
+ frames = (isoc_in->actual_length - 4)
+ / (rt->in_n_analog << 2);
+ frames = min_t(unsigned int, frames,
+ (rt->out_packet_size - 4)
+ / (rt->out_n_analog << 2));
+
isoc_out->offset = total_length;
- isoc_out->length = (isoc_in->actual_length - 4) / (rt->in_n_analog << 2)
- * (rt->out_n_analog << 2) + 4;
+ isoc_out->length = frames * (rt->out_n_analog << 2) + 4;
isoc_out->status = 0;
total_length += isoc_out->length;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 086/398] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (84 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 085/398] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 087/398] RDMA/efa: Keep admin queues alive while IRQ is registered Greg Kroah-Hartman
` (316 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Bereza, Frank Li, Suraj Gupta,
Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alex Bereza <alex@bereza.email>
[ Upstream commit 7ed1e3070c9b4bbd67d5519e14711038dd53ab13 ]
Using the DMA in cyclic mode modifies the hardware buffer descriptor
chain in xilinx_dma_prep_dma_cyclic so that the last descriptor used by
the cyclic transfer points back to the first descriptor, but it never
restores the original descriptor ring. This breaks using non-cyclic mode
after cyclic mode with an error like:
xilinx-vdma 86000000.dma: Channel 00000000354d5c8d has errors 100, cdr 6de40000 tdr 6de40400
The only way to get out of this error state is to rebuild the hardware
buffer descriptor ring by releasing and re-acquiring the channel.
Fix using non-cyclic mode after cyclic mode by always restoring the
original buffer descriptor ring in the same manner as it is set up by
xilinx_dma_alloc_chan_resources().
Fixes: 23059408b6a3 ("dmaengine: xilinx_dma: Fix race condition in the driver for multiple descriptor scenario")
Signed-off-by: Alex Bereza <alex@bereza.email>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Suraj Gupta <suraj.gupta2@amd.com>
Link: https://patch.msgid.link/20260817-fix-hw-buf-desc-after-cyclic-mode-v1-1-1fe47e701d6c@bereza.email
Link: https://patch.msgid.link/20260818-fix-hw-buf-desc-after-cyclic-mode-v2-1-530ff44c6a81@bereza.email
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/xilinx/xilinx_dma.c | 24 +++++++++++++++++-------
1 file changed, 17 insertions(+), 7 deletions(-)
diff --git a/drivers/dma/xilinx/xilinx_dma.c b/drivers/dma/xilinx/xilinx_dma.c
index 4ccf519d39610..8b010e0e0c5c4 100644
--- a/drivers/dma/xilinx/xilinx_dma.c
+++ b/drivers/dma/xilinx/xilinx_dma.c
@@ -754,15 +754,25 @@ xilinx_aximcdma_alloc_tx_segment(struct xilinx_dma_chan *chan)
return segment;
}
-static void xilinx_dma_clean_hw_desc(struct xilinx_axidma_desc_hw *hw)
+static void xilinx_dma_clean_hw_desc(struct xilinx_dma_chan *chan,
+ struct xilinx_axidma_tx_segment *segment)
{
- u32 next_desc = hw->next_desc;
- u32 next_desc_msb = hw->next_desc_msb;
+ dma_addr_t next;
+ u32 i;
- memset(hw, 0, sizeof(struct xilinx_axidma_desc_hw));
+ /*
+ * Restore the buffer descriptor's next descriptor pointer to the value
+ * set up in xilinx_dma_alloc_chan_resources(). Otherwise using the DMA
+ * in cyclic mode leaves the next descriptor pointer altered and
+ * prevents subsequent non-cyclic transfers.
+ */
+ i = segment - chan->seg_v;
+ next = chan->seg_p +
+ sizeof(*chan->seg_v) * ((i + 1) % XILINX_DMA_NUM_DESCS);
- hw->next_desc = next_desc;
- hw->next_desc_msb = next_desc_msb;
+ memset(&segment->hw, 0, sizeof(segment->hw));
+ segment->hw.next_desc = lower_32_bits(next);
+ segment->hw.next_desc_msb = upper_32_bits(next);
}
static void xilinx_mcdma_clean_hw_desc(struct xilinx_aximcdma_desc_hw *hw)
@@ -784,7 +794,7 @@ static void xilinx_mcdma_clean_hw_desc(struct xilinx_aximcdma_desc_hw *hw)
static void xilinx_dma_free_tx_segment(struct xilinx_dma_chan *chan,
struct xilinx_axidma_tx_segment *segment)
{
- xilinx_dma_clean_hw_desc(&segment->hw);
+ xilinx_dma_clean_hw_desc(chan, segment);
list_add_tail(&segment->node, &chan->free_seg_list);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 140/438] ksmbd: fix malformed procfs status output
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (138 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 139/438] ALSA: 6fire: fix OOB write from device-reported iso length Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 141/438] ksmbd: extend procfs server statistics Greg Kroah-Hartman
` (309 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 1f7dd03a88a8405143aab195f6fa9ed2243494b1 ]
The ksmbd procfs monitoring files produce misleading or malformed output.
The constant-name helper uses a bitwise test for enum values. This omits
zero-valued constants and can print multiple names for one lease state. It
also unconditionally emits a newline, splitting entries in the open-file
table across two lines. Session capabilities are printed as numeric flag
values even though a table of descriptive names is available.
Use exact matching for enum values. Print flag names as a comma-separated
list, preserving unknown bits as hexadecimal values. Let callers control
line termination so each open-file entry remains on one line. Print common
session properties once, and report signing and encryption independently.
Adjust client and open-file column widths for IPv6 addresses and 64-bit
file IDs, and fix the misspelled OPLOCK_EXCLUSIVE name. Also expose and
maintain the total request count alongside the per-command counters.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Stable-dep-of: d7fd1f98607f ("ksmbd: follow SMB2 session expiration semantics")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/connection.c | 12 ++---
fs/smb/server/mgmt/user_session.c | 75 +++++++++++++------------------
fs/smb/server/misc.h | 7 +--
fs/smb/server/proc.c | 38 ++++++++++++++++
fs/smb/server/stats.h | 4 +-
fs/smb/server/vfs_cache.c | 16 ++++---
6 files changed, 89 insertions(+), 63 deletions(-)
diff --git a/fs/smb/server/connection.c b/fs/smb/server/connection.c
index 39ac777fd4527..cef279b8fd27e 100644
--- a/fs/smb/server/connection.c
+++ b/fs/smb/server/connection.c
@@ -35,9 +35,9 @@ static int proc_show_clients(struct seq_file *m, void *v)
struct timespec64 now, t;
int i;
- seq_printf(m, "#%-20s %-10s %-10s %-10s %-10s %-10s\n",
- "<name>", "<dialect>", "<credits>", "<open files>",
- "<requests>", "<last active>");
+ seq_printf(m, "#%-40s %-10s %-10s %-12s %-10s %s\n",
+ "<client>", "<dialect>", "<credits>", "<open files>",
+ "<requests>", "<last active>");
down_read(&conn_list_lock);
hash_for_each(conn_list, i, conn, hlist) {
@@ -46,11 +46,11 @@ static int proc_show_clients(struct seq_file *m, void *v)
t = timespec64_sub(now, t);
#if IS_ENABLED(CONFIG_IPV6)
if (!conn->inet_addr)
- seq_printf(m, "%-20pI6c", &conn->inet6_addr);
+ seq_printf(m, " %-40pI6c", &conn->inet6_addr);
else
#endif
- seq_printf(m, "%-20pI4", &conn->inet_addr);
- seq_printf(m, " 0x%-10x %-10u %-12d %-10d %ptT\n",
+ seq_printf(m, " %-40pI4", &conn->inet_addr);
+ seq_printf(m, " 0x%-8x %-10u %-12d %-10d %ptT\n",
conn->dialect,
conn->total_credits,
atomic_read(&conn->stats.open_files_count),
diff --git a/fs/smb/server/mgmt/user_session.c b/fs/smb/server/mgmt/user_session.c
index 10b31df185a60..37ebfc914b6d4 100644
--- a/fs/smb/server/mgmt/user_session.c
+++ b/fs/smb/server/mgmt/user_session.c
@@ -90,9 +90,15 @@ static int show_proc_session(struct seq_file *m, void *v)
sess = (struct ksmbd_session *)m->private;
ksmbd_user_session_get(sess);
+ seq_printf(m, "%-20s\t%s\n", "user", session_user_name(sess));
+ seq_printf(m, "%-20s\t%llu\n", "id", sess->id);
+ seq_printf(m, "%-20s\t%s\n", "state", session_state_string(sess));
+
i = 0;
down_read(&sess->chann_lock);
xa_for_each(&sess->ksmbd_chann_list, id, chan) {
+ const char *name;
+
#if IS_ENABLED(CONFIG_IPV6)
if (chan->conn->inet_addr)
seq_printf(m, "%-20s\t%pI4\n", "client",
@@ -104,29 +110,37 @@ static int show_proc_session(struct seq_file *m, void *v)
seq_printf(m, "%-20s\t%pI4\n", "client",
&chan->conn->inet_addr);
#endif
- seq_printf(m, "%-20s\t%s\n", "user", session_user_name(sess));
- seq_printf(m, "%-20s\t%llu\n", "id", sess->id);
- seq_printf(m, "%-20s\t%s\n", "state",
- session_state_string(sess));
-
seq_printf(m, "%-20s\t", "capabilities");
ksmbd_proc_show_flag_names(m,
ksmbd_sess_cap_const_names,
ARRAY_SIZE(ksmbd_sess_cap_const_names),
chan->conn->vals->req_capabilities);
+ seq_putc(m, '\n');
if (sess->sign) {
- seq_printf(m, "%-20s\t", "signing");
- ksmbd_proc_show_const_name(m, "%s\t",
- ksmbd_signing_const_names,
- ARRAY_SIZE(ksmbd_signing_const_names),
- le16_to_cpu(chan->conn->signing_algorithm));
- } else if (sess->enc) {
- seq_printf(m, "%-20s\t", "encryption");
- ksmbd_proc_show_const_name(m, "%s\t",
- ksmbd_cipher_const_names,
- ARRAY_SIZE(ksmbd_cipher_const_names),
- le16_to_cpu(chan->conn->cipher_type));
+ unsigned int algorithm =
+ le16_to_cpu(chan->conn->signing_algorithm);
+
+ name = ksmbd_proc_const_name(ksmbd_signing_const_names,
+ ARRAY_SIZE(ksmbd_signing_const_names),
+ algorithm);
+ if (name)
+ seq_printf(m, "%-20s\t%s\n", "signing", name);
+ else
+ seq_printf(m, "%-20s\t0x%04x\n", "signing",
+ algorithm);
+ }
+ if (sess->enc) {
+ unsigned int cipher = le16_to_cpu(chan->conn->cipher_type);
+
+ name = ksmbd_proc_const_name(ksmbd_cipher_const_names,
+ ARRAY_SIZE(ksmbd_cipher_const_names),
+ cipher);
+ if (name)
+ seq_printf(m, "%-20s\t%s\n", "encryption", name);
+ else
+ seq_printf(m, "%-20s\t0x%04x\n", "encryption",
+ cipher);
}
i++;
}
@@ -152,35 +166,6 @@ static int show_proc_session(struct seq_file *m, void *v)
return 0;
}
-void ksmbd_proc_show_flag_names(struct seq_file *m,
- const struct ksmbd_const_name *table,
- int count,
- unsigned int flags)
-{
- int i;
-
- for (i = 0; i < count; i++) {
- if (table[i].const_value & flags)
- seq_printf(m, "0x%08x\t", table[i].const_value);
- }
- seq_putc(m, '\n');
-}
-
-void ksmbd_proc_show_const_name(struct seq_file *m,
- const char *format,
- const struct ksmbd_const_name *table,
- int count,
- unsigned int const_value)
-{
- int i;
-
- for (i = 0; i < count; i++) {
- if (table[i].const_value & const_value)
- seq_printf(m, format, table[i].name);
- }
- seq_putc(m, '\n');
-}
-
static int create_proc_session(struct ksmbd_session *sess)
{
char name[30];
diff --git a/fs/smb/server/misc.h b/fs/smb/server/misc.h
index c7b063f571a7a..1faaddd0f5f75 100644
--- a/fs/smb/server/misc.h
+++ b/fs/smb/server/misc.h
@@ -53,11 +53,8 @@ void ksmbd_proc_show_flag_names(struct seq_file *m,
const struct ksmbd_const_name *table,
int count,
unsigned int flags);
-void ksmbd_proc_show_const_name(struct seq_file *m,
- const char *format,
- const struct ksmbd_const_name *table,
- int count,
- unsigned int const_value);
+const char *ksmbd_proc_const_name(const struct ksmbd_const_name *table,
+ int count, unsigned int const_value);
#else
static inline int ksmbd_proc_init(void) { return 0; }
static inline void ksmbd_proc_cleanup(void) {}
diff --git a/fs/smb/server/proc.c b/fs/smb/server/proc.c
index 5c9f3f314dbe1..13742a2404a58 100644
--- a/fs/smb/server/proc.c
+++ b/fs/smb/server/proc.c
@@ -27,6 +27,42 @@ struct proc_dir_entry *ksmbd_proc_create(const char *name,
show, v);
}
+void ksmbd_proc_show_flag_names(struct seq_file *m,
+ const struct ksmbd_const_name *table,
+ int count, unsigned int flags)
+{
+ unsigned int remaining = flags;
+ bool separator = false;
+ int i;
+
+ for (i = 0; i < count; i++) {
+ unsigned int flag = table[i].const_value;
+
+ if (!flag || (remaining & flag) != flag)
+ continue;
+ seq_printf(m, "%s%s", separator ? "," : "", table[i].name);
+ separator = true;
+ remaining &= ~flag;
+ }
+
+ if (remaining)
+ seq_printf(m, "%s0x%08x", separator ? "," : "", remaining);
+ else if (!separator)
+ seq_puts(m, "none");
+}
+
+const char *ksmbd_proc_const_name(const struct ksmbd_const_name *table,
+ int count, unsigned int const_value)
+{
+ int i;
+
+ for (i = 0; i < count; i++) {
+ if (table[i].const_value == const_value)
+ return table[i].name;
+ }
+ return NULL;
+}
+
struct ksmbd_const_smb2_process_req {
unsigned int const_value;
const char *name;
@@ -71,6 +107,8 @@ static int proc_show_ksmbd_stats(struct seq_file *m, void *v)
ksmbd_counter_sum(KSMBD_COUNTER_SESSIONS));
seq_printf(m, "tree connects: %lld\n",
ksmbd_counter_sum(KSMBD_COUNTER_TREE_CONNS));
+ seq_printf(m, "requests: %lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_REQUESTS));
seq_printf(m, "read bytes: %lld\n",
ksmbd_counter_sum(KSMBD_COUNTER_READ_BYTES));
seq_printf(m, "written bytes: %lld\n",
diff --git a/fs/smb/server/stats.h b/fs/smb/server/stats.h
index b60c30c690770..08ee66f91eaab 100644
--- a/fs/smb/server/stats.h
+++ b/fs/smb/server/stats.h
@@ -52,8 +52,10 @@ static inline void ksmbd_counter_sub(int type, s64 value)
static inline void ksmbd_counter_inc_reqs(unsigned int cmd)
{
- if (cmd < KSMBD_COUNTER_MAX_REQS)
+ if (cmd < KSMBD_COUNTER_MAX_REQS) {
+ percpu_counter_inc(&ksmbd_counters.counters[KSMBD_COUNTER_REQUESTS]);
percpu_counter_inc(&ksmbd_counters.counters[KSMBD_COUNTER_FIRST_REQ + cmd]);
+ }
}
static inline s64 ksmbd_counter_sum(int type)
diff --git a/fs/smb/server/vfs_cache.c b/fs/smb/server/vfs_cache.c
index a23bd9b1a68bc..1b5f4efb6ae01 100644
--- a/fs/smb/server/vfs_cache.c
+++ b/fs/smb/server/vfs_cache.c
@@ -66,7 +66,7 @@ static const struct ksmbd_const_name ksmbd_lease_const_names[] = {
static const struct ksmbd_const_name ksmbd_oplock_const_names[] = {
{SMB2_OPLOCK_LEVEL_NONE, "OPLOCK_NONE"},
{SMB2_OPLOCK_LEVEL_II, "OPLOCK_II"},
- {SMB2_OPLOCK_LEVEL_EXCLUSIVE, "OPLOCK_EXECL"},
+ {SMB2_OPLOCK_LEVEL_EXCLUSIVE, "OPLOCK_EXCLUSIVE"},
{SMB2_OPLOCK_LEVEL_BATCH, "OPLOCK_BATCH"},
};
@@ -76,14 +76,14 @@ static int proc_show_files(struct seq_file *m, void *v)
unsigned int id;
struct oplock_info *opinfo;
- seq_printf(m, "#%-10s %-10s %-10s %-10s %-15s %-10s %-10s %s\n",
+ seq_printf(m, "#%-10s %-18s %-18s %-10s %-16s %-10s %-10s %s\n",
"<tree id>", "<pid>", "<vid>", "<refcnt>",
"<oplock>", "<daccess>", "<saccess>",
"<name>");
read_lock(&global_ft.lock);
idr_for_each_entry(global_ft.idr, fp, id) {
- seq_printf(m, "%#-10x %#-10llx %#-10llx %#-10x",
+ seq_printf(m, " %#-10x %#-18llx %#-18llx %#-10x",
fp->tcon ? fp->tcon->id : 0,
fp->persistent_id,
fp->volatile_id,
@@ -93,6 +93,7 @@ static int proc_show_files(struct seq_file *m, void *v)
opinfo = rcu_dereference(fp->f_opinfo);
if (opinfo) {
const struct ksmbd_const_name *const_names;
+ const char *name;
int count;
unsigned int level;
@@ -106,11 +107,14 @@ static int proc_show_files(struct seq_file *m, void *v)
level = opinfo->level;
}
rcu_read_unlock();
- ksmbd_proc_show_const_name(m, " %-15s",
- const_names, count, level);
+ name = ksmbd_proc_const_name(const_names, count, level);
+ if (name)
+ seq_printf(m, " %-16s", name);
+ else
+ seq_printf(m, " 0x%-14x", level);
} else {
rcu_read_unlock();
- seq_printf(m, " %-15s", " ");
+ seq_printf(m, " %-16s", " ");
}
seq_printf(m, " %#010x %#010x %s\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 087/398] RDMA/efa: Keep admin queues alive while IRQ is registered
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (85 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 086/398] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 088/398] RDMA/efa: Keep EQ resources " Greg Kroah-Hartman
` (315 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Margolin, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit e08aca85c02ff290f785f07acae758f0daf5f49e ]
The management IRQ handler accesses both the admin completion queue and the
async event queue. The driver registered the IRQ before constructing these
queues and destroyed them before freeing the IRQ, so the handler's lifetime
was not contained by the resources it accesses.
Initialize the queues with interrupts masked, request the IRQ, and then
switch to interrupt mode. On removal, reset the device and free the IRQ
before destroying the queues. Also reset the device before destroying the
queues if IRQ registration fails, because the device already has their DMA
addresses.
Fixes: b7f5e880f377 ("RDMA/efa: Add the efa module")
Link: https://patch.msgid.link/20260907-use-after-free-of-admin-queue-struct-v1-1-dd9d9267fbf4@nvidia.com
Reviewed-by: Michael Margolin <mrgolin@amazon.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/efa/efa_com.c | 4 +---
drivers/infiniband/hw/efa/efa_main.c | 15 +++++++++------
2 files changed, 10 insertions(+), 9 deletions(-)
diff --git a/drivers/infiniband/hw/efa/efa_com.c b/drivers/infiniband/hw/efa/efa_com.c
index e97b5f0d70038..7ee2c5cc55ac6 100644
--- a/drivers/infiniband/hw/efa/efa_com.c
+++ b/drivers/infiniband/hw/efa/efa_com.c
@@ -750,7 +750,7 @@ int efa_com_admin_init(struct efa_com_dev *edev,
aq->dmadev = edev->dmadev;
aq->efa_dev = edev->efa_dev;
- set_bit(EFA_AQ_STATE_POLLING_BIT, &aq->state);
+ efa_com_set_admin_polling_mode(edev, true);
sema_init(&aq->avail_cmds, aq->depth);
@@ -768,8 +768,6 @@ int efa_com_admin_init(struct efa_com_dev *edev,
if (err)
goto err_destroy_sq;
- efa_com_set_admin_polling_mode(edev, false);
-
err = efa_com_admin_init_aenq(edev, aenq_handlers);
if (err)
goto err_destroy_cq;
diff --git a/drivers/infiniband/hw/efa/efa_main.c b/drivers/infiniband/hw/efa/efa_main.c
index 6c415b9adb5fe..bd19150bc3fa7 100644
--- a/drivers/infiniband/hw/efa/efa_main.c
+++ b/drivers/infiniband/hw/efa/efa_main.c
@@ -611,18 +611,21 @@ static struct efa_dev *efa_probe_device(struct pci_dev *pdev)
edev->aq.msix_vector_idx = dev->admin_msix_vector_idx;
edev->aenq.msix_vector_idx = dev->admin_msix_vector_idx;
- err = efa_set_mgmnt_irq(dev);
+ err = efa_com_admin_init(edev, &aenq_handlers);
if (err)
goto err_disable_msix;
- err = efa_com_admin_init(edev, &aenq_handlers);
+ err = efa_set_mgmnt_irq(dev);
if (err)
- goto err_free_mgmnt_irq;
+ goto err_destroy_admin;
+
+ efa_com_set_admin_polling_mode(edev, false);
return dev;
-err_free_mgmnt_irq:
- efa_free_irq(dev, &dev->admin_irq);
+err_destroy_admin:
+ efa_com_dev_reset(edev, EFA_REGS_RESET_INIT_ERR);
+ efa_com_admin_destroy(edev);
err_disable_msix:
efa_disable_msix(dev);
err_reg_read_destroy:
@@ -646,8 +649,8 @@ static void efa_remove_device(struct pci_dev *pdev,
edev = &dev->edev;
efa_com_dev_reset(edev, reset_reason);
- efa_com_admin_destroy(edev);
efa_free_irq(dev, &dev->admin_irq);
+ efa_com_admin_destroy(edev);
efa_disable_msix(dev);
efa_com_mmio_reg_read_destroy(edev);
devm_iounmap(&pdev->dev, edev->reg_bar);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 141/438] ksmbd: extend procfs server statistics
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (139 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 140/438] ksmbd: fix malformed procfs status output Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 142/438] ksmbd: follow SMB2 session expiration semantics Greg Kroah-Hartman
` (308 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 4c670ccd5790816fc0f5714d5ee3c67dd5a9c67a ]
The server proc entry does not expose configured limits or enough outcome
data to distinguish protocol errors from transport stalls.
Report the server state, listener and signing configuration, connection
limits, timeout values, current client and open-file totals, IPC activity,
and durable scavenger state. Classify processed SMB2 response statuses by
NTSTATUS severity and provide counters for common error groups while
retaining the per-command counters.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Stable-dep-of: d7fd1f98607f ("ksmbd: follow SMB2 session expiration semantics")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/proc.c | 121 +++++++++++++++++++++++++++++++++----
fs/smb/server/server.c | 7 ++-
fs/smb/server/smb_common.h | 2 +-
fs/smb/server/stats.h | 53 +++++++++++++++-
fs/smb/server/vfs_cache.c | 10 +++
fs/smb/server/vfs_cache.h | 1 +
6 files changed, 176 insertions(+), 18 deletions(-)
diff --git a/fs/smb/server/proc.c b/fs/smb/server/proc.c
index 13742a2404a58..826353ed05538 100644
--- a/fs/smb/server/proc.c
+++ b/fs/smb/server/proc.c
@@ -11,10 +11,12 @@
#include <linux/seq_file.h>
#include "misc.h"
+#include "connection.h"
#include "server.h"
#include "stats.h"
#include "smb_common.h"
#include "smb2pdu.h"
+#include "vfs_cache.h"
static struct proc_dir_entry *ksmbd_proc_fs;
struct ksmbd_counters ksmbd_counters;
@@ -90,34 +92,127 @@ static const struct ksmbd_const_smb2_process_req smb2_process_req[KSMBD_COUNTER_
{le16_to_cpu(SMB2_OPLOCK_BREAK), "SMB2_OPLOCK_BREAK"},
};
+static const char *ksmbd_server_state_string(void)
+{
+ switch (READ_ONCE(server_conf.state)) {
+ case SERVER_STATE_STARTING_UP:
+ return "starting";
+ case SERVER_STATE_RUNNING:
+ return "running";
+ case SERVER_STATE_RESETTING:
+ return "resetting";
+ case SERVER_STATE_SHUTTING_DOWN:
+ return "shutdown";
+ default:
+ return "unknown";
+ }
+}
+
+static const char *ksmbd_signing_mode_string(void)
+{
+ switch (server_conf.signing) {
+ case KSMBD_CONFIG_OPT_DISABLED:
+ return "disabled";
+ case KSMBD_CONFIG_OPT_MANDATORY:
+ return "mandatory";
+ case KSMBD_CONFIG_OPT_AUTO:
+ return "auto";
+ default:
+ return "unknown";
+ }
+}
+
+static void proc_show_runtime_totals(struct seq_file *m)
+{
+ struct ksmbd_conn *conn;
+ unsigned int clients = 0;
+ unsigned int open_files = 0;
+ int i;
+
+ down_read(&conn_list_lock);
+ hash_for_each(conn_list, i, conn, hlist) {
+ clients++;
+ open_files += atomic_read(&conn->stats.open_files_count);
+ }
+ up_read(&conn_list_lock);
+
+ seq_printf(m, "clients:\t%u\n", clients);
+ seq_printf(m, "open_files:\t%u\n", open_files);
+}
+
static int proc_show_ksmbd_stats(struct seq_file *m, void *v)
{
int i;
seq_puts(m, "Server\n");
- seq_printf(m, "name: %s\n", ksmbd_server_string());
- seq_printf(m, "netbios: %s\n", ksmbd_netbios_name());
- seq_printf(m, "work group: %s\n", ksmbd_work_group());
- seq_printf(m, "min protocol: %s\n", ksmbd_get_protocol_string(server_conf.min_protocol));
- seq_printf(m, "max protocol: %s\n", ksmbd_get_protocol_string(server_conf.max_protocol));
- seq_printf(m, "flags: 0x%08x\n", server_conf.flags);
- seq_printf(m, "share_fake_fscaps: 0x%08x\n",
+ seq_printf(m, "state:\t%s\n", ksmbd_server_state_string());
+ seq_printf(m, "name:\t%s\n", ksmbd_server_string());
+ seq_printf(m, "netbios:\t%s\n", ksmbd_netbios_name());
+ seq_printf(m, "work_group:\t%s\n", ksmbd_work_group());
+ seq_printf(m, "min_protocol:\t%s\n", ksmbd_get_protocol_string(server_conf.min_protocol));
+ seq_printf(m, "max_protocol:\t%s\n", ksmbd_get_protocol_string(server_conf.max_protocol));
+ seq_printf(m, "flags:\t0x%08x\n", server_conf.flags);
+ seq_printf(m, "tcp_port:\t%u\n", server_conf.tcp_port);
+ seq_printf(m, "signing:\t%s\n", ksmbd_signing_mode_string());
+ seq_printf(m, "signing_enforced:\t%s\n",
+ server_conf.enforced_signing ? "yes" : "no");
+ seq_printf(m, "bind_interfaces_only:\t%s\n",
+ server_conf.bind_interfaces_only ? "yes" : "no");
+ seq_printf(m, "max_connections:\t%u\n", server_conf.max_connections);
+ seq_printf(m, "max_connections_per_ip:\t%u\n",
+ server_conf.max_ip_connections);
+ seq_printf(m, "max_inflight_requests:\t%u\n",
+ server_conf.max_inflight_req);
+ seq_printf(m, "deadtime_seconds:\t%lu\n", server_conf.deadtime / HZ);
+ seq_printf(m, "ipc_timeout_seconds:\t%u\n", server_conf.ipc_timeout / HZ);
+ if (server_conf.ipc_last_active)
+ seq_printf(m, "ipc_last_active_seconds:\t%lu\n",
+ jiffies_to_msecs(jiffies - server_conf.ipc_last_active) /
+ MSEC_PER_SEC);
+ else
+ seq_puts(m, "ipc_last_active_seconds:\tnever\n");
+ seq_printf(m, "durable_scavenger:\t%s\n",
+ ksmbd_durable_scavenger_active() ? "running" : "stopped");
+ seq_printf(m, "share_fake_fscaps:\t0x%08x\n",
server_conf.share_fake_fscaps);
- seq_printf(m, "sessions: %lld\n",
+ proc_show_runtime_totals(m);
+ seq_printf(m, "sessions:\t%lld\n",
ksmbd_counter_sum(KSMBD_COUNTER_SESSIONS));
- seq_printf(m, "tree connects: %lld\n",
+ seq_printf(m, "tree_connects:\t%lld\n",
ksmbd_counter_sum(KSMBD_COUNTER_TREE_CONNS));
- seq_printf(m, "requests: %lld\n",
+ seq_printf(m, "requests:\t%lld\n",
ksmbd_counter_sum(KSMBD_COUNTER_REQUESTS));
- seq_printf(m, "read bytes: %lld\n",
+ seq_printf(m, "read_bytes:\t%lld\n",
ksmbd_counter_sum(KSMBD_COUNTER_READ_BYTES));
- seq_printf(m, "written bytes: %lld\n",
+ seq_printf(m, "written_bytes:\t%lld\n",
ksmbd_counter_sum(KSMBD_COUNTER_WRITE_BYTES));
seq_puts(m, "\nSMB2\n");
for (i = 0; i < KSMBD_COUNTER_MAX_REQS; i++)
- seq_printf(m, "%-20s:\t%lld\n", smb2_process_req[i].name,
+ seq_printf(m, "%s:\t%lld\n", smb2_process_req[i].name,
ksmbd_counter_sum(KSMBD_COUNTER_FIRST_REQ + i));
+
+ seq_puts(m, "\nSMB2 status\n");
+ seq_printf(m, "success:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_STATUS_SUCCESS));
+ seq_printf(m, "informational:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_STATUS_INFORMATIONAL));
+ seq_printf(m, "warning:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_STATUS_WARNING));
+ seq_printf(m, "error:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_STATUS_ERROR));
+ seq_printf(m, "access_denied:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_ERROR_ACCESS_DENIED));
+ seq_printf(m, "not_found:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_ERROR_NOT_FOUND));
+ seq_printf(m, "invalid_parameter:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_ERROR_INVALID_PARAMETER));
+ seq_printf(m, "sharing_violation:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_ERROR_SHARING_VIOLATION));
+ seq_printf(m, "not_supported:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_ERROR_NOT_SUPPORTED));
+ seq_printf(m, "other:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_ERROR_OTHER));
return 0;
}
diff --git a/fs/smb/server/server.c b/fs/smb/server/server.c
index 0b080972e9085..26c424e6682ea 100644
--- a/fs/smb/server/server.c
+++ b/fs/smb/server/server.c
@@ -156,8 +156,11 @@ static int __process_request(struct ksmbd_work *work, struct ksmbd_conn *conn,
}
ret = cmds->proc(work);
- if (conn->ops->inc_reqs)
- conn->ops->inc_reqs(command);
+ if (conn->ops->inc_reqs) {
+ struct smb2_hdr *rsp = ksmbd_resp_buf_curr(work);
+
+ conn->ops->inc_reqs(command, rsp->Status);
+ }
if (ret < 0)
ksmbd_debug(CONN, "Failed to process %u [%d]\n", command, ret);
diff --git a/fs/smb/server/smb_common.h b/fs/smb/server/smb_common.h
index b090b56743c4c..7b9c5cfcb63b0 100644
--- a/fs/smb/server/smb_common.h
+++ b/fs/smb/server/smb_common.h
@@ -135,7 +135,7 @@ struct file_id_both_directory_info {
struct smb_version_ops {
u16 (*get_cmd_val)(struct ksmbd_work *swork);
- void (*inc_reqs)(unsigned int cmd);
+ void (*inc_reqs)(unsigned int cmd, __le32 status);
int (*init_rsp_hdr)(struct ksmbd_work *swork);
void (*set_rsp_status)(struct ksmbd_work *swork, __le32 err);
int (*allocate_rsp_buf)(struct ksmbd_work *work);
diff --git a/fs/smb/server/stats.h b/fs/smb/server/stats.h
index 08ee66f91eaab..bc864efa0d46b 100644
--- a/fs/smb/server/stats.h
+++ b/fs/smb/server/stats.h
@@ -9,12 +9,24 @@
#ifndef __KSMBD_STATS_H__
#define __KSMBD_STATS_H__
+#include "../common/smb2status.h"
+
#define KSMBD_COUNTER_MAX_REQS 19
enum {
KSMBD_COUNTER_SESSIONS = 0,
KSMBD_COUNTER_TREE_CONNS,
KSMBD_COUNTER_REQUESTS,
+ KSMBD_COUNTER_STATUS_SUCCESS,
+ KSMBD_COUNTER_STATUS_INFORMATIONAL,
+ KSMBD_COUNTER_STATUS_WARNING,
+ KSMBD_COUNTER_STATUS_ERROR,
+ KSMBD_COUNTER_ERROR_ACCESS_DENIED,
+ KSMBD_COUNTER_ERROR_NOT_FOUND,
+ KSMBD_COUNTER_ERROR_INVALID_PARAMETER,
+ KSMBD_COUNTER_ERROR_SHARING_VIOLATION,
+ KSMBD_COUNTER_ERROR_NOT_SUPPORTED,
+ KSMBD_COUNTER_ERROR_OTHER,
KSMBD_COUNTER_READ_BYTES,
KSMBD_COUNTER_WRITE_BYTES,
KSMBD_COUNTER_FIRST_REQ,
@@ -50,8 +62,45 @@ static inline void ksmbd_counter_sub(int type, s64 value)
percpu_counter_sub(&ksmbd_counters.counters[type], value);
}
-static inline void ksmbd_counter_inc_reqs(unsigned int cmd)
+static inline void ksmbd_counter_inc_reqs(unsigned int cmd, __le32 status)
{
+ unsigned int severity = le32_to_cpu(status) >> 30;
+ int type;
+
+ switch (severity) {
+ case 0:
+ type = KSMBD_COUNTER_STATUS_SUCCESS;
+ break;
+ case 1:
+ type = KSMBD_COUNTER_STATUS_INFORMATIONAL;
+ break;
+ case 2:
+ type = KSMBD_COUNTER_STATUS_WARNING;
+ break;
+ default:
+ type = KSMBD_COUNTER_STATUS_ERROR;
+ break;
+ }
+ percpu_counter_inc(&ksmbd_counters.counters[type]);
+
+ if (severity == 3) {
+ if (status == STATUS_ACCESS_DENIED)
+ type = KSMBD_COUNTER_ERROR_ACCESS_DENIED;
+ else if (status == STATUS_OBJECT_NAME_NOT_FOUND ||
+ status == STATUS_NO_SUCH_FILE)
+ type = KSMBD_COUNTER_ERROR_NOT_FOUND;
+ else if (status == STATUS_INVALID_PARAMETER)
+ type = KSMBD_COUNTER_ERROR_INVALID_PARAMETER;
+ else if (status == STATUS_SHARING_VIOLATION)
+ type = KSMBD_COUNTER_ERROR_SHARING_VIOLATION;
+ else if (status == STATUS_NOT_SUPPORTED ||
+ status == STATUS_NOT_IMPLEMENTED)
+ type = KSMBD_COUNTER_ERROR_NOT_SUPPORTED;
+ else
+ type = KSMBD_COUNTER_ERROR_OTHER;
+ percpu_counter_inc(&ksmbd_counters.counters[type]);
+ }
+
if (cmd < KSMBD_COUNTER_MAX_REQS) {
percpu_counter_inc(&ksmbd_counters.counters[KSMBD_COUNTER_REQUESTS]);
percpu_counter_inc(&ksmbd_counters.counters[KSMBD_COUNTER_FIRST_REQ + cmd]);
@@ -68,7 +117,7 @@ static inline void ksmbd_counter_inc(int type) {}
static inline void ksmbd_counter_dec(int type) {}
static inline void ksmbd_counter_add(int type, s64 value) {}
static inline void ksmbd_counter_sub(int type, s64 value) {}
-static inline void ksmbd_counter_inc_reqs(unsigned int cmd) {}
+static inline void ksmbd_counter_inc_reqs(unsigned int cmd, __le32 status) {}
static inline s64 ksmbd_counter_sum(int type) { return 0; }
#endif
diff --git a/fs/smb/server/vfs_cache.c b/fs/smb/server/vfs_cache.c
index 1b5f4efb6ae01..5eae49ed1c799 100644
--- a/fs/smb/server/vfs_cache.c
+++ b/fs/smb/server/vfs_cache.c
@@ -140,6 +140,16 @@ static bool durable_scavenger_running;
static DEFINE_MUTEX(durable_scavenger_lock);
static wait_queue_head_t dh_wq;
+bool ksmbd_durable_scavenger_active(void)
+{
+ bool active;
+
+ mutex_lock(&durable_scavenger_lock);
+ active = durable_scavenger_running;
+ mutex_unlock(&durable_scavenger_lock);
+ return active;
+}
+
void ksmbd_set_fd_limit(unsigned long limit)
{
limit = min(limit, get_max_files());
diff --git a/fs/smb/server/vfs_cache.h b/fs/smb/server/vfs_cache.h
index d6a9cd4b6d563..1c6fc4349b883 100644
--- a/fs/smb/server/vfs_cache.h
+++ b/fs/smb/server/vfs_cache.h
@@ -209,6 +209,7 @@ unsigned int ksmbd_open_durable_fd(struct ksmbd_file *fp);
struct ksmbd_file *ksmbd_open_fd(struct ksmbd_work *work, struct file *filp);
void ksmbd_launch_ksmbd_durable_scavenger(void);
void ksmbd_stop_durable_scavenger(void);
+bool ksmbd_durable_scavenger_active(void);
void ksmbd_close_tree_conn_fds(struct ksmbd_work *work);
void ksmbd_close_session_fds(struct ksmbd_work *work);
void ksmbd_wake_session_blocked_works(struct ksmbd_session *sess);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 088/398] RDMA/efa: Keep EQ resources alive while IRQ is registered
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (86 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 087/398] RDMA/efa: Keep admin queues alive while IRQ is registered Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 089/398] RDMA/siw: Bound fragmented header copies by the remaining length Greg Kroah-Hartman
` (314 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Margolin, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit e22a3627b7151754f07f90ea3d1ab6e85f5d93f4 ]
The completion IRQ handler accesses the EQ state and DMA buffer. Its IRQ was
registered before that state was initialized, while teardown released the
buffer before free_irq() synchronized the handler.
Initialize the EQ without arming it, register the IRQ, and then arm it.
Reverse the resource order during teardown by freeing the IRQ before
destroying the EQ.
Fixes: 2a152512a155 ("RDMA/efa: CQ notifications")
Link: https://patch.msgid.link/20260907-use-after-free-of-admin-queue-struct-v1-2-dd9d9267fbf4@nvidia.com
Reviewed-by: Michael Margolin <mrgolin@amazon.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/efa/efa_com.c | 3 +--
drivers/infiniband/hw/efa/efa_com.h | 1 +
drivers/infiniband/hw/efa/efa_main.c | 18 ++++++++++--------
3 files changed, 12 insertions(+), 10 deletions(-)
diff --git a/drivers/infiniband/hw/efa/efa_com.c b/drivers/infiniband/hw/efa/efa_com.c
index 7ee2c5cc55ac6..21b9bd1c1fef2 100644
--- a/drivers/infiniband/hw/efa/efa_com.c
+++ b/drivers/infiniband/hw/efa/efa_com.c
@@ -1156,7 +1156,7 @@ static void efa_com_destroy_eq(struct efa_com_dev *edev,
err);
}
-static void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq)
+void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq)
{
u32 val = 0;
@@ -1245,7 +1245,6 @@ int efa_com_eq_init(struct efa_com_dev *edev, struct efa_com_eq *eeq,
eeq->phase = 1;
eeq->depth = params.depth;
eeq->cb = cb;
- efa_com_arm_eq(edev, eeq);
return 0;
diff --git a/drivers/infiniband/hw/efa/efa_com.h b/drivers/infiniband/hw/efa/efa_com.h
index 4d9ca97e42962..1f635f4047ac9 100644
--- a/drivers/infiniband/hw/efa/efa_com.h
+++ b/drivers/infiniband/hw/efa/efa_com.h
@@ -157,6 +157,7 @@ int efa_com_admin_init(struct efa_com_dev *edev,
void efa_com_admin_destroy(struct efa_com_dev *edev);
int efa_com_eq_init(struct efa_com_dev *edev, struct efa_com_eq *eeq,
efa_eqe_handler cb, u16 depth, u8 msix_vec);
+void efa_com_arm_eq(struct efa_com_dev *edev, struct efa_com_eq *eeq);
void efa_com_eq_destroy(struct efa_com_dev *edev, struct efa_com_eq *eeq);
int efa_com_dev_reset(struct efa_com_dev *edev,
enum efa_regs_reset_reason_types reset_reason);
diff --git a/drivers/infiniband/hw/efa/efa_main.c b/drivers/infiniband/hw/efa/efa_main.c
index bd19150bc3fa7..fdaf88f0122db 100644
--- a/drivers/infiniband/hw/efa/efa_main.c
+++ b/drivers/infiniband/hw/efa/efa_main.c
@@ -300,28 +300,30 @@ static void efa_set_host_info(struct efa_dev *dev)
static void efa_destroy_eq(struct efa_dev *dev, struct efa_eq *eq)
{
- efa_com_eq_destroy(&dev->edev, &eq->eeq);
efa_free_irq(dev, &eq->irq);
+ efa_com_eq_destroy(&dev->edev, &eq->eeq);
}
static int efa_create_eq(struct efa_dev *dev, struct efa_eq *eq, u32 msix_vec)
{
int err;
- efa_setup_comp_irq(dev, eq, msix_vec);
- err = efa_request_irq(dev, &eq->irq);
+ err = efa_com_eq_init(&dev->edev, &eq->eeq, efa_process_eqe,
+ dev->dev_attr.max_eq_depth, msix_vec);
if (err)
return err;
- err = efa_com_eq_init(&dev->edev, &eq->eeq, efa_process_eqe,
- dev->dev_attr.max_eq_depth, msix_vec);
+ efa_setup_comp_irq(dev, eq, msix_vec);
+ err = efa_request_irq(dev, &eq->irq);
if (err)
- goto err_free_comp_irq;
+ goto err_destroy_eq;
+
+ efa_com_arm_eq(&dev->edev, &eq->eeq);
return 0;
-err_free_comp_irq:
- efa_free_irq(dev, &eq->irq);
+err_destroy_eq:
+ efa_com_eq_destroy(&dev->edev, &eq->eeq);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 142/438] ksmbd: follow SMB2 session expiration semantics
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (140 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 141/438] ksmbd: extend procfs server statistics Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 143/438] wifi: virt_wifi: dont transfer operstate before register Greg Kroah-Hartman
` (307 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mobin Aydinfar, Namjae Jeon,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit d7fd1f98607f2cd358e583f9548bdf0173090a86 ]
ksmbd_session_register() destroys valid sessions after ten seconds of
inactivity whenever a client starts another SessionSetup exchange. This
confuses Session.IdleTime with Session.ExpirationTime. Windows can create
additional authenticated sessions on an existing connection, so deleting
the older session invalidates its tree connects and makes mapped drives
fail with STATUS_NETWORK_NAME_DELETED.
The session expiration rules require the server to change a valid session
to expired only after its credential expiration time passes. A valid or
expired session otherwise keeps its connection from being scavenged.
Connections that have not negotiated a dialect, have no sessions, or have
only InProgress sessions are disconnected after an implementation-specific
timeout. Use the Windows-compatible 45 second value and run the expiration
check periodically for both TCP and SMB Direct.
Keep zero as an infinite credential expiration time, and count each
Valid-to-Expired transition. Set expired sessions to InProgress when they
reauthenticate. If authentication fails, remove the session from the
global and per-connection tables immediately, including SMB3 multichannel
connections.
Retain protection against abandoned SessionId-zero exchanges by allowing
only one InProgress authentication per connection. Additional exchanges
fail with STATUS_INSUFFICIENT_RESOURCES, and stale InProgress sessions are
reaped after the same 45 second setup timeout. This bounds the original
unauthenticated memory-exhaustion path without evicting established
sessions.
Fixes: ea174a918939 ("ksmbd: destroy expired sessions")
Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/connection.c | 72 +++++++++++++++++
fs/smb/server/connection.h | 3 +
fs/smb/server/mgmt/user_session.c | 124 ++++++++++++++++++++++++++++--
fs/smb/server/mgmt/user_session.h | 8 +-
fs/smb/server/proc.c | 2 +
fs/smb/server/server.c | 2 +-
fs/smb/server/smb2pdu.c | 37 ++++++---
fs/smb/server/smb2pdu.h | 2 -
fs/smb/server/stats.h | 1 +
9 files changed, 227 insertions(+), 24 deletions(-)
diff --git a/fs/smb/server/connection.c b/fs/smb/server/connection.c
index cef279b8fd27e..4f042a8a2fdbd 100644
--- a/fs/smb/server/connection.c
+++ b/fs/smb/server/connection.c
@@ -22,6 +22,8 @@
static DEFINE_MUTEX(init_lock);
static struct ksmbd_conn_ops default_conn_ops;
+static struct delayed_work session_expiration_work;
+static bool stopping_session_expiration_work;
DEFINE_HASHTABLE(conn_list, CONN_HASH_BITS);
DECLARE_RWSEM(conn_list_lock);
@@ -84,18 +86,28 @@ static void delete_proc_clients(void) {}
static struct workqueue_struct *ksmbd_conn_wq;
+static void ksmbd_session_expiration_worker(struct work_struct *work);
+
int ksmbd_conn_wq_init(void)
{
ksmbd_conn_wq = alloc_workqueue("ksmbd-conn-release",
WQ_UNBOUND | WQ_MEM_RECLAIM, 0);
if (!ksmbd_conn_wq)
return -ENOMEM;
+
+ WRITE_ONCE(stopping_session_expiration_work, false);
+ INIT_DELAYED_WORK(&session_expiration_work,
+ ksmbd_session_expiration_worker);
+ queue_delayed_work(ksmbd_conn_wq, &session_expiration_work,
+ KSMBD_SESSION_EXPIRATION_INTERVAL);
return 0;
}
void ksmbd_conn_wq_destroy(void)
{
if (ksmbd_conn_wq) {
+ WRITE_ONCE(stopping_session_expiration_work, true);
+ cancel_delayed_work_sync(&session_expiration_work);
destroy_workqueue(ksmbd_conn_wq);
ksmbd_conn_wq = NULL;
}
@@ -205,6 +217,7 @@ struct ksmbd_conn *ksmbd_conn_alloc(void)
return NULL;
conn->need_neg = true;
+ conn->creation_time = jiffies;
ksmbd_conn_set_new(conn);
conn->local_nls = load_nls("utf8");
if (!conn->local_nls)
@@ -487,6 +500,20 @@ bool ksmbd_conn_alive(struct ksmbd_conn *conn)
if (kthread_should_stop())
return false;
+ /*
+ * Stale connections that have not completed NEGOTIATE and SESSION_SETUP
+ * must be disconnected. Do not race a request that is currently
+ * completing authentication.
+ */
+ if (!atomic_read(&conn->req_running) &&
+ time_after(jiffies, conn->creation_time +
+ KSMBD_UNAUTHENTICATED_CONN_TIMEOUT) &&
+ (READ_ONCE(conn->need_neg) ||
+ !ksmbd_conn_has_valid_or_expired_session(conn))) {
+ ksmbd_debug(CONN, "Connection setup timed out\n");
+ return false;
+ }
+
if (atomic_read(&conn->stats.open_files_count) > 0)
return true;
@@ -504,6 +531,51 @@ bool ksmbd_conn_alive(struct ksmbd_conn *conn)
return true;
}
+static void ksmbd_session_expiration_worker(struct work_struct *work)
+{
+ struct ksmbd_conn *conn, *target;
+ int bkt;
+
+ if (!ksmbd_server_running())
+ goto reschedule;
+
+ ksmbd_expire_sessions();
+
+ /*
+ * An old connection without a Valid or Expired session must be
+ * disconnected. Process one connection at a time without holding
+ * conn_list_lock across transport shutdown.
+ */
+again:
+ target = NULL;
+ down_read(&conn_list_lock);
+ hash_for_each(conn_list, bkt, conn, hlist) {
+ if (ksmbd_conn_exiting(conn) || ksmbd_conn_releasing(conn) ||
+ atomic_read(&conn->req_running) ||
+ time_before_eq(jiffies, conn->creation_time +
+ KSMBD_UNAUTHENTICATED_CONN_TIMEOUT) ||
+ (!READ_ONCE(conn->need_neg) &&
+ ksmbd_conn_has_valid_or_expired_session(conn)))
+ continue;
+
+ target = ksmbd_conn_get(conn);
+ break;
+ }
+ up_read(&conn_list_lock);
+
+ if (target) {
+ ksmbd_debug(CONN, "Connection setup timed out\n");
+ ksmbd_conn_abort(target);
+ ksmbd_conn_put(target);
+ goto again;
+ }
+
+reschedule:
+ if (!READ_ONCE(stopping_session_expiration_work))
+ queue_delayed_work(ksmbd_conn_wq, &session_expiration_work,
+ KSMBD_SESSION_EXPIRATION_INTERVAL);
+}
+
/* "+2" for BCC field (ByteCount, 2 bytes) */
#define SMB1_MIN_SUPPORTED_PDU_SIZE (sizeof(struct smb_hdr) + 2)
#define SMB2_MIN_SUPPORTED_PDU_SIZE (sizeof(struct smb2_pdu))
diff --git a/fs/smb/server/connection.h b/fs/smb/server/connection.h
index 242a9757eb0db..909f73c6e3c14 100644
--- a/fs/smb/server/connection.h
+++ b/fs/smb/server/connection.h
@@ -67,6 +67,7 @@ struct ksmbd_conn {
struct rw_semaphore session_lock;
/* smb session 1 per user */
struct xarray sessions;
+ unsigned long creation_time;
unsigned long last_active;
/* How many request are running currently */
atomic_t req_running;
@@ -160,6 +161,8 @@ struct ksmbd_transport {
#define KSMBD_TCP_RECV_TIMEOUT (7 * HZ)
#define KSMBD_TCP_SEND_TIMEOUT (5 * HZ)
+#define KSMBD_SESSION_EXPIRATION_INTERVAL (5 * HZ)
+#define KSMBD_UNAUTHENTICATED_CONN_TIMEOUT (45 * HZ)
#define KSMBD_TCP_PEER_SOCKADDR(c) ((struct sockaddr *)&((c)->peer_addr))
#define CONN_HASH_BITS 12
diff --git a/fs/smb/server/mgmt/user_session.c b/fs/smb/server/mgmt/user_session.c
index 37ebfc914b6d4..c3c0557dcc19c 100644
--- a/fs/smb/server/mgmt/user_session.c
+++ b/fs/smb/server/mgmt/user_session.c
@@ -22,6 +22,7 @@
static DEFINE_IDA(session_ida);
#define SESSION_HASH_BITS 12
+#define KSMBD_MAX_PENDING_SESSIONS 1
static DEFINE_HASHTABLE(sessions_table, SESSION_HASH_BITS);
static DECLARE_RWSEM(sessions_table_lock);
@@ -401,26 +402,31 @@ struct ksmbd_session *__session_lookup(unsigned long long id)
return NULL;
}
-static void ksmbd_expire_session(struct ksmbd_conn *conn)
+static bool ksmbd_too_many_session_setups(struct ksmbd_conn *conn)
{
unsigned long id;
struct ksmbd_session *sess;
+ unsigned int pending = 0;
down_write(&sessions_table_lock);
down_write(&conn->session_lock);
xa_for_each(&conn->sessions, id, sess) {
+ if (READ_ONCE(sess->state) != SMB2_SESSION_IN_PROGRESS)
+ continue;
+
if (atomic_read(&sess->refcnt) <= 1 &&
- (sess->state != SMB2_SESSION_VALID ||
- time_after(jiffies,
- sess->last_active + SMB2_SESSION_TIMEOUT))) {
+ time_after(jiffies, sess->last_active +
+ KSMBD_UNAUTHENTICATED_CONN_TIMEOUT)) {
xa_erase(&conn->sessions, sess->id);
ksmbd_session_remove_from_table(sess);
ksmbd_session_destroy(sess);
continue;
}
+ pending++;
}
up_write(&conn->session_lock);
up_write(&sessions_table_lock);
+ return pending >= KSMBD_MAX_PENDING_SESSIONS;
}
int ksmbd_session_register(struct ksmbd_conn *conn,
@@ -430,9 +436,12 @@ int ksmbd_session_register(struct ksmbd_conn *conn,
sess->dialect = conn->dialect;
memcpy(sess->ClientGUID, conn->ClientGUID, SMB2_CLIENT_GUID_SIZE);
- ksmbd_expire_session(conn);
- ret = xa_err(xa_store(&conn->sessions, sess->id, sess,
- KSMBD_DEFAULT_GFP));
+ /* Bound abandoned SessionId-zero authentication exchanges. */
+ if (ksmbd_too_many_session_setups(conn))
+ ret = -ENOSPC;
+ else
+ ret = xa_err(xa_store(&conn->sessions, sess->id, sess,
+ KSMBD_DEFAULT_GFP));
if (ret) {
down_write(&sessions_table_lock);
ksmbd_session_remove_from_table(sess);
@@ -443,6 +452,105 @@ int ksmbd_session_register(struct ksmbd_conn *conn,
return ret;
}
+void ksmbd_session_unregister(struct ksmbd_conn *conn,
+ struct ksmbd_session *sess)
+{
+ struct ksmbd_conn *session_conns[KSMBD_MAX_CHANNELS];
+ struct channel *chann;
+ unsigned long index;
+ unsigned int nr_conns = 0, i;
+ bool removed = false;
+
+ down_write(&sessions_table_lock);
+ if (!hlist_unhashed(&sess->hlist)) {
+ /* Keep each channel connection stable under sessions_table_lock. */
+ down_read(&sess->chann_lock);
+ xa_for_each(&sess->ksmbd_chann_list, index, chann) {
+ if (nr_conns == ARRAY_SIZE(session_conns))
+ break;
+ session_conns[nr_conns++] = chann->conn;
+ }
+ up_read(&sess->chann_lock);
+
+ ksmbd_session_remove_from_table(sess);
+ removed = true;
+ }
+
+ down_write(&conn->session_lock);
+ if (xa_load(&conn->sessions, sess->id) == sess)
+ xa_erase(&conn->sessions, sess->id);
+ up_write(&conn->session_lock);
+ for (i = 0; i < nr_conns; i++) {
+ if (session_conns[i] == conn)
+ continue;
+ down_write(&session_conns[i]->session_lock);
+ if (xa_load(&session_conns[i]->sessions, sess->id) == sess)
+ xa_erase(&session_conns[i]->sessions, sess->id);
+ up_write(&session_conns[i]->session_lock);
+ }
+ up_write(&sessions_table_lock);
+
+ if (removed)
+ ksmbd_user_session_put(sess);
+}
+
+bool ksmbd_conn_has_valid_or_expired_session(struct ksmbd_conn *conn)
+{
+ struct ksmbd_session *sess;
+ unsigned long id;
+ int state, bkt;
+ bool found = false;
+
+ down_read(&conn->session_lock);
+ xa_for_each(&conn->sessions, id, sess) {
+ state = READ_ONCE(sess->state);
+ if (state == SMB2_SESSION_VALID ||
+ state == SMB2_SESSION_EXPIRED) {
+ found = true;
+ break;
+ }
+ }
+ up_read(&conn->session_lock);
+ if (found)
+ return true;
+
+ /* A session bound through SMB3 multichannel is not in conn->sessions. */
+ down_read(&sessions_table_lock);
+ hash_for_each(sessions_table, bkt, sess, hlist) {
+ state = READ_ONCE(sess->state);
+ if (state != SMB2_SESSION_VALID &&
+ state != SMB2_SESSION_EXPIRED)
+ continue;
+
+ down_read(&sess->chann_lock);
+ found = xa_load(&sess->ksmbd_chann_list, (long)conn);
+ up_read(&sess->chann_lock);
+ if (found)
+ break;
+ }
+ up_read(&sessions_table_lock);
+ return found;
+}
+
+void ksmbd_expire_sessions(void)
+{
+ struct ksmbd_session *sess;
+ u64 now = ktime_get_real_seconds();
+ int bkt;
+
+ down_read(&sessions_table_lock);
+ hash_for_each(sessions_table, bkt, sess, hlist) {
+ if (READ_ONCE(sess->state) != SMB2_SESSION_VALID ||
+ !sess->kerberos_expiry || now < sess->kerberos_expiry)
+ continue;
+
+ if (cmpxchg(&sess->state, SMB2_SESSION_VALID,
+ SMB2_SESSION_EXPIRED) == SMB2_SESSION_VALID)
+ ksmbd_counter_inc(KSMBD_COUNTER_SESSION_TIMEOUTS);
+ }
+ up_read(&sessions_table_lock);
+}
+
static int ksmbd_chann_del(struct ksmbd_conn *conn, struct ksmbd_session *sess)
{
struct channel *chann;
@@ -457,7 +565,7 @@ static int ksmbd_chann_del(struct ksmbd_conn *conn, struct ksmbd_session *sess)
return 0;
}
-void ksmbd_sessions_deregister(struct ksmbd_conn *conn)
+void ksmbd_conn_sessions_cleanup(struct ksmbd_conn *conn)
{
struct ksmbd_session *sess;
unsigned long id;
diff --git a/fs/smb/server/mgmt/user_session.h b/fs/smb/server/mgmt/user_session.h
index 3e52d4cc13247..217258551d6d0 100644
--- a/fs/smb/server/mgmt/user_session.h
+++ b/fs/smb/server/mgmt/user_session.h
@@ -72,6 +72,8 @@ struct ksmbd_session {
struct rw_semaphore rpc_lock;
};
+#define KSMBD_MAX_CHANNELS 32
+
static inline int test_session_flag(struct ksmbd_session *sess, int bit)
{
return sess->flags & bit;
@@ -98,7 +100,11 @@ bool is_ksmbd_session_in_connection(struct ksmbd_conn *conn,
unsigned long long id);
int ksmbd_session_register(struct ksmbd_conn *conn,
struct ksmbd_session *sess);
-void ksmbd_sessions_deregister(struct ksmbd_conn *conn);
+void ksmbd_session_unregister(struct ksmbd_conn *conn,
+ struct ksmbd_session *sess);
+void ksmbd_conn_sessions_cleanup(struct ksmbd_conn *conn);
+bool ksmbd_conn_has_valid_or_expired_session(struct ksmbd_conn *conn);
+void ksmbd_expire_sessions(void);
struct ksmbd_session *__session_lookup(unsigned long long id);
struct ksmbd_session *ksmbd_session_lookup_all(struct ksmbd_conn *conn,
unsigned long long id);
diff --git a/fs/smb/server/proc.c b/fs/smb/server/proc.c
index 826353ed05538..19f0f2cfbf543 100644
--- a/fs/smb/server/proc.c
+++ b/fs/smb/server/proc.c
@@ -178,6 +178,8 @@ static int proc_show_ksmbd_stats(struct seq_file *m, void *v)
proc_show_runtime_totals(m);
seq_printf(m, "sessions:\t%lld\n",
ksmbd_counter_sum(KSMBD_COUNTER_SESSIONS));
+ seq_printf(m, "session_timeouts:\t%lld\n",
+ ksmbd_counter_sum(KSMBD_COUNTER_SESSION_TIMEOUTS));
seq_printf(m, "tree_connects:\t%lld\n",
ksmbd_counter_sum(KSMBD_COUNTER_TREE_CONNS));
seq_printf(m, "requests:\t%lld\n",
diff --git a/fs/smb/server/server.c b/fs/smb/server/server.c
index 26c424e6682ea..e113b23d96f94 100644
--- a/fs/smb/server/server.c
+++ b/fs/smb/server/server.c
@@ -403,7 +403,7 @@ static int ksmbd_server_process_request(struct ksmbd_conn *conn)
static int ksmbd_server_terminate_conn(struct ksmbd_conn *conn)
{
- ksmbd_sessions_deregister(conn);
+ ksmbd_conn_sessions_cleanup(conn);
destroy_lease_table(conn);
return 0;
}
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 184b28072a6f0..3cb39dc7b149c 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -83,8 +83,6 @@ struct channel *lookup_chann_list(struct ksmbd_session *sess, struct ksmbd_conn
return chann;
}
-#define KSMBD_MAX_CHANNELS 32
-
static int register_session_channel(struct ksmbd_session *sess,
struct ksmbd_conn *conn,
const char *sess_key)
@@ -914,8 +912,14 @@ static bool smb2_session_expired_cmd_allowed(struct ksmbd_work *work,
static bool smb2_session_kerberos_expired(struct ksmbd_session *sess)
{
- return sess->kerberos_expiry &&
- ktime_get_real_seconds() >= sess->kerberos_expiry;
+ if (!sess->kerberos_expiry ||
+ ktime_get_real_seconds() < sess->kerberos_expiry)
+ return false;
+
+ if (cmpxchg(&sess->state, SMB2_SESSION_VALID,
+ SMB2_SESSION_EXPIRED) == SMB2_SESSION_VALID)
+ ksmbd_counter_inc(KSMBD_COUNTER_SESSION_TIMEOUTS);
+ return true;
}
/**
@@ -950,9 +954,8 @@ int smb2_check_user_session(struct ksmbd_work *work)
if (!work->next_smb2_rcv_hdr_off && sess_id)
work->sess = ksmbd_session_lookup_all_states(conn, sess_id);
if (work->sess) {
- if (smb2_session_kerberos_expired(work->sess)) {
- work->sess->state = SMB2_SESSION_EXPIRED;
- } else if (work->sess->state != SMB2_SESSION_VALID) {
+ if (!smb2_session_kerberos_expired(work->sess) &&
+ work->sess->state != SMB2_SESSION_VALID) {
ksmbd_user_session_put(work->sess);
work->sess = NULL;
}
@@ -977,8 +980,7 @@ int smb2_check_user_session(struct ksmbd_work *work)
sess_id, work->sess->id);
return -EINVAL;
}
- if (smb2_session_kerberos_expired(work->sess))
- work->sess->state = SMB2_SESSION_EXPIRED;
+ smb2_session_kerberos_expired(work->sess);
if (work->sess->state != SMB2_SESSION_VALID) {
pr_err("compound request on a non-valid session (state %d)\n",
work->sess->state);
@@ -995,7 +997,6 @@ int smb2_check_user_session(struct ksmbd_work *work)
work->sess = ksmbd_session_lookup_all_states(conn, sess_id);
if (work->sess) {
if (smb2_session_kerberos_expired(work->sess)) {
- work->sess->state = SMB2_SESSION_EXPIRED;
return smb2_session_expired_cmd_allowed(work, cmd) ?
1 : -EKEYEXPIRED;
}
@@ -2192,7 +2193,7 @@ int smb2_sess_setup(struct ksmbd_work *work)
struct ksmbd_conn *conn = work->conn;
struct smb2_sess_setup_req *req;
struct smb2_sess_setup_rsp *rsp;
- struct ksmbd_session *sess;
+ struct ksmbd_session *sess = NULL;
struct negotiate_message *negblob;
unsigned int negblob_len, negblob_off;
int rc = 0;
@@ -2333,6 +2334,9 @@ int smb2_sess_setup(struct ksmbd_work *work)
goto out_err;
}
+ if (work->session_setup_reauth)
+ WRITE_ONCE(sess->state, SMB2_SESSION_IN_PROGRESS);
+
conn->binding = false;
}
work->sess = sess;
@@ -2444,6 +2448,14 @@ int smb2_sess_setup(struct ksmbd_work *work)
}
if (rc < 0) {
+ bool setup_in_progress = sess &&
+ READ_ONCE(sess->state) == SMB2_SESSION_IN_PROGRESS &&
+ !(req->Flags & SMB2_SESSION_REQ_FLAG_BINDING);
+
+ /* Authentication errors must not leave the new session published. */
+ if (setup_in_progress)
+ ksmbd_session_unregister(conn, sess);
+
if (sess && conn->dialect == SMB311_PROT_ID &&
(req->Flags & SMB2_SESSION_REQ_FLAG_BINDING)) {
struct preauth_session *preauth_sess;
@@ -2477,7 +2489,8 @@ int smb2_sess_setup(struct ksmbd_work *work)
* For binding requests, session belongs to another
* connection. Do not expire it.
*/
- if (!(req->Flags & SMB2_SESSION_REQ_FLAG_BINDING)) {
+ if (!(req->Flags & SMB2_SESSION_REQ_FLAG_BINDING) &&
+ !setup_in_progress) {
sess->last_active = jiffies;
sess->kerberos_expiry = 0;
sess->state = SMB2_SESSION_EXPIRED;
diff --git a/fs/smb/server/smb2pdu.h b/fs/smb/server/smb2pdu.h
index 1836259be8971..2a8a2bc9a8a13 100644
--- a/fs/smb/server/smb2pdu.h
+++ b/fs/smb/server/smb2pdu.h
@@ -61,8 +61,6 @@ struct preauth_integrity_info {
#define SMB2_SESSION_IN_PROGRESS BIT(0)
#define SMB2_SESSION_VALID BIT(1)
-#define SMB2_SESSION_TIMEOUT (10 * HZ)
-
/* Apple Defined Contexts */
#define SMB2_CREATE_AAPL "AAPL"
diff --git a/fs/smb/server/stats.h b/fs/smb/server/stats.h
index bc864efa0d46b..8b32b8b4e8be4 100644
--- a/fs/smb/server/stats.h
+++ b/fs/smb/server/stats.h
@@ -15,6 +15,7 @@
enum {
KSMBD_COUNTER_SESSIONS = 0,
+ KSMBD_COUNTER_SESSION_TIMEOUTS,
KSMBD_COUNTER_TREE_CONNS,
KSMBD_COUNTER_REQUESTS,
KSMBD_COUNTER_STATUS_SUCCESS,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 089/398] RDMA/siw: Bound fragmented header copies by the remaining length
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (87 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 088/398] RDMA/efa: Keep EQ resources " Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 090/398] drm/msm: Fix the separate_gpu_kms parameter description Greg Kroah-Hartman
` (313 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jérémy Jean,
Bernard Metzler, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
[ Upstream commit 9ff797e516dbc1ecb73701ec4c24055712d44411 ]
siw_get_hdr() can receive an extended DDP/RDMAP header across more than
one TCP callback. The first callback may receive most of the header,
while the next one still limits the copy to hdrlen - MIN_DDP_HDR instead
of the number of missing bytes. This makes the destination move past the
end of the header and overwrite the receive state, including
fpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd
value as a copy offset, which creates an OOB write.
Use the number of header bytes already received when calculating the
next copy length.
Fixes: 754209850df8 ("RDMA/siw: Always consume all skbuf data in sk_data_ready() upcall.")
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Link: https://patch.msgid.link/20260908085520.1746329-1-Jeremy.Jean@oss.cyber.gouv.fr
Assisted-by: Codex:gpt-6
Acked-by: Bernard Metzler <bernard.metzler@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_qp_rx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/sw/siw/siw_qp_rx.c b/drivers/infiniband/sw/siw/siw_qp_rx.c
index b566d163c5aab..e5b641c8d694a 100644
--- a/drivers/infiniband/sw/siw/siw_qp_rx.c
+++ b/drivers/infiniband/sw/siw/siw_qp_rx.c
@@ -1079,7 +1079,7 @@ static int siw_get_hdr(struct siw_rx_stream *srx)
if (iwarp_pktinfo[opcode].hdr_len > sizeof(struct iwarp_ctrl_tagged)) {
int hdrlen = iwarp_pktinfo[opcode].hdr_len;
- bytes = min_t(int, hdrlen - MIN_DDP_HDR, srx->skb_new);
+ bytes = min_t(int, hdrlen - srx->fpdu_part_rcvd, srx->skb_new);
skb_copy_bits(skb, srx->skb_offset,
(char *)c_hdr + srx->fpdu_part_rcvd, bytes);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 143/438] wifi: virt_wifi: dont transfer operstate before register
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (141 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 142/438] ksmbd: follow SMB2 session expiration semantics Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 144/438] drm/xe/mmio_gem: forbid VMA split Greg Kroah-Hartman
` (306 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
[ Upstream commit e5c8d7acd31b27057ea42cd405d0b3ece097bc89 ]
virt_wifi_newlink() calls netif_stacked_transfer_operstate() before
register_netdevice(). If the lower device is dormant, that queues the
new netdev on lweventlist while it is still uninitialized. If
registration fails after that, for example because of an invalid name
such as "bad/name", free_netdev() immediately frees the object. A
later linkwatch_fire_event() then use-after-frees the list entry.
Move the transfer to after netdev_upper_dev_link(), as macvlan and
ipvlan already do.
Fixes: c7cdba31ed8b ("mac80211-next: rtnetlink wifi simulation device")
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Link: https://patch.msgid.link/f5a832fb0ab228ce6e2b5a91fba4ca8b79198a2f.1788948455.git.zihanx@nebusec.ai
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virtual/virt_wifi.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/virtual/virt_wifi.c b/drivers/net/wireless/virtual/virt_wifi.c
index b69a4650fba85..48afc2432f93a 100644
--- a/drivers/net/wireless/virtual/virt_wifi.c
+++ b/drivers/net/wireless/virtual/virt_wifi.c
@@ -558,7 +558,6 @@ static int virt_wifi_newlink(struct net_device *dev,
}
eth_hw_addr_inherit(dev, priv->lowerdev);
- netif_stacked_transfer_operstate(priv->lowerdev, dev);
dev->ieee80211_ptr = kzalloc_obj(*dev->ieee80211_ptr);
@@ -584,6 +583,8 @@ static int virt_wifi_newlink(struct net_device *dev,
goto unregister_netdev;
}
+ netif_stacked_transfer_operstate(priv->lowerdev, dev);
+
dev->priv_destructor = virt_wifi_net_device_destructor;
priv->being_deleted = false;
priv->is_connected = false;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 090/398] drm/msm: Fix the separate_gpu_kms parameter description
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (88 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 089/398] RDMA/siw: Bound fragmented header copies by the remaining length Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 091/398] drm/msm/adreno: Fix the skip_gpu " Greg Kroah-Hartman
` (312 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Rob Clark,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit adf5967331318bcb436fc80069915231ec039352 ]
The module parameter is separate_gpu_kms, but its MODULE_PARM_DESC()
names separate_gpu_drm, so modinfo describes a parameter that does not
exist and shows no description for the real one.
Use the parameter name in the description.
Fixes: 217ed15bd399 ("drm/msm: enable separate binding of GPU and display devices")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Patchwork: https://patchwork.freedesktop.org/patch/751407/
Message-ID: <20260906170347.2427-1-kmehltretter@gmail.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/msm_drv.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/msm/msm_drv.c b/drivers/gpu/drm/msm/msm_drv.c
index 94b32973cd6a1..c2a8aaa33f84a 100644
--- a/drivers/gpu/drm/msm/msm_drv.c
+++ b/drivers/gpu/drm/msm/msm_drv.c
@@ -55,7 +55,7 @@ MODULE_PARM_DESC(modeset, "Use kernel modesetting [KMS] (1=on (default), 0=disab
module_param(modeset, bool, 0600);
static bool separate_gpu_kms;
-MODULE_PARM_DESC(separate_gpu_drm, "Use separate DRM device for the GPU (0=single DRM device for both GPU and display (default), 1=two DRM devices)");
+MODULE_PARM_DESC(separate_gpu_kms, "Use separate DRM device for the GPU (0=single DRM device for both GPU and display (default), 1=two DRM devices)");
module_param(separate_gpu_kms, bool, 0400);
DECLARE_FAULT_ATTR(fail_gem_alloc);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 144/438] drm/xe/mmio_gem: forbid VMA split
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (142 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 143/438] wifi: virt_wifi: dont transfer operstate before register Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 145/438] drm/xe/mmio_gem: use write-back mapping for dummy page Greg Kroah-Hartman
` (305 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthew Auld, Ilia Levi,
Rodrigo Vivi, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilia Levi <ilia.levi@intel.com>
[ Upstream commit 247a82da6f563dcfd9074a68f99a0c0997d0679c ]
The fault handler assumes it always operates on a VMA spanning the entire
GEM object. This does not hold when the VMA has been split, e.g. by a
partial munmap or mprotect. In that case the handler may map wrong
physical pages or cause SIGBUS.
Handle this by forbidding VMA split, as partial unmaps are not deemed
useful for MMIO GEMs.
Suggested-by: Matthew Auld <matthew.auld@intel.com>
Signed-off-by: Ilia Levi <ilia.levi@intel.com>
Fixes: 1ffcf8b8ae8a ("drm/xe: Support for mmap-ing mmio regions")
Reviewed-by: Matthew Auld <matthew.auld@intel.com>
Signed-off-by: Matthew Auld <matthew.auld@intel.com>
Link: https://patch.msgid.link/20260908165046.1393557-11-matthew.auld@intel.com
(cherry picked from commit f3391a0b12d7bf826a0b21600d2f294f3dce4c14)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_mmio_gem.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/gpu/drm/xe/xe_mmio_gem.c b/drivers/gpu/drm/xe/xe_mmio_gem.c
index 8c803ef233cc4..f15a6a84af159 100644
--- a/drivers/gpu/drm/xe/xe_mmio_gem.c
+++ b/drivers/gpu/drm/xe/xe_mmio_gem.c
@@ -39,10 +39,20 @@ struct xe_mmio_gem {
phys_addr_t phys_addr;
};
+static int xe_mmio_gem_vm_may_split(struct vm_area_struct *area, unsigned long addr)
+{
+ /*
+ * Forbid splitting. Together with VM_DONTEXPAND, this keeps the VMA
+ * matching the GEM object exactly.
+ */
+ return -EINVAL;
+}
+
static const struct vm_operations_struct vm_ops = {
.open = drm_gem_vm_open,
.close = drm_gem_vm_close,
.fault = xe_mmio_gem_vm_fault,
+ .may_split = xe_mmio_gem_vm_may_split,
};
static const struct drm_gem_object_funcs xe_mmio_gem_funcs = {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 091/398] drm/msm/adreno: Fix the skip_gpu parameter description
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (89 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 090/398] drm/msm: Fix the separate_gpu_kms parameter description Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 092/398] netfilter: nft_nat: fully initialise new_addr in netmap setup Greg Kroah-Hartman
` (311 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Rob Clark,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 8061ee61b9426fe38350fa9eead2d9c50b03deb6 ]
The module parameter is skip_gpu, but its MODULE_PARM_DESC() names
no_gpu, so modinfo describes a parameter that does not exist and shows
no description for the real one.
Use the parameter name in the description.
Fixes: 3f17991488af ("drm/msm/adreno: Add a modparam to skip GPU")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Patchwork: https://patchwork.freedesktop.org/patch/751406/
Message-ID: <20260906170301.2393-1-kmehltretter@gmail.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/adreno/adreno_device.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/msm/adreno/adreno_device.c b/drivers/gpu/drm/msm/adreno/adreno_device.c
index 28f744f3caf7c..5d598815de45a 100644
--- a/drivers/gpu/drm/msm/adreno/adreno_device.c
+++ b/drivers/gpu/drm/msm/adreno/adreno_device.c
@@ -25,7 +25,7 @@ MODULE_PARM_DESC(disable_acd, "Forcefully disable GPU ACD");
module_param_unsafe(disable_acd, bool, 0400);
static bool skip_gpu;
-MODULE_PARM_DESC(no_gpu, "Disable GPU driver register (0=enable GPU driver register (default), 1=skip GPU driver register");
+MODULE_PARM_DESC(skip_gpu, "Disable GPU driver register (0=enable GPU driver register (default), 1=skip GPU driver register");
module_param(skip_gpu, bool, 0400);
extern const struct adreno_gpulist a2xx_gpulist;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 145/438] drm/xe/mmio_gem: use write-back mapping for dummy page
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (143 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 144/438] drm/xe/mmio_gem: forbid VMA split Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 146/438] drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy Greg Kroah-Hartman
` (304 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Ilia Levi, Matthew Auld,
Rodrigo Vivi, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilia Levi <ilia.levi@intel.com>
[ Upstream commit 819f189265a5955da743e78e20a713a038982e89 ]
Currently vmf_insert_pfn() maps the dummy page as UC, inheriting the
VMA's page protection which was set for the real MMIO region. This
conflicts with the direct map's WB mapping of the same page, creating a
cache type alias which is architecturally undefined on some platforms.
Use vmf_insert_pfn_prot() with a WB pgprot instead. Also simplify to
fault in the requested page instead of the whole VMA.
Fixes: 1ffcf8b8ae8a ("drm/xe: Support for mmap-ing mmio regions")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260525125801.975038-6-ilia.levi%40intel.com
Assisted-by: GitHub-Copilot:claude-opus-4.6
Signed-off-by: Ilia Levi <ilia.levi@intel.com>
Reviewed-by: Matthew Auld <matthew.auld@intel.com>
Signed-off-by: Matthew Auld <matthew.auld@intel.com>
Link: https://patch.msgid.link/20260908165046.1393557-12-matthew.auld@intel.com
(cherry picked from commit 1e8e28e35df0e77ae1b22fc091c1f422f62fa5e9)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_mmio_gem.c | 19 +++++--------------
1 file changed, 5 insertions(+), 14 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_mmio_gem.c b/drivers/gpu/drm/xe/xe_mmio_gem.c
index f15a6a84af159..418a24bdfa4ed 100644
--- a/drivers/gpu/drm/xe/xe_mmio_gem.c
+++ b/drivers/gpu/drm/xe/xe_mmio_gem.c
@@ -172,14 +172,13 @@ static void xe_mmio_gem_release_dummy_page(struct drm_device *dev, void *res)
__free_page((struct page *)res);
}
-static vm_fault_t xe_mmio_gem_vm_fault_dummy_page(struct vm_area_struct *vma)
+static vm_fault_t xe_mmio_gem_vm_fault_dummy_page(struct vm_fault *vmf)
{
+ struct vm_area_struct *vma = vmf->vma;
struct drm_gem_object *base = vma->vm_private_data;
struct drm_device *dev = base->dev;
- vm_fault_t ret = VM_FAULT_NOPAGE;
struct page *page;
unsigned long pfn;
- unsigned long i;
page = alloc_page(GFP_KERNEL | __GFP_ZERO);
if (!page)
@@ -190,16 +189,8 @@ static vm_fault_t xe_mmio_gem_vm_fault_dummy_page(struct vm_area_struct *vma)
pfn = page_to_pfn(page);
- /* Map the entire VMA to the same dummy page */
- for (i = 0; i < base->size; i += PAGE_SIZE) {
- unsigned long addr = vma->vm_start + i;
-
- ret = vmf_insert_pfn(vma, addr, pfn);
- if (ret & VM_FAULT_ERROR)
- break;
- }
-
- return ret;
+ return vmf_insert_pfn_prot(vma, vmf->address, pfn,
+ vm_get_page_prot(vma->vm_flags));
}
static vm_fault_t xe_mmio_gem_vm_fault(struct vm_fault *vmf)
@@ -219,7 +210,7 @@ static vm_fault_t xe_mmio_gem_vm_fault(struct vm_fault *vmf)
* It is assumed the userspace will receive the notification via some
* other channel (e.g. drm uevent).
*/
- return xe_mmio_gem_vm_fault_dummy_page(vma);
+ return xe_mmio_gem_vm_fault_dummy_page(vmf);
}
for (i = 0; i < base->size; i += PAGE_SIZE) {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 092/398] netfilter: nft_nat: fully initialise new_addr in netmap setup
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (90 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 091/398] drm/msm/adreno: Fix the skip_gpu " Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 093/398] netfilter: nf_tables: fix device name and prefix match in hook lookup Greg Kroah-Hartman
` (310 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Theodor Arsenij Larionov Trichkine,
Pablo Neira Ayuso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
[ Upstream commit d313499df66159b4b7971d760d16729598ab7e5a ]
nft_nat_setup_netmap() builds the mapped address in an on-stack
union nf_inet_addr. For an IPv4 mapping it writes only the 4-byte .ip
member and the loop runs a single 32-bit iteration, but it then copies
the whole 16-byte union into range->min_addr and range->max_addr, so the
upper 12 bytes reach nf_nat_setup_info() uninitialised.
KMSAN reports an uninit-value in nf_nat_setup_info() reached from
nft_nat_eval(). The IPv6 path fills all 16 bytes and is not affected.
Zero-initialise new_addr.
Fixes: 3ff7ddb1353d ("netfilter: nft_nat: add netmap support")
Signed-off-by: Theodor Arsenij Larionov Trichkine <theodorlarionov@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nft_nat.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/netfilter/nft_nat.c b/net/netfilter/nft_nat.c
index e32cd9fbc7c2e..cdbd800cac969 100644
--- a/net/netfilter/nft_nat.c
+++ b/net/netfilter/nft_nat.c
@@ -64,8 +64,8 @@ static void nft_nat_setup_netmap(struct nf_nat_range2 *range,
const struct nft_pktinfo *pkt,
const struct nft_nat *priv)
{
+ union nf_inet_addr new_addr = {};
struct sk_buff *skb = pkt->skb;
- union nf_inet_addr new_addr;
__be32 netmask;
int i, len = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 146/438] drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (144 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 145/438] drm/xe/mmio_gem: use write-back mapping for dummy page Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 147/438] drm/xe/shrinker: Return the freed page count through a parameter Greg Kroah-Hartman
` (303 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilia Levi, Shuicheng Lin,
Matthew Auld, Rodrigo Vivi, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuicheng Lin <shuicheng.lin@intel.com>
[ Upstream commit 37fcbd7b2f8996d783932dab11bc668e169b0de6 ]
xe_mmio_gem_create() calls drm_vma_node_allow() but nothing ever calls
drm_vma_node_revoke(). The drm_vma_offset_file rb-tree entry allocated
by drm_vma_node_allow() is not freed by drm_gem_object_release(), so
it is leaked on every create/destroy cycle.
Add a struct drm_file * parameter to xe_mmio_gem_destroy() and call
drm_vma_node_revoke() from there, mirroring the drm_vma_node_allow()
call in xe_mmio_gem_create().
Fixes: 1ffcf8b8ae8a ("drm/xe: Support for mmap-ing mmio regions")
Suggested-by: Ilia Levi <ilia.levi@intel.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Shuicheng Lin <shuicheng.lin@intel.com>
Reviewed-by: Ilia Levi <ilia.levi@intel.com>
Signed-off-by: Matthew Auld <matthew.auld@intel.com>
Link: https://patch.msgid.link/20260908165046.1393557-14-matthew.auld@intel.com
(cherry picked from commit 32f0cb250598456d812fb7ca57a040282858323d)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_mmio_gem.c | 4 +++-
drivers/gpu/drm/xe/xe_mmio_gem.h | 2 +-
2 files changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_mmio_gem.c b/drivers/gpu/drm/xe/xe_mmio_gem.c
index 418a24bdfa4ed..ad3c9fa05223d 100644
--- a/drivers/gpu/drm/xe/xe_mmio_gem.c
+++ b/drivers/gpu/drm/xe/xe_mmio_gem.c
@@ -138,14 +138,16 @@ static void xe_mmio_gem_free(struct drm_gem_object *base)
/**
* xe_mmio_gem_destroy - Destroy the GEM object that exposes an MMIO region
* @gem: the GEM object to destroy
+ * @file: DRM file descriptor previously passed to xe_mmio_gem_create()
*
* This function releases resources associated with the GEM object created by
* xe_mmio_gem_create().
*
* See: "Exposing MMIO regions to userspace"
*/
-void xe_mmio_gem_destroy(struct xe_mmio_gem *gem)
+void xe_mmio_gem_destroy(struct xe_mmio_gem *gem, struct drm_file *file)
{
+ drm_vma_node_revoke(&gem->base.vma_node, file);
xe_mmio_gem_free(&gem->base);
}
diff --git a/drivers/gpu/drm/xe/xe_mmio_gem.h b/drivers/gpu/drm/xe/xe_mmio_gem.h
index 4b76d5586ebb8..80d7795f07c8e 100644
--- a/drivers/gpu/drm/xe/xe_mmio_gem.h
+++ b/drivers/gpu/drm/xe/xe_mmio_gem.h
@@ -15,6 +15,6 @@ struct xe_mmio_gem;
struct xe_mmio_gem *xe_mmio_gem_create(struct xe_device *xe, struct drm_file *file,
phys_addr_t phys_addr, size_t size);
u64 xe_mmio_gem_mmap_offset(struct xe_mmio_gem *gem);
-void xe_mmio_gem_destroy(struct xe_mmio_gem *gem);
+void xe_mmio_gem_destroy(struct xe_mmio_gem *gem, struct drm_file *file);
#endif /* _XE_MMIO_GEM_H_ */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 093/398] netfilter: nf_tables: fix device name and prefix match in hook lookup
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (91 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 092/398] netfilter: nft_nat: fully initialise new_addr in netmap setup Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 094/398] netfilter: nf_nat: unregister and release hooks on error Greg Kroah-Hartman
` (309 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wei Fang, Fernando Fernandez Mancera,
Pablo Neira Ayuso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fernando Fernandez Mancera <fmancera@suse.de>
[ Upstream commit 444e4c88c9c62a3d823069006563513fe7d5aa66 ]
Currently, a netdev chain or flowtable hooked to a device prefix can be
unintentionally deleted by a control-plane request targeting an exact
device name or even a shorter one due to the usage of min() to calculate
the length to match.
Fix this by making sure an exact device match never matches a prefix and
that both the target and the candidate have the same length during
delete operation. The add and update paths retain the existing overlap
matching to prevent a single device from matching multiple hooks.
Reported-by: Wei Fang <void0red@gmail.com>
Closes: https://lore.kernel.org/netfilter-devel/CANE+tVrDeNCHQVmsqkV2ozeBqyE3GtRDMhZgsg1bhw10yGNTRQ@mail.gmail.com/
Fixes: 6d07a289504a ("netfilter: nf_tables: Support wildcard netdev hook specs")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_tables_api.c | 22 +++++++++++++---------
1 file changed, 13 insertions(+), 9 deletions(-)
diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
index a3a66b6268cd6..321a0dd92178b 100644
--- a/net/netfilter/nf_tables_api.c
+++ b/net/netfilter/nf_tables_api.c
@@ -2343,11 +2343,14 @@ static struct nft_hook *nft_netdev_hook_alloc(struct net *net,
}
static struct nft_hook *nft_hook_list_find(struct list_head *hook_list,
- const struct nft_hook *this)
+ const struct nft_hook *this,
+ bool strict)
{
struct nft_hook *hook;
list_for_each_entry(hook, hook_list, list) {
+ if (strict && hook->ifnamelen != this->ifnamelen)
+ continue;
if (!strncmp(hook->ifname, this->ifname,
min(hook->ifnamelen, this->ifnamelen)))
return hook;
@@ -2385,7 +2388,7 @@ static int nf_tables_parse_netdev_hooks(struct net *net,
err = PTR_ERR(hook);
goto err_hook;
}
- if (nft_hook_list_find(hook_list, hook)) {
+ if (nft_hook_list_find(hook_list, hook, false)) {
NL_SET_BAD_ATTR(extack, tmp);
nft_netdev_hook_free(hook);
err = -EEXIST;
@@ -2842,7 +2845,7 @@ static int nf_tables_updchain(struct nft_ctx *ctx, u8 genmask, u8 policy,
ops->hook = basechain->ops.hook;
}
- if (nft_hook_list_find(&basechain->hook_list, h)) {
+ if (nft_hook_list_find(&basechain->hook_list, h, false)) {
list_del(&h->list);
nft_netdev_hook_free(h);
continue;
@@ -2855,7 +2858,8 @@ static int nf_tables_updchain(struct nft_ctx *ctx, u8 genmask, u8 policy,
!nft_trans_chain_update(trans))
continue;
- if (nft_hook_list_find(&nft_trans_chain_hooks(trans), h)) {
+ if (nft_hook_list_find(&nft_trans_chain_hooks(trans),
+ h, false)) {
nft_chain_release_hook(&hook);
return -EEXIST;
}
@@ -3130,7 +3134,7 @@ static int nft_delchain_hook(struct nft_ctx *ctx,
return err;
list_for_each_entry(this, &chain_hook.list, list) {
- hook = nft_hook_list_find(&basechain->hook_list, this);
+ hook = nft_hook_list_find(&basechain->hook_list, this, true);
if (!hook) {
err = -ENOENT;
goto err_chain_del_hook;
@@ -8921,7 +8925,7 @@ static int nft_register_flowtable_net_hooks(struct net *net,
if (!nft_is_active_next(net, ft))
continue;
- if (nft_hook_list_find(&ft->hook_list, hook)) {
+ if (nft_hook_list_find(&ft->hook_list, hook, false)) {
err = -EEXIST;
goto err_unregister_net_hooks;
}
@@ -8980,7 +8984,7 @@ static int nft_flowtable_update(struct nft_ctx *ctx, const struct nlmsghdr *nlh,
return err;
list_for_each_entry_safe(hook, next, &flowtable_hook.list, list) {
- if (nft_hook_list_find(&flowtable->hook_list, hook)) {
+ if (nft_hook_list_find(&flowtable->hook_list, hook, false)) {
list_del(&hook->list);
nft_netdev_hook_free(hook);
continue;
@@ -8993,7 +8997,7 @@ static int nft_flowtable_update(struct nft_ctx *ctx, const struct nlmsghdr *nlh,
!nft_trans_flowtable_update(trans))
continue;
- if (nft_hook_list_find(&nft_trans_flowtable_hooks(trans), hook)) {
+ if (nft_hook_list_find(&nft_trans_flowtable_hooks(trans), hook, false)) {
err = -EEXIST;
goto err_flowtable_update_hook;
}
@@ -9213,7 +9217,7 @@ static int nft_delflowtable_hook(struct nft_ctx *ctx,
return err;
list_for_each_entry(this, &flowtable_hook.list, list) {
- hook = nft_hook_list_find(&flowtable->hook_list, this);
+ hook = nft_hook_list_find(&flowtable->hook_list, this, true);
if (!hook) {
err = -ENOENT;
goto err_flowtable_del_hook;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 147/438] drm/xe/shrinker: Return the freed page count through a parameter
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (145 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 146/438] drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 148/438] drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory Greg Kroah-Hartman
` (302 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Hellström, Matthew Brost,
Shuicheng Lin, Rodrigo Vivi, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuicheng Lin <shuicheng.lin@intel.com>
[ Upstream commit 3c90e42a01426262f0cd166bc01b45c05562640d ]
__xe_shrinker_walk() and xe_shrinker_walk() return either the number of
pages freed or a negative error, so the two cannot be reported at once.
On error the pages already freed are dropped, and since xe_shrinker_scan()
only accumulates non-negative returns while *scanned is updated by
pointer, the shrinker tells mm that it scanned without freeing.
Accumulate the count into a caller-provided counter and return only the
status, so an error no longer discards what the walk had freed.
Fixes: 00c8efc3180f ("drm/xe: Add a shrinker for xe bos")
Assisted-by: Claude:claude-opus-5
Reviewed-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Link: https://patch.msgid.link/20260909162102.1097006-2-shuicheng.lin@intel.com
Signed-off-by: Shuicheng Lin <shuicheng.lin@intel.com>
(cherry picked from commit d7aac1a0235a6ce41e30cec385e2db8c33dad12d)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_shrinker.c | 62 ++++++++++++++------------------
1 file changed, 26 insertions(+), 36 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_shrinker.c b/drivers/gpu/drm/xe/xe_shrinker.c
index 83374cd576608..89445cd202380 100644
--- a/drivers/gpu/drm/xe/xe_shrinker.c
+++ b/drivers/gpu/drm/xe/xe_shrinker.c
@@ -54,13 +54,14 @@ xe_shrinker_mod_pages(struct xe_shrinker *shrinker, long shrinkable, long purgea
write_unlock(&shrinker->lock);
}
-static s64 __xe_shrinker_walk(struct xe_device *xe,
+static int __xe_shrinker_walk(struct xe_device *xe,
struct ttm_operation_ctx *ctx,
const struct xe_bo_shrink_flags flags,
- unsigned long to_scan, unsigned long *scanned)
+ unsigned long to_scan, unsigned long *scanned,
+ unsigned long *freed)
{
unsigned int mem_type;
- s64 freed = 0, lret;
+ s64 lret;
for (mem_type = XE_PL_SYSTEM; mem_type <= XE_PL_TT; ++mem_type) {
struct ttm_resource_manager *man = ttm_manager_type(&xe->ttm, mem_type);
@@ -82,7 +83,7 @@ static s64 __xe_shrinker_walk(struct xe_device *xe,
if (lret < 0)
return lret;
- freed += lret;
+ *freed += lret;
if (*scanned >= to_scan)
break;
}
@@ -90,7 +91,7 @@ static s64 __xe_shrinker_walk(struct xe_device *xe,
xe_assert(xe, !IS_ERR(ttm_bo));
}
- return freed;
+ return 0;
}
/*
@@ -99,40 +100,35 @@ static s64 __xe_shrinker_walk(struct xe_device *xe,
* add writeback. This avoids stalls and explicit writebacks with light or
* moderate memory pressure.
*/
-static s64 xe_shrinker_walk(struct xe_device *xe,
+static int xe_shrinker_walk(struct xe_device *xe,
struct ttm_operation_ctx *ctx,
const struct xe_bo_shrink_flags flags,
- unsigned long to_scan, unsigned long *scanned)
+ unsigned long to_scan, unsigned long *scanned,
+ unsigned long *freed)
{
bool no_wait_gpu = true;
struct xe_bo_shrink_flags save_flags = flags;
- s64 lret, freed;
+ int ret;
swap(no_wait_gpu, ctx->no_wait_gpu);
save_flags.writeback = false;
- lret = __xe_shrinker_walk(xe, ctx, save_flags, to_scan, scanned);
+ ret = __xe_shrinker_walk(xe, ctx, save_flags, to_scan, scanned, freed);
swap(no_wait_gpu, ctx->no_wait_gpu);
- if (lret < 0 || *scanned >= to_scan)
- return lret;
+ if (ret || *scanned >= to_scan)
+ return ret;
- freed = lret;
if (!ctx->no_wait_gpu) {
- lret = __xe_shrinker_walk(xe, ctx, save_flags, to_scan, scanned);
- if (lret < 0)
- return lret;
- freed += lret;
- if (*scanned >= to_scan)
- return freed;
+ ret = __xe_shrinker_walk(xe, ctx, save_flags, to_scan, scanned,
+ freed);
+ if (ret || *scanned >= to_scan)
+ return ret;
}
- if (flags.writeback) {
- lret = __xe_shrinker_walk(xe, ctx, flags, to_scan, scanned);
- if (lret < 0)
- return lret;
- freed += lret;
- }
+ if (flags.writeback)
+ ret = __xe_shrinker_walk(xe, ctx, flags, to_scan, scanned,
+ freed);
- return freed;
+ return ret;
}
static unsigned long
@@ -214,7 +210,6 @@ static unsigned long xe_shrinker_scan(struct shrinker *shrink, struct shrink_con
bool runtime_pm;
bool purgeable;
bool can_backup = !!(sc->gfp_mask & __GFP_FS);
- s64 lret;
nr_to_scan = sc->nr_to_scan;
@@ -225,12 +220,9 @@ static unsigned long xe_shrinker_scan(struct shrinker *shrink, struct shrink_con
/* Might need runtime PM. Try to wake early if it looks like it. */
runtime_pm = xe_shrinker_runtime_pm_get(shrinker, false, nr_to_scan, can_backup);
- if (purgeable && nr_scanned < nr_to_scan) {
- lret = xe_shrinker_walk(shrinker->xe, &ctx, shrink_flags,
- nr_to_scan, &nr_scanned);
- if (lret >= 0)
- freed += lret;
- }
+ if (purgeable && nr_scanned < nr_to_scan)
+ xe_shrinker_walk(shrinker->xe, &ctx, shrink_flags,
+ nr_to_scan, &nr_scanned, &freed);
sc->nr_scanned = nr_scanned;
if (nr_scanned >= nr_to_scan || !can_backup)
@@ -242,10 +234,8 @@ static unsigned long xe_shrinker_scan(struct shrinker *shrink, struct shrink_con
shrink_flags.purge = false;
- lret = xe_shrinker_walk(shrinker->xe, &ctx, shrink_flags,
- nr_to_scan, &nr_scanned);
- if (lret >= 0)
- freed += lret;
+ xe_shrinker_walk(shrinker->xe, &ctx, shrink_flags,
+ nr_to_scan, &nr_scanned, &freed);
sc->nr_scanned = nr_scanned;
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 094/398] netfilter: nf_nat: unregister and release hooks on error
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (92 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 093/398] netfilter: nf_tables: fix device name and prefix match in hook lookup Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 095/398] netfilter: flowtable: hold reference on ct until flow is released Greg Kroah-Hartman
` (308 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit cbdd39ce42530a193c56beb206a3356cb6d01016 ]
If nf_hook_entries_insert_raw() fails, the NAT hooks get never released,
resulting in a memleak.
Postpone setting nat_proto_net->nat_hook_ops when the hooks are
registered to simplify the error path to decide whether the nat hooks
need unwinding.
Fixes: 1cd472bf036c ("netfilter: nf_nat: add nat hook register functions to nf_nat")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_nat_core.c | 46 ++++++++++++++++++++++++-------------
1 file changed, 30 insertions(+), 16 deletions(-)
diff --git a/net/netfilter/nf_nat_core.c b/net/netfilter/nf_nat_core.c
index cd84f2aa08f2d..658b0f1438340 100644
--- a/net/netfilter/nf_nat_core.c
+++ b/net/netfilter/nf_nat_core.c
@@ -1236,31 +1236,45 @@ int nf_nat_register_fn(struct net *net, u8 pf, const struct nf_hook_ops *ops,
}
ret = nf_register_net_hooks(net, nat_ops, ops_count);
- if (ret < 0) {
- mutex_unlock(&nf_nat_proto_mutex);
- for (i = 0; i < ops_count; i++) {
- priv = nat_ops[i].priv;
- kfree_rcu(priv, rcu_head);
- }
- kfree_rcu(nat_ops, rcu);
- return ret;
- }
-
- nat_proto_net->nat_hook_ops = nat_ops;
+ if (ret < 0)
+ goto err_free_hooks;
+ } else {
+ nat_ops = nat_proto_net->nat_hook_ops;
}
- nat_ops = nat_proto_net->nat_hook_ops;
priv = nat_ops[hooknum].priv;
if (WARN_ON_ONCE(!priv)) {
- mutex_unlock(&nf_nat_proto_mutex);
- return -EOPNOTSUPP;
+ ret = -EOPNOTSUPP;
+ goto err_unregister_hooks;
}
ret = nf_hook_entries_insert_raw(&priv->entries, ops);
- if (ret == 0)
- nat_proto_net->users++;
+ if (ret)
+ goto err_unregister_hooks;
+
+ if (!nat_proto_net->nat_hook_ops)
+ nat_proto_net->nat_hook_ops = nat_ops;
+
+ nat_proto_net->users++;
mutex_unlock(&nf_nat_proto_mutex);
+
+ return 0;
+
+err_unregister_hooks:
+ if (nat_proto_net->nat_hook_ops) {
+ mutex_unlock(&nf_nat_proto_mutex);
+ return ret;
+ }
+ nf_unregister_net_hooks(net, nat_ops, ops_count);
+err_free_hooks:
+ mutex_unlock(&nf_nat_proto_mutex);
+ for (i = 0; i < ops_count; i++) {
+ priv = nat_ops[i].priv;
+ kfree_rcu(priv, rcu_head);
+ }
+ kfree_rcu(nat_ops, rcu);
+
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 148/438] drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (146 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 147/438] drm/xe/shrinker: Return the freed page count through a parameter Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 149/438] drm/vc4: Use managed KMS polling to fix UAF on unbind Greg Kroah-Hartman
` (301 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tejas Upadhyay, Matthew Brost,
Thomas Hellström, Shuicheng Lin, Rodrigo Vivi, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuicheng Lin <shuicheng.lin@intel.com>
[ Upstream commit 985862be16c7e4da808c51f393d631fb60c0be5c ]
__xe_shrinker_walk() walks the SYSTEM and TT LRUs without a runtime PM
reference. Shrinking a bo outside system memory invalidates its GPU
mappings, which needs the device resumed, so while it is runtime
suspended the page table zap trips an assert and the TLB invalidation
returns -ENODEV:
WARNING: drivers/gpu/drm/xe/xe_bo.c:770 at xe_bo_move_notify+0x1fc/0x450 [xe]
xe_bo_shrink+0x20f/0x2b0 [xe]
__xe_shrinker_walk+0x174/0x410 [xe]
xe_shrinker_scan+0x10c/0x1e0 [xe]
do_shrink_slab+0x176/0x7e0
drop_caches_sysctl_handler+0x9c/0xf0
Take a reference before walking a memory type other than XE_PL_SYSTEM
and stop there if it cannot be acquired. Reuse the shrinker's existing
acquire path, which resumes the device directly where reclaim allows
that and otherwise queues the PM worker for a later scan. Stop the walk
once the scan target is met, so a satisfied scan does not wake the
device. System memory is still reclaimed while the device is suspended.
Gate this on xe_device_is_l2_flush_optimized(), the same condition under
which xe_bo_trigger_rebind() issues the invalidation for a non-fault-mode
vm, so reclaim is unaffected elsewhere. The System CCS copy already has
its own reference in xe_bo_shrink().
Only a non-fault-mode vm can reach this, since a fault-mode vm requires
LR mode and that holds a runtime PM reference for the vm's lifetime.
Reproduced with igt@xe_madvise@dontneed-before-exec while the GPU is
runtime suspended.
v2: simplify needs_rpm check. (Matt)
retarget Fixes tag since the issue occurs with the non-fault-mode
path added by 4e7ebff69aed.
v3: handle this in xe_shrinker.c instead of xe_bo.c (Thomas)
v4: stop the walk once the scan target is met. (Sashiko)
v5: rebase on the freed page accounting fix. (Sashiko)
v6: reuse the shrinker acquire path so runtime pm can be resumed
directly instead of always queueing a worker. (Thomas)
v7: replace xe_pm_runtime_put() with xe_shrinker_runtime_pm_put(). (Thomas)
Fixes: 4e7ebff69aed ("drm/xe/xe3p_lpg: flush shrinker bo cachelines manually")
Assisted-by: Claude:claude-opus-5
Cc: Tejas Upadhyay <tejas.upadhyay@intel.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Reviewed-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Link: https://patch.msgid.link/20260909162102.1097006-3-shuicheng.lin@intel.com
Signed-off-by: Shuicheng Lin <shuicheng.lin@intel.com>
(cherry picked from commit 628f92b28bf4c371c10207daf6fc4caee0c0db2e)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_shrinker.c | 78 +++++++++++++++++++++-----------
1 file changed, 51 insertions(+), 27 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_shrinker.c b/drivers/gpu/drm/xe/xe_shrinker.c
index 89445cd202380..deb4378c1ec15 100644
--- a/drivers/gpu/drm/xe/xe_shrinker.c
+++ b/drivers/gpu/drm/xe/xe_shrinker.c
@@ -54,13 +54,39 @@ xe_shrinker_mod_pages(struct xe_shrinker *shrinker, long shrinkable, long purgea
write_unlock(&shrinker->lock);
}
-static int __xe_shrinker_walk(struct xe_device *xe,
+static bool __xe_shrinker_runtime_pm_get(struct xe_shrinker *shrinker)
+{
+ struct xe_device *xe = shrinker->xe;
+
+ if (xe_pm_runtime_get_if_active(xe))
+ return true;
+
+ if (xe_rpm_reclaim_safe(xe) && !ttm_bo_shrink_avoid_wait()) {
+ xe_pm_runtime_get(xe);
+ return true;
+ }
+
+ queue_work(xe->unordered_wq, &shrinker->pm_worker);
+
+ return false;
+}
+
+static void xe_shrinker_runtime_pm_put(struct xe_shrinker *shrinker, bool runtime_pm)
+{
+ if (runtime_pm)
+ xe_pm_runtime_put(shrinker->xe);
+}
+
+static int __xe_shrinker_walk(struct xe_shrinker *shrinker,
struct ttm_operation_ctx *ctx,
const struct xe_bo_shrink_flags flags,
unsigned long to_scan, unsigned long *scanned,
unsigned long *freed)
{
+ struct xe_device *xe = shrinker->xe;
unsigned int mem_type;
+ bool rpm = false;
+ int ret = 0;
s64 lret;
for (mem_type = XE_PL_SYSTEM; mem_type <= XE_PL_TT; ++mem_type) {
@@ -75,23 +101,35 @@ static int __xe_shrinker_walk(struct xe_device *xe,
if (!man || !man->use_tt)
continue;
+ if (mem_type != XE_PL_SYSTEM && !rpm &&
+ xe_device_is_l2_flush_optimized(xe)) {
+ if (!__xe_shrinker_runtime_pm_get(shrinker))
+ break;
+ rpm = true;
+ }
+
ttm_bo_lru_for_each_reserved_guarded(&curs, man, &arg, ttm_bo) {
if (!ttm_bo_shrink_suitable(ttm_bo, ctx))
continue;
lret = xe_bo_shrink(ctx, ttm_bo, flags, scanned);
- if (lret < 0)
- return lret;
+ if (lret < 0) {
+ ret = lret;
+ goto out;
+ }
*freed += lret;
if (*scanned >= to_scan)
- break;
+ goto out;
}
/* Trylocks should never error, just fail. */
xe_assert(xe, !IS_ERR(ttm_bo));
}
- return 0;
+out:
+ xe_shrinker_runtime_pm_put(shrinker, rpm);
+
+ return ret;
}
/*
@@ -100,7 +138,7 @@ static int __xe_shrinker_walk(struct xe_device *xe,
* add writeback. This avoids stalls and explicit writebacks with light or
* moderate memory pressure.
*/
-static int xe_shrinker_walk(struct xe_device *xe,
+static int xe_shrinker_walk(struct xe_shrinker *shrinker,
struct ttm_operation_ctx *ctx,
const struct xe_bo_shrink_flags flags,
unsigned long to_scan, unsigned long *scanned,
@@ -112,20 +150,21 @@ static int xe_shrinker_walk(struct xe_device *xe,
swap(no_wait_gpu, ctx->no_wait_gpu);
save_flags.writeback = false;
- ret = __xe_shrinker_walk(xe, ctx, save_flags, to_scan, scanned, freed);
+ ret = __xe_shrinker_walk(shrinker, ctx, save_flags, to_scan, scanned,
+ freed);
swap(no_wait_gpu, ctx->no_wait_gpu);
if (ret || *scanned >= to_scan)
return ret;
if (!ctx->no_wait_gpu) {
- ret = __xe_shrinker_walk(xe, ctx, save_flags, to_scan, scanned,
+ ret = __xe_shrinker_walk(shrinker, ctx, save_flags, to_scan, scanned,
freed);
if (ret || *scanned >= to_scan)
return ret;
}
if (flags.writeback)
- ret = __xe_shrinker_walk(xe, ctx, flags, to_scan, scanned,
+ ret = __xe_shrinker_walk(shrinker, ctx, flags, to_scan, scanned,
freed);
return ret;
@@ -176,22 +215,7 @@ static bool xe_shrinker_runtime_pm_get(struct xe_shrinker *shrinker, bool force,
return false;
}
- if (!xe_pm_runtime_get_if_active(xe)) {
- if (xe_rpm_reclaim_safe(xe) && !ttm_bo_shrink_avoid_wait()) {
- xe_pm_runtime_get(xe);
- return true;
- }
- queue_work(xe->unordered_wq, &shrinker->pm_worker);
- return false;
- }
-
- return true;
-}
-
-static void xe_shrinker_runtime_pm_put(struct xe_shrinker *shrinker, bool runtime_pm)
-{
- if (runtime_pm)
- xe_pm_runtime_put(shrinker->xe);
+ return __xe_shrinker_runtime_pm_get(shrinker);
}
static unsigned long xe_shrinker_scan(struct shrinker *shrink, struct shrink_control *sc)
@@ -221,7 +245,7 @@ static unsigned long xe_shrinker_scan(struct shrinker *shrink, struct shrink_con
runtime_pm = xe_shrinker_runtime_pm_get(shrinker, false, nr_to_scan, can_backup);
if (purgeable && nr_scanned < nr_to_scan)
- xe_shrinker_walk(shrinker->xe, &ctx, shrink_flags,
+ xe_shrinker_walk(shrinker, &ctx, shrink_flags,
nr_to_scan, &nr_scanned, &freed);
sc->nr_scanned = nr_scanned;
@@ -234,7 +258,7 @@ static unsigned long xe_shrinker_scan(struct shrinker *shrink, struct shrink_con
shrink_flags.purge = false;
- xe_shrinker_walk(shrinker->xe, &ctx, shrink_flags,
+ xe_shrinker_walk(shrinker, &ctx, shrink_flags,
nr_to_scan, &nr_scanned, &freed);
sc->nr_scanned = nr_scanned;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 095/398] netfilter: flowtable: hold reference on ct until flow is released
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (93 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 094/398] netfilter: nf_nat: unregister and release hooks on error Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 096/398] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations Greg Kroah-Hartman
` (307 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit e75a9fa1d44bcbd66ea02e8781bcca6ea4076e0d ]
nf_ct_put() releases the ct->ext area inmediately, the rcu typesafe
semantics also allow to refer to the wrong conntrack from the flowtable
datapath. Hold reference on ct until flow is released after rcu grace
period.
Add rcu_barrier() on module exit path, to ensure pending flow entries
are release before module goes away.
Fixes: 0ff90b6c2034 ("netfilter: nf_flow_offload: fix use-after-free and a resource leak")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_flow_table_core.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/net/netfilter/nf_flow_table_core.c b/net/netfilter/nf_flow_table_core.c
index 7a93e22d049db..2fc2e08aecfb1 100644
--- a/net/netfilter/nf_flow_table_core.c
+++ b/net/netfilter/nf_flow_table_core.c
@@ -250,6 +250,14 @@ static void flow_offload_route_release(struct flow_offload *flow)
nft_flow_dst_release(flow, FLOW_OFFLOAD_DIR_REPLY);
}
+static void flow_offload_free_rcu(struct rcu_head *rcu_head)
+{
+ struct flow_offload *flow = container_of(rcu_head, struct flow_offload, rcu_head);
+
+ nf_ct_put(flow->ct);
+ kfree(flow);
+}
+
void flow_offload_free(struct flow_offload *flow)
{
switch (flow->type) {
@@ -259,8 +267,7 @@ void flow_offload_free(struct flow_offload *flow)
default:
break;
}
- nf_ct_put(flow->ct);
- kfree_rcu(flow, rcu_head);
+ call_rcu(&flow->rcu_head, flow_offload_free_rcu);
}
EXPORT_SYMBOL_GPL(flow_offload_free);
@@ -839,6 +846,7 @@ static int __init nf_flow_table_module_init(void)
static void __exit nf_flow_table_module_exit(void)
{
+ rcu_barrier();
nf_flow_table_offload_exit();
unregister_pernet_subsys(&nf_flow_table_net_ops);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 149/438] drm/vc4: Use managed KMS polling to fix UAF on unbind
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (147 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 148/438] drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 150/438] ALSA: hda: trace PCM open only after assigning a stream Greg Kroah-Hartman
` (300 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Maíra Canal,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 073a30d75f309812ed61af134f24ffef4107b13a ]
vc4_kms_load() calls drm_kms_helper_poll_init() but the driver provides
no matching drm_kms_helper_poll_fini(). The output poll work stays
scheduled after unbind and runs on the freed drm_device:
# modprobe vc4; rmmod vc4; sleep 10
BUG: KASAN: slab-use-after-free in delayed_work_timer_fn
BUG: KASAN: slab-use-after-free in drm_client_dev_hotplug [drm]
Workqueue: events output_poll_execute [drm_kms_helper]
Allocated by task 171: __devm_drm_dev_alloc
Freed by task 262 (rmmod): drm_dev_put / component_del
Use drmm_kms_helper_poll_init() so polling is finalized with the device,
as other drivers do.
Fixes: c8b75bca92cb ("drm/vc4: Add KMS support for Raspberry Pi.")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260822143110.68594-1-kmehltretter@gmail.com
Reviewed-by: Maíra Canal <mcanal@igalia.com>
Signed-off-by: Maíra Canal <mcanal@igalia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/vc4/vc4_kms.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/vc4/vc4_kms.c b/drivers/gpu/drm/vc4/vc4_kms.c
index b17e73bce3841..82a7f2ac4c7e2 100644
--- a/drivers/gpu/drm/vc4/vc4_kms.c
+++ b/drivers/gpu/drm/vc4/vc4_kms.c
@@ -1188,7 +1188,7 @@ int vc4_kms_load(struct drm_device *dev)
drm_mode_config_reset(dev);
- drm_kms_helper_poll_init(dev);
+ drmm_kms_helper_poll_init(dev);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 096/398] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (94 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 095/398] netfilter: flowtable: hold reference on ct until flow is released Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 097/398] arm64: hibernate: clone only the linear map that exists at runtime Greg Kroah-Hartman
` (306 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shouping Wang, Robin Murphy,
Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shouping Wang <allen.wang@hj-micro.com>
[ Upstream commit 49daa3d668b69a5454b5aba0078848a479f79f1c ]
When MXP_MULTIPLE_DTM_EN is TRUE, each DTM will monitor at most
two device ports. In this case, {wp_dev_sel2, wp_dev_sel} will
only use values 2'b00 and 2'b01 per DTM.
Previously the setting allowed values beyond the supported range
per DTM, which could cause each DTM to select invalid ports when
MXP_MULTIPLE_DTM_EN is TRUE.
Fix this by only setting CMN_DTM_WPn_CONFIG_WP_DEV_SEL2 when
!multi_dtm.
Fixes: 60d1504070c2 ("perf/arm-cmn: Support new IP features")
Signed-off-by: Shouping Wang <allen.wang@hj-micro.com>
Reviewed-by: Robin Murphy <robin.murphy@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/perf/arm-cmn.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/perf/arm-cmn.c b/drivers/perf/arm-cmn.c
index 8924f482806ba..527a953bf4744 100644
--- a/drivers/perf/arm-cmn.c
+++ b/drivers/perf/arm-cmn.c
@@ -1393,13 +1393,14 @@ static void arm_cmn_claim_wp_idx(struct arm_cmn_dtm *dtm,
static u32 arm_cmn_wp_config(struct perf_event *event, int wp_idx)
{
+ struct arm_cmn *cmn = to_cmn(event->pmu);
u32 config;
u32 dev = CMN_EVENT_WP_DEV_SEL(event);
u32 chn = CMN_EVENT_WP_CHN_SEL(event);
u32 grp = CMN_EVENT_WP_GRP(event);
u32 exc = CMN_EVENT_WP_EXCLUSIVE(event);
u32 combine = CMN_EVENT_WP_COMBINE(event);
- bool is_cmn600 = to_cmn(event->pmu)->part == PART_CMN600;
+ bool is_cmn600 = cmn->part == PART_CMN600;
/* CMN-600 supports only primary and secondary matching groups */
if (is_cmn600)
@@ -1407,8 +1408,11 @@ static u32 arm_cmn_wp_config(struct perf_event *event, int wp_idx)
config = FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL, dev) |
FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_CHN_SEL, chn) |
- FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_GRP, grp) |
- FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL2, dev >> 1);
+ FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_GRP, grp);
+
+ if (!cmn->multi_dtm)
+ config |= FIELD_PREP(CMN_DTM_WPn_CONFIG_WP_DEV_SEL2, dev >> 1);
+
if (exc)
config |= is_cmn600 ? CMN600_WPn_CONFIG_WP_EXCLUSIVE :
CMN_DTM_WPn_CONFIG_WP_EXCLUSIVE;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 150/438] ALSA: hda: trace PCM open only after assigning a stream
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (148 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 149/438] drm/vc4: Use managed KMS polling to fix UAF on unbind Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 151/438] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() Greg Kroah-Hartman
` (299 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Slavin Liu, Takashi Iwai,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Slavin Liu <bolin.liu@seu.edu.cn>
[ Upstream commit c9e6e5f38bf75276605f1952b22285f5f3abcaff ]
Stream assignment can fail when hardware streams are exhausted.
Move the tracepoint after the NULL check because its payload accesses
the assigned stream tag.
Detected by static analysis and reviewed with AI-assisted source auditing.
Fixes: 184865085b88 ("ALSA: hda - rename hda_intel_trace.h to hda_controller_trace.h")
Assisted-by: LLM
Signed-off-by: Slavin Liu <bolin.liu@seu.edu.cn>
Link: https://patch.msgid.link/20260913125154.109944-1-bolin.liu@seu.edu.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/hda/common/controller.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/hda/common/controller.c b/sound/hda/common/controller.c
index afec5c5546ec7..18dae022b324f 100644
--- a/sound/hda/common/controller.c
+++ b/sound/hda/common/controller.c
@@ -586,11 +586,11 @@ static int azx_pcm_open(struct snd_pcm_substream *substream)
snd_hda_codec_pcm_get(apcm->info);
mutex_lock(&chip->open_mutex);
azx_dev = azx_assign_device(chip, substream);
- trace_azx_pcm_open(chip, azx_dev);
if (azx_dev == NULL) {
err = -EBUSY;
goto unlock;
}
+ trace_azx_pcm_open(chip, azx_dev);
runtime->private_data = azx_dev;
runtime->hw = azx_pcm_hw;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 097/398] arm64: hibernate: clone only the linear map that exists at runtime
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (95 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 096/398] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 098/398] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr Greg Kroah-Hartman
` (305 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Breno Leitao, Ard Biesheuvel,
Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Breno Leitao <leitao@debian.org>
[ Upstream commit e4a6f57d22e079e23fafac51057fad534160b269 ]
This is similar to commit 1537e55728ec2 ("arm64: trans_pgd: clone only
the linear map that exists at runtime"), but in a different place.
swsusp_arch_resume() clones the kernel linear map with
trans_pgd_create_copy(..., PAGE_OFFSET, PAGE_END). PAGE_OFFSET comes
from the compile-time VA_BITS, so a CONFIG_ARM64_VA_BITS_52 kernel
booting on hardware without LPA2 -- vabits_actual is 48 and the fifth
level is folded -- hands the walk a 3.9PB window while its linear map
only spans the top 128TB.
On a VA_BITS_52 4k kernel with CONFIG_KASAN_GENERIC in a 4GB VM, I see:
swapper/0: page allocation failure: order:0, mode:0x920(GFP_ATOMIC|__GFP_ZERO)
hibernate_page_alloc+0x10/0x1c
swsusp_arch_resume+0x70/0x320
hibernation_restore+0xa4/0x138
software_resume+0x15c/0x270
PM: hibernation: Failed to load image, recovering.
PM: hibernation: resume failed (-12)
Fix it by copying the linear map that is the actual one, not the
compiled one.
Fixes: a6bbf5d4d9d1 ("arm64: mm: Add definitions to support 5 levels of paging")
Signed-off-by: Breno Leitao <leitao@debian.org>
Reviewed-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kernel/hibernate.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c
index 7bf1174277772..424291c547f02 100644
--- a/arch/arm64/kernel/hibernate.c
+++ b/arch/arm64/kernel/hibernate.c
@@ -423,8 +423,8 @@ int __nocfi swsusp_arch_resume(void)
* Create a second copy of just the linear map, and use this when
* restoring.
*/
- rc = trans_pgd_create_copy(&trans_info, &tmp_pg_dir, PAGE_OFFSET,
- PAGE_END);
+ rc = trans_pgd_create_copy(&trans_info, &tmp_pg_dir,
+ _PAGE_OFFSET(vabits_actual), PAGE_END);
if (rc)
return rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 151/438] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (149 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 150/438] ALSA: hda: trace PCM open only after assigning a stream Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 152/438] btrfs: tree-checker: print dev extent offset in error message Greg Kroah-Hartman
` (298 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolas Escande,
Rameshkumar Sundaram, Baochen Qiang, Jeff Johnson, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Escande <nico.escande@gmail.com>
[ Upstream commit 820b8cff81c796ba20573e04722ab62500713f97 ]
When mac80211 removes a sta, it calls .sta_state() which in turn calls
ath11k_mac_station_remove(). In that function we clean up both peers &
arsta related resources.
But when the firmware crashes, ath11k calls ieee80211_restart_hw(), which
assumes that all driver related resources are cleaned up beforehand. This
cleanup is supposedly done by ath11k_mac_peer_cleanup_all() but does not
in fact free arsta->rx_stats / tx_stats.
Extract the arsta cleanup from ath11k_mac_station_remove() into a
new ath11k_mac_station_cleanup() and call it from both there and
ath11k_mac_peer_cleanup_all().
This should handle kmemleaks reports like:
unreferenced object 0xffffff801ae66400 (size 1024):
comm "hostapd", pid 1306, jiffies 4295011565
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace (crc d61c08ec):
kmemleak_alloc+0x3c/0x50
__kmalloc_cache_noprof+0x2b0/0x3e0
ath11k_mac_op_sta_state+0x1dc/0xb10
drv_sta_state+0xac/0x6f8
sta_info_insert_rcu+0x314/0x5e0
sta_info_insert+0x14/0x38
ieee80211_add_station+0x10c/0x1a0
nl80211_new_station+0x3e8/0x680
genl_family_rcv_msg_doit+0xc0/0x120
genl_rcv_msg+0x1b4/0x258
netlink_rcv_skb+0x4c/0x108
genl_rcv+0x38/0x60
netlink_unicast+0x190/0x278
netlink_sendmsg+0x15c/0x370
____sys_sendmsg+0x120/0x290
___sys_sendmsg+0x70/0xa0
Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.9.0.1-01977-QCAHKSWPL_SILICONZ-1
Fixes: d5c65159f289 ("ath11k: driver for Qualcomm IEEE 802.11ax devices")
Signed-off-by: Nicolas Escande <nico.escande@gmail.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260731145830.769811-1-nico.escande@gmail.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath11k/mac.c | 25 ++++++++++++++++++-------
1 file changed, 18 insertions(+), 7 deletions(-)
diff --git a/drivers/net/wireless/ath/ath11k/mac.c b/drivers/net/wireless/ath/ath11k/mac.c
index 2d55cdc4d165d..ae91b57c8422f 100644
--- a/drivers/net/wireless/ath/ath11k/mac.c
+++ b/drivers/net/wireless/ath/ath11k/mac.c
@@ -873,6 +873,22 @@ static int ath11k_mac_set_kickout(struct ath11k_vif *arvif)
return 0;
}
+static void ath11k_mac_station_cleanup(struct ieee80211_sta *sta)
+{
+ struct ath11k_sta *arsta;
+
+ if (!sta)
+ return;
+
+ arsta = ath11k_sta_to_arsta(sta);
+
+ kfree(arsta->tx_stats);
+ arsta->tx_stats = NULL;
+
+ kfree(arsta->rx_stats);
+ arsta->rx_stats = NULL;
+}
+
void ath11k_mac_peer_cleanup_all(struct ath11k *ar)
{
struct ath11k_peer *peer, *tmp;
@@ -885,6 +901,7 @@ void ath11k_mac_peer_cleanup_all(struct ath11k *ar)
list_for_each_entry_safe(peer, tmp, &ab->peers, list) {
ath11k_peer_rx_tid_cleanup(ar, peer);
ath11k_peer_rhash_delete(ab, peer);
+ ath11k_mac_station_cleanup(peer->sta);
list_del(&peer->list);
kfree(peer);
}
@@ -9892,7 +9909,6 @@ static int ath11k_mac_station_remove(struct ath11k *ar,
{
struct ath11k_base *ab = ar->ab;
struct ath11k_vif *arvif = ath11k_vif_to_arvif(vif);
- struct ath11k_sta *arsta = ath11k_sta_to_arsta(sta);
int ret;
if (ab->hw_params.vdev_start_delay &&
@@ -9916,12 +9932,7 @@ static int ath11k_mac_station_remove(struct ath11k *ar,
sta->addr, arvif->vdev_id);
ath11k_mac_dec_num_stations(arvif, sta);
-
- kfree(arsta->tx_stats);
- arsta->tx_stats = NULL;
-
- kfree(arsta->rx_stats);
- arsta->rx_stats = NULL;
+ ath11k_mac_station_cleanup(sta);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 098/398] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (96 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 097/398] arm64: hibernate: clone only the linear map that exists at runtime Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 099/398] keys: fix lost wakeup when reaping a dead key type Greg Kroah-Hartman
` (304 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Thadeu Lima de Souza Cascardo, Melissa Wen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
[ Upstream commit 9eb1a393c89a79c4210230d23e7d88d239c61d7b ]
When an out_fence_ptr is provided but DRM_MODE_PAGE_FLIP_EVENT is not
set, a drm_pending_vblank_event will be allocated. If later, there is an
allocation failure or another failure at setup_out_fence(), that event
will not have base.fence set and it will not be released at
complete_signaling().
Release the event and set crtc_state->event to NULL just like in the
DRM_MODE_PAGE_FLIP_EVENT case when there is a failure at
drm_event_reserve_init(). That is, prepare_signaling() releases the
event and there is nothing to be done at complete_signaling(). Use
drm_event_cancel_free() as that will also undo drm_event_reserve_init()
in case it has been called.
Reported-by: sashiko-bot@kernel.org
Closes: https://sashiko.dev/#/patchset/20260727-drm_crtc_atomic_commit_leak-v1-1-23d9948a9d7c@igalia.com?part=1
Fixes: 92c715fca907 ("drm/atomic: Fix double free in drm_atomic_state_default_clear")
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Reviewed-by: Melissa Wen <mwen@igalia.com>
Signed-off-by: Melissa Wen <mwen@igalia.com>
Link: https://patch.msgid.link/20260826-drm_pending_vblank_event_leak-v4-1-f8de8b996b9d@igalia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/drm_atomic_uapi.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/drm_atomic_uapi.c b/drivers/gpu/drm/drm_atomic_uapi.c
index 1a11eebfbab06..4fc5f95731842 100644
--- a/drivers/gpu/drm/drm_atomic_uapi.c
+++ b/drivers/gpu/drm/drm_atomic_uapi.c
@@ -1244,10 +1244,12 @@ static int prepare_signaling(struct drm_device *dev,
struct dma_fence *fence;
struct drm_out_fence_state *f;
+ ret = -ENOMEM;
+
f = krealloc(*fence_state, sizeof(**fence_state) *
(*num_fences + 1), GFP_KERNEL);
if (!f)
- return -ENOMEM;
+ goto err_free_event;
memset(&f[*num_fences], 0, sizeof(*f));
@@ -1256,12 +1258,12 @@ static int prepare_signaling(struct drm_device *dev,
fence = drm_crtc_create_fence(crtc);
if (!fence)
- return -ENOMEM;
+ goto err_free_event;
ret = setup_out_fence(&f[(*num_fences)++], fence);
if (ret) {
dma_fence_put(fence);
- return ret;
+ goto err_free_event;
}
crtc_state->event->base.fence = fence;
@@ -1317,6 +1319,11 @@ static int prepare_signaling(struct drm_device *dev,
}
return 0;
+
+err_free_event:
+ drm_event_cancel_free(dev, &crtc_state->event->base);
+ crtc_state->event = NULL;
+ return ret;
}
static void complete_signaling(struct drm_device *dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 152/438] btrfs: tree-checker: print dev extent offset in error message
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (150 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 151/438] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 153/438] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL Greg Kroah-Hartman
` (297 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Filipe Manana,
David Sterba, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit a1167d9420474ab9ed9efca99d86aeb6217c0265 ]
If a dev extent's offset is not sector size aligned, the error message is
printing the dev extent's objectid instead of the offset. This is a copy
paste error, as before this check we check the objectid field.
Fixes: 008e2512dc56 ("btrfs: tree-checker: add dev extent item checks")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/tree-checker.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/btrfs/tree-checker.c b/fs/btrfs/tree-checker.c
index 0ce91396b517f..1326bbc1322dc 100644
--- a/fs/btrfs/tree-checker.c
+++ b/fs/btrfs/tree-checker.c
@@ -2100,7 +2100,7 @@ static int check_dev_extent_item(const struct extent_buffer *leaf,
sectorsize))) {
generic_err(leaf, slot,
"invalid dev extent chunk offset, has %llu not aligned to %u",
- btrfs_dev_extent_chunk_objectid(leaf, de),
+ btrfs_dev_extent_chunk_offset(leaf, de),
sectorsize);
return -EUCLEAN;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 099/398] keys: fix lost wakeup when reaping a dead key type
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (97 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 098/398] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 100/398] neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS Greg Kroah-Hartman
` (303 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Jarkko Sakkinen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 2725ab3f5ad1c5f375c7c9fee4af02a9b138f701 ]
clear_bit() is atomic with respect to the word it modifies, but it is
an unordered operation: it implies no memory barrier on either side
(Documentation/atomic_bitops.txt).
key_garbage_collector() clears KEY_GC_REAPING_KEYTYPE with clear_bit()
and calls wake_up_bit() after reaping a dead key type. wake_up_bit()
uses a lockless waitqueue check and requires a full barrier after the
clear.
The existing smp_mb() is before clear_bit(), so nothing orders the clear
against that check. The GC can see an empty waitqueue while
unregister_key_type() still sees the bit set. The final wakeup is then
lost, leaving module unload stuck in wait_on_bit().
Use clear_and_wake_up_bit(). Its clear_bit_unlock() has RELEASE
semantics, so the completed GC work stays ordered before the clear, and
its smp_mb__after_atomic() orders the clear before the waitqueue check.
Fixes: 0c061b5707ab ("KEYS: Correctly destroy key payloads when their keytype is removed")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://lore.kernel.org/r/20260821025327.61488-1-kmehltretter@gmail.com
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/keys/gc.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/security/keys/gc.c b/security/keys/gc.c
index 748e83818a760..eda445f815d47 100644
--- a/security/keys/gc.c
+++ b/security/keys/gc.c
@@ -318,9 +318,7 @@ static void key_garbage_collector(struct work_struct *work)
if (unlikely(gc_state & KEY_GC_REAPING_DEAD_3)) {
kdebug("dead wake");
- smp_mb();
- clear_bit(KEY_GC_REAPING_KEYTYPE, &key_gc_flags);
- wake_up_bit(&key_gc_flags, KEY_GC_REAPING_KEYTYPE);
+ clear_and_wake_up_bit(KEY_GC_REAPING_KEYTYPE, &key_gc_flags);
}
if (gc_state & KEY_GC_REAP_AGAIN)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 153/438] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (151 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 152/438] btrfs: tree-checker: print dev extent offset in error message Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 154/438] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Greg Kroah-Hartman
` (296 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abel Vesa, Krzysztof Kozlowski,
Dmitry Baryshkov, Konrad Dybcio, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 2028280686f4fa78e2f1f6dede4b6c1fd782b9e3 ]
DSI 6G v2.9 hosts (SM8650, SM8750, Kaanapali, etc.) reparent the byte and
pixel RCGs to the DSI PHY PLL at runtime from
dsi_link_clk_set_rate_6g_v2_9(), after the PHY has been enabled. However
dsi_calc_clk_rate_6g() runs earlier, in order to compute the bit clock
request for the PHY. At that point the byte RCG still has its reset
parent (XO), so clk_round_rate() returns a bogus rate, which then ends up
in the PHY bit clock request and the PLL gets programmed to a wrong
frequency, breaking the panel.
Move the rounding to dsi_link_clk_set_rate_6g(), which is called after
the RCGs have been reparented to the PLL. Storing the rounded rate at
this point still makes later link_clk_set_rate() calls no-ops in the
CCF. Derive the byte interface clock rate from the rounded byte clock
rate, otherwise it would keep requesting the idealized rate and
retrigger the PLL on every transfer.
Reported-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reported-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Fixes: 6cd33b6f4155 ("drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value")
Assisted-by: LLM
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Tested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com> # SM6115P J606F
Tested-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/750496/
Link: https://lore.kernel.org/r/20260903-fix-eliza-dsi-v1-1-3474a6c9f2e0@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dsi/dsi_host.c | 36 ++++++++++++++++--------------
1 file changed, 19 insertions(+), 17 deletions(-)
diff --git a/drivers/gpu/drm/msm/dsi/dsi_host.c b/drivers/gpu/drm/msm/dsi/dsi_host.c
index 2685cc3d03590..89face2670187 100644
--- a/drivers/gpu/drm/msm/dsi/dsi_host.c
+++ b/drivers/gpu/drm/msm/dsi/dsi_host.c
@@ -129,7 +129,7 @@ struct msm_dsi_host {
struct clk *dsi_pll_pixel_clk;
unsigned long byte_clk_rate;
- unsigned long byte_intf_clk_rate;
+ bool byte_intf_clk_div_2;
unsigned long pixel_clk_rate;
unsigned long esc_clk_rate;
@@ -381,8 +381,20 @@ int msm_dsi_runtime_resume(struct device *dev)
int dsi_link_clk_set_rate_6g(struct msm_dsi_host *msm_host)
{
+ unsigned long byte_intf_clk_rate;
+ long rounded_byte_clk_rate;
int ret;
+ rounded_byte_clk_rate = clk_round_rate(msm_host->byte_clk,
+ msm_host->byte_clk_rate);
+ if (rounded_byte_clk_rate < 0) {
+ pr_err("%s: failed to round byte clock rate, %ld\n",
+ __func__, rounded_byte_clk_rate);
+ return rounded_byte_clk_rate;
+ }
+
+ msm_host->byte_clk_rate = rounded_byte_clk_rate;
+
DBG("Set clk rates: pclk=%lu, byteclk=%lu",
msm_host->pixel_clk_rate, msm_host->byte_clk_rate);
@@ -400,7 +412,11 @@ int dsi_link_clk_set_rate_6g(struct msm_dsi_host *msm_host)
}
if (msm_host->byte_intf_clk) {
- ret = clk_set_rate(msm_host->byte_intf_clk, msm_host->byte_intf_clk_rate);
+ byte_intf_clk_rate = msm_host->byte_clk_rate;
+ if (msm_host->byte_intf_clk_div_2)
+ byte_intf_clk_rate /= 2;
+
+ ret = clk_set_rate(msm_host->byte_intf_clk, byte_intf_clk_rate);
if (ret) {
pr_err("%s: Failed to set rate byte intf clk, %d\n",
__func__, ret);
@@ -668,24 +684,12 @@ static void dsi_calc_pclk(struct msm_dsi_host *msm_host, bool is_bonded_dsi)
int dsi_calc_clk_rate_6g(struct msm_dsi_host *msm_host, bool is_bonded_dsi)
{
- long rounded_byte_clk_rate;
-
if (!msm_host->mode) {
pr_err("%s: mode not set\n", __func__);
return -EINVAL;
}
dsi_calc_pclk(msm_host, is_bonded_dsi);
-
- rounded_byte_clk_rate = clk_round_rate(msm_host->byte_clk,
- msm_host->byte_clk_rate);
- if (rounded_byte_clk_rate < 0) {
- pr_err("%s: failed to round byte clock rate, %ld\n",
- __func__, rounded_byte_clk_rate);
- return rounded_byte_clk_rate;
- }
-
- msm_host->byte_clk_rate = rounded_byte_clk_rate;
msm_host->esc_clk_rate = clk_get_rate(msm_host->esc_clk);
return 0;
}
@@ -2500,9 +2504,7 @@ int msm_dsi_host_power_on(struct mipi_dsi_host *host,
goto unlock_ret;
}
- msm_host->byte_intf_clk_rate = msm_host->byte_clk_rate;
- if (phy_shared_timings->byte_intf_clk_div_2)
- msm_host->byte_intf_clk_rate /= 2;
+ msm_host->byte_intf_clk_div_2 = phy_shared_timings->byte_intf_clk_div_2;
msm_dsi_sfpb_config(msm_host, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 100/398] neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (98 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 099/398] keys: fix lost wakeup when reaping a dead key type Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 101/398] neighbour: Convert RTM_GETNEIGHTBL to RCU Greg Kroah-Hartman
` (302 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 6d79b223ec44ada58ad37db42f539b60985a7722 ]
NDTPA_INTERVAL_PROBE_TIME_MS sets .type and .min but misses
.validation_type, so no validation is applied:
# ynl --family rt-neigh --do setneightbl \
--json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 0}}'
# ynl --family rt-neigh --dump getneightbl --output-json | \
jq '.[] | select(.name == "arp_cache" and has("config"))
| .parms["interval-probe-time-ms"]'
0
Moreover, nla_get_msecs() uses msecs_to_jiffies(), and u64 is
silently cast to u32, so a larger value can bypass the min check:
e.g. 4294967296 == 0x100000000
# ynl --family rt-neigh --do setneightbl \
--json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 4294967296}}'
# ynl --family rt-neigh --dump getneightbl --output-json | \
jq '.[] | select(.name == "arp_cache" and has("config"))
| .parms["interval-probe-time-ms"]'
0
msecs_to_jiffies() returns MAX_JIFFY_OFFSET if the value is
larger than INT_MAX. Also, INT_MAX ms overflows int NEIGH_VAR()
when HZ > 1000 (Alpha, MIPS), and passing a negative integer to
queue_delayed_work(unsigned long delay) causes sign extension,
which wraps around the expiry time to the past, resulting in it
being handled as 0 delay in the timer wheel.
Let's use NLA_POLICY_FULL_RANGE() and limit the max to 1 day.
The same max check is applied to sysctl as well.
Note that this controls the probe interval for NTF_MANAGED
entries, so the max of 1 day is unlikely to break any
deployments.
Fixes: 211da42eaa45 ("net, neigh: introduce interval_probe_time_ms for periodic probe")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260909233143.2401847-3-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/netlink/specs/rt-neigh.yaml | 3 +++
Documentation/networking/ip-sysctl.rst | 2 +-
net/core/neighbour.c | 17 +++++++++++++----
3 files changed, 17 insertions(+), 5 deletions(-)
diff --git a/Documentation/netlink/specs/rt-neigh.yaml b/Documentation/netlink/specs/rt-neigh.yaml
index 2f568a6231c93..e366e958234e4 100644
--- a/Documentation/netlink/specs/rt-neigh.yaml
+++ b/Documentation/netlink/specs/rt-neigh.yaml
@@ -341,6 +341,9 @@ attribute-sets:
-
name: interval-probe-time-ms
type: u64
+ checks:
+ min: 1
+ max: 86400000
operations:
enum-model: directional
diff --git a/Documentation/networking/ip-sysctl.rst b/Documentation/networking/ip-sysctl.rst
index 7a637e87005fe..e13131770fa0c 100644
--- a/Documentation/networking/ip-sysctl.rst
+++ b/Documentation/networking/ip-sysctl.rst
@@ -230,7 +230,7 @@ neigh/default/unres_qlen - INTEGER
neigh/default/interval_probe_time_ms - INTEGER
The probe interval for neighbor entries with NTF_MANAGED flag,
- the min value is 1.
+ the min value is 1, and the max value is 86400000 (1 day).
Default: 5000
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index dabd368eaa4e7..4c018170edfeb 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2353,6 +2353,13 @@ static const struct nla_policy nl_neightbl_policy[NDTA_MAX+1] = {
[NDTA_PARMS] = { .type = NLA_NESTED },
};
+#define NTBL_PARM_MS_MAX (24 * 60 * 60 * MSEC_PER_SEC)
+
+static const struct netlink_range_validation nl_ntbl_parm_ms_range = {
+ .min = 1,
+ .max = NTBL_PARM_MS_MAX,
+};
+
static const struct nla_policy nl_ntbl_parm_policy[NDTPA_MAX+1] = {
[NDTPA_IFINDEX] = { .type = NLA_U32 },
[NDTPA_QUEUE_LEN] = { .type = NLA_U32 },
@@ -2369,7 +2376,8 @@ static const struct nla_policy nl_ntbl_parm_policy[NDTPA_MAX+1] = {
[NDTPA_ANYCAST_DELAY] = { .type = NLA_U64 },
[NDTPA_PROXY_DELAY] = { .type = NLA_U64 },
[NDTPA_LOCKTIME] = { .type = NLA_U64 },
- [NDTPA_INTERVAL_PROBE_TIME_MS] = { .type = NLA_U64, .min = 1 },
+ [NDTPA_INTERVAL_PROBE_TIME_MS] = NLA_POLICY_FULL_RANGE(NLA_U64,
+ &nl_ntbl_parm_ms_range),
};
static int neightbl_set(struct sk_buff *skb, struct nlmsghdr *nlh,
@@ -3641,12 +3649,13 @@ static int neigh_proc_dointvec_ms_jiffies_positive(const struct ctl_table *ctl,
void *buffer, size_t *lenp, loff_t *ppos)
{
struct ctl_table tmp = *ctl;
- int ret;
+ int ret, min, max;
- int min = msecs_to_jiffies(1);
+ min = msecs_to_jiffies(1);
+ max = msecs_to_jiffies(NTBL_PARM_MS_MAX);
tmp.extra1 = &min;
- tmp.extra2 = NULL;
+ tmp.extra2 = &max;
ret = proc_dointvec_ms_jiffies_minmax(&tmp, write, buffer, lenp, ppos);
neigh_proc_update(ctl, write);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 154/438] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (152 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 153/438] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 155/438] net: dsa: mxl862xx: disable the stats poll on teardown Greg Kroah-Hartman
` (295 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrea Mayer, David Ahern,
Hangbin Liu, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrea Mayer <andrea.mayer@uniroma2.it>
[ Upstream commit 7616242a2b37883f7322aaa1d2bd6cd0fed28315 ]
When an SRv6 packet arrives on an interface enslaved to a VRF,
vrf_ip6_rcv() sets IP6SKB_L3SLAVE in IP6CB, but decap_and_validate()
has never set IPSKB_L3SLAVE in IPCB. The bit stayed clear in the
common case, and with CONFIG_IPV6_MIP6 the leftover frag_max_size of
a reassembled outer packet could even set it, with no VRF involved.
Commit 44930446dde4 ("ipv6: seg6: clear IPv4 control block on IPIP
decapsulation") then made the unreliable bit reliably clear.
The effect of the missing flag is visible with End.DX4 when a
delivery to a local address of the node reaches the socket lookup.
For example, a UDP socket bound to the enslaved ingress interface
does not receive any of the decapsulated packets, while an unbound
socket outside the VRF does.
This contradicts Documentation/networking/vrf.rst: by default the
scope of an unbound UDP or TCP socket is limited to the default VRF.
Set IPSKB_L3SLAVE for IPv4 in decap_and_validate(), which already does
the same for IPv6. The socket lookup then matches the decapsulated
packet like any other packet received on that enslaved interface. Such
a packet matches an unbound UDP or TCP socket only when
udp_l3mdev_accept or tcp_l3mdev_accept is set.
Fixes: 891ef8dd2a8d ("ipv6: sr: implement additional seg6local actions")
Signed-off-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Reviewed-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260913194421.31-1-andrea.mayer@uniroma2.it
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/seg6_local.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/ipv6/seg6_local.c b/net/ipv6/seg6_local.c
index 7b52122201858..d1070aec7b72b 100644
--- a/net/ipv6/seg6_local.c
+++ b/net/ipv6/seg6_local.c
@@ -257,10 +257,13 @@ static bool decap_and_validate(struct sk_buff *skb, int proto)
return false;
if (proto == IPPROTO_IPIP) {
+ bool l3slave = ipv6_l3mdev_skb(IP6CB(skb)->flags);
int iif = IP6CB(skb)->iif;
memset(IPCB(skb), 0, sizeof(*IPCB(skb)));
IPCB(skb)->iif = iif;
+ if (l3slave)
+ IPCB(skb)->flags |= IPSKB_L3SLAVE;
} else if (proto == IPPROTO_IPV6) {
bool l3slave = ipv6_l3mdev_skb(IP6CB(skb)->flags);
int iif = IP6CB(skb)->iif;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 101/398] neighbour: Convert RTM_GETNEIGHTBL to RCU.
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (99 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 100/398] neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 102/398] neighbour: Add missing RCU annotation for neightbl_dump_info() Greg Kroah-Hartman
` (301 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Eric Dumazet,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 4ae34be500649ec452ac1fc2748958683ad9b55d ]
neightbl_dump_info() calls these functions for each neigh_tables[]
entry:
1. neightbl_fill_info() for tbl->parms
2. neightbl_fill_param_info() for tbl->parms_list (except tbl->parms)
Both functions rely on the table lock (read_lock_bh(&tbl->lock))
and RTNL is not needed.
Let's fetch the table under RCU and convert RTM_GETNEIGHTBL to RCU.
Note that the first entry of tbl->parms_list is tbl->parms.list and
embedded in neigh_table, so list_next_entry() is safe.
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20251022054004.2514876-4-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 979aabdad8dd ("neighbour: Skip default parms when resumed in neightbl_dump_info().")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 23 +++++++++--------------
1 file changed, 9 insertions(+), 14 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 4c018170edfeb..9873fc08b7494 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2180,7 +2180,7 @@ static int neightbl_fill_parms(struct sk_buff *skb, struct neigh_parms *parms)
return -ENOBUFS;
if ((parms->dev &&
- nla_put_u32(skb, NDTPA_IFINDEX, parms->dev->ifindex)) ||
+ nla_put_u32(skb, NDTPA_IFINDEX, READ_ONCE(parms->dev->ifindex))) ||
nla_put_u32(skb, NDTPA_REFCNT, refcount_read(&parms->refcnt)) ||
nla_put_u32(skb, NDTPA_QUEUE_LENBYTES,
NEIGH_VAR(parms, QUEUE_LEN_BYTES)) ||
@@ -2232,8 +2232,6 @@ static int neightbl_fill_info(struct sk_buff *skb, struct neigh_table *tbl,
return -EMSGSIZE;
ndtmsg = nlmsg_data(nlh);
-
- read_lock_bh(&tbl->lock);
ndtmsg->ndtm_family = tbl->family;
ndtmsg->ndtm_pad1 = 0;
ndtmsg->ndtm_pad2 = 0;
@@ -2259,11 +2257,9 @@ static int neightbl_fill_info(struct sk_buff *skb, struct neigh_table *tbl,
.ndtc_proxy_qlen = READ_ONCE(tbl->proxy_queue.qlen),
};
- rcu_read_lock();
nht = rcu_dereference(tbl->nht);
ndc.ndtc_hash_rnd = nht->hash_rnd[0];
ndc.ndtc_hash_mask = ((1 << nht->hash_shift) - 1);
- rcu_read_unlock();
if (nla_put(skb, NDTA_CONFIG, sizeof(ndc), &ndc))
goto nla_put_failure;
@@ -2301,12 +2297,10 @@ static int neightbl_fill_info(struct sk_buff *skb, struct neigh_table *tbl,
if (neightbl_fill_parms(skb, &tbl->parms) < 0)
goto nla_put_failure;
- read_unlock_bh(&tbl->lock);
nlmsg_end(skb, nlh);
return 0;
nla_put_failure:
- read_unlock_bh(&tbl->lock);
nlmsg_cancel(skb, nlh);
return -EMSGSIZE;
}
@@ -2325,8 +2319,6 @@ static int neightbl_fill_param_info(struct sk_buff *skb,
return -EMSGSIZE;
ndtmsg = nlmsg_data(nlh);
-
- read_lock_bh(&tbl->lock);
ndtmsg->ndtm_family = tbl->family;
ndtmsg->ndtm_pad1 = 0;
ndtmsg->ndtm_pad2 = 0;
@@ -2335,11 +2327,9 @@ static int neightbl_fill_param_info(struct sk_buff *skb,
neightbl_fill_parms(skb, parms) < 0)
goto errout;
- read_unlock_bh(&tbl->lock);
nlmsg_end(skb, nlh);
return 0;
errout:
- read_unlock_bh(&tbl->lock);
nlmsg_cancel(skb, nlh);
return -EMSGSIZE;
}
@@ -2588,10 +2578,12 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
family = ((struct rtgenmsg *)nlmsg_data(nlh))->rtgen_family;
+ rcu_read_lock();
+
for (tidx = 0; tidx < NEIGH_NR_TABLES; tidx++) {
struct neigh_parms *p;
- tbl = rcu_dereference_rtnl(neigh_tables[tidx]);
+ tbl = rcu_dereference(neigh_tables[tidx]);
if (!tbl)
continue;
@@ -2605,7 +2597,7 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
nidx = 0;
p = list_next_entry(&tbl->parms, list);
- list_for_each_entry_from(p, &tbl->parms_list, list) {
+ list_for_each_entry_from_rcu(p, &tbl->parms_list, list) {
if (!net_eq(neigh_parms_net(p), net))
continue;
@@ -2625,6 +2617,8 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
neigh_skip = 0;
}
out:
+ rcu_read_unlock();
+
cb->args[0] = tidx;
cb->args[1] = nidx;
@@ -3928,7 +3922,8 @@ static const struct rtnl_msg_handler neigh_rtnl_msg_handlers[] __initconst = {
{.msgtype = RTM_DELNEIGH, .doit = neigh_delete},
{.msgtype = RTM_GETNEIGH, .doit = neigh_get, .dumpit = neigh_dump_info,
.flags = RTNL_FLAG_DOIT_UNLOCKED | RTNL_FLAG_DUMP_UNLOCKED},
- {.msgtype = RTM_GETNEIGHTBL, .dumpit = neightbl_dump_info},
+ {.msgtype = RTM_GETNEIGHTBL, .dumpit = neightbl_dump_info,
+ .flags = RTNL_FLAG_DUMP_UNLOCKED},
{.msgtype = RTM_SETNEIGHTBL, .doit = neightbl_set},
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 155/438] net: dsa: mxl862xx: disable the stats poll on teardown
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (153 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 154/438] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 156/438] net: bcmgenet: restore the hardware filters on open Greg Kroah-Hartman
` (294 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Golle, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Golle <daniel@makrotopia.org>
[ Upstream commit 9e92ad4630f5dd1838ce6bbe6b1bd2c73d34de36 ]
mxl862xx_setup() arms the stats poll before mxl862xx_setup_mdio(), and
nothing stops it until dsa_register_switch() has returned an error to
mxl862xx_probe(). DSA frees the dsa_port list before it returns, so a
poll that fires once .setup or a later step of dsa_tree_setup() has
failed walks freed ports. On shutdown the user ports stay registered,
and the WORK_STOPPED flag test in mxl862xx_get_stats64() is not atomic
with the cancel in mxl862xx_shutdown(), so a re-arm that read the flag
before it was set queues the poll after cancel_delayed_work_sync() has
returned.
Arm the poll once .setup has succeeded and stop it from a .teardown op,
which DSA calls on unregister and after a failed registration, in both
cases before it frees the ports. Use disable_delayed_work_sync() there
and in shutdown(): it drains a running poll as the cancel did and turns
every later attempt to queue the work into a no-op, so the re-arm
cannot bring the poll back. remove() and the probe error path only set
WORK_STOPPED, which crc_err_work tests before it walks the ports.
Fixes: a21d33a5265f ("net: dsa: mxl862xx: implement .get_stats64")
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Link: https://patch.msgid.link/1eb6f7fc1789b67e4b11e3f4d5ff080d0b6f7cbb.1789045590.git.daniel@makrotopia.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/dsa/mxl862xx/mxl862xx.c | 23 ++++++++++++++++-------
1 file changed, 16 insertions(+), 7 deletions(-)
diff --git a/drivers/net/dsa/mxl862xx/mxl862xx.c b/drivers/net/dsa/mxl862xx/mxl862xx.c
index cfa7e3e269a28..e05ad52cd297e 100644
--- a/drivers/net/dsa/mxl862xx/mxl862xx.c
+++ b/drivers/net/dsa/mxl862xx/mxl862xx.c
@@ -685,10 +685,22 @@ static int mxl862xx_setup(struct dsa_switch *ds)
if (ret)
return ret;
+ ret = mxl862xx_setup_mdio(ds);
+ if (ret)
+ return ret;
+
schedule_delayed_work(&priv->stats_work,
MXL862XX_STATS_POLL_INTERVAL);
- return mxl862xx_setup_mdio(ds);
+ return 0;
+}
+
+static void mxl862xx_teardown(struct dsa_switch *ds)
+{
+ struct mxl862xx_priv *priv = ds->priv;
+
+ set_bit(MXL862XX_FLAG_WORK_STOPPED, &priv->flags);
+ disable_delayed_work_sync(&priv->stats_work);
}
static int mxl862xx_port_state(struct dsa_switch *ds, int port, bool enable)
@@ -2047,9 +2059,7 @@ static void mxl862xx_get_stats64(struct dsa_switch *ds, int port,
spin_unlock_bh(&priv->ports[port].stats_lock);
- /* Trigger a fresh poll so the next read sees up-to-date counters.
- * No-op if the work is already pending, running, or teardown started.
- */
+ /* Trigger a fresh poll so the next read sees up-to-date counters. */
if (!test_bit(MXL862XX_FLAG_WORK_STOPPED, &priv->flags))
schedule_delayed_work(&priv->stats_work, 0);
}
@@ -2057,6 +2067,7 @@ static void mxl862xx_get_stats64(struct dsa_switch *ds, int port,
static const struct dsa_switch_ops mxl862xx_switch_ops = {
.get_tag_protocol = mxl862xx_get_tag_protocol,
.setup = mxl862xx_setup,
+ .teardown = mxl862xx_teardown,
.port_setup = mxl862xx_port_setup,
.port_teardown = mxl862xx_port_teardown,
.phylink_get_caps = mxl862xx_phylink_get_caps,
@@ -2131,7 +2142,6 @@ static int mxl862xx_probe(struct mdio_device *mdiodev)
err = dsa_register_switch(ds);
if (err) {
set_bit(MXL862XX_FLAG_WORK_STOPPED, &priv->flags);
- cancel_delayed_work_sync(&priv->stats_work);
mxl862xx_host_shutdown(priv);
for (i = 0; i < MXL862XX_MAX_PORTS; i++)
cancel_work_sync(&priv->ports[i].host_flood_work);
@@ -2152,7 +2162,6 @@ static void mxl862xx_remove(struct mdio_device *mdiodev)
priv = ds->priv;
set_bit(MXL862XX_FLAG_WORK_STOPPED, &priv->flags);
- cancel_delayed_work_sync(&priv->stats_work);
dsa_unregister_switch(ds);
@@ -2181,7 +2190,7 @@ static void mxl862xx_shutdown(struct mdio_device *mdiodev)
dsa_switch_shutdown(ds);
set_bit(MXL862XX_FLAG_WORK_STOPPED, &priv->flags);
- cancel_delayed_work_sync(&priv->stats_work);
+ disable_delayed_work_sync(&priv->stats_work);
mxl862xx_host_shutdown(priv);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 102/398] neighbour: Add missing RCU annotation for neightbl_dump_info().
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (100 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 101/398] neighbour: Convert RTM_GETNEIGHTBL to RCU Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 103/398] neighbour: Skip default parms when resumed in neightbl_dump_info() Greg Kroah-Hartman
` (300 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 764dcebb033764633700a036c7351a7c6350eec6 ]
neightbl_dump_info() fetches the first non-default neigh_parms
with list_next_entry(&tbl->parms, ...) and iterates through the
list with list_for_each_entry_from_rcu().
However, list_next_entry() does not use RCU helper.
Let's use list_for_each_entry_rcu() and skip the default parms.
Fixes: 4ae34be50064 ("neighbour: Convert RTM_GETNEIGHTBL to RCU.")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260909233143.2401847-2-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 979aabdad8dd ("neighbour: Skip default parms when resumed in neightbl_dump_info().")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 9873fc08b7494..d51899b011ddd 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2596,11 +2596,14 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
break;
nidx = 0;
- p = list_next_entry(&tbl->parms, list);
- list_for_each_entry_from_rcu(p, &tbl->parms_list, list) {
+
+ list_for_each_entry_rcu(p, &tbl->parms_list, list) {
if (!net_eq(neigh_parms_net(p), net))
continue;
+ if (!p->dev)
+ continue;
+
if (nidx < neigh_skip)
goto next;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 156/438] net: bcmgenet: restore the hardware filters on open
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (154 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 155/438] net: dsa: mxl862xx: disable the stats poll on teardown Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 157/438] sysctl: Check range in proc_dointvec_ms_jiffies_minmax Greg Kroah-Hartman
` (293 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Justin Chen,
Florian Fainelli, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolai Buchwitz <nb@tipi-net.de>
[ Upstream commit 23ca4ddc4fce2c233a49e9fd34d4b5b02bd7324e ]
bcmgenet_hfb_init() runs INIT_LIST_HEAD() on priv->rxnfc_list, which drops
every rule off the list, and bcmgenet_open() calls it on each ifup. Every
rule the user configured is silently lost:
# ethtool -N eth0 flow-type ether dst $MAC action 0
Added rule with ID 0
# ethtool -n eth0 | grep -c Filter:
1
# ip link set eth0 down && ip link set eth0 up
# ethtool -n eth0 | grep -c Filter:
0
Initialise the lists once at probe and restore the rules on open, as
bcmgenet_resume() already does.
Fixes: 3e370952287c ("net: bcmgenet: add support for ethtool rxnfc flows")
Signed-off-by: Nicolai Buchwitz <nb@tipi-net.de>
Reviewed-by: Justin Chen <justin.chen@broadcom.com>
Reviewed-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260913190052.939955-1-nb@tipi-net.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/broadcom/genet/bcmgenet.c | 19 +++++++++++++------
1 file changed, 13 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index a2305e6428d1f..b916080f4ff17 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -749,8 +749,17 @@ static void bcmgenet_hfb_init(struct bcmgenet_priv *priv)
INIT_LIST_HEAD(&priv->rxnfc_rules[i].list);
priv->rxnfc_rules[i].state = BCMGENET_RXNFC_STATE_UNUSED;
}
+}
+
+static void bcmgenet_hfb_restore(struct bcmgenet_priv *priv)
+{
+ struct bcmgenet_rxnfc_rule *rule;
bcmgenet_hfb_clear(priv);
+
+ list_for_each_entry(rule, &priv->rxnfc_list, list)
+ if (rule->state != BCMGENET_RXNFC_STATE_UNUSED)
+ bcmgenet_hfb_create_rxnfc_filter(priv, rule);
}
static int bcmgenet_begin(struct net_device *dev)
@@ -3376,8 +3385,8 @@ static int bcmgenet_open(struct net_device *dev)
bcmgenet_set_hw_addr(priv, dev->dev_addr);
- /* HFB init */
- bcmgenet_hfb_init(priv);
+ /* Restore the filters, the MAC was reset above */
+ bcmgenet_hfb_restore(priv);
/* Reinitialize TDMA and RDMA and SW housekeeping */
ret = bcmgenet_init_dma(priv, true);
@@ -4075,6 +4084,7 @@ static int bcmgenet_probe(struct platform_device *pdev)
/* Mii wait queue */
init_waitqueue_head(&priv->wq);
+ bcmgenet_hfb_init(priv);
INIT_WORK(&priv->bcmgenet_irq_work, bcmgenet_irq_task);
priv->clk_wol = devm_clk_get_optional(&priv->pdev->dev, "enet-wol");
@@ -4272,10 +4282,7 @@ static int bcmgenet_resume(struct device *d)
bcmgenet_set_hw_addr(priv, dev->dev_addr);
/* Restore hardware filters */
- bcmgenet_hfb_clear(priv);
- list_for_each_entry(rule, &priv->rxnfc_list, list)
- if (rule->state != BCMGENET_RXNFC_STATE_UNUSED)
- bcmgenet_hfb_create_rxnfc_filter(priv, rule);
+ bcmgenet_hfb_restore(priv);
/* Reinitialize TDMA and RDMA and SW housekeeping */
ret = bcmgenet_init_dma(priv, false);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 103/398] neighbour: Skip default parms when resumed in neightbl_dump_info().
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (101 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 102/398] neighbour: Add missing RCU annotation for neightbl_dump_info() Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 104/398] ALSA: bcd2000: Fix race between rawmidi and disconnect Greg Kroah-Hartman
` (299 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Ido Schimmel,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 979aabdad8dd03394467ee484a1a70f3d40b19ba ]
neightbl_dump_info() calls neightbl_fill_info() in each loop
to render the default parms.
If there are many devices and neightbl_fill_param_info() failed,
neightbl_fill_info() is called again when the dump resumes:
# ynl --family rt-neigh --dump getneightbl --output-json |
jq '.[] | {name: .name, ifindex: .parms.ifindex}'
...
{
"name": "ndisc_cache",
"ifindex": null
}
...
{
"name": "ndisc_cache",
"ifindex": 6
}
{
"name": "ndisc_cache",
"ifindex": null
}
{
"name": "ndisc_cache",
"ifindex": 5
}
Let's skip neightbl_fill_info() if it is already called in
neightbl_dump_info().
Note that we cannot use !neigh_skip instead of !default_skip
because default_skip == 1 && neigh_skip == 0 could be true
if the first neightbl_fill_param_info() fails.
Also, nidx must be cleared at the end of each table loop;
otherwise, if neightbl_fill_info() for a subsequent table
fails, the leftover nidx from the previous table would be
saved in cb->args[1], resulting in erroneously skipping parms
of the subsequent table in the next dump.
Fixes: c7fb64db001f ("[NETLINK]: Neighbour table configuration and statistics via rtnetlink")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260909233143.2401847-5-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/neighbour.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index d51899b011ddd..862867874e121 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -2564,9 +2564,10 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
{
const struct nlmsghdr *nlh = cb->nlh;
struct net *net = sock_net(skb->sk);
+ int default_skip = cb->args[2];
+ int neigh_skip = cb->args[1];
int family, tidx, nidx = 0;
int tbl_skip = cb->args[0];
- int neigh_skip = cb->args[1];
struct neigh_table *tbl;
if (cb->strict_check) {
@@ -2590,12 +2591,13 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
if (tidx < tbl_skip || (family && tbl->family != family))
continue;
- if (neightbl_fill_info(skb, tbl, NETLINK_CB(cb->skb).portid,
+ if (!default_skip &&
+ neightbl_fill_info(skb, tbl, NETLINK_CB(cb->skb).portid,
nlh->nlmsg_seq, RTM_NEWNEIGHTBL,
NLM_F_MULTI) < 0)
break;
- nidx = 0;
+ default_skip = 1;
list_for_each_entry_rcu(p, &tbl->parms_list, list) {
if (!net_eq(neigh_parms_net(p), net))
@@ -2618,12 +2620,15 @@ static int neightbl_dump_info(struct sk_buff *skb, struct netlink_callback *cb)
}
neigh_skip = 0;
+ nidx = 0;
+ default_skip = 0;
}
out:
rcu_read_unlock();
cb->args[0] = tidx;
cb->args[1] = nidx;
+ cb->args[2] = default_skip;
return skb->len;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 157/438] sysctl: Check range in proc_dointvec_ms_jiffies_minmax
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (155 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 156/438] net: bcmgenet: restore the hardware filters on open Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 158/438] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup Greg Kroah-Hartman
` (292 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuniyuki Iwashima, Joel Granados,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 82431877d837a6c2593efd8e66ba28b35a220ca4 ]
Add the range check to do_proc_int_conv_ms_jiffies_minmax that commit
d174174c6776 ("sysctl: replace SYSCTL_INT_CONV_CUSTOM macro with
functions") incorrectly removed.
Fixes: d174174c6776 ("sysctl: replace SYSCTL_INT_CONV_CUSTOM macro with functions")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Signed-off-by: Joel Granados <joel.granados@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/time/jiffies.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/time/jiffies.c b/kernel/time/jiffies.c
index d51428867a339..f4c43b9716f89 100644
--- a/kernel/time/jiffies.c
+++ b/kernel/time/jiffies.c
@@ -181,7 +181,7 @@ static int do_proc_int_conv_ms_jiffies_minmax(bool *negp, ulong *u_ptr,
int *k_ptr, int dir,
const struct ctl_table *tbl)
{
- return proc_int_conv(negp, u_ptr, k_ptr, dir, tbl, false,
+ return proc_int_conv(negp, u_ptr, k_ptr, dir, tbl, true,
sysctl_u2k_int_conv_ms, sysctl_k2u_int_conv_ms);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 104/398] ALSA: bcd2000: Fix race between rawmidi and disconnect
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (102 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 103/398] neighbour: Skip default parms when resumed in neightbl_dump_info() Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 105/398] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow Greg Kroah-Hartman
` (298 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 221253723dc58bb901c3f27a7659823e63fc598c ]
Although we tried to fix the potential UAF issues at USB disconnect on
bcd2000 driver, there is still an overlooked case -- namely, when a
rawmidi trigger callback has been already running at USB disconnect
handling, the in-flight function (e.g. bcd2000_midi_send()) could
still access the URB, because the previous URB NULL-check & clearance
was considered only for the URB complete callbacks, but not about the
parallel rawmidi operations.
For addressing the race, this patch introduced a new spinlock that
covers each rawmidi operation as well as the rawmidi handling in the
complete callback. The URB is cleared with the lock, so it guarantees
that the pending rawmidi task already finished or a NULL check is
effective.
Fixes: 459d3a64766f ("ALSA: bcd2000: clear the URB pointers on disconnect")
Link: https://patch.msgid.link/20260910155227.996210-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/bcd2000/bcd2000.c | 33 ++++++++++++++++++++++++++-------
1 file changed, 26 insertions(+), 7 deletions(-)
diff --git a/sound/usb/bcd2000/bcd2000.c b/sound/usb/bcd2000/bcd2000.c
index c5c542d17ccc1..2bd49bf827489 100644
--- a/sound/usb/bcd2000/bcd2000.c
+++ b/sound/usb/bcd2000/bcd2000.c
@@ -43,6 +43,7 @@ struct bcd2000 {
struct usb_interface *intf;
int card_index;
+ spinlock_t midi_lock;
int midi_out_active;
struct snd_rawmidi *rmidi;
struct snd_rawmidi_substream *midi_receive_substream;
@@ -90,6 +91,8 @@ static void bcd2000_midi_input_trigger(struct snd_rawmidi_substream *substream,
int up)
{
struct bcd2000 *bcd2k = substream->rmidi->private_data;
+
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
bcd2k->midi_receive_substream = up ? substream : NULL;
}
@@ -195,6 +198,8 @@ static void bcd2000_midi_output_trigger(struct snd_rawmidi_substream *substream,
{
struct bcd2000 *bcd2k = substream->rmidi->private_data;
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
+
if (up) {
bcd2k->midi_out_substream = substream;
/* check if there is data userspace wants to send */
@@ -219,6 +224,7 @@ static void bcd2000_output_complete(struct urb *urb)
return;
/* check if there is more data userspace wants to send */
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
bcd2000_midi_send(bcd2k);
}
@@ -234,6 +240,8 @@ static void bcd2000_input_complete(struct urb *urb)
if (!bcd2k || urb->status == -ESHUTDOWN)
return;
+ guard(spinlock_irqsave)(&bcd2k->midi_lock);
+
if (urb->actual_length > 0)
bcd2000_midi_handle_input(bcd2k, urb->transfer_buffer,
urb->actual_length);
@@ -348,16 +356,26 @@ static int bcd2000_init_midi(struct bcd2000 *bcd2k)
return 0;
}
+static void bcd2000_midi_free(struct bcd2000 *bcd2k,
+ struct urb **urb_p)
+{
+ struct urb *urb = *urb_p;
+
+ if (!urb)
+ return;
+
+ usb_poison_urb(urb);
+ scoped_guard(spinlock_irq, &bcd2k->midi_lock)
+ *urb_p = NULL;
+
+ usb_free_urb(urb);
+}
+
static void bcd2000_free_usb_related_resources(struct bcd2000 *bcd2k,
struct usb_interface *interface)
{
- usb_poison_urb(bcd2k->midi_out_urb);
- usb_poison_urb(bcd2k->midi_in_urb);
-
- usb_free_urb(bcd2k->midi_out_urb);
- usb_free_urb(bcd2k->midi_in_urb);
- bcd2k->midi_out_urb = NULL;
- bcd2k->midi_in_urb = NULL;
+ bcd2000_midi_free(bcd2k, &bcd2k->midi_out_urb);
+ bcd2000_midi_free(bcd2k, &bcd2k->midi_in_urb);
if (bcd2k->intf) {
usb_set_intfdata(bcd2k->intf, NULL);
@@ -393,6 +411,7 @@ static int bcd2000_probe(struct usb_interface *interface,
bcd2k->card = card;
bcd2k->card_index = card_index;
bcd2k->intf = interface;
+ spin_lock_init(&bcd2k->midi_lock);
snd_card_set_dev(card, &interface->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 158/438] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (156 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 157/438] sysctl: Check range in proc_dointvec_ms_jiffies_minmax Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 159/438] net: fddi: skfp: fix NULL deref when setting the MAC address while down Greg Kroah-Hartman
` (291 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, Jiayuan Chen,
Dong Chenchen, Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dong Chenchen <dongchenchen2@huawei.com>
[ Upstream commit 2998147b59c9df0a51477c7a6b3d1f0ba3127dd4 ]
When the forward output route cannot be used in icmp_route_lookup(),
it enters the "reverse path" and calls ip_route_input() on fl4_dec.daddr,
the original packet's source address.
ip_route_input() only returns an error for truly invalid packets. For
unreachable addresses it will succeed and return an input route whose
dst.output is set to ip_rt_bug(). The existing check only rejects
RTN_LOCAL routes, so the RTN_UNREACHABLE route types can still be returned
and later used for output, syzkaller triggering a WARN_ON_ONCE()
in ip_rt_bug() as bellow:
------------[ cut here ]------------
WARNING: net/ipv4/route.c:1273 at ip_rt_bug+0x14/0x20
RIP: 0010:ip_rt_bug+0x14/0x20
Call Trace:
ip_push_pending_frames+0xfa/0x100
__icmp_send+0x905/0xf10
ip_options_compile+0xc0/0xd0
ip_rcv_finish_core+0x321/0xae0
ip_rcv+0x1de/0x260
__netif_receive_skb_one_core+0x11a/0x130
netif_receive_skb+0x7b/0x260
tun_get_user+0x11bf/0x1c10
------------[ cut here ]------------
Reject input route that is RTN_UNREACHABLE to fix it. The net warning
is only printed for RTN_LOCAL, as RTN_UNREACHABLE is not the result of
a race condition.
Fixes: 8b7817f3a959 ("[IPSEC]: Add ICMP host relookup support")
Suggested-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Signed-off-by: Dong Chenchen <dongchenchen2@huawei.com>
Link: https://patch.msgid.link/20260910140042.1880242-1-dongchenchen2@huawei.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/icmp.c | 17 ++++++++++-------
1 file changed, 10 insertions(+), 7 deletions(-)
diff --git a/net/ipv4/icmp.c b/net/ipv4/icmp.c
index 0caedfc7ca92f..90c0e22c29bea 100644
--- a/net/ipv4/icmp.c
+++ b/net/ipv4/icmp.c
@@ -581,16 +581,19 @@ static struct rtable *icmp_route_lookup(struct net *net, struct flowi4 *fl4,
skb_dstref_restore(skb_in, orefdst);
/*
- * At this point, fl4_dec.daddr should NOT be local (we
- * checked fl4_dec.saddr above). However, a race condition
- * may occur if the address is added to the interface
- * concurrently. In that case, ip_route_input() returns a
- * LOCAL route with dst.output=ip_rt_bug, which must not
- * be used for output.
+ * fl4_dec.daddr is not expected to be local here, but it can be
+ * added to an interface concurrently, in which case
+ * ip_route_input() returns a LOCAL route. It can also fail to
+ * build a forwarding route towards fl4_dec.daddr, for example,
+ * when forwarding is disabled, and return an UNREACHABLE route.
+ * Both cases will result in a route with dst.output=ip_rt_bug,
+ * which must not be used for output.
*/
- if (!err && rt2 && rt2->rt_type == RTN_LOCAL) {
+ if (!err && rt2 && rt2->rt_type == RTN_LOCAL)
net_warn_ratelimited("detected local route for %pI4 during ICMP sending, src %pI4\n",
&fl4_dec.daddr, &fl4_dec.saddr);
+ if (!err && rt2 &&
+ (rt2->rt_type == RTN_LOCAL || rt2->rt_type == RTN_UNREACHABLE)) {
dst_release(&rt2->dst);
err = -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 105/398] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (103 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 104/398] ALSA: bcd2000: Fix race between rawmidi and disconnect Greg Kroah-Hartman
@ 2026-09-23 14:02 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 106/398] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting Greg Kroah-Hartman
` (297 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:02 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam,
AngeloGioacchino Del Regno, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
[ Upstream commit de7f29a1fe1dc2864d8a47f8c39d508442cae167 ]
When trying to calculate a PLL rate for target display resolutions
above 2560x1440, 24bpp, 30Hz, the pixel clock value will be more
than 32-bits long but the division to finally calculate the digital
clock divider is being done with div_u64(), which expects a 32bit
unsigned divisor.
Fix the overflow by using div64_u64() instead.
Fixes: 9d9ff3d2a4a5 ("phy: mediatek: hdmi: mt8195: fix wrong pll calculus")
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Link: https://patch.msgid.link/20260911074015.9994-2-angelogioacchino.delregno@collabora.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
index b38f3ae26b3f3..829d329af1732 100644
--- a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
+++ b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
@@ -290,7 +290,7 @@ static int mtk_hdmi_pll_calc(struct mtk_hdmi_phy *hdmi_phy, struct clk_hw *hw,
posdiv2 = 1;
/* Digital clk divider, max /32 */
- digital_div = div_u64(ns_hdmipll_ck, posdiv1 * posdiv2 * pixel_clk);
+ digital_div = div64_u64(ns_hdmipll_ck, posdiv1 * posdiv2 * pixel_clk);
if (!(digital_div <= 32 && digital_div >= 1))
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 159/438] net: fddi: skfp: fix NULL deref when setting the MAC address while down
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (157 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 7.2 158/438] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 160/438] wifi: brcmfmac: fix lost 802.1x TX completion wakeup Greg Kroah-Hartman
` (290 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hohyun Sim, Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hohyun Sim <tlaghgus0425@korea.ac.kr>
[ Upstream commit 7c8810c2e69c3d9ca6df870b40ae9218e50b4fb1 ]
skfp_ctl_set_mac_address() calls ResetAdapter() unconditionally, without
checking netif_running(). ResetAdapter() first calls card_stop(), which
sets smc->hw.hw_state to STOPPED, and then mac_drv_clear_tx_queue(),
which walks the two transmit queues:
for (i = QUEUE_S; i <= QUEUE_A0; i++) {
queue = smc->hw.fp.tx[i] ;
...
t = queue->tx_curr_get ;
smc->hw.fp.tx[] is only populated by init_tx(), which is reached from
skfp_open() through init_smt() -> init_fddi_driver() -> init_fplus() ->
init_mac() -> init_tx(). The private area is allocated and zeroed by
alloc_fddidev(), so on an interface that has never been brought up both
queue pointers are still NULL. The hw_state test at the top of
mac_drv_clear_tx_queue() does not catch this, because card_stop() has
just set STOPPED; the function proceeds into the loop and dereferences
NULL. ResetAdapter() does call init_smt() itself, but only after the
queues have been cleared.
Setting the MAC address on a down interface therefore oopses:
ip link set dev fddi0 address 02:00:00:00:00:01
BUG: KASAN: null-ptr-deref in mac_drv_clear_tx_queue+0x68/0x2c0 [skfp]
Read of size 8 at addr 0000000000000010 by task ip/302
Call Trace:
<TASK>
mac_drv_clear_tx_queue+0x68/0x2c0 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
ResetAdapter+0x29/0x100 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
skfp_ctl_set_mac_address+0x57/0x80 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
netif_set_mac_address+0x1e4/0x2c0
do_setlink+0x684/0x2680
</TASK>
Address 0x10 is the offset of tx_curr_get, the third pointer in
struct s_smt_tx_queue, on 64-bit. mac_drv_clear_rx_queue(), which
ResetAdapter() calls immediately afterwards, dereferences
smc->hw.fp.rx[QUEUE_R1] in the same way behind the same ineffective
hw_state test; the transmit queue merely crashes first. Both are
covered by the guard below.
Skip the adapter reset when the interface is down. dev_addr_set() is
left unconditional, so the new address is still recorded in
dev->dev_addr. Nothing is lost by not resetting the adapter here:
skfp_open() deliberately re-reads the factory address on every open,
read_address(smc, NULL);
eth_hw_addr_set(dev, smc->hw.fddi_canon_addr.a);
and the comment above it states this is done to discard exactly such an
address override across a close/open cycle. An address set while the
interface is down could not have survived the following open even
before this change, so the guard removes no working behaviour. Guarding
the hardware side of ndo_set_mac_address() with netif_running() is
established practice; skge_set_mac_address() has done so since commit
2eb3e621c4e0 ("skge: set mac address bonding fix").
Guarding the reset as a whole, rather than NULL-checking the queues, is
also what the rest of the driver expects. After a previous open/close
the queue pointers are stale but non-NULL, so there is no crash, yet
ResetAdapter() goes on to call smt_online() and STI_FBI() ("Enable
Board Interrupts") while skfp_close() has already called free_irq() -
the adapter would be brought back online with no handler installed. The
only other ResetAdapter() caller is skfp_interrupt(), which by
construction runs only while the device is open.
Found by automated driver testing against an emulated SysKonnect FDDI
adapter under a KASAN-enabled 7.0.0 kernel. Triggering it requires
CAP_NET_ADMIN.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: LLM KASAN
Signed-off-by: Hohyun Sim <tlaghgus0425@korea.ac.kr>
Link: https://patch.msgid.link/20260910063743.110747-1-tlaghgus0425@korea.ac.kr
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/fddi/skfp/skfddi.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/fddi/skfp/skfddi.c b/drivers/net/fddi/skfp/skfddi.c
index a273362c9e703..feea7baa48168 100644
--- a/drivers/net/fddi/skfp/skfddi.c
+++ b/drivers/net/fddi/skfp/skfddi.c
@@ -928,7 +928,8 @@ static int skfp_ctl_set_mac_address(struct net_device *dev, void *addr)
dev_addr_set(dev, p_sockaddr->sa_data);
spin_lock_irqsave(&bp->DriverLock, Flags);
- ResetAdapter(smc);
+ if (netif_running(dev))
+ ResetAdapter(smc);
spin_unlock_irqrestore(&bp->DriverLock, Flags);
return 0; /* always return zero */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 106/398] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (104 preceding siblings ...)
2026-09-23 14:02 ` [PATCH 6.18 105/398] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 107/398] ALSA: pcm: set timer->private_data before registering the PCM timer Greg Kroah-Hartman
` (296 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam,
AngeloGioacchino Del Regno, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
[ Upstream commit 486a70ef848264dcf9a57f0bb0452848db9537de ]
The comment in the mtk_phy_tmds_clk_ratio() function clearly and
correctly explains that the TMDS ratio has to be 1/10 for data
rates under 3.4Gbps, and 1/40 over that.
Unfortunately though, the TXC_DIV register setting was wrong, as
in value 3 means to divide by 8 and, in order to achieve the in
spec 1/40 (tmds) data rate, this has to divide by 4 instead!
Add definitions for the TXC_DIV register values clearly explaining
the meanings (DIV2, DIV4, DIV8), and program the correct, DIV 4,
value to the register in mtk_phy_tmds_clk_ratio().
This fixes out of spec clocking and, with this change, SoCs using
the MT8195 class HDMI PHYs can now successfully be configured to
output 3840x2160@60Hz over HDMI.
Fixes: 45810d486bb4 ("phy: mediatek: add support for phy-mtk-hdmi-mt8195")
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Signed-off-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Link: https://patch.msgid.link/20260911074015.9994-3-angelogioacchino.delregno@collabora.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c | 2 +-
drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h | 3 +++
2 files changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
index 829d329af1732..2f03c4e66d6fe 100644
--- a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
+++ b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.c
@@ -36,7 +36,7 @@ mtk_phy_tmds_clk_ratio(struct mtk_hdmi_phy *hdmi_phy, bool enable)
* clock bit ratio 1:40, under 3.4Gbps, clock bit ratio 1:10
*/
if (enable)
- mtk_phy_update_field(regs + HDMI20_CLK_CFG, REG_TXC_DIV, 3);
+ mtk_phy_update_field(regs + HDMI20_CLK_CFG, REG_TXC_DIV, VAL_TXC_DIV4);
else
mtk_phy_clear_bits(regs + HDMI20_CLK_CFG, REG_TXC_DIV);
}
diff --git a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h
index e26caaf4d104c..58800d7659ca0 100644
--- a/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h
+++ b/drivers/phy/mediatek/phy-mtk-hdmi-mt8195.h
@@ -17,6 +17,9 @@
#define HDMI20_CLK_CFG 0x70
#define REG_TXC_DIV GENMASK(31, 30)
+#define VAL_TXC_DIV2 1
+#define VAL_TXC_DIV4 2
+#define VAL_TXC_DIV8 3
#define HDMI_1_CFG_0 0x00
#define RG_HDMITX21_DRV_IBIAS_CLK GENMASK(10, 5)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 160/438] wifi: brcmfmac: fix lost 802.1x TX completion wakeup
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (158 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 159/438] net: fddi: skfp: fix NULL deref when setting the MAC address while down Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 161/438] net: bridge: mst: move switchdev call outside rcu Greg Kroah-Hartman
` (289 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Arend van Spriel,
Johannes Berg, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 621d90169cef6c8da5b6134db5c0c4e23cdd09ce ]
brcmf_txfinalize() decrements pend_8021x_cnt before a lockless
waitqueue_active() check. atomic_dec() does not order the decrement
against the check.
The waiter can therefore observe a nonzero count while the waker observes
an empty queue, losing the final wakeup and delaying key installation
until the 950 ms timeout.
Add smp_mb__after_atomic() to order the decrement before the queue
check. wait_event_timeout() provides the matching barrier. LKMM confirms
that this forbids the lost-wakeup outcome.
Fixes: 21fff75d2fb6 ("brcmfmac: use wait_event_timeout for 8021x pending count")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260811082702.44521-1-kmehltretter@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
index dad6f4563d146..d2ae679856067 100644
--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
@@ -555,6 +555,8 @@ void brcmf_txfinalize(struct brcmf_if *ifp, struct sk_buff *txp, bool success)
if (type == ETH_P_PAE) {
atomic_dec(&ifp->pend_8021x_cnt);
+ /* Order the decrement before waitqueue_active() */
+ smp_mb__after_atomic();
if (waitqueue_active(&ifp->pend_8021x_wait))
wake_up(&ifp->pend_8021x_wait);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 107/398] ALSA: pcm: set timer->private_data before registering the PCM timer
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (105 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 106/398] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 108/398] drm/msm/dp: skip PUSH_IDLE when the link was never enabled Greg Kroah-Hartman
` (295 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+19da64013c46df87f971,
Nguyen Ngoc Thang, Takashi Iwai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
[ Upstream commit 1e713f9bb2ac583521f06b0eb4e22440b1e3d078 ]
snd_pcm_timer_init() calls snd_device_register() to link the new
struct snd_timer into the global timer list while it still carries
hw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop),
and only afterwards sets timer->private_data = substream.
Once the timer is on the list under register_mutex, a concurrent
reader can already reach it through the same mutex and invoke these
callbacks. /proc/asound/timers does this via c_resolution(), and
snd_timer_open()+snd_timer_start() reach start()/stop() the same way.
All three dereference timer->private_data, which for this brief
window is NULL, giving a NULL-pointer dereference:
substream = timer->private_data;
return substream->runtime ? ... // substream is NULL
Move the private_data/private_free assignment before
snd_device_register() so the timer is never visible on the list
without its private_data set. On the snd_device_register() failure
path, private_free() (snd_pcm_timer_free()) can now run, but it only
does substream->timer = NULL, which is already NULL at that point
since substream->timer is set to the new timer just once, after a
successful registration -- so the failure path stays safe.
Reported-by: syzbot+19da64013c46df87f971@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=19da64013c46df87f971
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
Link: https://patch.msgid.link/20260913134446.114724-1-ngocthang2710.1999@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/core/pcm_timer.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/sound/core/pcm_timer.c b/sound/core/pcm_timer.c
index ab0e5bd70f8fa..18bedd66435dc 100644
--- a/sound/core/pcm_timer.c
+++ b/sound/core/pcm_timer.c
@@ -111,12 +111,15 @@ void snd_pcm_timer_init(struct snd_pcm_substream *substream)
snd_pcm_direction_name(substream->stream),
tid.card, tid.device, tid.subdevice);
timer->hw = snd_pcm_timer;
+ /* Set before registering: a concurrent reader can invoke our hw
+ * callbacks as soon as the timer is on the global list.
+ */
+ timer->private_data = substream;
+ timer->private_free = snd_pcm_timer_free;
if (snd_device_register(timer->card, timer) < 0) {
snd_device_free(timer->card, timer);
return;
}
- timer->private_data = substream;
- timer->private_free = snd_pcm_timer_free;
substream->timer = timer;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 161/438] net: bridge: mst: move switchdev call outside rcu
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (159 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 160/438] wifi: brcmfmac: fix lost 802.1x TX completion wakeup Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 162/438] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() Greg Kroah-Hartman
` (288 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nikolay Aleksandrov, Ido Schimmel,
Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nikolay Aleksandrov <razor@blackwall.org>
[ Upstream commit 18a6fe05fb6e18de29fa90d388bb34044114b3d8 ]
This is a follow-up of one of sashiko's pre-existing bug reports.
br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs
while holding rcu_read_lock() which invokes the blocking switchdev
notifier chain and may sleep. Nonzero MSTI changes come from netlink
with rtnl held. Move the switchdev call before entering the rcu section and
assert that rtnl is held.
The call cannot be deferred because netlink needs its error and extack.
Also DSA reads the old bridge MST state during the callback and checks it.
A deferred callback will be late and will see the updated state.
Fixes: 3a7c1661ae13 ("net: bridge: mst: fix vlan use-after-free")
Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260911105021.1385934-1-razor@blackwall.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bridge/br_mst.c | 20 ++++++++++++--------
1 file changed, 12 insertions(+), 8 deletions(-)
diff --git a/net/bridge/br_mst.c b/net/bridge/br_mst.c
index 43a300ae6bfaf..1654efd3045b0 100644
--- a/net/bridge/br_mst.c
+++ b/net/bridge/br_mst.c
@@ -107,21 +107,24 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state,
struct net_bridge_vlan *v;
int err = 0;
- rcu_read_lock();
- vg = nbp_vlan_group_rcu(p);
- if (!vg)
- goto out;
-
/* MSTI 0 (CST) state changes are notified via the regular
- * SWITCHDEV_ATTR_ID_PORT_STP_STATE.
+ * SWITCHDEV_ATTR_ID_PORT_STP_STATE. All other MSTIs are handled via
+ * netlink with RTNL held
*/
if (msti) {
+ ASSERT_RTNL();
+
err = switchdev_port_attr_set(p->dev, &attr, extack);
if (err && err != -EOPNOTSUPP)
goto out;
+ err = 0;
}
- err = 0;
+ rcu_read_lock();
+ vg = nbp_vlan_group_rcu(p);
+ if (!vg)
+ goto out_rcu_unlock;
+
list_for_each_entry_rcu(v, &vg->vlan_list, vlist) {
if (v->brvlan->msti != msti)
continue;
@@ -129,8 +132,9 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state,
br_mst_vlan_set_state(vg, v, state);
}
-out:
+out_rcu_unlock:
rcu_read_unlock();
+out:
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 108/398] drm/msm/dp: skip PUSH_IDLE when the link was never enabled
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (106 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 107/398] ALSA: pcm: set timer->private_data before registering the PCM timer Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 109/398] drm/msm/dp: fix link bandwidth check when wide bus is enabled Greg Kroah-Hartman
` (294 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jesse Casco, Dmitry Baryshkov,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jesse Casco <jesse.casco@gmail.com>
[ Upstream commit e249a6e2a130c08bb4d8b0a55cbe29754307e5c9 ]
msm_dp_display_atomic_enable() returns early when link training fails,
leaving ->power_on false and the main link down.
msm_dp_display_atomic_disable() nevertheless writes DP_STATE_CTRL_PUSH_IDLE
and waits for an idle-pattern completion that cannot arrive, so every failed
enable is followed by "PUSH_IDLE pattern timedout".
Every other step of the teardown is already gated on that flag:
msm_dp_display_disable(), called from .atomic_post_disable(), returns early
on !power_on. The PUSH_IDLE write is the only one that is not, so the
controller's runtime-PM reference is then dropped without the link having
been taken down.
On glymur (Snapdragon X2 Elite) the consequence is not a warning. The SoC
does not survive it: TrustZone force-stops the SOCCP and ADSP remote
processors and the machine resets silently about 50 ms later, with no oops
and no panic. On an ASUS Zenbook A16 (UX3607OA), whose eDP panel does not
currently train, this reproduces without any compositor or GPU involvement:
# eDP enable has already failed with "Failed link training (rc=-104)"
echo 1 > /sys/class/graphics/fb0/blank
[535.645455] === marker ===
[535.694833] qcom_q6v5_pas d00000.remoteproc: fatal error received: \
sys_m_smsm.c:512:TZ force stop
[535.694875] remoteproc remoteproc0: crash detected in soccp: type fatal error
[535.728857] qcom_q6v5_pas 6800000.remoteproc: fatal error received: \
sys_m_smsm.c:783:err fatal notification received from TZ
<SoC reset>
Gate the PUSH_IDLE write on ->power_on so the disable path is consistent
with the rest of the teardown. With this applied the same sequence is
harmless and the machine stays up; without it, it resets every time.
The unconditional write dates back to the original DP driver
(c943b4948b58 ("drm/msm/dp: add displayPort driver support")), but the
surrounding code has been restructured several times since, so no Fixes:
tag is offered.
Note that the eDP link-training failure that exposes this on the A16 is a
separate problem in the glymur eDP PHY and is reported separately; this
change is about not damaging the machine when training fails, for whatever
reason.
Tested on ASUS Zenbook A16 (UX3607OA), Snapdragon X2 Elite Extreme, on
linux-next next-20260803 and next-20260807. The machine has since been
running next-20260807 with this patch as its daily driver.
Assisted-by: Anthropic:Claude-Opus-5
Signed-off-by: Jesse Casco <jesse.casco@gmail.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/745167/
Link: https://lore.kernel.org/r/20260808171325.133041-1-jesse.casco@gmail.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dp/dp_display.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/drivers/gpu/drm/msm/dp/dp_display.c b/drivers/gpu/drm/msm/dp/dp_display.c
index 68043dbe72bfa..0f6e4a1072a8f 100644
--- a/drivers/gpu/drm/msm/dp/dp_display.c
+++ b/drivers/gpu/drm/msm/dp/dp_display.c
@@ -1647,6 +1647,20 @@ void msm_dp_bridge_atomic_disable(struct drm_bridge *drm_bridge,
msm_dp_display = container_of(dp, struct msm_dp_display_private, msm_dp_display);
+ /*
+ * If .atomic_enable() bailed out - link training failure is the common
+ * case - the mainlink was never brought up and ->power_on stayed false.
+ * Driving the PUSH_IDLE pattern into a controller that was never
+ * enabled times out, and .atomic_post_disable() then drops the
+ * controller's runtime-PM reference without tearing the PHY back down,
+ * because msm_dp_display_disable() returns early on !power_on. On
+ * glymur (Snapdragon X2 Elite) that combination is answered by a
+ * TrustZone-level SOCCP/ADSP force-stop and a silent SoC reset.
+ * There is nothing to push idle, so leave it alone.
+ */
+ if (!dp->power_on)
+ return;
+
msm_dp_ctrl_push_idle(msm_dp_display->ctrl);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 162/438] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (160 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 161/438] net: bridge: mst: move switchdev call outside rcu Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 163/438] tcp: do not let tcp_rmem be set below 4096 Greg Kroah-Hartman
` (287 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Taras Madan, Kuniyuki Iwashima,
Xuanqiang Luo, Eric Dumazet, Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 8e759cd1f6444a946bd1fd2b2b29eea582eea1d5 ]
tcp_v6_do_rcv() no longer calls skb_clone_and_charge_r() for
TCP_LISTEN since commit 073d89808c06 ("net: fix data-races around
sk->sk_forward_alloc").
However, there is still a small race window between tcp_v6_rcv()
and tcp_v6_do_rcv(), where concurrent close() changes TCP_LISTEN
to TCP_CLOSE, causing skb_clone_and_charge_r() to be called
locklessly and resulting in the splat below. [0]
Let's avoid calling skb_clone_and_charge_r() for TCP_CLOSE as well.
This is fine for non-listeners because tcp_rcv_state_process()
drops skb for TCP_CLOSE and opt_skb was freed immediately anyway.
[0]:
sk->sk_forward_alloc
WARNING: net/ipv4/af_inet.c:162 at inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162, CPU#1: ksoftirqd/1/28
Modules linked in:
CPU: 1 UID: 0 PID: 28 Comm: ksoftirqd/1 Not tainted 7.2.0 #17 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
RIP: 0010:inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162
Code: 3d 49 ff e9 06 fd ff ff e8 d0 5b 83 f8 90 0f 0b 90 e9 35 fe ff ff e8 c2 5b 83 f8 90 0f 0b 90 e9 c5 fe ff ff e8 b4 5b 83 f8 90 <0f> 0b 90 e9 04 ff ff ff e8 a6 5b 83 f8 90 0f 0b 90 e9 65 fe ff ff
RSP: 0018:ffffc90000677bb8 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffff8880117bde80 RCX: ffffffff8957eb41
RDX: ffff88801dad5d00 RSI: ffffffff8957ec3c RDI: 0000000000000005
RBP: 00000000fffff000 R08: ffffffff8957eb41 R09: 00000000fffff000
R10: 0000000000000005 R11: 0000000000000000 R12: dffffc0000000000
R13: ffff8880117bdf10 R14: ffffffff81c08eb7 R15: 0000000000000003
FS: 0000000000000000(0000) GS:ffff8880d7ae5000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f93a1021138 CR3: 00000000207a9000 CR4: 0000000000350ef0
Call Trace:
<TASK>
__sk_destruct+0x82/0xae0 net/core/sock.c:2356
rcu_do_batch kernel/rcu/tree.c:2645 [inline]
rcu_core+0x59c/0x1100 kernel/rcu/tree.c:2897
handle_softirqs+0x1e4/0x9b0 kernel/softirq.c:622
run_ksoftirqd kernel/softirq.c:1076 [inline]
run_ksoftirqd+0x38/0x60 kernel/softirq.c:1068
smpboot_thread_fn+0x458/0xc80 kernel/smpboot.c:160
kthread+0x396/0x4a0 kernel/kthread.c:436
ret_from_fork+0x8e0/0xe40 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Fixes: e994b2f0fb92 ("tcp: do not lock listener to process SYN packets")
Reported-by: Taras Madan <tarasmadan@google.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260914011420.115556-1-kuniyu@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/tcp_ipv6.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c
index df9c29eb5c1f4..7fa4ed2fd4f16 100644
--- a/net/ipv6/tcp_ipv6.c
+++ b/net/ipv6/tcp_ipv6.c
@@ -1604,7 +1604,8 @@ int tcp_v6_do_rcv(struct sock *sk, struct sk_buff *skb)
by tcp. Feel free to propose better solution.
--ANK (980728)
*/
- if (np->rxopt.all && sk->sk_state != TCP_LISTEN)
+ if (np->rxopt.all &&
+ !((1 << sk->sk_state) & (TCPF_LISTEN | TCPF_CLOSE)))
opt_skb = skb_clone_and_charge_r(skb, sk);
if (sk->sk_state == TCP_ESTABLISHED) { /* Fast path */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 109/398] drm/msm/dp: fix link bandwidth check when wide bus is enabled
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (107 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 108/398] drm/msm/dp: skip PUSH_IDLE when the link was never enabled Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 110/398] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask Greg Kroah-Hartman
` (293 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, William Bright, Dmitry Baryshkov,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: William Bright <william.bright@imd-tec.com>
[ Upstream commit 58995b11dfb7dda095d23f22fa4dc79b923b5adf ]
msm_dp_display_mode_valid() halves the pixel clock when either YUV420 or
wide bus is in use, then uses that halved value both for the controller
pixel clock limit and for the DP link bandwidth check.
Only YUV420 halves the data crossing the link. Wide bus widens the
internal DPU to DP interface to two pixels per clock, halving the
controller clock. Every pixel is still transmitted, so the link
bandwidth requirement remains.
As a result, modes needing up to twice the available link bandwidth pass
validation. On the IMDT QCS8550 SBC (rev5 with CYPD6125), where DP runs
over USB-C alt mode where only two lanes are available, 3840x2160@60 was
accepted despite needing 9.6 Gbps against the 8.64 Gbps the link can
carry.
Use a separate link pixel clock that is only halved for YUV420 for the
bandwidth calculation, leaving the wide bus halving to apply solely to
the controller pixel clock limit. With this, 4k@60 is correctly rejected
and 4k@30 selected instead.
Fixes: df9cf852ca30 ("drm/msm/dp: account for widebus and yuv420 during mode validation")
Assisted-by: Claude:claude-opus-5
Signed-off-by: William Bright <william.bright@imd-tec.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/746145/
Link: https://lore.kernel.org/r/20260812-msm-dp-link-bw-v1-1-b0e3ce1190be@imd-tec.com
[DB: dropped useless comment]
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dp/dp_display.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/msm/dp/dp_display.c b/drivers/gpu/drm/msm/dp/dp_display.c
index 0f6e4a1072a8f..131753ba57b5e 100644
--- a/drivers/gpu/drm/msm/dp/dp_display.c
+++ b/drivers/gpu/drm/msm/dp/dp_display.c
@@ -930,6 +930,7 @@ enum drm_mode_status msm_dp_bridge_mode_valid(struct drm_bridge *bridge,
u32 mode_rate_khz = 0, supported_rate_khz = 0, mode_bpp = 0;
struct msm_dp *dp;
int mode_pclk_khz = mode->clock;
+ int link_pclk_khz;
bool is_yuv_420;
dp = to_dp_bridge(bridge)->msm_dp_display;
@@ -951,6 +952,8 @@ enum drm_mode_status msm_dp_bridge_mode_valid(struct drm_bridge *bridge,
if (is_yuv_420 && !msm_dp_display->panel->vsc_sdp_supported)
return MODE_NO_420;
+ link_pclk_khz = is_yuv_420 ? mode_pclk_khz / 2 : mode_pclk_khz;
+
if (is_yuv_420 || msm_dp_display->wide_bus_supported)
mode_pclk_khz /= 2;
@@ -962,9 +965,9 @@ enum drm_mode_status msm_dp_bridge_mode_valid(struct drm_bridge *bridge,
mode_bpp = default_bpp;
mode_bpp = msm_dp_panel_get_mode_bpp(msm_dp_display->panel,
- mode_bpp, mode_pclk_khz);
+ mode_bpp, link_pclk_khz);
- mode_rate_khz = mode_pclk_khz * mode_bpp;
+ mode_rate_khz = link_pclk_khz * mode_bpp;
supported_rate_khz = link_info->num_lanes * link_info->rate * 8;
if (mode_rate_khz > supported_rate_khz)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 163/438] tcp: do not let tcp_rmem be set below 4096
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (161 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 162/438] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 164/438] ksmbd: return buffer overflow for partial filesystem info Greg Kroah-Hartman
` (286 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Simon Horman,
Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 83a945a529d6e002dd7339c532288a931f463dba ]
We can hit a division by zero crash in tcp_rcvbuf_grow()
and tcp_rcv_space_adjust():
divide error: 0000 [#1] PREEMPT SMP
RIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939
...
grow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval);
The division uses oldval = tp->rcvq_space.space as divisor.
When tp->rcvq_space.space is zero, this leads to a divide-by-zero
exception.
tp->rcvq_space.space is initialized in tcp_init_buffer_space():
tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd,
(u32)TCP_INIT_CWND * tp->advmss);
If tcp_rmem[1] is configured to very small values (such as 1),
sk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which
computes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0.
This sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and
tp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked,
tcp_rcvbuf_grow() divides by oldval == 0.
Back in 2015, commit b1cb59cf2efe ("net: sysctl_net_core: check SNDBUF
and RCVBUF for min length") ensured that net.core.rmem_default and
net.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly,
SO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF).
However, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing
arbitrarily small values.
Because SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline
alignment, its value varies across architectures and configuration options.
Using a fixed constant of 4096 ensures a predictable, architecture-
independent lower bound that is safely above SOCK_MIN_RCVBUF everywhere
and matches the documented 4K default.
Fix this by setting tcp_rmem.extra1 to 4096 and updating the documentation.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260912144848.3448026-1-edumazet@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/networking/ip-sysctl.rst | 2 ++
net/ipv4/sysctl_net_ipv4.c | 4 +++-
2 files changed, 5 insertions(+), 1 deletion(-)
diff --git a/Documentation/networking/ip-sysctl.rst b/Documentation/networking/ip-sysctl.rst
index b05829e44d8fc..f7af0286341c9 100644
--- a/Documentation/networking/ip-sysctl.rst
+++ b/Documentation/networking/ip-sysctl.rst
@@ -874,6 +874,8 @@ tcp_rmem - vector of 3 INTEGERs: min, default, max
case this value is ignored.
Default: between 131072 and 32MB, depending on RAM size.
+ Each of the three values cannot be set below 4096.
+
tcp_sack - BOOLEAN
Enable select acknowledgments (SACKS).
diff --git a/net/ipv4/sysctl_net_ipv4.c b/net/ipv4/sysctl_net_ipv4.c
index ca1180dba1dea..e921cb381b53c 100644
--- a/net/ipv4/sysctl_net_ipv4.c
+++ b/net/ipv4/sysctl_net_ipv4.c
@@ -51,6 +51,8 @@ static int tcp_ecn_mode_max = 5;
static u32 icmp_errors_extension_mask_all =
GENMASK_U8(ICMP_ERR_EXT_COUNT - 1, 0);
+static int tcp_min_rcvbuf = 4096;
+
/* obsolete */
static int sysctl_tcp_low_latency __read_mostly;
@@ -1462,7 +1464,7 @@ static struct ctl_table ipv4_net_table[] = {
.maxlen = sizeof(init_net.ipv4.sysctl_tcp_rmem),
.mode = 0644,
.proc_handler = proc_dointvec_minmax,
- .extra1 = SYSCTL_ONE,
+ .extra1 = &tcp_min_rcvbuf,
},
{
.procname = "tcp_comp_sack_delay_ns",
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 110/398] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (108 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 109/398] drm/msm/dp: fix link bandwidth check when wide bus is enabled Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 111/398] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map Greg Kroah-Hartman
` (292 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Fitzgerald <rf@opensource.cirrus.com>
[ Upstream commit 4d855d747521505b54457c96bc73577bf74b2374 ]
Rename the ch_mask member of snd_soc_dai_link_ch_map to cpu_ch_mask,
as that is what it is used for.
The CPU and codec channel masks are not necessarily the same, and are
quite likely different. SoundWire and I2S/TDM both support assigning
different sample slots to each codec, so for example channel 0 on each
codec could map to different channels at the CPU. So it's quite normal
that the channel mask at the CPU end is different for each codec, but
the codec channel masks are the same for each codec.
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260910114500.1586637-2-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 6b382bdfe26a ("ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc.h | 2 +-
sound/soc/sdw_utils/soc_sdw_utils.c | 2 +-
sound/soc/soc-pcm.c | 2 +-
3 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/include/sound/soc.h b/include/sound/soc.h
index 33968935d00a9..99a8edfd1d7d8 100644
--- a/include/sound/soc.h
+++ b/include/sound/soc.h
@@ -682,7 +682,7 @@ struct snd_soc_dai_link_component {
struct snd_soc_dai_link_ch_map {
unsigned int cpu;
unsigned int codec;
- unsigned int ch_mask;
+ unsigned int cpu_ch_mask;
};
struct snd_soc_dai_link {
diff --git a/sound/soc/sdw_utils/soc_sdw_utils.c b/sound/soc/sdw_utils/soc_sdw_utils.c
index 3facb78748acf..2c5c370503675 100644
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -974,7 +974,7 @@ int asoc_sdw_hw_params(struct snd_pcm_substream *substream,
* ASoC will set the corresponding channel numbers for each cpu dai.
*/
for_each_link_ch_maps(rtd->dai_link, i, ch_maps)
- ch_maps->ch_mask = ch_mask << (i * step);
+ ch_maps->cpu_ch_mask = ch_mask << (i * step);
return 0;
}
diff --git a/sound/soc/soc-pcm.c b/sound/soc/soc-pcm.c
index 99299364c9ba3..ebd766e00bac6 100644
--- a/sound/soc/soc-pcm.c
+++ b/sound/soc/soc-pcm.c
@@ -1133,7 +1133,7 @@ static int __soc_pcm_hw_params(struct snd_pcm_substream *substream,
*/
for_each_rtd_ch_maps(rtd, j, ch_maps)
if (ch_maps->cpu == i)
- ch_mask |= ch_maps->ch_mask;
+ ch_mask |= ch_maps->cpu_ch_mask;
/* fixup cpu channel number */
if (ch_mask)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 164/438] ksmbd: return buffer overflow for partial filesystem info
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (162 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 163/438] tcp: do not let tcp_rmem be set below 4096 Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 165/438] ksmbd: fix partial file information responses Greg Kroah-Hartman
` (285 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 0ecd35fac4b4f2828490689b46039744d201dcb0 ]
The query-info buffer check returns STATUS_INFO_LENGTH_MISMATCH for
every output buffer smaller than the complete response. Variable-length
filesystem information instead requires STATUS_BUFFER_OVERFLOW when the
fixed portion fits but the complete data does not.
Pass the fixed size for each filesystem information class to the buffer
checker. Keep INFO_LENGTH_MISMATCH for buffers below that size, and
return BUFFER_OVERFLOW with a response truncated to the requested length
for larger partial buffers.
This fixes smb2.getinfo.qfs_buffercheck.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Stable-dep-of: 9fa26285ae70 ("ksmbd: keep compound responses on query info errors")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 26 +++++++++++++++++++++++++-
1 file changed, 25 insertions(+), 1 deletion(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 3cb39dc7b149c..cd533dbdc2b23 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -5622,21 +5622,30 @@ int smb2_query_dir(struct ksmbd_work *work)
/**
* buffer_check_err() - helper function to check buffer errors
* @reqOutputBufferLength: max buffer length expected in command response
+ * @fixed_len: minimum fixed response length
* @rsp: query info response buffer contains output buffer length
* @rsp_org: base response buffer pointer in case of chained response
*
* Return: 0 on success, otherwise error
*/
static int buffer_check_err(int reqOutputBufferLength,
+ unsigned int fixed_len,
struct smb2_query_info_rsp *rsp,
void *rsp_org)
{
- if (reqOutputBufferLength < le32_to_cpu(rsp->OutputBufferLength)) {
+ unsigned int output_len = le32_to_cpu(rsp->OutputBufferLength);
+
+ if (reqOutputBufferLength < fixed_len) {
pr_err("Invalid Buffer Size Requested\n");
rsp->hdr.Status = STATUS_INFO_LENGTH_MISMATCH;
*(__be32 *)rsp_org = cpu_to_be32(sizeof(struct smb2_hdr));
return -EINVAL;
}
+
+ if (reqOutputBufferLength < output_len) {
+ rsp->hdr.Status = STATUS_BUFFER_OVERFLOW;
+ rsp->OutputBufferLength = cpu_to_le32(reqOutputBufferLength);
+ }
return 0;
}
@@ -5699,11 +5708,13 @@ static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
case FILE_STANDARD_INFORMATION:
get_standard_info_pipe(rsp, rsp_org);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, rsp_org);
break;
case FILE_INTERNAL_INFORMATION:
get_internal_info_pipe(rsp, id, rsp_org);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, rsp_org);
break;
default:
@@ -6524,6 +6535,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
}
if (!rc)
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, work->response_buf);
ksmbd_fd_put(work, fp);
@@ -6545,6 +6557,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
struct kstatfs stfs;
struct path path;
int rc = 0, len;
+ unsigned int fixed_len = 0;
if (!share->path)
return -EIO;
@@ -6579,6 +6592,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->DeviceCharacteristics |=
cpu_to_le32(FILE_READ_ONLY_DEVICE);
rsp->OutputBufferLength = cpu_to_le32(8);
+ fixed_len = 8;
break;
}
case FS_ATTRIBUTE_INFORMATION:
@@ -6631,6 +6645,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->FileSystemNameLen = cpu_to_le32(len);
sz = sizeof(FILE_SYSTEM_ATTRIBUTE_INFO) + len;
rsp->OutputBufferLength = cpu_to_le32(sz);
+ fixed_len = 16;
break;
}
case FS_VOLUME_INFORMATION:
@@ -6658,6 +6673,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->SupportsObjects = 0;
sz = sizeof(struct filesystem_vol_info) + len;
rsp->OutputBufferLength = cpu_to_le32(sz);
+ fixed_len = 24;
break;
}
case FS_SIZE_INFORMATION:
@@ -6670,6 +6686,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->SectorsPerAllocationUnit = cpu_to_le32(1);
info->BytesPerSector = cpu_to_le32(stfs.f_bsize);
rsp->OutputBufferLength = cpu_to_le32(24);
+ fixed_len = 24;
break;
}
case FS_FULL_SIZE_INFORMATION:
@@ -6685,6 +6702,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->SectorsPerAllocationUnit = cpu_to_le32(1);
info->BytesPerSector = cpu_to_le32(stfs.f_bsize);
rsp->OutputBufferLength = cpu_to_le32(32);
+ fixed_len = 32;
break;
}
case FS_OBJECT_ID_INFORMATION:
@@ -6705,6 +6723,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->extended_info.rel_date = 0;
memcpy(info->extended_info.version_string, "1.1.0", strlen("1.1.0"));
rsp->OutputBufferLength = cpu_to_le32(64);
+ fixed_len = 64;
break;
}
case FS_SECTOR_SIZE_INFORMATION:
@@ -6726,6 +6745,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->ByteOffsetForSectorAlignment = 0;
info->ByteOffsetForPartitionAlignment = 0;
rsp->OutputBufferLength = cpu_to_le32(28);
+ fixed_len = 28;
break;
}
case FS_CONTROL_INFORMATION:
@@ -6746,6 +6766,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->DefaultQuotaLimit = cpu_to_le64(SMB2_NO_FID);
info->Padding = 0;
rsp->OutputBufferLength = cpu_to_le32(48);
+ fixed_len = 48;
break;
}
case FS_POSIX_INFORMATION:
@@ -6766,6 +6787,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->TotalFileNodes = cpu_to_le64(stfs.f_files);
info->FreeFileNodes = cpu_to_le64(stfs.f_ffree);
rsp->OutputBufferLength = cpu_to_le32(56);
+ fixed_len = 56;
}
break;
}
@@ -6774,6 +6796,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
return -EOPNOTSUPP;
}
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ fixed_len,
rsp, work->response_buf);
path_put(&path);
@@ -6875,6 +6898,7 @@ static int smb2_get_info_sec(struct ksmbd_work *work,
rsp->OutputBufferLength = cpu_to_le32(secdesclen);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, work->response_buf);
if (rc)
goto err_out;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 111/398] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (109 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 110/398] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 112/398] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params Greg Kroah-Hartman
` (291 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Fitzgerald <rf@opensource.cirrus.com>
[ Upstream commit 88b14c0d0bab5c0f3e7c641f274e3c70210c0e36 ]
Add a codec_ch_mask member to snd_soc_dai_link_ch_map.
The CPU and codec channel masks are not necessarily the same, and are
quite likely different. SoundWire and I2S/TDM both support assigning
different sample slots to each codec, so for example channel 0 on each
codec could map to different channels at the CPU.
It is also possible for one TX channel to map to multiple RX channels.
So it isn't _always_ safe to assume that the total number of set bits
in the CPU ch_mask is the same as the total number of enabled channels
on the codec.
For example consider this mapping on a capture stream:
CPU0 CODEC0 cpu_ch_mask = 0x03
CPU1 CODEC0 cpu_ch_mask = 0x03
This could be either four TX channels on the codec split across two
receiving CPUs, or two TX channels on the codec duplicated to two CPUs.
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260910114500.1586637-3-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 6b382bdfe26a ("ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc.h | 1 +
1 file changed, 1 insertion(+)
diff --git a/include/sound/soc.h b/include/sound/soc.h
index 99a8edfd1d7d8..bfe8cd7cc338d 100644
--- a/include/sound/soc.h
+++ b/include/sound/soc.h
@@ -683,6 +683,7 @@ struct snd_soc_dai_link_ch_map {
unsigned int cpu;
unsigned int codec;
unsigned int cpu_ch_mask;
+ unsigned int codec_ch_mask;
};
struct snd_soc_dai_link {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 165/438] ksmbd: fix partial file information responses
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (163 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 164/438] ksmbd: return buffer overflow for partial filesystem info Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 166/438] ksmbd: keep compound responses on query info errors Greg Kroah-Hartman
` (284 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 6b8b79226bc3e0ac3fdd4e91836241af712e8cd1 ]
Variable-length file information handlers use the client output length
while constructing the response. FILE_ALL_INFORMATION can consequently
return -EINVAL before the common buffer check, while stream information
can stop building the complete result too early.
Build the complete response within the available server response buffer
and apply the client output length only when selecting the final status
and transmitted length. Use the protocol-defined fixed sizes for all,
alternate-name, and stream information to distinguish
STATUS_INFO_LENGTH_MISMATCH from STATUS_BUFFER_OVERFLOW.
This fixes smb2.getinfo.qfile_buffercheck.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Stable-dep-of: 9fa26285ae70 ("ksmbd: keep compound responses on query info errors")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 31 ++++++++++++++++++++-----------
1 file changed, 20 insertions(+), 11 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index cd533dbdc2b23..f6b9a0ad922ff 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -5997,7 +5997,6 @@ static int get_file_all_info(struct ksmbd_work *work,
char *filename;
u64 time;
int ret, buf_free_len, filename_len;
- struct smb2_query_info_req *req = ksmbd_req_buf_next(work);
if (!(fp->daccess & FILE_READ_ATTRIBUTES_LE)) {
ksmbd_debug(SMB, "no right to read the attributes : 0x%x\n",
@@ -6010,10 +6009,9 @@ static int get_file_all_info(struct ksmbd_work *work,
return PTR_ERR(filename);
filename_len = strlen(filename);
- buf_free_len = smb2_calc_max_out_buf_len(work,
+ buf_free_len = smb2_resp_buf_len(work,
offsetof(struct smb2_query_info_rsp, Buffer) +
- offsetof(struct smb2_file_all_info, FileName),
- le32_to_cpu(req->OutputBufferLength));
+ offsetof(struct smb2_file_all_info, FileName));
if (buf_free_len < (filename_len + 1) * 2) {
kfree(filename);
return -EINVAL;
@@ -6104,7 +6102,6 @@ static int get_file_stream_info(struct ksmbd_work *work,
ssize_t xattr_list_len;
int nbytes = 0, streamlen, stream_name_len, next, idx = 0;
int buf_free_len;
- struct smb2_query_info_req *req = ksmbd_req_buf_next(work);
int ret;
ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS,
@@ -6114,10 +6111,8 @@ static int get_file_stream_info(struct ksmbd_work *work,
file_info = (struct smb2_file_stream_info *)rsp->Buffer;
- buf_free_len =
- smb2_calc_max_out_buf_len(work,
- offsetof(struct smb2_query_info_rsp, Buffer),
- le32_to_cpu(req->OutputBufferLength));
+ buf_free_len = smb2_resp_buf_len(work,
+ offsetof(struct smb2_query_info_rsp, Buffer));
if (buf_free_len < 0)
goto out;
@@ -6430,6 +6425,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
struct ksmbd_file *fp;
int fileinfoclass = 0;
int rc = 0;
+ unsigned int fixed_len;
unsigned int id = KSMBD_NO_FID, pid = KSMBD_NO_FID;
if (test_share_config_flag(work->tcon->share_conf,
@@ -6533,10 +6529,23 @@ static int smb2_get_info_file(struct ksmbd_work *work,
fileinfoclass);
rc = -EOPNOTSUPP;
}
- if (!rc)
+ if (!rc) {
+ fixed_len = le32_to_cpu(rsp->OutputBufferLength);
+ switch (fileinfoclass) {
+ case FILE_ALL_INFORMATION:
+ fixed_len = FILE_ALL_INFORMATION_SIZE;
+ break;
+ case FILE_ALTERNATE_NAME_INFORMATION:
+ fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
+ break;
+ case FILE_STREAM_INFORMATION:
+ fixed_len = FILE_STREAM_INFORMATION_SIZE;
+ break;
+ }
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
- le32_to_cpu(rsp->OutputBufferLength),
+ fixed_len,
rsp, work->response_buf);
+ }
ksmbd_fd_put(work, fp);
iov_pin_out:
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 112/398] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (110 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 111/398] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 113/398] spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register Greg Kroah-Hartman
` (290 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Fitzgerald <rf@opensource.cirrus.com>
[ Upstream commit 6b382bdfe26a2232091bf743e454e6794295783e ]
In __soc_pcm_hw_params() if there is a snd_soc_dai_link_ch_map with
non-zero codec_ch_mask, use that channel mask to restrict which channels
are enabled on the codec. But only if there isn't a TDM mask.
It is possible that a snd_soc_dai_link_ch_map could include the same codec
multiple times on different CPUs so the for_each_rtd_ch_maps() loop
accumulates the channel masks for all entries of that codec.
If a TDM mask was also set, it takes priority and is used instead of any
possible snd_soc_dai_link_ch_map entries. (They cannot be ANDed together
because the bit positions are indicating different things: TDM is a bit
for each TDM slot, codec_ch_mask is a bit for each codec channel.)
This fixes a problem of incorrect TX channels enabled on the codec when
multiple codecs are aggregated on a single capture link. For example:
- Two CPUs with six 4-channel codecs.
- The machine driver chooses to assign one channel from each codec to
one channel on the CPU
- But the codec hw_params() would be passed a channel count of 6, which
(a) is more channels than the codec has and (b) allows enabling channels
that should not be driving the audio bus.
Fixes: ac950278b087 ("ASoC: add N cpus to M codecs dai link support")
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260910114500.1586637-4-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/soc-pcm.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
diff --git a/sound/soc/soc-pcm.c b/sound/soc/soc-pcm.c
index ebd766e00bac6..b6e35cfe50b7c 100644
--- a/sound/soc/soc-pcm.c
+++ b/sound/soc/soc-pcm.c
@@ -1075,7 +1075,9 @@ static int __soc_pcm_hw_params(struct snd_pcm_substream *substream,
goto out;
for_each_rtd_codec_dais(rtd, i, codec_dai) {
- unsigned int tdm_mask = snd_soc_dai_tdm_mask_get(codec_dai, substream->stream);
+ unsigned int ch_mask = snd_soc_dai_tdm_mask_get(codec_dai, substream->stream);
+ struct snd_soc_dai_link_ch_map *ch_maps;
+ int j;
/*
* Skip CODECs which don't support the current stream type,
@@ -1097,9 +1099,15 @@ static int __soc_pcm_hw_params(struct snd_pcm_substream *substream,
/* copy params for each codec */
tmp_params = *params;
- /* fixup params based on TDM slot masks */
- if (tdm_mask)
- soc_pcm_codec_params_fixup(&tmp_params, tdm_mask);
+ /* fixup params based on TDM or ch_map masks */
+ if (!ch_mask) {
+ for_each_rtd_ch_maps(rtd, j, ch_maps)
+ if (ch_maps->codec == i)
+ ch_mask |= ch_maps->codec_ch_mask;
+ }
+
+ if (ch_mask)
+ soc_pcm_codec_params_fixup(&tmp_params, ch_mask);
ret = snd_soc_dai_hw_params(codec_dai, substream,
&tmp_params);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 166/438] ksmbd: keep compound responses on query info errors
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (164 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 165/438] ksmbd: fix partial file information responses Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 167/438] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() Greg Kroah-Hartman
` (283 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mobin Aydinfar, ChenXiaoSong,
Namjae Jeon, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 9fa26285ae70ac2d3d1b47459a6b4463ab053e1c ]
Do not reset the RFC1002 length of the complete response when a query
info buffer is too small. The current command will add its error response
through ksmbd_iov_pin_rsp(), while resetting the base length can truncate
earlier responses in a compound request.
This lets ksmbd return the earlier responses and the query-info error
response together. Remove the now-unused rsp_org parameter from the pipe
query-info helpers.
Fixes: e2b76ab8b5c9 ("ksmbd: add support for read compound")
Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 31 ++++++++++++-------------------
1 file changed, 12 insertions(+), 19 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index f6b9a0ad922ff..5312ae3fc5023 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -5624,21 +5624,18 @@ int smb2_query_dir(struct ksmbd_work *work)
* @reqOutputBufferLength: max buffer length expected in command response
* @fixed_len: minimum fixed response length
* @rsp: query info response buffer contains output buffer length
- * @rsp_org: base response buffer pointer in case of chained response
*
* Return: 0 on success, otherwise error
*/
static int buffer_check_err(int reqOutputBufferLength,
unsigned int fixed_len,
- struct smb2_query_info_rsp *rsp,
- void *rsp_org)
+ struct smb2_query_info_rsp *rsp)
{
unsigned int output_len = le32_to_cpu(rsp->OutputBufferLength);
if (reqOutputBufferLength < fixed_len) {
pr_err("Invalid Buffer Size Requested\n");
rsp->hdr.Status = STATUS_INFO_LENGTH_MISMATCH;
- *(__be32 *)rsp_org = cpu_to_be32(sizeof(struct smb2_hdr));
return -EINVAL;
}
@@ -5649,8 +5646,7 @@ static int buffer_check_err(int reqOutputBufferLength,
return 0;
}
-static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp,
- void *rsp_org)
+static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp)
{
struct smb2_file_standard_info *sinfo;
@@ -5665,8 +5661,7 @@ static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp,
cpu_to_le32(sizeof(struct smb2_file_standard_info));
}
-static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num,
- void *rsp_org)
+static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num)
{
struct smb2_file_internal_info *file_info;
@@ -5680,8 +5675,7 @@ static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num,
static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
struct smb2_query_info_req *req,
- struct smb2_query_info_rsp *rsp,
- void *rsp_org)
+ struct smb2_query_info_rsp *rsp)
{
u64 id;
int rc;
@@ -5706,16 +5700,16 @@ static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
switch (req->FileInfoClass) {
case FILE_STANDARD_INFORMATION:
- get_standard_info_pipe(rsp, rsp_org);
+ get_standard_info_pipe(rsp);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
le32_to_cpu(rsp->OutputBufferLength),
- rsp, rsp_org);
+ rsp);
break;
case FILE_INTERNAL_INFORMATION:
- get_internal_info_pipe(rsp, id, rsp_org);
+ get_internal_info_pipe(rsp, id);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
le32_to_cpu(rsp->OutputBufferLength),
- rsp, rsp_org);
+ rsp);
break;
default:
ksmbd_debug(SMB, "smb2_info_file_pipe for %u not supported\n",
@@ -6431,8 +6425,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
if (test_share_config_flag(work->tcon->share_conf,
KSMBD_SHARE_FLAG_PIPE)) {
/* smb2 info file called for pipe */
- rc = smb2_get_info_file_pipe(work->sess, req, rsp,
- work->response_buf);
+ rc = smb2_get_info_file_pipe(work->sess, req, rsp);
goto iov_pin_out;
}
@@ -6544,7 +6537,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
}
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
fixed_len,
- rsp, work->response_buf);
+ rsp);
}
ksmbd_fd_put(work, fp);
@@ -6806,7 +6799,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
}
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
fixed_len,
- rsp, work->response_buf);
+ rsp);
path_put(&path);
if (!rc)
@@ -6908,7 +6901,7 @@ static int smb2_get_info_sec(struct ksmbd_work *work,
rsp->OutputBufferLength = cpu_to_le32(secdesclen);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
le32_to_cpu(rsp->OutputBufferLength),
- rsp, work->response_buf);
+ rsp);
if (rc)
goto err_out;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 113/398] spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (111 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 112/398] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 114/398] Input: trackpoint - fix the inertia attribute name in the ABI document Greg Kroah-Hartman
` (289 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gabor Juhos, Md Sadre Alam,
Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gabor Juhos <j4g8y7@gmail.com>
[ Upstream commit 930a7312c946bf4731721cadd82bb9a2ada496ca ]
The description of commit bfb34eced559 ("mtd: rawnand: qcom: avoid writing
to obsolete register") says this:
"QPIC_EBI2_ECC_BUF_CFG register got obsolete from QPIC V2.0 onwards.
Avoid writing this register if QPIC version is V2.0 or newer."
Although the referenced commit is related to the 'qcom-nandc' driver,
however the hardware supported by the current driver is also based on
QPIC v2.0 so we should avoid writing that register here as well.
Remove the register writing code to avoid undefined behaviour.
Fixes: 7304d1909080 ("spi: spi-qpic: add driver for QCOM SPI NAND flash Interface")
Signed-off-by: Gabor Juhos <j4g8y7@gmail.com>
Reviewed-by: Md Sadre Alam <md.alam@oss.qualcomm.com>
Link: https://patch.msgid.link/20260909-qpic-snand-avoid-ebi2-reg-write-v1-1-9b1b1466cc75@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-qpic-snand.c | 4 ----
1 file changed, 4 deletions(-)
diff --git a/drivers/spi/spi-qpic-snand.c b/drivers/spi/spi-qpic-snand.c
index 42f8fb272fa68..222e4aa7ee488 100644
--- a/drivers/spi/spi-qpic-snand.c
+++ b/drivers/spi/spi-qpic-snand.c
@@ -740,8 +740,6 @@ static int qcom_spi_read_cw_raw(struct qcom_nand_controller *snandc, u8 *data_bu
qcom_write_reg_dma(snandc, &snandc->regs->addr0, NAND_ADDR0, 2, 0);
qcom_write_reg_dma(snandc, &snandc->regs->cfg0, NAND_DEV0_CFG0, 3, 0);
- qcom_write_reg_dma(snandc, &snandc->regs->ecc_buf_cfg, NAND_EBI2_ECC_BUF_CFG, 1, 0);
-
qcom_write_reg_dma(snandc, &snandc->regs->erased_cw_detect_cfg_clr,
NAND_ERASED_CW_DETECT_CFG, 1, 0);
qcom_write_reg_dma(snandc, &snandc->regs->erased_cw_detect_cfg_set,
@@ -1012,8 +1010,6 @@ static void qcom_spi_config_page_write(struct qcom_nand_controller *snandc)
{
qcom_write_reg_dma(snandc, &snandc->regs->addr0, NAND_ADDR0, 2, 0);
qcom_write_reg_dma(snandc, &snandc->regs->cfg0, NAND_DEV0_CFG0, 3, 0);
- qcom_write_reg_dma(snandc, &snandc->regs->ecc_buf_cfg, NAND_EBI2_ECC_BUF_CFG,
- 1, NAND_BAM_NEXT_SGL);
}
static void qcom_spi_config_cw_write(struct qcom_nand_controller *snandc)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 167/438] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (165 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 166/438] ksmbd: keep compound responses on query info errors Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 168/438] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained Greg Kroah-Hartman
` (282 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baineng Shou, Frank Li, Vinod Koul,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baineng Shou <shoubaineng@gmail.com>
[ Upstream commit 075bc7b1d3dde5ed43fbaabbc1a69f09b7fc3a47 ]
In mmp_pdma_prep_slave_sg(), for_each_sg() iterates the scatterlist
putting each entry into 'sg', but the entry length is read from 'sgl'
(the list head) instead of 'sg' (the current entry):
for_each_sg(sgl, sg, sg_len, i) {
addr = sg_dma_address(sg);
avail = sg_dma_len(sgl); /* should be 'sg' */
Consequently 'avail' is always the length of the first entry. For
multi-sg lists this causes out-of-bounds reads when a later entry is
shorter than the first, and silent data loss when it is longer.
Single-sg or uniformly-sized lists happen to mask the issue.
Fixes: c8acd6aa6bed3 ("dmaengine: mmp-pdma support")
Signed-off-by: Baineng Shou <shoubaineng@gmail.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260910021652.1296640-1-shoubaineng@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/mmp_pdma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/mmp_pdma.c b/drivers/dma/mmp_pdma.c
index 78e3e07e681df..ed520737882bc 100644
--- a/drivers/dma/mmp_pdma.c
+++ b/drivers/dma/mmp_pdma.c
@@ -712,7 +712,7 @@ mmp_pdma_prep_slave_sg(struct dma_chan *dchan, struct scatterlist *sgl,
for_each_sg(sgl, sg, sg_len, i) {
addr = sg_dma_address(sg);
- avail = sg_dma_len(sgl);
+ avail = sg_dma_len(sg);
do {
len = min_t(size_t, avail, PDMA_MAX_DESC_BYTES);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 114/398] Input: trackpoint - fix the inertia attribute name in the ABI document
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (112 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 113/398] spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 115/398] gpio: virtuser: skip free_irq when no IRQ is installed Greg Kroah-Hartman
` (288 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Dmitry Torokhov,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 45b0037899704caf9078be2be4de69361ca7d933 ]
The attribute is created as "inertia" (TRACKPOINT_INT_ATTR(inertia, ...)
in drivers/input/mouse/trackpoint.c); the ABI file spells the path
"intertia". The description below it already says inertia.
Fix the spelling.
Fixes: aebb47d4e7a9 ("Input: trackpoint: document sysfs interface")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260905102038.42882-1-kmehltretter@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/ABI/testing/sysfs-devices-platform-trackpoint | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Documentation/ABI/testing/sysfs-devices-platform-trackpoint b/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
index df11901a6b3df..7954434b0434a 100644
--- a/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
+++ b/Documentation/ABI/testing/sysfs-devices-platform-trackpoint
@@ -5,7 +5,7 @@ Contact: linux-input@vger.kernel.org
Description:
(RW) Trackpoint sensitivity.
-What: /sys/devices/platform/i8042/.../intertia
+What: /sys/devices/platform/i8042/.../inertia
Date: Aug, 2005
KernelVersion: 2.6.14
Contact: linux-input@vger.kernel.org
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 168/438] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (166 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 167/438] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 169/438] Bluetooth: btintel_pcie: validate TX skb length in send_sync Greg Kroah-Hartman
` (281 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b6919040d9958e2fc1ae,
ThangNN99, Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: ThangNN99 <ngocthang2710.1999@gmail.com>
[ Upstream commit 6610c6fe4b8936c232048e6049bf77c70a6f759c ]
hci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev->tx_work
unconditionally. They can run from the L2CAP/SCO/ISO socket send path
while hci_dev_close_sync() is draining hdev->workqueue (HCIDEVDOWN
racing with a socket write). Since that queue_work() is not chained
work from the tx_work worker itself, __queue_work() sees the queue
marked __WQ_DRAINING, warns "cannot queue %ps on wq %s", and drops
the work:
WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work
Call Trace:
queue_work_on
l2cap_chan_send
l2cap_sock_sendmsg
...
hci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before
draining, but only hci_cmd_work() and handle_cmd_cnt_and_timer()
check it before queuing. Route the tx_work producers through the
same guard via a shared hci_sched_tx() helper.
Fixes: 525daaea459f ("Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close")
Reported-by: syzbot+b6919040d9958e2fc1ae@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b6919040d9958e2fc1ae
Signed-off-by: ThangNN99 <ngocthang2710.1999@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_core.c | 17 ++++++++++++++---
1 file changed, 14 insertions(+), 3 deletions(-)
diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
index f747492da5f66..86a9677ed7025 100644
--- a/net/bluetooth/hci_core.c
+++ b/net/bluetooth/hci_core.c
@@ -3234,6 +3234,17 @@ static void hci_queue_acl(struct hci_chan *chan, struct sk_buff_head *queue,
bt_dev_dbg(hdev, "chan %p queued %d", chan, skb_queue_len(queue));
}
+/* Queue hdev->tx_work, unless hdev->workqueue is being drained by
+ * hci_dev_close_sync(), which would otherwise WARN and drop the work.
+ */
+static void hci_sched_tx(struct hci_dev *hdev)
+{
+ rcu_read_lock();
+ if (!hci_dev_test_flag(hdev, HCI_CMD_DRAIN_WORKQUEUE))
+ queue_work(hdev->workqueue, &hdev->tx_work);
+ rcu_read_unlock();
+}
+
void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
{
struct hci_dev *hdev = chan->conn->hdev;
@@ -3242,7 +3253,7 @@ void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
hci_queue_acl(chan, &chan->data_q, skb, flags);
- queue_work(hdev->workqueue, &hdev->tx_work);
+ hci_sched_tx(hdev);
}
/* Send SCO data */
@@ -3267,7 +3278,7 @@ void hci_send_sco(struct hci_conn *conn, struct sk_buff *skb)
bt_dev_dbg(hdev, "hcon %p queued %d", conn,
skb_queue_len(&conn->data_q));
- queue_work(hdev->workqueue, &hdev->tx_work);
+ hci_sched_tx(hdev);
}
/* Send ISO data */
@@ -3338,7 +3349,7 @@ void hci_send_iso(struct hci_conn *conn, struct sk_buff *skb)
hci_queue_iso(conn, &conn->data_q, skb);
- queue_work(hdev->workqueue, &hdev->tx_work);
+ hci_sched_tx(hdev);
}
/* ---- HCI TX task (outgoing data) ---- */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 115/398] gpio: virtuser: skip free_irq when no IRQ is installed
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (113 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 114/398] Input: trackpoint - fix the inertia attribute name in the ABI document Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 116/398] ALSA: usb: 6fire: Avoid embedded URBs Greg Kroah-Hartman
` (287 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Linus Walleij,
Bartosz Golaszewski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
[ Upstream commit 50fd0ada8d37587223001600933270b59cb30e19 ]
Disabling interrupt monitoring uses atomic_xchg() to clear the stored IRQ.
When monitoring is already disabled, atomic_xchg() returns 0. It must not
be passed to free_irq().
The bug is reproducible on an x86_64 QEMU guest with
CONFIG_GPIO_VIRTUSER=y and CONFIG_GPIO_SIM=y. Configure a live
gpio-virtuser device through configfs. Its input lookup must refer to a
live gpio-sim bank, such as key gpio-sim-test with offset 0. The
consumer's dev_name attribute is shown as <dev> below; then run:
echo 0 > /sys/kernel/debug/gpio-virtuser/<dev>/gpiod:input:0/interrupts
On an unpatched kernel, this reaches gpio_virtuser_interrupts_set() with
ld->irq still at its initial value 0, and free_irq() reports:
Trying to free already-free IRQ 0
The same reproducer completes without the warning on the patched kernel.
Fixes: 91581c4b3f29 ("gpio: virtuser: new virtual testing driver for the GPIO API")
Assisted-by: LLM
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260914051537.15320-1-runyu.xiao@seu.edu.cn
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpio/gpio-virtuser.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/gpio/gpio-virtuser.c b/drivers/gpio/gpio-virtuser.c
index 1901b4ba558f0..ce7ada0f17981 100644
--- a/drivers/gpio/gpio-virtuser.c
+++ b/drivers/gpio/gpio-virtuser.c
@@ -697,7 +697,8 @@ static int gpio_virtuser_interrupts_set(void *data, u64 val)
atomic_set(&ld->irq, irq);
} else {
irq = atomic_xchg(&ld->irq, 0);
- free_irq(irq, ld);
+ if (irq)
+ free_irq(irq, ld);
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 169/438] Bluetooth: btintel_pcie: validate TX skb length in send_sync
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (167 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 168/438] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 170/438] Bluetooth: coredump: Quiesce dump work on unregister Greg Kroah-Hartman
` (280 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chandrashekar Devegowda,
Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chandrashekar Devegowda <chandrashekar.devegowda@intel.com>
[ Upstream commit 4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9 ]
btintel_pcie_prepare_tx() copies skb->len bytes into a fixed
BTINTEL_PCIE_BUFFER_SIZE (4096) DMA slot via an unchecked memcpy.
Oversized packets are currently rejected only in
btintel_pcie_send_frame(); any future caller of
btintel_pcie_send_sync() would silently overflow the DMA buffer.
Add the bounds check in btintel_pcie_send_sync() itself, right
before skb_push() and the DMA copy.
Assisted-by: Copilot:claude-sonnet-5 code-review code-generation
Fixes: 6e65a09f9275 ("Bluetooth: btintel_pcie: Add *setup* function to download firmware")
Signed-off-by: Chandrashekar Devegowda <chandrashekar.devegowda@intel.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btintel_pcie.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c
index c64e96fe88976..aad466e453013 100644
--- a/drivers/bluetooth/btintel_pcie.c
+++ b/drivers/bluetooth/btintel_pcie.c
@@ -404,6 +404,12 @@ static int btintel_pcie_send_sync(struct btintel_pcie_data *data,
if (tfd_index > txq->count)
return -ERANGE;
+ if (skb->len > BTINTEL_PCIE_BUFFER_SIZE - BTINTEL_PCIE_HCI_TYPE_LEN) {
+ bt_dev_err(hdev, "TX skb too large (%u > %u)", skb->len,
+ BTINTEL_PCIE_BUFFER_SIZE - BTINTEL_PCIE_HCI_TYPE_LEN);
+ return -EMSGSIZE;
+ }
+
/* Firmware raises alive interrupt on HCI_OP_RESET or
* BTINTEL_HCI_OP_RESET
*/
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 116/398] ALSA: usb: 6fire: Avoid embedded URBs
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (114 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 115/398] gpio: virtuser: skip free_irq when no IRQ is installed Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 117/398] ALSA: 6fire: fix OOB write from device-reported iso length Greg Kroah-Hartman
` (286 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 9fe49dbc023e82dfaee7b245997d820d01742a9a ]
The USB 6fire driver uses URBs embedded in different structs for PCM,
MIDI and communication, and this is basically a buggy implementation
nowadays; since a URB is managed with a refcount, this may lead to a
UAF when the URB is released asynchronously.
For addressing the problem, this patch converts those embedded URBs to
ones that are properly allocated via usb_alloc_urb(). The
pcm_urb.packets[] is gone, as it's allocated by usb_alloc_urb(), hence
it's found in urb.iso_frame_desc[] instead.
The conversions are rather straightforward; each embedded struct urb
is changed to a pointer, and its callers are updated accordingly.
The resource for those structs are released in the common destructor
functions (usb6fire_comm_free(), etc), which are called at both the
init error path and the disconnect.
No functional changes, only compile-tested.
Link: https://lore.kernel.org/20260903130757.0668310a.michal.pecio@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260903160458.1938392-4-tiwai@suse.de
Stable-dep-of: 1589afe2d099 ("ALSA: 6fire: fix OOB write from device-reported iso length")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/6fire/comm.c | 42 +++++++++-----
sound/usb/6fire/comm.h | 2 +-
sound/usb/6fire/midi.c | 43 +++++++++-----
sound/usb/6fire/midi.h | 2 +-
sound/usb/6fire/pcm.c | 128 ++++++++++++++++++++++++-----------------
sound/usb/6fire/pcm.h | 5 +-
6 files changed, 136 insertions(+), 86 deletions(-)
diff --git a/sound/usb/6fire/comm.c b/sound/usb/6fire/comm.c
index bcfb34db37d95..cfaaad9d24028 100644
--- a/sound/usb/6fire/comm.c
+++ b/sound/usb/6fire/comm.c
@@ -21,7 +21,6 @@ enum {
static void usb6fire_comm_init_urb(struct comm_runtime *rt, struct urb *urb,
u8 *buffer, void *context, void(*handler)(struct urb *urb))
{
- usb_init_urb(urb);
urb->transfer_buffer = buffer;
urb->pipe = usb_sndintpipe(rt->chip->dev, COMM_EP);
urb->complete = handler;
@@ -142,6 +141,19 @@ static int usb6fire_comm_write16(struct comm_runtime *rt, u8 request,
return ret;
}
+static void usb6fire_comm_free(struct comm_runtime *rt)
+{
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->comm = NULL;
+
+ usb_free_urb(rt->receiver);
+ kfree(rt->receiver_buffer);
+ kfree(rt);
+}
+
int usb6fire_comm_init(struct sfire_chip *chip)
{
struct comm_runtime *rt = kzalloc(sizeof(struct comm_runtime),
@@ -154,14 +166,18 @@ int usb6fire_comm_init(struct sfire_chip *chip)
rt->receiver_buffer = kzalloc(COMM_RECEIVER_BUFSIZE, GFP_KERNEL);
if (!rt->receiver_buffer) {
- kfree(rt);
- return -ENOMEM;
+ ret = -ENOMEM;
+ goto error;
}
- urb = &rt->receiver;
+ urb = usb_alloc_urb(0, GFP_KERNEL);
+ if (!urb) {
+ ret = -ENOMEM;
+ goto error;
+ }
+ rt->receiver = urb;
rt->serial = 1;
rt->chip = chip;
- usb_init_urb(urb);
rt->init_urb = usb6fire_comm_init_urb;
rt->write8 = usb6fire_comm_write8;
rt->write16 = usb6fire_comm_write16;
@@ -176,13 +192,15 @@ int usb6fire_comm_init(struct sfire_chip *chip)
urb->interval = 1;
ret = usb_submit_urb(urb, GFP_KERNEL);
if (ret < 0) {
- kfree(rt->receiver_buffer);
- kfree(rt);
dev_err(&chip->dev->dev, "cannot create comm data receiver.");
- return ret;
+ goto error;
}
chip->comm = rt;
return 0;
+
+ error:
+ usb6fire_comm_free(rt);
+ return ret;
}
void usb6fire_comm_abort(struct sfire_chip *chip)
@@ -190,14 +208,10 @@ void usb6fire_comm_abort(struct sfire_chip *chip)
struct comm_runtime *rt = chip->comm;
if (rt)
- usb_poison_urb(&rt->receiver);
+ usb_poison_urb(rt->receiver);
}
void usb6fire_comm_destroy(struct sfire_chip *chip)
{
- struct comm_runtime *rt = chip->comm;
-
- kfree(rt->receiver_buffer);
- kfree(rt);
- chip->comm = NULL;
+ usb6fire_comm_free(chip->comm);
}
diff --git a/sound/usb/6fire/comm.h b/sound/usb/6fire/comm.h
index 2447d7ecf1798..89976f510f6c2 100644
--- a/sound/usb/6fire/comm.h
+++ b/sound/usb/6fire/comm.h
@@ -19,7 +19,7 @@ enum /* settings for comm */
struct comm_runtime {
struct sfire_chip *chip;
- struct urb receiver;
+ struct urb *receiver;
u8 *receiver_buffer;
u8 serial; /* urb serial */
diff --git a/sound/usb/6fire/midi.c b/sound/usb/6fire/midi.c
index 4d1eeb32c5fe2..f79fb368594d7 100644
--- a/sound/usb/6fire/midi.c
+++ b/sound/usb/6fire/midi.c
@@ -66,7 +66,7 @@ static void usb6fire_midi_out_trigger(
struct snd_rawmidi_substream *alsa_sub, int up)
{
struct midi_runtime *rt = alsa_sub->rmidi->private_data;
- struct urb *urb = &rt->out_urb;
+ struct urb *urb = rt->out_urb;
__s8 ret;
guard(spinlock_irqsave)(&rt->out_lock);
@@ -137,6 +137,19 @@ static const struct snd_rawmidi_ops in_ops = {
.trigger = usb6fire_midi_in_trigger
};
+static void usb6fire_midi_free(struct midi_runtime *rt)
+{
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->midi = NULL;
+
+ usb_free_urb(rt->out_urb);
+ kfree(rt->out_buffer);
+ kfree(rt);
+}
+
int usb6fire_midi_init(struct sfire_chip *chip)
{
int ret;
@@ -149,8 +162,14 @@ int usb6fire_midi_init(struct sfire_chip *chip)
rt->out_buffer = kzalloc(MIDI_BUFSIZE, GFP_KERNEL);
if (!rt->out_buffer) {
- kfree(rt);
- return -ENOMEM;
+ ret = -ENOMEM;
+ goto error;
+ }
+
+ rt->out_urb = usb_alloc_urb(0, GFP_KERNEL);
+ if (!rt->out_urb) {
+ ret = -ENOMEM;
+ goto error;
}
rt->chip = chip;
@@ -161,15 +180,13 @@ int usb6fire_midi_init(struct sfire_chip *chip)
spin_lock_init(&rt->in_lock);
spin_lock_init(&rt->out_lock);
- comm_rt->init_urb(comm_rt, &rt->out_urb, rt->out_buffer, rt,
+ comm_rt->init_urb(comm_rt, rt->out_urb, rt->out_buffer, rt,
usb6fire_midi_out_handler);
ret = snd_rawmidi_new(chip->card, "6FireUSB", 0, 1, 1, &rt->instance);
if (ret < 0) {
- kfree(rt->out_buffer);
- kfree(rt);
dev_err(&chip->dev->dev, "unable to create midi.\n");
- return ret;
+ goto error;
}
rt->instance->private_data = rt;
strscpy(rt->instance->name, "DMX6FireUSB MIDI");
@@ -183,6 +200,10 @@ int usb6fire_midi_init(struct sfire_chip *chip)
chip->midi = rt;
return 0;
+
+ error:
+ usb6fire_midi_free(rt);
+ return ret;
}
void usb6fire_midi_abort(struct sfire_chip *chip)
@@ -190,14 +211,10 @@ void usb6fire_midi_abort(struct sfire_chip *chip)
struct midi_runtime *rt = chip->midi;
if (rt)
- usb_poison_urb(&rt->out_urb);
+ usb_poison_urb(rt->out_urb);
}
void usb6fire_midi_destroy(struct sfire_chip *chip)
{
- struct midi_runtime *rt = chip->midi;
-
- kfree(rt->out_buffer);
- kfree(rt);
- chip->midi = NULL;
+ usb6fire_midi_free(chip->midi);
}
diff --git a/sound/usb/6fire/midi.h b/sound/usb/6fire/midi.h
index 47640c845903b..8716ab8a863ae 100644
--- a/sound/usb/6fire/midi.h
+++ b/sound/usb/6fire/midi.h
@@ -22,7 +22,7 @@ struct midi_runtime {
spinlock_t in_lock;
spinlock_t out_lock;
struct snd_rawmidi_substream *out;
- struct urb out_urb;
+ struct urb *out_urb;
u8 out_serial; /* serial number of out packet */
u8 *out_buffer;
int buffer_offset;
diff --git a/sound/usb/6fire/pcm.c b/sound/usb/6fire/pcm.c
index 08515da5dcc85..52e6606d3ccb6 100644
--- a/sound/usb/6fire/pcm.c
+++ b/sound/usb/6fire/pcm.c
@@ -138,8 +138,8 @@ static void usb6fire_pcm_stream_stop(struct pcm_runtime *rt)
rt->stream_state = STREAM_STOPPING;
for (i = 0; i < PCM_N_URBS; i++) {
- usb_kill_urb(&rt->in_urbs[i].instance);
- usb_kill_urb(&rt->out_urbs[i].instance);
+ usb_kill_urb(rt->in_urbs[i].instance);
+ usb_kill_urb(rt->out_urbs[i].instance);
}
ctrl_rt->usb_streaming = false;
ctrl_rt->update_streaming(ctrl_rt);
@@ -161,13 +161,13 @@ static int usb6fire_pcm_stream_start(struct pcm_runtime *rt)
rt->stream_state = STREAM_STARTING;
for (i = 0; i < PCM_N_URBS; i++) {
for (k = 0; k < PCM_N_PACKETS_PER_URB; k++) {
- packet = &rt->in_urbs[i].packets[k];
+ packet = &rt->in_urbs[i].instance->iso_frame_desc[k];
packet->offset = k * rt->in_packet_size;
packet->length = rt->in_packet_size;
packet->actual_length = 0;
packet->status = 0;
}
- ret = usb_submit_urb(&rt->in_urbs[i].instance,
+ ret = usb_submit_urb(rt->in_urbs[i].instance,
GFP_ATOMIC);
if (ret) {
usb6fire_pcm_stream_stop(rt);
@@ -197,6 +197,7 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
unsigned int total_length = 0;
struct pcm_runtime *rt = snd_pcm_substream_chip(sub->instance);
struct snd_pcm_runtime *alsa_rt = sub->instance->runtime;
+ struct usb_iso_packet_descriptor *isoc;
u32 *src = NULL;
u32 *dest = (u32 *) (alsa_rt->dma_area + sub->dma_off
* (alsa_rt->frame_bits >> 3));
@@ -207,8 +208,9 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
/* at least 4 header bytes for valid packet.
* after that: 32 bits per sample for analog channels */
- if (urb->packets[i].actual_length > 4)
- frame_count = (urb->packets[i].actual_length - 4)
+ isoc = &urb->instance->iso_frame_desc[i];
+ if (isoc->actual_length > 4)
+ frame_count = (isoc->actual_length - 4)
/ (rt->in_n_analog << 2);
else
frame_count = 0;
@@ -220,7 +222,7 @@ static void usb6fire_pcm_capture(struct pcm_substream *sub, struct pcm_urb *urb)
else
return;
src++; /* skip leading 4 bytes of every packet */
- total_length += urb->packets[i].length;
+ total_length += isoc->length;
for (frame = 0; frame < frame_count; frame++) {
memcpy(dest, src, bytes_per_frame);
dest += alsa_rt->channels;
@@ -244,6 +246,7 @@ static void usb6fire_pcm_playback(struct pcm_substream *sub,
int frame_count;
struct pcm_runtime *rt = snd_pcm_substream_chip(sub->instance);
struct snd_pcm_runtime *alsa_rt = sub->instance->runtime;
+ struct usb_iso_packet_descriptor *isoc;
u32 *src = (u32 *) (alsa_rt->dma_area + sub->dma_off
* (alsa_rt->frame_bits >> 3));
u32 *src_end = (u32 *) (alsa_rt->dma_area + alsa_rt->buffer_size
@@ -263,8 +266,9 @@ static void usb6fire_pcm_playback(struct pcm_substream *sub,
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
/* at least 4 header bytes for valid packet.
* after that: 32 bits per sample for analog channels */
- if (urb->packets[i].length > 4)
- frame_count = (urb->packets[i].length - 4)
+ isoc = &urb->instance->iso_frame_desc[i];
+ if (isoc->length > 4)
+ frame_count = (isoc->length - 4)
/ (rt->out_n_analog << 2);
else
frame_count = 0;
@@ -289,6 +293,7 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
struct pcm_urb *out_urb = in_urb->peer;
struct pcm_runtime *rt = in_urb->chip->pcm;
struct pcm_substream *sub;
+ struct usb_iso_packet_descriptor *isoc_out, *isoc_in;
bool period_elapsed;
int total_length = 0;
int frame_count;
@@ -299,11 +304,13 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
if (usb_urb->status || rt->panic || rt->stream_state == STREAM_STOPPING)
return;
- for (i = 0; i < PCM_N_PACKETS_PER_URB; i++)
- if (in_urb->packets[i].status) {
+ for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ isoc_in = &in_urb->instance->iso_frame_desc[i];
+ if (isoc_in->status) {
rt->panic = true;
return;
}
+ }
if (rt->stream_state == STREAM_DISABLED) {
dev_err(&rt->chip->dev->dev,
@@ -328,12 +335,13 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup out urb structure */
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
- out_urb->packets[i].offset = total_length;
- out_urb->packets[i].length = (in_urb->packets[i].actual_length
- - 4) / (rt->in_n_analog << 2)
+ isoc_out = &out_urb->instance->iso_frame_desc[i];
+ isoc_in = &in_urb->instance->iso_frame_desc[i];
+ isoc_out->offset = total_length;
+ isoc_out->length = (isoc_in->actual_length - 4) / (rt->in_n_analog << 2)
* (rt->out_n_analog << 2) + 4;
- out_urb->packets[i].status = 0;
- total_length += out_urb->packets[i].length;
+ isoc_out->status = 0;
+ total_length += isoc_out->length;
}
memset(out_urb->buffer, 0, total_length);
@@ -354,9 +362,10 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup the 4th byte of each sample (0x40 for analog channels) */
dest = out_urb->buffer;
- for (i = 0; i < PCM_N_PACKETS_PER_URB; i++)
- if (out_urb->packets[i].length >= 4) {
- frame_count = (out_urb->packets[i].length - 4)
+ for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ isoc_out = &out_urb->instance->iso_frame_desc[i];
+ if (isoc_out->length >= 4) {
+ frame_count = (isoc_out->length - 4)
/ (rt->out_n_analog << 2);
*(dest++) = 0xaa;
*(dest++) = 0xaa;
@@ -370,8 +379,10 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
*(dest++) = 0x40;
}
}
- usb_submit_urb(&out_urb->instance, GFP_ATOMIC);
- usb_submit_urb(&in_urb->instance, GFP_ATOMIC);
+ }
+
+ usb_submit_urb(out_urb->instance, GFP_ATOMIC);
+ usb_submit_urb(in_urb->instance, GFP_ATOMIC);
}
static void usb6fire_pcm_out_urb_handler(struct urb *usb_urb)
@@ -534,22 +545,25 @@ static const struct snd_pcm_ops pcm_ops = {
.pointer = usb6fire_pcm_pointer,
};
-static void usb6fire_pcm_init_urb(struct pcm_urb *urb,
- struct sfire_chip *chip, bool in, int ep,
- void (*handler)(struct urb *))
+static int usb6fire_pcm_init_urb(struct pcm_urb *urb,
+ struct sfire_chip *chip, bool in, int ep,
+ void (*handler)(struct urb *))
{
urb->chip = chip;
- usb_init_urb(&urb->instance);
- urb->instance.transfer_buffer = urb->buffer;
- urb->instance.transfer_buffer_length =
+ urb->instance = usb_alloc_urb(PCM_N_PACKETS_PER_URB, GFP_KERNEL);
+ if (!urb->instance)
+ return -ENOMEM;
+ urb->instance->transfer_buffer = urb->buffer;
+ urb->instance->transfer_buffer_length =
PCM_N_PACKETS_PER_URB * PCM_MAX_PACKET_SIZE;
- urb->instance.dev = chip->dev;
- urb->instance.pipe = in ? usb_rcvisocpipe(chip->dev, ep)
+ urb->instance->dev = chip->dev;
+ urb->instance->pipe = in ? usb_rcvisocpipe(chip->dev, ep)
: usb_sndisocpipe(chip->dev, ep);
- urb->instance.interval = 1;
- urb->instance.complete = handler;
- urb->instance.context = urb;
- urb->instance.number_of_packets = PCM_N_PACKETS_PER_URB;
+ urb->instance->interval = 1;
+ urb->instance->complete = handler;
+ urb->instance->context = urb;
+ urb->instance->number_of_packets = PCM_N_PACKETS_PER_URB;
+ return 0;
}
static int usb6fire_pcm_buffers_init(struct pcm_runtime *rt)
@@ -571,14 +585,23 @@ static int usb6fire_pcm_buffers_init(struct pcm_runtime *rt)
return 0;
}
-static void usb6fire_pcm_buffers_destroy(struct pcm_runtime *rt)
+static void usb6fire_pcm_free(struct pcm_runtime *rt)
{
int i;
+ if (!rt)
+ return;
+
+ if (rt->chip)
+ rt->chip->pcm = NULL;
+
for (i = 0; i < PCM_N_URBS; i++) {
+ usb_free_urb(rt->out_urbs[i].instance);
kfree(rt->out_urbs[i].buffer);
+ usb_free_urb(rt->in_urbs[i].instance);
kfree(rt->in_urbs[i].buffer);
}
+ kfree(rt);
}
int usb6fire_pcm_init(struct sfire_chip *chip)
@@ -593,11 +616,8 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
return -ENOMEM;
ret = usb6fire_pcm_buffers_init(rt);
- if (ret) {
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
- return ret;
- }
+ if (ret)
+ goto error;
rt->chip = chip;
rt->stream_state = STREAM_DISABLED;
@@ -609,10 +629,14 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
spin_lock_init(&rt->capture.lock);
for (i = 0; i < PCM_N_URBS; i++) {
- usb6fire_pcm_init_urb(&rt->in_urbs[i], chip, true, IN_EP,
- usb6fire_pcm_in_urb_handler);
- usb6fire_pcm_init_urb(&rt->out_urbs[i], chip, false, OUT_EP,
- usb6fire_pcm_out_urb_handler);
+ ret = usb6fire_pcm_init_urb(&rt->in_urbs[i], chip, true, IN_EP,
+ usb6fire_pcm_in_urb_handler);
+ if (ret < 0)
+ goto error;
+ ret = usb6fire_pcm_init_urb(&rt->out_urbs[i], chip, false, OUT_EP,
+ usb6fire_pcm_out_urb_handler);
+ if (ret < 0)
+ goto error;
rt->in_urbs[i].peer = &rt->out_urbs[i];
rt->out_urbs[i].peer = &rt->in_urbs[i];
@@ -620,10 +644,8 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
ret = snd_pcm_new(chip->card, "DMX6FireUSB", 0, 1, 1, &pcm);
if (ret < 0) {
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
dev_err(&chip->dev->dev, "cannot create pcm instance.\n");
- return ret;
+ goto error;
}
pcm->private_data = rt;
@@ -636,6 +658,10 @@ int usb6fire_pcm_init(struct sfire_chip *chip)
chip->pcm = rt;
return 0;
+
+ error:
+ usb6fire_pcm_free(rt);
+ return ret;
}
void usb6fire_pcm_abort(struct sfire_chip *chip)
@@ -653,8 +679,8 @@ void usb6fire_pcm_abort(struct sfire_chip *chip)
snd_pcm_stop_xrun(rt->capture.instance);
for (i = 0; i < PCM_N_URBS; i++) {
- usb_poison_urb(&rt->in_urbs[i].instance);
- usb_poison_urb(&rt->out_urbs[i].instance);
+ usb_poison_urb(rt->in_urbs[i].instance);
+ usb_poison_urb(rt->out_urbs[i].instance);
}
}
@@ -662,9 +688,5 @@ void usb6fire_pcm_abort(struct sfire_chip *chip)
void usb6fire_pcm_destroy(struct sfire_chip *chip)
{
- struct pcm_runtime *rt = chip->pcm;
-
- usb6fire_pcm_buffers_destroy(rt);
- kfree(rt);
- chip->pcm = NULL;
+ usb6fire_pcm_free(chip->pcm);
}
diff --git a/sound/usb/6fire/pcm.h b/sound/usb/6fire/pcm.h
index 5a092dfd69f5a..b586fe220fd11 100644
--- a/sound/usb/6fire/pcm.h
+++ b/sound/usb/6fire/pcm.h
@@ -24,10 +24,7 @@ enum /* settings for pcm */
struct pcm_urb {
struct sfire_chip *chip;
- /* BEGIN DO NOT SEPARATE */
- struct urb instance;
- struct usb_iso_packet_descriptor packets[PCM_N_PACKETS_PER_URB];
- /* END DO NOT SEPARATE */
+ struct urb *instance;
u8 *buffer;
struct pcm_urb *peer;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 170/438] Bluetooth: coredump: Quiesce dump work on unregister
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (168 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 169/438] Bluetooth: btintel_pcie: validate TX skb length in send_sync Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 171/438] Bluetooth: put the peers on-air address on air when we cannot resolve Greg Kroah-Hartman
` (279 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b170dbf55520ebf5969a,
Aby Sam Ross, Tristan Madani, Xiang Mei, Weiming Shi,
Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit d236517c264e41dc09833c708ef23bccb7a91219 ]
hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers
queue dump_rx without holding an hdev reference. Unregister leaves both
works live, so disconnecting during an active dump lets them access hdev
after hci_release_dev() frees it.
Shut down coredump processing during unregister. Close the producer gate
under dump_q.lock before disabling both works, then free the active buffer
and queued packets under hci_dev_lock. Serializing the gate with enqueue
prevents controller-specific workers from adding packets after the final
purge.
Fixes: 9695ef876fd1 ("Bluetooth: Add support for hci devcoredump")
Reported-by: syzbot+b170dbf55520ebf5969a@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b170dbf55520ebf5969a
Reported-by: Aby Sam Ross <abysamross@gmail.com>
Link: https://lore.kernel.org/r/20260322210849.68743-1-abysamross@gmail.com
Suggested-by: Aby Sam Ross <abysamross@gmail.com>
Reported-by: Tristan Madani <tristan@talencesecurity.com>
Link: https://lore.kernel.org/r/20260814231248.3096377-1-tristmd@gmail.com
Reported-by: Xiang Mei <xmei5@asu.edu>
Assisted-by: OpenAI Codex:gpt-5
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/bluetooth/coredump.h | 2 +
net/bluetooth/coredump.c | 65 +++++++++++++++++++++-----------
net/bluetooth/hci_core.c | 1 +
3 files changed, 47 insertions(+), 21 deletions(-)
diff --git a/include/net/bluetooth/coredump.h b/include/net/bluetooth/coredump.h
index 72f51b587a046..00c12c7ac042f 100644
--- a/include/net/bluetooth/coredump.h
+++ b/include/net/bluetooth/coredump.h
@@ -61,6 +61,7 @@ struct hci_devcoredump {
#ifdef CONFIG_DEV_COREDUMP
void hci_devcd_reset(struct hci_dev *hdev);
+void hci_devcd_shutdown(struct hci_dev *hdev);
void hci_devcd_rx(struct work_struct *work);
void hci_devcd_timeout(struct work_struct *work);
@@ -75,6 +76,7 @@ int hci_devcd_abort(struct hci_dev *hdev);
#else
static inline void hci_devcd_reset(struct hci_dev *hdev) {}
+static inline void hci_devcd_shutdown(struct hci_dev *hdev) {}
static inline void hci_devcd_rx(struct work_struct *work) {}
static inline void hci_devcd_timeout(struct work_struct *work) {}
diff --git a/net/bluetooth/coredump.c b/net/bluetooth/coredump.c
index 720cb79adf964..b15971ad78a8f 100644
--- a/net/bluetooth/coredump.c
+++ b/net/bluetooth/coredump.c
@@ -105,6 +105,22 @@ static void hci_devcd_free(struct hci_dev *hdev)
hci_devcd_reset(hdev);
}
+void hci_devcd_shutdown(struct hci_dev *hdev)
+{
+ unsigned long flags;
+
+ spin_lock_irqsave(&hdev->dump.dump_q.lock, flags);
+ hdev->dump.supported = false;
+ spin_unlock_irqrestore(&hdev->dump.dump_q.lock, flags);
+
+ disable_work_sync(&hdev->dump.dump_rx);
+ disable_delayed_work_sync(&hdev->dump.dump_timeout);
+
+ hci_dev_lock(hdev);
+ hci_devcd_free(hdev);
+ hci_dev_unlock(hdev);
+}
+
/* Call with hci_dev_lock only. */
static int hci_devcd_alloc(struct hci_dev *hdev, u32 size)
{
@@ -444,7 +460,29 @@ EXPORT_SYMBOL(hci_devcd_register);
static inline bool hci_devcd_enabled(struct hci_dev *hdev)
{
- return hdev->dump.supported;
+ return READ_ONCE(hdev->dump.supported);
+}
+
+static int hci_devcd_queue(struct hci_dev *hdev, struct sk_buff *skb)
+{
+ unsigned long flags;
+ int err = 0;
+
+ spin_lock_irqsave(&hdev->dump.dump_q.lock, flags);
+ if (!hdev->dump.supported)
+ err = -EOPNOTSUPP;
+ else
+ __skb_queue_tail(&hdev->dump.dump_q, skb);
+ spin_unlock_irqrestore(&hdev->dump.dump_q.lock, flags);
+
+ if (err) {
+ kfree_skb(skb);
+ return err;
+ }
+
+ queue_work(hdev->workqueue, &hdev->dump.dump_rx);
+
+ return 0;
}
int hci_devcd_init(struct hci_dev *hdev, u32 dump_size)
@@ -461,10 +499,7 @@ int hci_devcd_init(struct hci_dev *hdev, u32 dump_size)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_INIT;
put_unaligned_le32(dump_size, skb_put(skb, 4));
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_init);
@@ -480,10 +515,7 @@ int hci_devcd_append(struct hci_dev *hdev, struct sk_buff *skb)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_SKB;
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_append);
@@ -505,10 +537,7 @@ int hci_devcd_append_pattern(struct hci_dev *hdev, u8 pattern, u32 len)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_PATTERN;
skb_put_data(skb, &p, sizeof(p));
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_append_pattern);
@@ -525,10 +554,7 @@ int hci_devcd_complete(struct hci_dev *hdev)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_COMPLETE;
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_complete);
@@ -545,9 +571,6 @@ int hci_devcd_abort(struct hci_dev *hdev)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_ABORT;
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_abort);
diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
index 86a9677ed7025..3ea5ea7267d9c 100644
--- a/net/bluetooth/hci_core.c
+++ b/net/bluetooth/hci_core.c
@@ -2670,6 +2670,7 @@ void hci_unregister_dev(struct hci_dev *hdev)
disable_work_sync(&hdev->error_reset);
disable_delayed_work_sync(&hdev->cmd_timer);
disable_delayed_work_sync(&hdev->ncmd_timer);
+ hci_devcd_shutdown(hdev);
hci_cmd_sync_clear(hdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 117/398] ALSA: 6fire: fix OOB write from device-reported iso length
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (115 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 116/398] ALSA: usb: 6fire: Avoid embedded URBs Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 118/398] wifi: virt_wifi: dont transfer operstate before register Greg Kroah-Hartman
` (285 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+855929c2df672879, Xiang Mei,
Takashi Iwai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit 1589afe2d099d3e817873bc474676968d7080410 ]
usb6fire_pcm_in_urb_handler() sizes each outgoing isochronous packet as
(actual_length - 4) / (in_n_analog << 2) * (out_n_analog << 2) + 4, where
actual_length is the unsigned length the device reported for the matching
IN packet. A packet completed with status 0 and actual_length < 4 wraps
the subtraction to 0x7fffffec; a zero-length isochronous packet is legal
on the bus, and the preceding loop rejects only non-zero status. The sum
reaches memset() on out_urb->buffer, a 4832-byte object from
kcalloc(PCM_MAX_PACKET_SIZE, PCM_N_PACKETS_PER_URB).
Even without the wrap the result is out of bounds: at 88.2/96 kHz the
4-in/6-out scaling turns a full 420-byte IN packet into 628, so eight
packets span 5024 bytes of that buffer. usb_submit_urb() rejects an
over-long descriptor only after the memset() and the
usb6fire_pcm_playback() copy of user PCM data have run.
Guard the subtraction as the sibling usb6fire_pcm_capture() already does,
and limit the frame count to what fits in rt->out_packet_size, the OUT
endpoint's wMaxPacketSize. This bounds total_length by the buffer size
while keeping each packet length aligned to a whole output frame.
BUG: KASAN: out-of-bounds in usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)
Write of size 18446744073709551456 at addr ffff88802a3d0000 by task vhci_rx/5018
Call Trace:
dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)
print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)
kasan_report (mm/kasan/report.c:595)
kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200)
__asan_memset (mm/kasan/shadow.c:84)
usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)
__usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107 drivers/usb/usbip/vhci_rx.c:242)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
Allocated by task 10:
__kmalloc_cache_noprof (mm/slub.c:5563)
usb6fire_pcm_init (sound/usb/6fire/pcm.c:560 sound/usb/6fire/pcm.c:595)
usb6fire_chip_probe (sound/usb/6fire/chip.c:133)
usb_probe_interface (drivers/usb/core/driver.c:399)
The buggy address belongs to the object at ffff88802a3d0000
which belongs to the cache kmalloc-8k of size 8192
The buggy address is located 0 bytes inside of
4832-byte region [ffff88802a3d0000, ffff88802a3d12e0)
Kernel panic - not syncing: Fatal exception in interrupt
Fixes: c6d43ba816d1 ("ALSA: usb/6fire - Driver for TerraTec DMX 6Fire USB")
Reported-by: co+855929c2df672879@bugs.sh
Closes: https://lore.kernel.org/all/gisnub8aWGLbyZLcDCSc7zWsHonMWGcyRgt5%40bugs.sh/
Assisted-by: LLM
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Link: https://patch.msgid.link/20260914074324.3590843-1-xmei5@asu.edu
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/usb/6fire/pcm.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/sound/usb/6fire/pcm.c b/sound/usb/6fire/pcm.c
index 52e6606d3ccb6..ff00137ab13e3 100644
--- a/sound/usb/6fire/pcm.c
+++ b/sound/usb/6fire/pcm.c
@@ -335,11 +335,19 @@ static void usb6fire_pcm_in_urb_handler(struct urb *usb_urb)
/* setup out urb structure */
for (i = 0; i < PCM_N_PACKETS_PER_URB; i++) {
+ unsigned int frames = 0;
+
isoc_out = &out_urb->instance->iso_frame_desc[i];
isoc_in = &in_urb->instance->iso_frame_desc[i];
+ if (isoc_in->actual_length > 4)
+ frames = (isoc_in->actual_length - 4)
+ / (rt->in_n_analog << 2);
+ frames = min_t(unsigned int, frames,
+ (rt->out_packet_size - 4)
+ / (rt->out_n_analog << 2));
+
isoc_out->offset = total_length;
- isoc_out->length = (isoc_in->actual_length - 4) / (rt->in_n_analog << 2)
- * (rt->out_n_analog << 2) + 4;
+ isoc_out->length = frames * (rt->out_n_analog << 2) + 4;
isoc_out->status = 0;
total_length += isoc_out->length;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 171/438] Bluetooth: put the peers on-air address on air when we cannot resolve
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (169 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 170/438] Bluetooth: coredump: Quiesce dump work on unregister Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 172/438] Bluetooth: hci_qca: Do not write to the serial port after it is closed Greg Kroah-Hartman
` (278 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Radek Podgorny,
Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Radek Podgorny <radek@podgorny.cz>
[ Upstream commit 4914c499896121ae8b9d5b90f0abc5c8287ff396 ]
An identity address only reaches a peer that is advertising an RPA if the
controller resolves it on our behalf. Where it cannot, the host has to put
the peer's on-air address on air itself.
hci_connect_le() still swaps the caller's identity address for the peer's
cached RPA before creating the connection, but __hci_conn_add() resolves
the RPA back to the identity address when it stores it, so the identity is
what goes out. Storing the identity is right when the controller
translates it on the way to the radio; without LL Privacy, or with this
peer absent from the resolving list, nothing does.
A peer advertising an RPA cannot answer its identity address, so the
attempt burns a full create-connection timeout. That is not merely a slow
connect: a controller without extended scanning cannot scan while it is
initiating, so every dead attempt also takes the scanner off the air for
the whole timeout.
Measured on a CYW43438, which reports neither LL Privacy nor extended
advertising (LE features 3f 00 00 08 00 00 00 00), against a peer
advertising a resolvable private address the host holds the IRK for, with
the connection requested on the peer's identity address:
before: LE Create Connection to the identity address, public type
1.61s -> 22.07s, then LE Create Connection Cancel
LE Connection Complete: Unknown Connection Identifier (0x02)
after: LE Create Connection to the peer's RPA, random type
LE Connection Complete: Success
Advertising reports reaching the host per second, same window, same five
unrelated devices on the adapter:
before 1s:2 [nothing from 2s through 21s] 22s:5 23s:3
after 0s:11 1s:5 2s:2 3s:5 4s:3 5s:4 ... 21s:2 22s:1 23s:2
One dead connect costs twenty seconds of scanning for every device on the
adapter, not just the one being dialled.
Keep the RPA in conn->dst unless the controller will translate the
identity address: address resolution enabled and the peer's identity
actually programmed into the resolving list. Testing ll_privacy_capable()
alone would not be enough: it reports the feature bit, not whether
resolution is switched on and not whether this peer is in the list.
Resolution is cleared with the other volatile flags on power-off and
switched off again while suspend pauses scanning, and a peer's IRK is only
programmed along the accept list path, so a direct-connect target, a peer
without HCI_CONN_FLAG_ADDRESS_RESOLUTION, and one that did not fit in a
full list are all absent from it.
With the peer programmed, the identity address stays in conn->dst and the
controller translates it: measured on an Intel controller, the host dials
the identity and LE Enhanced Connection Complete reports Resolved Public
with the peer's RPA in the separate peer resolvable private address field.
With the peer absent from the list the same setup dials the RPA itself.
Everything downstream already copes with an RPA in conn->dst: it is what
every outgoing LE connection stored before 14b06c3a88f7, the connection
complete event names the address that was dialled, and
le_conn_complete_evt() resolves it back to the identity once the link is
up. ISO links keep the unconditional conversion: they are created from an
existing ACL or a periodic sync and never dial this address themselves.
Keeping the RPA is only right while the peer is still using it, which is
why the preceding patch drops the cached RPA as soon as the peer is seen
advertising its identity address. Without that, a peer that turns privacy
off would be dialled on the address it abandoned rather than the one it
is answering on.
Fixes: 14b06c3a88f7 ("Bluetooth: HCI: Always use the identity address when initializing a connection")
Assisted-by: Claude:claude-opus-5
Assisted-by: Claude:claude-fable-5
Signed-off-by: Radek Podgorny <radek@podgorny.cz>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_conn.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
diff --git a/net/bluetooth/hci_conn.c b/net/bluetooth/hci_conn.c
index 8de98af2fb581..c9466cb2c7c00 100644
--- a/net/bluetooth/hci_conn.c
+++ b/net/bluetooth/hci_conn.c
@@ -1023,6 +1023,19 @@ static struct hci_conn *__hci_conn_add(struct hci_dev *hdev, int type,
if (!hdev->le_mtu && hdev->acl_mtu < HCI_MIN_LE_MTU)
return ERR_PTR(-ECONNREFUSED);
irk = hci_get_irk(hdev, dst, dst_type);
+ /* An identity address only reaches a peer advertising an RPA
+ * if the controller translates it. Unless address resolution
+ * is enabled and this peer is programmed into the resolving
+ * list, keep the RPA the peer is on air with;
+ * le_conn_complete_evt() resolves it back once the link is
+ * up.
+ */
+ if (irk &&
+ (!hci_dev_test_flag(hdev, HCI_LL_RPA_RESOLUTION) ||
+ !hci_bdaddr_list_lookup_with_irk(&hdev->le_resolv_list,
+ &irk->bdaddr,
+ irk->addr_type)))
+ irk = NULL;
break;
case SCO_LINK:
case ESCO_LINK:
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 118/398] wifi: virt_wifi: dont transfer operstate before register
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (116 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 117/398] ALSA: 6fire: fix OOB write from device-reported iso length Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 119/398] drm/xe/mmio_gem: forbid VMA split Greg Kroah-Hartman
` (284 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Luxing Yin, Zihan Xi,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zihan Xi <zihanx@nebusec.ai>
[ Upstream commit e5c8d7acd31b27057ea42cd405d0b3ece097bc89 ]
virt_wifi_newlink() calls netif_stacked_transfer_operstate() before
register_netdevice(). If the lower device is dormant, that queues the
new netdev on lweventlist while it is still uninitialized. If
registration fails after that, for example because of an invalid name
such as "bad/name", free_netdev() immediately frees the object. A
later linkwatch_fire_event() then use-after-frees the list entry.
Move the transfer to after netdev_upper_dev_link(), as macvlan and
ipvlan already do.
Fixes: c7cdba31ed8b ("mac80211-next: rtnetlink wifi simulation device")
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Co-developed-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Luxing Yin <root@tr0jan.top>
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Link: https://patch.msgid.link/f5a832fb0ab228ce6e2b5a91fba4ca8b79198a2f.1788948455.git.zihanx@nebusec.ai
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virtual/virt_wifi.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/virtual/virt_wifi.c b/drivers/net/wireless/virtual/virt_wifi.c
index b976b90c1c2d2..16d1d3cedd981 100644
--- a/drivers/net/wireless/virtual/virt_wifi.c
+++ b/drivers/net/wireless/virtual/virt_wifi.c
@@ -556,7 +556,6 @@ static int virt_wifi_newlink(struct net_device *dev,
}
eth_hw_addr_inherit(dev, priv->lowerdev);
- netif_stacked_transfer_operstate(priv->lowerdev, dev);
dev->ieee80211_ptr = kzalloc(sizeof(*dev->ieee80211_ptr), GFP_KERNEL);
@@ -582,6 +581,8 @@ static int virt_wifi_newlink(struct net_device *dev,
goto unregister_netdev;
}
+ netif_stacked_transfer_operstate(priv->lowerdev, dev);
+
dev->priv_destructor = virt_wifi_net_device_destructor;
priv->being_deleted = false;
priv->is_connected = false;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 172/438] Bluetooth: hci_qca: Do not write to the serial port after it is closed
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (170 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 171/438] Bluetooth: put the peers on-air address on air when we cannot resolve Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 173/438] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() Greg Kroah-Hartman
` (277 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ibrahim Abdelkader, Hans de Goede,
Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ibrahim Abdelkader <iabdelka@qti.qualcomm.com>
[ Upstream commit 4e93c65f87825e1e012bce56615320aeb123815d ]
hci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP
is set (for example, for the WCN399x family). A failed hci_dev_open_sync()
following a successful qca_setup() calls hdev->close() but not
hdev->shutdown(), so the port is closed while power->vregs_on is left true.
qca_serdev_remove() then passes its power->vregs_on test and calls
qca_power_off(), which writes to the closed port unconditionally.
Seen on a WCN3988 by unbinding the driver after a controller failure. The
trace below is from a 7.0.0 based kernel, where qca_power_off() was still
named qca_power_shutdown():
Unable to handle kernel NULL pointer dereference at virtual address
0000000000000038
Call trace:
tty_set_termios+0x50/0x238 (P)
ttyport_set_baudrate+0x84/0xc0
serdev_device_set_baudrate+0x24/0x40
qca_power_shutdown+0x158/0x1fc [hci_uart]
qca_serdev_remove+0x54/0x68 [hci_uart]
serdev_drv_remove+0x1c/0x2c
device_remove+0x4c/0x80
device_release_driver_internal+0x1cc/0x224
device_driver_detach+0x18/0x24
unbind_store+0xb4/0xc0
Check HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place
it closes the port, before writing to it. The regulator disable is left
unconditional so the controller is still powered down.
The dangling serport->tty that turns this into a use-after-free is
addressed in a separate patch.
Fixes: fa9ad876b8e0 ("Bluetooth: hci_qca: Add support for Qualcomm Bluetooth chip wcn3990")
Signed-off-by: Ibrahim Abdelkader <iabdelka@qti.qualcomm.com>
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/hci_qca.c | 14 ++++++++++----
1 file changed, 10 insertions(+), 4 deletions(-)
diff --git a/drivers/bluetooth/hci_qca.c b/drivers/bluetooth/hci_qca.c
index 1222f97800f4a..875093e61c681 100644
--- a/drivers/bluetooth/hci_qca.c
+++ b/drivers/bluetooth/hci_qca.c
@@ -2228,8 +2228,8 @@ static void qca_power_off(struct hci_uart *hu)
bool sw_ctrl_state;
struct qca_power *power;
- /* From this point we go into power off state. But serial port is
- * still open, stop queueing the IBS data and flush all the buffered
+ /* From this point we go into power off state. But serial port may
+ * still be open, stop queueing the IBS data and flush all the buffered
* data in skb's.
*/
spin_lock_irqsave(&qca->hci_ibs_lock, flags);
@@ -2251,8 +2251,14 @@ static void qca_power_off(struct hci_uart *hu)
case QCA_WCN3990:
case QCA_WCN3991:
case QCA_WCN3998:
- host_set_baudrate(hu, 2400);
- qca_send_power_pulse(hu, false);
+ /* Both of these write to the serial port which may have
+ * already been closed by hci_uart_close(), which closes
+ * the port if HCI_QUIRK_NON_PERSISTENT_SETUP is set.
+ */
+ if (test_bit(HCI_UART_PROTO_READY, &hu->flags)) {
+ host_set_baudrate(hu, 2400);
+ qca_send_power_pulse(hu, false);
+ }
break;
default:
break;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 119/398] drm/xe/mmio_gem: forbid VMA split
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (117 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 118/398] wifi: virt_wifi: dont transfer operstate before register Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 120/398] drm/xe/mmio_gem: use write-back mapping for dummy page Greg Kroah-Hartman
` (283 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Matthew Auld, Ilia Levi,
Rodrigo Vivi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilia Levi <ilia.levi@intel.com>
[ Upstream commit 247a82da6f563dcfd9074a68f99a0c0997d0679c ]
The fault handler assumes it always operates on a VMA spanning the entire
GEM object. This does not hold when the VMA has been split, e.g. by a
partial munmap or mprotect. In that case the handler may map wrong
physical pages or cause SIGBUS.
Handle this by forbidding VMA split, as partial unmaps are not deemed
useful for MMIO GEMs.
Suggested-by: Matthew Auld <matthew.auld@intel.com>
Signed-off-by: Ilia Levi <ilia.levi@intel.com>
Fixes: 1ffcf8b8ae8a ("drm/xe: Support for mmap-ing mmio regions")
Reviewed-by: Matthew Auld <matthew.auld@intel.com>
Signed-off-by: Matthew Auld <matthew.auld@intel.com>
Link: https://patch.msgid.link/20260908165046.1393557-11-matthew.auld@intel.com
(cherry picked from commit f3391a0b12d7bf826a0b21600d2f294f3dce4c14)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_mmio_gem.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/gpu/drm/xe/xe_mmio_gem.c b/drivers/gpu/drm/xe/xe_mmio_gem.c
index 9a97c4387e4fc..6daedf0feae99 100644
--- a/drivers/gpu/drm/xe/xe_mmio_gem.c
+++ b/drivers/gpu/drm/xe/xe_mmio_gem.c
@@ -39,10 +39,20 @@ struct xe_mmio_gem {
phys_addr_t phys_addr;
};
+static int xe_mmio_gem_vm_may_split(struct vm_area_struct *area, unsigned long addr)
+{
+ /*
+ * Forbid splitting. Together with VM_DONTEXPAND, this keeps the VMA
+ * matching the GEM object exactly.
+ */
+ return -EINVAL;
+}
+
static const struct vm_operations_struct vm_ops = {
.open = drm_gem_vm_open,
.close = drm_gem_vm_close,
.fault = xe_mmio_gem_vm_fault,
+ .may_split = xe_mmio_gem_vm_may_split,
};
static const struct drm_gem_object_funcs xe_mmio_gem_funcs = {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 173/438] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (171 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 172/438] Bluetooth: hci_qca: Do not write to the serial port after it is closed Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 174/438] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync Greg Kroah-Hartman
` (276 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Upstream commit ca18ee413a7cb6f09885778039225e58bae0d607 ]
iso_get_sock() returns the parent socket with a reference held, which is
dropped by sock_put() once the child socket has been set up. The error
path taken when iso_sock_alloc() fails only calls release_sock() and
returns, leaking the reference and thus the parent socket itself.
Drop the reference on that path as well.
Fixes: fa224d0c094a ("Bluetooth: ISO: Reassociate a socket with an active BIS")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 75bfd5938b2ea..4de332b8901f2 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -2289,6 +2289,7 @@ static void iso_conn_ready(struct iso_conn *conn)
BTPROTO_ISO, GFP_ATOMIC, 0);
if (!sk) {
release_sock(parent);
+ sock_put(parent);
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 120/398] drm/xe/mmio_gem: use write-back mapping for dummy page
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (118 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 119/398] drm/xe/mmio_gem: forbid VMA split Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 121/398] drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy Greg Kroah-Hartman
` (282 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Ilia Levi, Matthew Auld,
Rodrigo Vivi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ilia Levi <ilia.levi@intel.com>
[ Upstream commit 819f189265a5955da743e78e20a713a038982e89 ]
Currently vmf_insert_pfn() maps the dummy page as UC, inheriting the
VMA's page protection which was set for the real MMIO region. This
conflicts with the direct map's WB mapping of the same page, creating a
cache type alias which is architecturally undefined on some platforms.
Use vmf_insert_pfn_prot() with a WB pgprot instead. Also simplify to
fault in the requested page instead of the whole VMA.
Fixes: 1ffcf8b8ae8a ("drm/xe: Support for mmap-ing mmio regions")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260525125801.975038-6-ilia.levi%40intel.com
Assisted-by: GitHub-Copilot:claude-opus-4.6
Signed-off-by: Ilia Levi <ilia.levi@intel.com>
Reviewed-by: Matthew Auld <matthew.auld@intel.com>
Signed-off-by: Matthew Auld <matthew.auld@intel.com>
Link: https://patch.msgid.link/20260908165046.1393557-12-matthew.auld@intel.com
(cherry picked from commit 1e8e28e35df0e77ae1b22fc091c1f422f62fa5e9)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_mmio_gem.c | 19 +++++--------------
1 file changed, 5 insertions(+), 14 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_mmio_gem.c b/drivers/gpu/drm/xe/xe_mmio_gem.c
index 6daedf0feae99..30c31b0658e2b 100644
--- a/drivers/gpu/drm/xe/xe_mmio_gem.c
+++ b/drivers/gpu/drm/xe/xe_mmio_gem.c
@@ -172,14 +172,13 @@ static void xe_mmio_gem_release_dummy_page(struct drm_device *dev, void *res)
__free_page((struct page *)res);
}
-static vm_fault_t xe_mmio_gem_vm_fault_dummy_page(struct vm_area_struct *vma)
+static vm_fault_t xe_mmio_gem_vm_fault_dummy_page(struct vm_fault *vmf)
{
+ struct vm_area_struct *vma = vmf->vma;
struct drm_gem_object *base = vma->vm_private_data;
struct drm_device *dev = base->dev;
- vm_fault_t ret = VM_FAULT_NOPAGE;
struct page *page;
unsigned long pfn;
- unsigned long i;
page = alloc_page(GFP_KERNEL | __GFP_ZERO);
if (!page)
@@ -190,16 +189,8 @@ static vm_fault_t xe_mmio_gem_vm_fault_dummy_page(struct vm_area_struct *vma)
pfn = page_to_pfn(page);
- /* Map the entire VMA to the same dummy page */
- for (i = 0; i < base->size; i += PAGE_SIZE) {
- unsigned long addr = vma->vm_start + i;
-
- ret = vmf_insert_pfn(vma, addr, pfn);
- if (ret & VM_FAULT_ERROR)
- break;
- }
-
- return ret;
+ return vmf_insert_pfn_prot(vma, vmf->address, pfn,
+ vm_get_page_prot(vma->vm_flags));
}
static vm_fault_t xe_mmio_gem_vm_fault(struct vm_fault *vmf)
@@ -219,7 +210,7 @@ static vm_fault_t xe_mmio_gem_vm_fault(struct vm_fault *vmf)
* It is assumed the userspace will receive the notification via some
* other channel (e.g. drm uevent).
*/
- return xe_mmio_gem_vm_fault_dummy_page(vma);
+ return xe_mmio_gem_vm_fault_dummy_page(vmf);
}
for (i = 0; i < base->size; i += PAGE_SIZE) {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 174/438] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (172 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 173/438] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 175/438] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events Greg Kroah-Hartman
` (275 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Upstream commit 296e7f3c5071cc02dc22e1566e759179fa1792ae ]
A BIS connection is matched to its parent socket by looking for a
socket in BT_LISTEN state with the same BIG handle:
iso_conn_ready()
if (test_bit(HCI_CONN_BIG_SYNC, &hcon->flags))
parent = iso_get_sock(hdev, &hcon->src, &hcon->dst,
BT_LISTEN, iso_match_big_hcon, hcon);
The socket was only moved to BT_LISTEN after iso_conn_big_sync()
returned, while the LE BIG Create Sync command has already been queued
by then. If the BIG sync is established before the state is updated,
which is easy to hit with an emulated controller as the command may
complete in a few hundred microseconds, no parent is found and the BIS
connections are never notified to the listening socket.
The user space is then left waiting for connections that never arrive,
e.g. bluetoothd never completes a MediaTransport1.Acquire of a
Broadcast Sink transport.
Move the socket to BT_LISTEN before requesting the BIG sync, so the
state is visible by the time the command is queued, and restore the
previous state if the request could not be started. Since the socket is
briefly visible as a listening socket, child sockets may have been
queued in the meantime, so drain the accept queue before restoring the
state: the cleanup paths of BT_CONNECT2/BT_CONNECTED don't do it and the
children would be left with a dangling parent pointer.
Fixes: fbdc4bc47268 ("Bluetooth: ISO: Use defer setup to separate PA sync and BIG sync")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 52 +++++++++++++++++++++++++++++++++++----------
1 file changed, 41 insertions(+), 11 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 4de332b8901f2..eb99653f33f91 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -819,19 +819,24 @@ static void iso_sock_destruct(struct sock *sk)
skb_queue_purge(&sk->sk_error_queue);
}
-static void iso_sock_cleanup_listen(struct sock *parent)
+/* Close not yet accepted channels */
+static void iso_sock_flush_accept_q(struct sock *parent)
{
struct sock *sk;
- BT_DBG("parent %p", parent);
-
- /* Close not yet accepted channels */
while ((sk = bt_accept_dequeue(parent, NULL))) {
iso_sock_close(sk);
iso_sock_kill(sk);
/* Drop the reference handed back by bt_accept_dequeue(). */
sock_put(sk);
}
+}
+
+static void iso_sock_cleanup_listen(struct sock *parent)
+{
+ BT_DBG("parent %p", parent);
+
+ iso_sock_flush_accept_q(parent);
/* If listening socket has a hcon, properly disconnect it */
if (iso_pi(parent)->conn && iso_pi(parent)->conn->hcon) {
@@ -1737,6 +1742,13 @@ static int iso_sock_recvmsg(struct socket *sock, struct msghdr *msg,
switch (sk->sk_state) {
case BT_CONNECT2:
if (test_bit(BT_SK_PA_SYNC, &pi->flags)) {
+ /* Move to BT_LISTEN before requesting the BIG
+ * sync: the BIS connections are matched to a
+ * parent socket in BT_LISTEN state, and they
+ * may be notified before the request returns.
+ */
+ sk->sk_state = BT_LISTEN;
+
release_sock(sk);
err = iso_conn_big_sync(sk);
lock_sock(sk);
@@ -1745,12 +1757,20 @@ static int iso_sock_recvmsg(struct socket *sock, struct msghdr *msg,
* connection may have been torn down
* meanwhile and iso_chan_del() may have
* already moved the socket to BT_CLOSED.
- * Only move on to BT_LISTEN if the BIG sync
- * was actually started and nothing else has
- * changed the state.
+ * Only move back if the BIG sync could not be
+ * started and nothing else has changed the
+ * state.
*/
- if (!err && sk->sk_state == BT_CONNECT2)
- sk->sk_state = BT_LISTEN;
+ if (err && sk->sk_state == BT_LISTEN) {
+ /* Discard any child socket that may
+ * have been queued while the socket
+ * was in BT_LISTEN, as the cleanup of
+ * BT_CONNECT2 doesn't drain the
+ * accept queue.
+ */
+ iso_sock_flush_accept_q(sk);
+ sk->sk_state = BT_CONNECT2;
+ }
} else {
iso_conn_defer_accept(pi->conn->hcon);
sk->sk_state = BT_CONFIG;
@@ -1760,12 +1780,22 @@ static int iso_sock_recvmsg(struct socket *sock, struct msghdr *msg,
break;
case BT_CONNECTED:
if (test_bit(BT_SK_PA_SYNC, &iso_pi(sk)->flags)) {
+ /* As above, the BIS connections may be
+ * notified before the request returns.
+ */
+ sk->sk_state = BT_LISTEN;
+
release_sock(sk);
err = iso_conn_big_sync(sk);
lock_sock(sk);
- if (!err && sk->sk_state == BT_CONNECTED)
- sk->sk_state = BT_LISTEN;
+ if (err && sk->sk_state == BT_LISTEN) {
+ /* As above, don't leave any child
+ * socket behind in the accept queue.
+ */
+ iso_sock_flush_accept_q(sk);
+ sk->sk_state = BT_CONNECTED;
+ }
early_ret = true;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 121/398] drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (119 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 120/398] drm/xe/mmio_gem: use write-back mapping for dummy page Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 122/398] drm/xe/shrinker: Return the freed page count through a parameter Greg Kroah-Hartman
` (281 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilia Levi, Shuicheng Lin,
Matthew Auld, Rodrigo Vivi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuicheng Lin <shuicheng.lin@intel.com>
[ Upstream commit 37fcbd7b2f8996d783932dab11bc668e169b0de6 ]
xe_mmio_gem_create() calls drm_vma_node_allow() but nothing ever calls
drm_vma_node_revoke(). The drm_vma_offset_file rb-tree entry allocated
by drm_vma_node_allow() is not freed by drm_gem_object_release(), so
it is leaked on every create/destroy cycle.
Add a struct drm_file * parameter to xe_mmio_gem_destroy() and call
drm_vma_node_revoke() from there, mirroring the drm_vma_node_allow()
call in xe_mmio_gem_create().
Fixes: 1ffcf8b8ae8a ("drm/xe: Support for mmap-ing mmio regions")
Suggested-by: Ilia Levi <ilia.levi@intel.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Shuicheng Lin <shuicheng.lin@intel.com>
Reviewed-by: Ilia Levi <ilia.levi@intel.com>
Signed-off-by: Matthew Auld <matthew.auld@intel.com>
Link: https://patch.msgid.link/20260908165046.1393557-14-matthew.auld@intel.com
(cherry picked from commit 32f0cb250598456d812fb7ca57a040282858323d)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_mmio_gem.c | 4 +++-
drivers/gpu/drm/xe/xe_mmio_gem.h | 2 +-
2 files changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_mmio_gem.c b/drivers/gpu/drm/xe/xe_mmio_gem.c
index 30c31b0658e2b..afb880c7955eb 100644
--- a/drivers/gpu/drm/xe/xe_mmio_gem.c
+++ b/drivers/gpu/drm/xe/xe_mmio_gem.c
@@ -138,14 +138,16 @@ static void xe_mmio_gem_free(struct drm_gem_object *base)
/**
* xe_mmio_gem_destroy - Destroy the GEM object that exposes an MMIO region
* @gem: the GEM object to destroy
+ * @file: DRM file descriptor previously passed to xe_mmio_gem_create()
*
* This function releases resources associated with the GEM object created by
* xe_mmio_gem_create().
*
* See: "Exposing MMIO regions to userspace"
*/
-void xe_mmio_gem_destroy(struct xe_mmio_gem *gem)
+void xe_mmio_gem_destroy(struct xe_mmio_gem *gem, struct drm_file *file)
{
+ drm_vma_node_revoke(&gem->base.vma_node, file);
xe_mmio_gem_free(&gem->base);
}
diff --git a/drivers/gpu/drm/xe/xe_mmio_gem.h b/drivers/gpu/drm/xe/xe_mmio_gem.h
index 4b76d5586ebb8..80d7795f07c8e 100644
--- a/drivers/gpu/drm/xe/xe_mmio_gem.h
+++ b/drivers/gpu/drm/xe/xe_mmio_gem.h
@@ -15,6 +15,6 @@ struct xe_mmio_gem;
struct xe_mmio_gem *xe_mmio_gem_create(struct xe_device *xe, struct drm_file *file,
phys_addr_t phys_addr, size_t size);
u64 xe_mmio_gem_mmap_offset(struct xe_mmio_gem *gem);
-void xe_mmio_gem_destroy(struct xe_mmio_gem *gem);
+void xe_mmio_gem_destroy(struct xe_mmio_gem *gem, struct drm_file *file);
#endif /* _XE_MMIO_GEM_H_ */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 175/438] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (173 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 174/438] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 176/438] Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access Greg Kroah-Hartman
` (274 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Lu, Luiz Augusto von Dentz,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Lu <chris.lu@mediatek.com>
[ Upstream commit 78b6abd6c7a7591aacdae657f813214dae4fcd3b ]
A too-short BTMTK_WMT_FUNC_CTRL event (WMT header only, no trailing
2-byte status word) is always treated as BTMTK_WMT_ON_UNDONE. This
short form is how firmware acks a plain enable/disable request, and
the actual result is carried in the header's own flag byte (0 =
success), not a separate status word. Decode it from there instead of
assuming failure.
Verified setup on MT7920, MT7921, MT7922 and MT7925: no regression.
Fixes: e3ac0d9f1a20 ("Bluetooth: btmtk: accept too short WMT FUNC_CTRL events")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Chris Lu <chris.lu@mediatek.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btmtk.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btmtk.c b/drivers/bluetooth/btmtk.c
index 26d525acd6590..7ea8bcd8a7eca 100644
--- a/drivers/bluetooth/btmtk.c
+++ b/drivers/bluetooth/btmtk.c
@@ -721,7 +721,12 @@ static int btmtk_usb_hci_wmt_sync(struct hci_dev *hdev,
case BTMTK_WMT_FUNC_CTRL:
if (!skb_pull_data(data->evt_skb,
sizeof(wmt_evt_funcc->status))) {
- status = BTMTK_WMT_ON_UNDONE;
+ /* A plain enable/disable request is acked with just
+ * the WMT header and no trailing status word; the
+ * result is carried in the header's own flag byte.
+ */
+ status = wmt_evt->whdr.flag ? BTMTK_WMT_ON_UNDONE :
+ BTMTK_WMT_ON_DONE;
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 122/398] drm/xe/shrinker: Return the freed page count through a parameter
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (120 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 121/398] drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 123/398] drm/vc4: Use managed KMS polling to fix UAF on unbind Greg Kroah-Hartman
` (280 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Hellström, Matthew Brost,
Shuicheng Lin, Rodrigo Vivi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuicheng Lin <shuicheng.lin@intel.com>
[ Upstream commit 3c90e42a01426262f0cd166bc01b45c05562640d ]
__xe_shrinker_walk() and xe_shrinker_walk() return either the number of
pages freed or a negative error, so the two cannot be reported at once.
On error the pages already freed are dropped, and since xe_shrinker_scan()
only accumulates non-negative returns while *scanned is updated by
pointer, the shrinker tells mm that it scanned without freeing.
Accumulate the count into a caller-provided counter and return only the
status, so an error no longer discards what the walk had freed.
Fixes: 00c8efc3180f ("drm/xe: Add a shrinker for xe bos")
Assisted-by: Claude:claude-opus-5
Reviewed-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Link: https://patch.msgid.link/20260909162102.1097006-2-shuicheng.lin@intel.com
Signed-off-by: Shuicheng Lin <shuicheng.lin@intel.com>
(cherry picked from commit d7aac1a0235a6ce41e30cec385e2db8c33dad12d)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_shrinker.c | 62 ++++++++++++++------------------
1 file changed, 26 insertions(+), 36 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_shrinker.c b/drivers/gpu/drm/xe/xe_shrinker.c
index 90244fe59b599..8a50fea09ef47 100644
--- a/drivers/gpu/drm/xe/xe_shrinker.c
+++ b/drivers/gpu/drm/xe/xe_shrinker.c
@@ -54,13 +54,14 @@ xe_shrinker_mod_pages(struct xe_shrinker *shrinker, long shrinkable, long purgea
write_unlock(&shrinker->lock);
}
-static s64 __xe_shrinker_walk(struct xe_device *xe,
+static int __xe_shrinker_walk(struct xe_device *xe,
struct ttm_operation_ctx *ctx,
const struct xe_bo_shrink_flags flags,
- unsigned long to_scan, unsigned long *scanned)
+ unsigned long to_scan, unsigned long *scanned,
+ unsigned long *freed)
{
unsigned int mem_type;
- s64 freed = 0, lret;
+ s64 lret;
for (mem_type = XE_PL_SYSTEM; mem_type <= XE_PL_TT; ++mem_type) {
struct ttm_resource_manager *man = ttm_manager_type(&xe->ttm, mem_type);
@@ -82,7 +83,7 @@ static s64 __xe_shrinker_walk(struct xe_device *xe,
if (lret < 0)
return lret;
- freed += lret;
+ *freed += lret;
if (*scanned >= to_scan)
break;
}
@@ -90,7 +91,7 @@ static s64 __xe_shrinker_walk(struct xe_device *xe,
xe_assert(xe, !IS_ERR(ttm_bo));
}
- return freed;
+ return 0;
}
/*
@@ -99,40 +100,35 @@ static s64 __xe_shrinker_walk(struct xe_device *xe,
* add writeback. This avoids stalls and explicit writebacks with light or
* moderate memory pressure.
*/
-static s64 xe_shrinker_walk(struct xe_device *xe,
+static int xe_shrinker_walk(struct xe_device *xe,
struct ttm_operation_ctx *ctx,
const struct xe_bo_shrink_flags flags,
- unsigned long to_scan, unsigned long *scanned)
+ unsigned long to_scan, unsigned long *scanned,
+ unsigned long *freed)
{
bool no_wait_gpu = true;
struct xe_bo_shrink_flags save_flags = flags;
- s64 lret, freed;
+ int ret;
swap(no_wait_gpu, ctx->no_wait_gpu);
save_flags.writeback = false;
- lret = __xe_shrinker_walk(xe, ctx, save_flags, to_scan, scanned);
+ ret = __xe_shrinker_walk(xe, ctx, save_flags, to_scan, scanned, freed);
swap(no_wait_gpu, ctx->no_wait_gpu);
- if (lret < 0 || *scanned >= to_scan)
- return lret;
+ if (ret || *scanned >= to_scan)
+ return ret;
- freed = lret;
if (!ctx->no_wait_gpu) {
- lret = __xe_shrinker_walk(xe, ctx, save_flags, to_scan, scanned);
- if (lret < 0)
- return lret;
- freed += lret;
- if (*scanned >= to_scan)
- return freed;
+ ret = __xe_shrinker_walk(xe, ctx, save_flags, to_scan, scanned,
+ freed);
+ if (ret || *scanned >= to_scan)
+ return ret;
}
- if (flags.writeback) {
- lret = __xe_shrinker_walk(xe, ctx, flags, to_scan, scanned);
- if (lret < 0)
- return lret;
- freed += lret;
- }
+ if (flags.writeback)
+ ret = __xe_shrinker_walk(xe, ctx, flags, to_scan, scanned,
+ freed);
- return freed;
+ return ret;
}
static unsigned long
@@ -214,7 +210,6 @@ static unsigned long xe_shrinker_scan(struct shrinker *shrink, struct shrink_con
bool runtime_pm;
bool purgeable;
bool can_backup = !!(sc->gfp_mask & __GFP_FS);
- s64 lret;
nr_to_scan = sc->nr_to_scan;
@@ -225,12 +220,9 @@ static unsigned long xe_shrinker_scan(struct shrinker *shrink, struct shrink_con
/* Might need runtime PM. Try to wake early if it looks like it. */
runtime_pm = xe_shrinker_runtime_pm_get(shrinker, false, nr_to_scan, can_backup);
- if (purgeable && nr_scanned < nr_to_scan) {
- lret = xe_shrinker_walk(shrinker->xe, &ctx, shrink_flags,
- nr_to_scan, &nr_scanned);
- if (lret >= 0)
- freed += lret;
- }
+ if (purgeable && nr_scanned < nr_to_scan)
+ xe_shrinker_walk(shrinker->xe, &ctx, shrink_flags,
+ nr_to_scan, &nr_scanned, &freed);
sc->nr_scanned = nr_scanned;
if (nr_scanned >= nr_to_scan || !can_backup)
@@ -242,10 +234,8 @@ static unsigned long xe_shrinker_scan(struct shrinker *shrink, struct shrink_con
shrink_flags.purge = false;
- lret = xe_shrinker_walk(shrinker->xe, &ctx, shrink_flags,
- nr_to_scan, &nr_scanned);
- if (lret >= 0)
- freed += lret;
+ xe_shrinker_walk(shrinker->xe, &ctx, shrink_flags,
+ nr_to_scan, &nr_scanned, &freed);
sc->nr_scanned = nr_scanned;
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 176/438] Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (174 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 175/438] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 177/438] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown Greg Kroah-Hartman
` (273 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Lu, Luiz Augusto von Dentz,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Lu <chris.lu@mediatek.com>
[ Upstream commit 8879e3e0a84a86954c855caceead4867e74a9a27 ]
btmtksdio.c and btmtkuart.c cast a received WMT event straight to
struct btmtk_hci_wmt_evt and read its op/flag fields without checking
the event is long enough to contain them, unlike btmtk.c. The
FUNC_CTRL case then further casts to struct btmtk_hci_wmt_evt_funcc
and reads its 2-byte status field, again without a length check.
Firmware that sends a short or malformed WMT event makes both drivers
read past the end of the received SKB.
Mirror btmtk.c: validate the base WMT header with skb_pull_data()
before touching any of its fields, and when a FUNC_CTRL event turns
out to be the short, header-only form (a plain enable/disable ack
with no status word), decode the result from the header's own flag
byte instead (0 = success, otherwise failure).
Verified setup on MT7920, MT7921, MT7922 and MT7925: no regression.
Fixes: 9aebfd4a2200 ("Bluetooth: mediatek: add support for MediaTek MT7663S and MT7668S SDIO devices")
Fixes: e0b67035a90b ("Bluetooth: mediatek: update the common setup between MT7622 and other devices")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Chris Lu <chris.lu@mediatek.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btmtksdio.c | 20 +++++++++++++++++++-
drivers/bluetooth/btmtkuart.c | 20 +++++++++++++++++++-
2 files changed, 38 insertions(+), 2 deletions(-)
diff --git a/drivers/bluetooth/btmtksdio.c b/drivers/bluetooth/btmtksdio.c
index 94aa60d9cc207..7fab678925d19 100644
--- a/drivers/bluetooth/btmtksdio.c
+++ b/drivers/bluetooth/btmtksdio.c
@@ -217,7 +217,14 @@ static int mtk_hci_wmt_sync(struct hci_dev *hdev,
}
/* Parse and handle the return WMT event */
- wmt_evt = (struct btmtk_hci_wmt_evt *)bdev->evt_skb->data;
+ wmt_evt = skb_pull_data(bdev->evt_skb, sizeof(*wmt_evt));
+ if (!wmt_evt) {
+ bt_dev_err(hdev, "WMT event too short (%u bytes)",
+ bdev->evt_skb->len);
+ err = -EINVAL;
+ goto err_free_skb;
+ }
+
if (wmt_evt->whdr.op != hdr->op) {
bt_dev_err(hdev, "Wrong op received %d expected %d",
wmt_evt->whdr.op, hdr->op);
@@ -233,6 +240,17 @@ static int mtk_hci_wmt_sync(struct hci_dev *hdev,
status = BTMTK_WMT_PATCH_DONE;
break;
case BTMTK_WMT_FUNC_CTRL:
+ if (!skb_pull_data(bdev->evt_skb,
+ sizeof(wmt_evt_funcc->status))) {
+ /* A plain enable/disable request is acked with just
+ * the WMT header and no trailing status word; the
+ * result is carried in the header's own flag byte.
+ */
+ status = wmt_evt->whdr.flag ? BTMTK_WMT_ON_UNDONE :
+ BTMTK_WMT_ON_DONE;
+ break;
+ }
+
wmt_evt_funcc = (struct btmtk_hci_wmt_evt_funcc *)wmt_evt;
if (be16_to_cpu(wmt_evt_funcc->status) == 0x404)
status = BTMTK_WMT_ON_DONE;
diff --git a/drivers/bluetooth/btmtkuart.c b/drivers/bluetooth/btmtkuart.c
index 27aa48ff3ac2c..4af6fbbbd302a 100644
--- a/drivers/bluetooth/btmtkuart.c
+++ b/drivers/bluetooth/btmtkuart.c
@@ -151,7 +151,14 @@ static int mtk_hci_wmt_sync(struct hci_dev *hdev,
}
/* Parse and handle the return WMT event */
- wmt_evt = (struct btmtk_hci_wmt_evt *)bdev->evt_skb->data;
+ wmt_evt = skb_pull_data(bdev->evt_skb, sizeof(*wmt_evt));
+ if (!wmt_evt) {
+ bt_dev_err(hdev, "WMT event too short (%u bytes)",
+ bdev->evt_skb->len);
+ err = -EINVAL;
+ goto err_free_wc;
+ }
+
if (wmt_evt->whdr.op != hdr->op) {
bt_dev_err(hdev, "Wrong op received %d expected %d",
wmt_evt->whdr.op, hdr->op);
@@ -167,6 +174,17 @@ static int mtk_hci_wmt_sync(struct hci_dev *hdev,
status = BTMTK_WMT_PATCH_DONE;
break;
case BTMTK_WMT_FUNC_CTRL:
+ if (!skb_pull_data(bdev->evt_skb,
+ sizeof(wmt_evt_funcc->status))) {
+ /* A plain enable/disable request is acked with just
+ * the WMT header and no trailing status word; the
+ * result is carried in the header's own flag byte.
+ */
+ status = wmt_evt->whdr.flag ? BTMTK_WMT_ON_UNDONE :
+ BTMTK_WMT_ON_DONE;
+ break;
+ }
+
wmt_evt_funcc = (struct btmtk_hci_wmt_evt_funcc *)wmt_evt;
if (be16_to_cpu(wmt_evt_funcc->status) == 0x404)
status = BTMTK_WMT_ON_DONE;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 123/398] drm/vc4: Use managed KMS polling to fix UAF on unbind
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (121 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 122/398] drm/xe/shrinker: Return the freed page count through a parameter Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 124/398] ALSA: hda: trace PCM open only after assigning a stream Greg Kroah-Hartman
` (279 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Maíra Canal,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 073a30d75f309812ed61af134f24ffef4107b13a ]
vc4_kms_load() calls drm_kms_helper_poll_init() but the driver provides
no matching drm_kms_helper_poll_fini(). The output poll work stays
scheduled after unbind and runs on the freed drm_device:
# modprobe vc4; rmmod vc4; sleep 10
BUG: KASAN: slab-use-after-free in delayed_work_timer_fn
BUG: KASAN: slab-use-after-free in drm_client_dev_hotplug [drm]
Workqueue: events output_poll_execute [drm_kms_helper]
Allocated by task 171: __devm_drm_dev_alloc
Freed by task 262 (rmmod): drm_dev_put / component_del
Use drmm_kms_helper_poll_init() so polling is finalized with the device,
as other drivers do.
Fixes: c8b75bca92cb ("drm/vc4: Add KMS support for Raspberry Pi.")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260822143110.68594-1-kmehltretter@gmail.com
Reviewed-by: Maíra Canal <mcanal@igalia.com>
Signed-off-by: Maíra Canal <mcanal@igalia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/vc4/vc4_kms.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/vc4/vc4_kms.c b/drivers/gpu/drm/vc4/vc4_kms.c
index 8f983edb81ff0..20dad6245ac10 100644
--- a/drivers/gpu/drm/vc4/vc4_kms.c
+++ b/drivers/gpu/drm/vc4/vc4_kms.c
@@ -1162,7 +1162,7 @@ int vc4_kms_load(struct drm_device *dev)
drm_mode_config_reset(dev);
- drm_kms_helper_poll_init(dev);
+ drmm_kms_helper_poll_init(dev);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 177/438] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (175 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 176/438] Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 178/438] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit Greg Kroah-Hartman
` (272 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih,
Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit 7b60ee5f46f2ee329de661f7c68b6818d8136220 ]
In btmtksdio_shutdown(), pm_runtime_get_sync() is called at the
beginning of the function. However, if sending the WMT function
control command fails later, the driver returns early.
It bypasses the corresponding pm_runtime_put_noidle() and
pm_runtime_disable() calls, leaking the PM usage counter and leaving PM
runtime enabled indefinitely.
Fall through to execute the PM runtime cleanup block even if WMT errors.
Fixes: 7f3c563c575e ("Bluetooth: btmtksdio: Add runtime PM support to SDIO based Bluetooth")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btmtksdio.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/bluetooth/btmtksdio.c b/drivers/bluetooth/btmtksdio.c
index 7fab678925d19..a15ae6598c665 100644
--- a/drivers/bluetooth/btmtksdio.c
+++ b/drivers/bluetooth/btmtksdio.c
@@ -1262,10 +1262,8 @@ static int btmtksdio_shutdown(struct hci_dev *hdev)
wmt_params.status = NULL;
err = mtk_hci_wmt_sync(hdev, &wmt_params);
- if (err < 0) {
+ if (err < 0)
bt_dev_err(hdev, "Failed to send wmt func ctrl (%d)", err);
- return err;
- }
ignore_wmt_cmd:
pm_runtime_put_noidle(bdev->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 124/398] ALSA: hda: trace PCM open only after assigning a stream
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (122 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 123/398] drm/vc4: Use managed KMS polling to fix UAF on unbind Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 125/398] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() Greg Kroah-Hartman
` (278 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Slavin Liu, Takashi Iwai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Slavin Liu <bolin.liu@seu.edu.cn>
[ Upstream commit c9e6e5f38bf75276605f1952b22285f5f3abcaff ]
Stream assignment can fail when hardware streams are exhausted.
Move the tracepoint after the NULL check because its payload accesses
the assigned stream tag.
Detected by static analysis and reviewed with AI-assisted source auditing.
Fixes: 184865085b88 ("ALSA: hda - rename hda_intel_trace.h to hda_controller_trace.h")
Assisted-by: LLM
Signed-off-by: Slavin Liu <bolin.liu@seu.edu.cn>
Link: https://patch.msgid.link/20260913125154.109944-1-bolin.liu@seu.edu.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/hda/common/controller.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sound/hda/common/controller.c b/sound/hda/common/controller.c
index b1cfd9bd4dcb7..98ab47977e318 100644
--- a/sound/hda/common/controller.c
+++ b/sound/hda/common/controller.c
@@ -584,11 +584,11 @@ static int azx_pcm_open(struct snd_pcm_substream *substream)
snd_hda_codec_pcm_get(apcm->info);
mutex_lock(&chip->open_mutex);
azx_dev = azx_assign_device(chip, substream);
- trace_azx_pcm_open(chip, azx_dev);
if (azx_dev == NULL) {
err = -EBUSY;
goto unlock;
}
+ trace_azx_pcm_open(chip, azx_dev);
runtime->private_data = azx_dev;
runtime->hw = azx_pcm_hw;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 178/438] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (176 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 177/438] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 179/438] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup Greg Kroah-Hartman
` (271 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sai Teja Aluvala,
Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sai Teja Aluvala <aluvala.sai.teja@intel.com>
[ Upstream commit 2ea5a87a5a7ae58cb2662b8a7d06f209383e1765 ]
btintel_pcie_submit_rx() used frbd_index > rxq->count to guard the
FRBD array access, allowing frbd_index == rxq->count to pass through
and index one element past the end of the array. Change the check to
>= rxq->count so every out-of-range index is rejected.
This issue was reported by Claude Mythos.
Fixes: c2b636b3f788 (Bluetooth: btintel_pcie: Add support for PCIe transport)
Signed-off-by: Sai Teja Aluvala <aluvala.sai.teja@intel.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btintel_pcie.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c
index aad466e453013..3262e950a6bd8 100644
--- a/drivers/bluetooth/btintel_pcie.c
+++ b/drivers/bluetooth/btintel_pcie.c
@@ -508,7 +508,7 @@ static int btintel_pcie_submit_rx(struct btintel_pcie_data *data)
frbd_index = data->ia.tr_hia[BTINTEL_PCIE_RXQ_NUM];
- if (frbd_index > rxq->count)
+ if (frbd_index >= rxq->count)
return -ERANGE;
/* Prepare for RX submit. It updates the FRBD with the address of DMA
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 125/398] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (123 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 124/398] ALSA: hda: trace PCM open only after assigning a stream Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 126/398] btrfs: tree-checker: print dev extent offset in error message Greg Kroah-Hartman
` (277 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolas Escande,
Rameshkumar Sundaram, Baochen Qiang, Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Escande <nico.escande@gmail.com>
[ Upstream commit 820b8cff81c796ba20573e04722ab62500713f97 ]
When mac80211 removes a sta, it calls .sta_state() which in turn calls
ath11k_mac_station_remove(). In that function we clean up both peers &
arsta related resources.
But when the firmware crashes, ath11k calls ieee80211_restart_hw(), which
assumes that all driver related resources are cleaned up beforehand. This
cleanup is supposedly done by ath11k_mac_peer_cleanup_all() but does not
in fact free arsta->rx_stats / tx_stats.
Extract the arsta cleanup from ath11k_mac_station_remove() into a
new ath11k_mac_station_cleanup() and call it from both there and
ath11k_mac_peer_cleanup_all().
This should handle kmemleaks reports like:
unreferenced object 0xffffff801ae66400 (size 1024):
comm "hostapd", pid 1306, jiffies 4295011565
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace (crc d61c08ec):
kmemleak_alloc+0x3c/0x50
__kmalloc_cache_noprof+0x2b0/0x3e0
ath11k_mac_op_sta_state+0x1dc/0xb10
drv_sta_state+0xac/0x6f8
sta_info_insert_rcu+0x314/0x5e0
sta_info_insert+0x14/0x38
ieee80211_add_station+0x10c/0x1a0
nl80211_new_station+0x3e8/0x680
genl_family_rcv_msg_doit+0xc0/0x120
genl_rcv_msg+0x1b4/0x258
netlink_rcv_skb+0x4c/0x108
genl_rcv+0x38/0x60
netlink_unicast+0x190/0x278
netlink_sendmsg+0x15c/0x370
____sys_sendmsg+0x120/0x290
___sys_sendmsg+0x70/0xa0
Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.9.0.1-01977-QCAHKSWPL_SILICONZ-1
Fixes: d5c65159f289 ("ath11k: driver for Qualcomm IEEE 802.11ax devices")
Signed-off-by: Nicolas Escande <nico.escande@gmail.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260731145830.769811-1-nico.escande@gmail.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath11k/mac.c | 25 ++++++++++++++++++-------
1 file changed, 18 insertions(+), 7 deletions(-)
diff --git a/drivers/net/wireless/ath/ath11k/mac.c b/drivers/net/wireless/ath/ath11k/mac.c
index 4794caa9f7eaa..c97c07a7ef0fd 100644
--- a/drivers/net/wireless/ath/ath11k/mac.c
+++ b/drivers/net/wireless/ath/ath11k/mac.c
@@ -873,6 +873,22 @@ static int ath11k_mac_set_kickout(struct ath11k_vif *arvif)
return 0;
}
+static void ath11k_mac_station_cleanup(struct ieee80211_sta *sta)
+{
+ struct ath11k_sta *arsta;
+
+ if (!sta)
+ return;
+
+ arsta = ath11k_sta_to_arsta(sta);
+
+ kfree(arsta->tx_stats);
+ arsta->tx_stats = NULL;
+
+ kfree(arsta->rx_stats);
+ arsta->rx_stats = NULL;
+}
+
void ath11k_mac_peer_cleanup_all(struct ath11k *ar)
{
struct ath11k_peer *peer, *tmp;
@@ -885,6 +901,7 @@ void ath11k_mac_peer_cleanup_all(struct ath11k *ar)
list_for_each_entry_safe(peer, tmp, &ab->peers, list) {
ath11k_peer_rx_tid_cleanup(ar, peer);
ath11k_peer_rhash_delete(ab, peer);
+ ath11k_mac_station_cleanup(peer->sta);
list_del(&peer->list);
kfree(peer);
}
@@ -9720,7 +9737,6 @@ static int ath11k_mac_station_remove(struct ath11k *ar,
{
struct ath11k_base *ab = ar->ab;
struct ath11k_vif *arvif = ath11k_vif_to_arvif(vif);
- struct ath11k_sta *arsta = ath11k_sta_to_arsta(sta);
int ret;
if (ab->hw_params.vdev_start_delay &&
@@ -9744,12 +9760,7 @@ static int ath11k_mac_station_remove(struct ath11k *ar,
sta->addr, arvif->vdev_id);
ath11k_mac_dec_num_stations(arvif, sta);
-
- kfree(arsta->tx_stats);
- arsta->tx_stats = NULL;
-
- kfree(arsta->rx_stats);
- arsta->rx_stats = NULL;
+ ath11k_mac_station_cleanup(sta);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 179/438] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (177 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 178/438] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 180/438] af_unix: Unify scc_index when finalising SCC in __unix_walk_scc() Greg Kroah-Hartman
` (270 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+0cece8fa7d83523f47a3,
Juan Perdomo, Luiz Augusto von Dentz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Juan Perdomo <jcperdomo100@gmail.com>
[ Upstream commit 801fb950cae7048eb7d83b18857d1ca37b8cd5a4 ]
rfcomm_sock_cleanup_listen() closes unaccepted child sockets through
rfcomm_sock_close(), which takes the child socket lock before
rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these
locks in reverse order while handling connections and DLC state changes,
so lockdep reports a possible deadlock.
Close dequeued children without taking their socket lock. The accept queue
owns a reference to each child, and bt_accept_dequeue() locks the child
while unlinking it and clearing its parent pointer.
Dropping the child lock makes it important to prevent a concurrent
rfcomm_connect_ind() from enqueueing a new child after cleanup observes an
empty queue. Set a listening socket to BT_CLOSED while its lock is still
held, before dropping the lock and draining the queue. The state check in
rfcomm_connect_ind() then rejects new children once cleanup starts.
Reported-by: syzbot+0cece8fa7d83523f47a3@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0cece8fa7d83523f47a3
Fixes: b7ce436a5d79 ("Bluetooth: switch to lock_sock in RFCOMM")
Signed-off-by: Juan Perdomo <jcperdomo100@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/rfcomm/sock.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/net/bluetooth/rfcomm/sock.c b/net/bluetooth/rfcomm/sock.c
index feb302a491fa0..24b42483b3c0c 100644
--- a/net/bluetooth/rfcomm/sock.c
+++ b/net/bluetooth/rfcomm/sock.c
@@ -241,9 +241,7 @@ static void __rfcomm_sock_close(struct sock *sk)
*/
static void rfcomm_sock_close(struct sock *sk)
{
- lock_sock(sk);
__rfcomm_sock_close(sk);
- release_sock(sk);
}
static void rfcomm_sock_init(struct sock *sk, struct sock *parent)
@@ -904,6 +902,7 @@ static int rfcomm_sock_compat_ioctl(struct socket *sock, unsigned int cmd, unsig
static int rfcomm_sock_shutdown(struct socket *sock, int how)
{
struct sock *sk = sock->sk;
+ bool cleanup_listen = false;
int err = 0;
BT_DBG("sock %p, sk %p", sock, sk);
@@ -914,9 +913,17 @@ static int rfcomm_sock_shutdown(struct socket *sock, int how)
lock_sock(sk);
if (!sk->sk_shutdown) {
sk->sk_shutdown = SHUTDOWN_MASK;
+ if (sk->sk_state == BT_LISTEN) {
+ /* Block new children before cleaning up without sk lock. */
+ sk->sk_state = BT_CLOSED;
+ cleanup_listen = true;
+ }
release_sock(sk);
- __rfcomm_sock_close(sk);
+ if (cleanup_listen)
+ rfcomm_sock_cleanup_listen(sk);
+ else
+ __rfcomm_sock_close(sk);
lock_sock(sk);
if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime &&
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 126/398] btrfs: tree-checker: print dev extent offset in error message
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (124 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 125/398] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 127/398] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL Greg Kroah-Hartman
` (276 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Filipe Manana,
David Sterba, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit a1167d9420474ab9ed9efca99d86aeb6217c0265 ]
If a dev extent's offset is not sector size aligned, the error message is
printing the dev extent's objectid instead of the offset. This is a copy
paste error, as before this check we check the objectid field.
Fixes: 008e2512dc56 ("btrfs: tree-checker: add dev extent item checks")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/tree-checker.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/btrfs/tree-checker.c b/fs/btrfs/tree-checker.c
index 79f297d9ebc4a..baaca330e5dba 100644
--- a/fs/btrfs/tree-checker.c
+++ b/fs/btrfs/tree-checker.c
@@ -1925,7 +1925,7 @@ static int check_dev_extent_item(const struct extent_buffer *leaf,
sectorsize))) {
generic_err(leaf, slot,
"invalid dev extent chunk offset, has %llu not aligned to %u",
- btrfs_dev_extent_chunk_objectid(leaf, de),
+ btrfs_dev_extent_chunk_offset(leaf, de),
sectorsize);
return -EUCLEAN;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 180/438] af_unix: Unify scc_index when finalising SCC in __unix_walk_scc().
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (178 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 179/438] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 181/438] net: stmmac: fix TSO header length truncation Greg Kroah-Hartman
` (269 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Burton, Kuniyuki Iwashima,
Simon Horman, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 4a4263dfeabad72f95e8ab6e15146861fa4144dd ]
Commit bfdb01283ee8 ("af_unix: Assign a unique index to SCC.")
changed Tarjan's algorithm to update lowlink with lowlink,
which is called lowpoint (unix_vertex.scc_index).
unix_vertex_dead() assumes all vertices in an SCC share the same
lowpoint, but this is not always true if an SCC has two or more
back edges, depending on the order of DFS.
For example, the graph below has two back edges from B to A
and from C to B.
A --> B --> C
^ | ^ |
`----' `----'
If DFS walks through A -> B -> C -> B (-> C -> B) -> A (-> B -> A),
each index and scc_index will be updated as follows.
A --> B --> C C = (3, 3) (index, scc_index)
B = (2, 2)
A = (1, 1)
A ... B ... C C = (3, 2)<-.
^ | B = (2, 2) -'
`----' A = (1, 1)
A ... B ... C C = (3, 2)
^ | . . B = (2, 1)<-.
`----' .... A = (1, 1) -'
Then, unix_vertex_dead() thinks that B is passed to another
SCC with scc_index 2, and the SCC is not garbage-collected.
This does not happen if DFS walks in a different order below
or starts from B.
1 3
A --> B --> C
^ | ^ |
`----' `----'
2 4
Let's unify scc_index across the SCC when finalising it.
Note that updating v->index was previously done in unix_scc_dead(),
when called from __unix_walk_scc(), just to save one loop. Since
__unix_walk_scc() now iterates over the SCC anyway, the update is
moved back to __unix_walk_scc() and 'fast' argument is dropped.
Fixes: 4090fa373f0e ("af_unix: Replace garbage collection algorithm.")
Reported-by: James Burton <jamesburton@meta.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260912030852.1467872-2-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/unix/garbage.c | 17 ++++++++++-------
1 file changed, 10 insertions(+), 7 deletions(-)
diff --git a/net/unix/garbage.c b/net/unix/garbage.c
index 9fcaaf55cba5d..da774f56ca648 100644
--- a/net/unix/garbage.c
+++ b/net/unix/garbage.c
@@ -374,7 +374,7 @@ static bool unix_vertex_dead(struct unix_vertex *vertex)
static LIST_HEAD(unix_visited_vertices);
static unsigned long unix_vertex_grouped_index = UNIX_VERTEX_INDEX_MARK2;
-static bool unix_scc_dead(struct list_head *scc, bool fast)
+static bool unix_scc_dead(struct list_head *scc)
{
struct unix_vertex *vertex;
bool scc_dead = true;
@@ -386,10 +386,6 @@ static bool unix_scc_dead(struct list_head *scc, bool fast)
/* Don't restart DFS from this vertex. */
list_move_tail(&vertex->entry, &unix_visited_vertices);
- /* Mark vertex as off-stack for __unix_walk_scc(). */
- if (!fast)
- vertex->index = unix_vertex_grouped_index;
-
if (scc_dead)
scc_dead = unix_vertex_dead(vertex);
}
@@ -521,6 +517,7 @@ static unsigned long __unix_walk_scc(struct unix_vertex *vertex,
}
if (vertex->index == vertex->scc_index) {
+ struct unix_vertex *v;
struct list_head scc;
/* SCC finalised.
@@ -530,7 +527,13 @@ static unsigned long __unix_walk_scc(struct unix_vertex *vertex,
*/
__list_cut_position(&scc, &vertex_stack, &vertex->scc_entry);
- if (unix_scc_dead(&scc, false)) {
+ list_for_each_entry_reverse(v, &scc, scc_entry) {
+ /* Mark vertex as off-stack and assign a unique ID. */
+ v->index = unix_vertex_grouped_index;
+ v->scc_index = vertex->scc_index;
+ }
+
+ if (unix_scc_dead(&scc)) {
unix_collect_skb(&scc, hitlist);
} else {
if (unix_vertex_max_scc_index < vertex->scc_index)
@@ -588,7 +591,7 @@ static void unix_walk_scc_fast(struct sk_buff_head *hitlist)
vertex = list_first_entry(&unix_unvisited_vertices, typeof(*vertex), entry);
list_add(&scc, &vertex->scc_entry);
- if (unix_scc_dead(&scc, true)) {
+ if (unix_scc_dead(&scc)) {
cyclic_sccs--;
unix_collect_skb(&scc, hitlist);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 127/398] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (125 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 126/398] btrfs: tree-checker: print dev extent offset in error message Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 128/398] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Greg Kroah-Hartman
` (275 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abel Vesa, Krzysztof Kozlowski,
Dmitry Baryshkov, Konrad Dybcio, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 2028280686f4fa78e2f1f6dede4b6c1fd782b9e3 ]
DSI 6G v2.9 hosts (SM8650, SM8750, Kaanapali, etc.) reparent the byte and
pixel RCGs to the DSI PHY PLL at runtime from
dsi_link_clk_set_rate_6g_v2_9(), after the PHY has been enabled. However
dsi_calc_clk_rate_6g() runs earlier, in order to compute the bit clock
request for the PHY. At that point the byte RCG still has its reset
parent (XO), so clk_round_rate() returns a bogus rate, which then ends up
in the PHY bit clock request and the PLL gets programmed to a wrong
frequency, breaking the panel.
Move the rounding to dsi_link_clk_set_rate_6g(), which is called after
the RCGs have been reparented to the PLL. Storing the rounded rate at
this point still makes later link_clk_set_rate() calls no-ops in the
CCF. Derive the byte interface clock rate from the rounded byte clock
rate, otherwise it would keep requesting the idealized rate and
retrigger the PLL on every transfer.
Reported-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reported-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Fixes: 6cd33b6f4155 ("drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value")
Assisted-by: LLM
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Tested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com> # SM6115P J606F
Tested-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/750496/
Link: https://lore.kernel.org/r/20260903-fix-eliza-dsi-v1-1-3474a6c9f2e0@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dsi/dsi_host.c | 36 ++++++++++++++++--------------
1 file changed, 19 insertions(+), 17 deletions(-)
diff --git a/drivers/gpu/drm/msm/dsi/dsi_host.c b/drivers/gpu/drm/msm/dsi/dsi_host.c
index 5110fe05ca841..4e93f8dd39d7d 100644
--- a/drivers/gpu/drm/msm/dsi/dsi_host.c
+++ b/drivers/gpu/drm/msm/dsi/dsi_host.c
@@ -129,7 +129,7 @@ struct msm_dsi_host {
struct clk *dsi_pll_pixel_clk;
unsigned long byte_clk_rate;
- unsigned long byte_intf_clk_rate;
+ bool byte_intf_clk_div_2;
unsigned long pixel_clk_rate;
unsigned long esc_clk_rate;
@@ -381,8 +381,20 @@ int msm_dsi_runtime_resume(struct device *dev)
int dsi_link_clk_set_rate_6g(struct msm_dsi_host *msm_host)
{
+ unsigned long byte_intf_clk_rate;
+ long rounded_byte_clk_rate;
int ret;
+ rounded_byte_clk_rate = clk_round_rate(msm_host->byte_clk,
+ msm_host->byte_clk_rate);
+ if (rounded_byte_clk_rate < 0) {
+ pr_err("%s: failed to round byte clock rate, %ld\n",
+ __func__, rounded_byte_clk_rate);
+ return rounded_byte_clk_rate;
+ }
+
+ msm_host->byte_clk_rate = rounded_byte_clk_rate;
+
DBG("Set clk rates: pclk=%lu, byteclk=%lu",
msm_host->pixel_clk_rate, msm_host->byte_clk_rate);
@@ -400,7 +412,11 @@ int dsi_link_clk_set_rate_6g(struct msm_dsi_host *msm_host)
}
if (msm_host->byte_intf_clk) {
- ret = clk_set_rate(msm_host->byte_intf_clk, msm_host->byte_intf_clk_rate);
+ byte_intf_clk_rate = msm_host->byte_clk_rate;
+ if (msm_host->byte_intf_clk_div_2)
+ byte_intf_clk_rate /= 2;
+
+ ret = clk_set_rate(msm_host->byte_intf_clk, byte_intf_clk_rate);
if (ret) {
pr_err("%s: Failed to set rate byte intf clk, %d\n",
__func__, ret);
@@ -668,24 +684,12 @@ static void dsi_calc_pclk(struct msm_dsi_host *msm_host, bool is_bonded_dsi)
int dsi_calc_clk_rate_6g(struct msm_dsi_host *msm_host, bool is_bonded_dsi)
{
- long rounded_byte_clk_rate;
-
if (!msm_host->mode) {
pr_err("%s: mode not set\n", __func__);
return -EINVAL;
}
dsi_calc_pclk(msm_host, is_bonded_dsi);
-
- rounded_byte_clk_rate = clk_round_rate(msm_host->byte_clk,
- msm_host->byte_clk_rate);
- if (rounded_byte_clk_rate < 0) {
- pr_err("%s: failed to round byte clock rate, %ld\n",
- __func__, rounded_byte_clk_rate);
- return rounded_byte_clk_rate;
- }
-
- msm_host->byte_clk_rate = rounded_byte_clk_rate;
msm_host->esc_clk_rate = clk_get_rate(msm_host->esc_clk);
return 0;
}
@@ -2470,9 +2474,7 @@ int msm_dsi_host_power_on(struct mipi_dsi_host *host,
goto unlock_ret;
}
- msm_host->byte_intf_clk_rate = msm_host->byte_clk_rate;
- if (phy_shared_timings->byte_intf_clk_div_2)
- msm_host->byte_intf_clk_rate /= 2;
+ msm_host->byte_intf_clk_div_2 = phy_shared_timings->byte_intf_clk_div_2;
msm_dsi_sfpb_config(msm_host, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 181/438] net: stmmac: fix TSO header length truncation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (179 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 180/438] af_unix: Unify scc_index when finalising SCC in __unix_walk_scc() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 182/438] pppoatm: ensure a writable skb header and linear data Greg Kroah-Hartman
` (268 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit 15989abd74f16f44bf953d056b95f1d2fda9b0cd ]
stmmac_tso_xmit() stores the protocol header length returned by
stmmac_tso_header_size() in a u8. stmmac_tso_valid_packet() admits
headers up to 1023 bytes, so a header longer than 255 bytes wraps modulo
256 (486 becomes 230, 256 becomes 0).
A TCP over IPv6 socket carrying a few hundred bytes of sticky
destination/hop-by-hop options makes skb_tcp_all_headers() exceed 255
while staying below the 1023-byte limit, so such an skb reaches
stmmac_tso_xmit().
Widen proto_hdr_len to unsigned int, which is sufficient since the value
is bounded by the hardware limit, and adjust the debug print specifier
accordingly.
Fixes: 9edfa7dab811 ("net: stmmac: enable TSO for IPv6")
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260911-stmmac-fix-header-length-v1-1-8fc103334327@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
index f801caf65fff1..5f717f02c3c01 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
@@ -4513,16 +4513,16 @@ static int stmmac_tso_get_num_desc(struct stmmac_tx_queue *tx_q,
*/
static netdev_tx_t stmmac_tso_xmit(struct sk_buff *skb, struct net_device *dev)
{
+ unsigned int first_entry, entry, tx_packets, proto_hdr_len;
struct dma_desc *desc, *first, *mss_desc = NULL;
struct stmmac_priv *priv = netdev_priv(dev);
- unsigned int first_entry, entry, tx_packets;
struct stmmac_txq_stats *txq_stats;
int i, first_tx, nfrags, ndesc;
struct stmmac_tx_queue *tx_q;
bool set_ic, is_last_segment;
u32 pay_len, mss, queue;
- u8 proto_hdr_len, hdr;
dma_addr_t des;
+ u8 hdr;
nfrags = skb_shinfo(skb)->nr_frags;
queue = skb_get_queue_mapping(skb);
@@ -4570,7 +4570,7 @@ static netdev_tx_t stmmac_tso_xmit(struct sk_buff *skb, struct net_device *dev)
}
if (netif_msg_tx_queued(priv)) {
- pr_info("%s: hdrlen %d, hdr_len %d, pay_len %d, mss %d\n",
+ pr_info("%s: hdrlen %d, hdr_len %u, pay_len %d, mss %d\n",
__func__, hdr, proto_hdr_len, pay_len, mss);
pr_info("\tskb->len %d, skb->data_len %d\n", skb->len,
skb->data_len);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 128/398] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (126 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 127/398] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 129/398] net: bcmgenet: convert RX path to page_pool Greg Kroah-Hartman
` (274 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrea Mayer, David Ahern,
Hangbin Liu, Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrea Mayer <andrea.mayer@uniroma2.it>
[ Upstream commit 7616242a2b37883f7322aaa1d2bd6cd0fed28315 ]
When an SRv6 packet arrives on an interface enslaved to a VRF,
vrf_ip6_rcv() sets IP6SKB_L3SLAVE in IP6CB, but decap_and_validate()
has never set IPSKB_L3SLAVE in IPCB. The bit stayed clear in the
common case, and with CONFIG_IPV6_MIP6 the leftover frag_max_size of
a reassembled outer packet could even set it, with no VRF involved.
Commit 44930446dde4 ("ipv6: seg6: clear IPv4 control block on IPIP
decapsulation") then made the unreliable bit reliably clear.
The effect of the missing flag is visible with End.DX4 when a
delivery to a local address of the node reaches the socket lookup.
For example, a UDP socket bound to the enslaved ingress interface
does not receive any of the decapsulated packets, while an unbound
socket outside the VRF does.
This contradicts Documentation/networking/vrf.rst: by default the
scope of an unbound UDP or TCP socket is limited to the default VRF.
Set IPSKB_L3SLAVE for IPv4 in decap_and_validate(), which already does
the same for IPv6. The socket lookup then matches the decapsulated
packet like any other packet received on that enslaved interface. Such
a packet matches an unbound UDP or TCP socket only when
udp_l3mdev_accept or tcp_l3mdev_accept is set.
Fixes: 891ef8dd2a8d ("ipv6: sr: implement additional seg6local actions")
Signed-off-by: Andrea Mayer <andrea.mayer@uniroma2.it>
Reviewed-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260913194421.31-1-andrea.mayer@uniroma2.it
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/seg6_local.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/ipv6/seg6_local.c b/net/ipv6/seg6_local.c
index 7b52122201858..d1070aec7b72b 100644
--- a/net/ipv6/seg6_local.c
+++ b/net/ipv6/seg6_local.c
@@ -257,10 +257,13 @@ static bool decap_and_validate(struct sk_buff *skb, int proto)
return false;
if (proto == IPPROTO_IPIP) {
+ bool l3slave = ipv6_l3mdev_skb(IP6CB(skb)->flags);
int iif = IP6CB(skb)->iif;
memset(IPCB(skb), 0, sizeof(*IPCB(skb)));
IPCB(skb)->iif = iif;
+ if (l3slave)
+ IPCB(skb)->flags |= IPSKB_L3SLAVE;
} else if (proto == IPPROTO_IPV6) {
bool l3slave = ipv6_l3mdev_skb(IP6CB(skb)->flags);
int iif = IP6CB(skb)->iif;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 182/438] pppoatm: ensure a writable skb header and linear data
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (180 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 181/438] net: stmmac: fix TSO header length truncation Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 183/438] drop_monitor: synchronize tracepoint unregistration on error path Greg Kroah-Hartman
` (267 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit ecc7253683a3c55caa868ce0ee530fcb0044bd3c ]
In pppoatm_send(), LLC encapsulation checks whether there is sufficient
headroom for the 4-byte LLC header, but does not ensure that the skb header
is writable.
Normal transmit packets passing through ppp_start_xmit() have their header
unshared via skb_cow_head(). However, packets can also reach pppoatm_send()
via PPP channel bridging (PPPIOCBRIDGECHAN) without going through
ppp_start_xmit().
Use skb_cow_head() to ensure both sufficient headroom and a writable
header before pushing the LLC header.
While at it:
- Call pskb_may_pull(skb, 1) before inspecting skb->data[0] to prevent
out-of-bounds reads on zero-length or non-linear frames (e.g. from
bridging).
- Defer SC_COMP_PROT protocol compression until after pppoatm_may_send()
succeeds. This eliminates the temporary skb allocation on admission failure
and completely removes the fragile "undo" heuristic at the nospace label,
avoiding any risk of reading uninitialized headroom or performing an
unbalanced skb_push().
Fixes: 4cf476ced45d ("ppp: add PPPIOCBRIDGECHAN and PPPIOCUNBRIDGECHAN ioctls")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260912233048.3977192-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/atm/pppoatm.c | 42 +++++++++++++++++-------------------------
1 file changed, 17 insertions(+), 25 deletions(-)
diff --git a/net/atm/pppoatm.c b/net/atm/pppoatm.c
index 6da52d12df68e..5214786e61d11 100644
--- a/net/atm/pppoatm.c
+++ b/net/atm/pppoatm.c
@@ -292,10 +292,13 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
struct atm_vcc *vcc;
int ret;
+ if (!pskb_may_pull(skb, 1)) {
+ kfree_skb(skb);
+ return DROP_PACKET;
+ }
+
ATM_SKB(skb)->vcc = pvcc->atmvcc;
pr_debug("(skb=0x%p, vcc=0x%p)\n", skb, pvcc->atmvcc);
- if (skb->data[0] == '\0' && (pvcc->flags & SC_COMP_PROT))
- (void) skb_pull(skb, 1);
vcc = ATM_SKB(skb)->vcc;
bh_lock_sock(sk_atm(vcc));
@@ -317,23 +320,13 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
switch (pvcc->encaps) { /* LLC encapsulation needed */
case e_llc:
- if (skb_headroom(skb) < LLC_LEN) {
- struct sk_buff *n;
- n = skb_realloc_headroom(skb, LLC_LEN);
- if (n != NULL &&
- !pppoatm_may_send(pvcc, n->truesize)) {
- kfree_skb(n);
- goto nospace;
- }
- consume_skb(skb);
- skb = n;
- if (skb == NULL) {
- bh_unlock_sock(sk_atm(vcc));
- return DROP_PACKET;
- }
- } else if (!pppoatm_may_send(pvcc, skb->truesize))
+ if (skb_cow_head(skb, LLC_LEN)) {
+ bh_unlock_sock(sk_atm(vcc));
+ kfree_skb(skb);
+ return DROP_PACKET;
+ }
+ if (!pppoatm_may_send(pvcc, skb->truesize))
goto nospace;
- memcpy(skb_push(skb, LLC_LEN), pppllc, LLC_LEN);
break;
case e_vc:
if (!pppoatm_may_send(pvcc, skb->truesize))
@@ -346,6 +339,12 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
return 1;
}
+ if (skb->data[0] == '\0' && (pvcc->flags & SC_COMP_PROT))
+ skb_pull(skb, 1);
+
+ if (pvcc->encaps == e_llc)
+ memcpy(skb_push(skb, LLC_LEN), pppllc, LLC_LEN);
+
atm_account_tx(vcc, skb);
pr_debug("atm_skb(%p)->vcc(%p)->dev(%p)\n",
skb, ATM_SKB(skb)->vcc, ATM_SKB(skb)->vcc->dev);
@@ -355,13 +354,6 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
return ret;
nospace:
bh_unlock_sock(sk_atm(vcc));
- /*
- * We don't have space to send this SKB now, but we might have
- * already applied SC_COMP_PROT compression, so may need to undo
- */
- if ((pvcc->flags & SC_COMP_PROT) && skb_headroom(skb) > 0 &&
- skb->data[-1] == '\0')
- (void) skb_push(skb, 1);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 129/398] net: bcmgenet: convert RX path to page_pool
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (127 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 128/398] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-24 6:58 ` Karl Mehltretter
2026-09-23 14:03 ` [PATCH 6.18 130/398] net: bcmgenet: restore the hardware filters on open Greg Kroah-Hartman
` (273 subsequent siblings)
402 siblings, 1 reply; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Justin Chen,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolai Buchwitz <nb@tipi-net.de>
[ Upstream commit 7bc054c2d4ed1fa3560144fea41d91a87eaa25f1 ]
Replace the per-packet __netdev_alloc_skb() + dma_map_single() in the
RX path with page_pool. SKBs are built from pool pages via
napi_build_skb() with skb_mark_for_recycle() so the network stack
returns pages to the pool, and DMA mapping happens once per page
instead of once per packet.
Reject HW-reported lengths smaller than the RSB so a runt cannot
underflow the SKB build path.
Drop the now-unused priv->rx_buf_len field and the rx_dma_failed soft
MIB counter (nothing increments it after the conversion). This
removes the "rx_dma_failed" entry from ethtool -S, which is a
user-visible change for monitoring tools that key on stat names.
Signed-off-by: Nicolai Buchwitz <nb@tipi-net.de>
Reviewed-by: Justin Chen <justin.chen@broadcom.com>
Tested-by: Justin Chen <justin.chen@broadcom.com>
Link: https://patch.msgid.link/20260610114835.2225423-1-nb@tipi-net.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 23ca4ddc4fce ("net: bcmgenet: restore the hardware filters on open")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/broadcom/Kconfig | 1 +
.../net/ethernet/broadcom/genet/bcmgenet.c | 220 +++++++++++-------
.../net/ethernet/broadcom/genet/bcmgenet.h | 5 +-
3 files changed, 141 insertions(+), 85 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/Kconfig b/drivers/net/ethernet/broadcom/Kconfig
index fe15d684990fc..47e9ece4b37af 100644
--- a/drivers/net/ethernet/broadcom/Kconfig
+++ b/drivers/net/ethernet/broadcom/Kconfig
@@ -77,6 +77,7 @@ config BCMGENET
select BCM7XXX_PHY
select MDIO_BCM_UNIMAC
select DIMLIB
+ select PAGE_POOL
select BROADCOM_PHY if ARCH_BCM2835
help
This driver supports the built-in Ethernet MACs found in the
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index fc5c8a4ae41eb..7f9d43a75f3bd 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -52,6 +52,12 @@
#define RX_BUF_LENGTH 2048
#define SKB_ALIGNMENT 32
+/* Page pool RX buffer layout:
+ * RSB(64) + pad(2) | frame data | skb_shared_info
+ * The HW writes the 64B RSB + 2B alignment padding before the frame.
+ */
+#define GENET_RSB_PAD (sizeof(struct status_64) + 2)
+
/* Tx/Rx DMA register offset, skip 256 descriptors */
#define WORDS_PER_BD(p) (p->hw_params->words_per_bd)
#define DMA_DESC_SIZE (WORDS_PER_BD(priv) * sizeof(u32))
@@ -1153,7 +1159,6 @@ static const struct bcmgenet_stats bcmgenet_gstrings_stats[] = {
UMAC_RBUF_ERR_CNT_V1),
STAT_GENET_MISC("mdf_err_cnt", mib.mdf_err_cnt, UMAC_MDF_ERR_CNT),
STAT_GENET_SOFT_MIB("alloc_rx_buff_failed", mib.alloc_rx_buff_failed),
- STAT_GENET_SOFT_MIB("rx_dma_failed", mib.rx_dma_failed),
STAT_GENET_SOFT_MIB("tx_dma_failed", mib.tx_dma_failed),
STAT_GENET_SOFT_MIB("tx_realloc_tsb", mib.tx_realloc_tsb),
STAT_GENET_SOFT_MIB("tx_realloc_tsb_failed",
@@ -1889,21 +1894,13 @@ static struct sk_buff *bcmgenet_free_tx_cb(struct device *dev,
}
/* Simple helper to free a receive control block's resources */
-static struct sk_buff *bcmgenet_free_rx_cb(struct device *dev,
- struct enet_cb *cb)
+static void bcmgenet_free_rx_cb(struct enet_cb *cb,
+ struct page_pool *pool)
{
- struct sk_buff *skb;
-
- skb = cb->skb;
- cb->skb = NULL;
-
- if (dma_unmap_addr(cb, dma_addr)) {
- dma_unmap_single(dev, dma_unmap_addr(cb, dma_addr),
- dma_unmap_len(cb, dma_len), DMA_FROM_DEVICE);
- dma_unmap_addr_set(cb, dma_addr, 0);
+ if (cb->rx_page) {
+ page_pool_put_full_page(pool, cb->rx_page, false);
+ cb->rx_page = NULL;
}
-
- return skb;
}
/* Unlocked version of the reclaim routine */
@@ -2237,46 +2234,29 @@ static netdev_tx_t bcmgenet_xmit(struct sk_buff *skb, struct net_device *dev)
goto out;
}
-static struct sk_buff *bcmgenet_rx_refill(struct bcmgenet_priv *priv,
- struct enet_cb *cb)
+static int bcmgenet_rx_refill(struct bcmgenet_rx_ring *ring,
+ struct enet_cb *cb)
{
- struct device *kdev = &priv->pdev->dev;
- struct sk_buff *skb;
- struct sk_buff *rx_skb;
+ struct bcmgenet_priv *priv = ring->priv;
dma_addr_t mapping;
+ struct page *page;
- /* Allocate a new Rx skb */
- skb = __netdev_alloc_skb(priv->dev, priv->rx_buf_len + SKB_ALIGNMENT,
- GFP_ATOMIC | __GFP_NOWARN);
- if (!skb) {
+ page = page_pool_alloc_pages(ring->page_pool,
+ GFP_ATOMIC);
+ if (!page) {
priv->mib.alloc_rx_buff_failed++;
netif_err(priv, rx_err, priv->dev,
- "%s: Rx skb allocation failed\n", __func__);
- return NULL;
- }
-
- /* DMA-map the new Rx skb */
- mapping = dma_map_single(kdev, skb->data, priv->rx_buf_len,
- DMA_FROM_DEVICE);
- if (dma_mapping_error(kdev, mapping)) {
- priv->mib.rx_dma_failed++;
- dev_kfree_skb_any(skb);
- netif_err(priv, rx_err, priv->dev,
- "%s: Rx skb DMA mapping failed\n", __func__);
- return NULL;
+ "%s: Rx page allocation failed\n", __func__);
+ return -ENOMEM;
}
- /* Grab the current Rx skb from the ring and DMA-unmap it */
- rx_skb = bcmgenet_free_rx_cb(kdev, cb);
+ /* page_pool handles DMA mapping via PP_FLAG_DMA_MAP */
+ mapping = page_pool_get_dma_addr(page);
- /* Put the new Rx skb on the ring */
- cb->skb = skb;
- dma_unmap_addr_set(cb, dma_addr, mapping);
- dma_unmap_len_set(cb, dma_len, priv->rx_buf_len);
+ cb->rx_page = page;
dmadesc_set_addr(priv, cb->bd_addr, mapping);
- /* Return the current Rx skb to caller */
- return rx_skb;
+ return 0;
}
/* bcmgenet_desc_rx - descriptor based rx process.
@@ -2328,25 +2308,29 @@ static unsigned int bcmgenet_desc_rx(struct bcmgenet_rx_ring *ring,
while ((rxpktprocessed < rxpkttoprocess) &&
(rxpktprocessed < budget)) {
struct status_64 *status;
+ struct page *rx_page;
+ void *hard_start;
__be16 rx_csum;
cb = &priv->rx_cbs[ring->read_ptr];
- skb = bcmgenet_rx_refill(priv, cb);
- if (unlikely(!skb)) {
+ /* Save the received page before refilling */
+ rx_page = cb->rx_page;
+
+ if (bcmgenet_rx_refill(ring, cb)) {
BCMGENET_STATS64_INC(stats, dropped);
goto next;
}
- status = (struct status_64 *)skb->data;
+ /* Sync the full buffer; the HW may have written anywhere
+ * up to RX_BUF_LENGTH.
+ */
+ page_pool_dma_sync_for_cpu(ring->page_pool, rx_page, 0,
+ RX_BUF_LENGTH);
+
+ hard_start = page_address(rx_page);
+ status = (struct status_64 *)hard_start;
dma_length_status = status->length_status;
- if (dev->features & NETIF_F_RXCSUM) {
- rx_csum = (__force __be16)(status->rx_csum & 0xffff);
- if (rx_csum) {
- skb->csum = (__force __wsum)ntohs(rx_csum);
- skb->ip_summed = CHECKSUM_COMPLETE;
- }
- }
/* DMA flags and length are still valid no matter how
* we got the Receive Status Vector (64B RSB or register)
@@ -2359,10 +2343,13 @@ static unsigned int bcmgenet_desc_rx(struct bcmgenet_rx_ring *ring,
__func__, p_index, ring->c_index,
ring->read_ptr, dma_length_status);
- if (unlikely(len > RX_BUF_LENGTH)) {
- netif_err(priv, rx_status, dev, "oversized packet\n");
+ /* Reject lengths that would underflow the SKB build path. */
+ if (unlikely(len > RX_BUF_LENGTH || len < GENET_RSB_PAD)) {
+ netif_err(priv, rx_status, dev,
+ "invalid packet length %d\n", len);
BCMGENET_STATS64_INC(stats, length_errors);
- dev_kfree_skb_any(skb);
+ page_pool_put_full_page(ring->page_pool, rx_page,
+ true);
goto next;
}
@@ -2370,7 +2357,8 @@ static unsigned int bcmgenet_desc_rx(struct bcmgenet_rx_ring *ring,
netif_err(priv, rx_status, dev,
"dropping fragmented packet!\n");
BCMGENET_STATS64_INC(stats, fragmented_errors);
- dev_kfree_skb_any(skb);
+ page_pool_put_full_page(ring->page_pool, rx_page,
+ true);
goto next;
}
@@ -2398,21 +2386,42 @@ static unsigned int bcmgenet_desc_rx(struct bcmgenet_rx_ring *ring,
DMA_RX_RXER)) == DMA_RX_RXER)
u64_stats_inc(&stats->errors);
u64_stats_update_end(&stats->syncp);
- dev_kfree_skb_any(skb);
+ page_pool_put_full_page(ring->page_pool, rx_page,
+ true);
goto next;
} /* error packet */
- skb_put(skb, len);
+ /* Build SKB from the page - data starts at hard_start,
+ * frame begins after RSB(64) + pad(2) = 66 bytes.
+ */
+ skb = napi_build_skb(hard_start, PAGE_SIZE);
+ if (unlikely(!skb)) {
+ BCMGENET_STATS64_INC(stats, dropped);
+ page_pool_put_full_page(ring->page_pool, rx_page,
+ true);
+ goto next;
+ }
+
+ skb_mark_for_recycle(skb);
- /* remove RSB and hardware 2bytes added for IP alignment */
- skb_pull(skb, 66);
- len -= 66;
+ /* Reserve the RSB + pad, then set the data length */
+ skb_reserve(skb, GENET_RSB_PAD);
+ __skb_put(skb, len - GENET_RSB_PAD);
if (priv->crc_fwd_en) {
- skb_trim(skb, len - ETH_FCS_LEN);
- len -= ETH_FCS_LEN;
+ skb_trim(skb, skb->len - ETH_FCS_LEN);
+ }
+
+ /* Set up checksum offload */
+ if (dev->features & NETIF_F_RXCSUM) {
+ rx_csum = (__force __be16)(status->rx_csum & 0xffff);
+ if (rx_csum) {
+ skb->csum = (__force __wsum)ntohs(rx_csum);
+ skb->ip_summed = CHECKSUM_COMPLETE;
+ }
}
+ len = skb->len;
bytes_processed += len;
/*Finish setting up the received SKB and send it to the kernel*/
@@ -2484,12 +2493,11 @@ static void bcmgenet_dim_work(struct work_struct *work)
dim->state = DIM_START_MEASURE;
}
-/* Assign skb to RX DMA descriptor. */
+/* Assign page_pool pages to RX DMA descriptors. */
static int bcmgenet_alloc_rx_buffers(struct bcmgenet_priv *priv,
struct bcmgenet_rx_ring *ring)
{
struct enet_cb *cb;
- struct sk_buff *skb;
int i;
netif_dbg(priv, hw, priv->dev, "%s\n", __func__);
@@ -2497,10 +2505,7 @@ static int bcmgenet_alloc_rx_buffers(struct bcmgenet_priv *priv,
/* loop here for each buffer needing assign */
for (i = 0; i < ring->size; i++) {
cb = ring->cbs + i;
- skb = bcmgenet_rx_refill(priv, cb);
- if (skb)
- dev_consume_skb_any(skb);
- if (!cb->skb)
+ if (bcmgenet_rx_refill(ring, cb))
return -ENOMEM;
}
@@ -2509,16 +2514,18 @@ static int bcmgenet_alloc_rx_buffers(struct bcmgenet_priv *priv,
static void bcmgenet_free_rx_buffers(struct bcmgenet_priv *priv)
{
- struct sk_buff *skb;
+ struct bcmgenet_rx_ring *ring;
struct enet_cb *cb;
- int i;
-
- for (i = 0; i < priv->num_rx_bds; i++) {
- cb = &priv->rx_cbs[i];
+ int q, i;
- skb = bcmgenet_free_rx_cb(&priv->pdev->dev, cb);
- if (skb)
- dev_consume_skb_any(skb);
+ for (q = 0; q <= priv->hw_params->rx_queues; q++) {
+ ring = &priv->rx_rings[q];
+ if (!ring->page_pool)
+ continue;
+ for (i = 0; i < ring->size; i++) {
+ cb = ring->cbs + i;
+ bcmgenet_free_rx_cb(cb, ring->page_pool);
+ }
}
}
@@ -2736,6 +2743,30 @@ static void bcmgenet_init_tx_ring(struct bcmgenet_priv *priv,
netif_napi_add_tx(priv->dev, &ring->napi, bcmgenet_tx_poll);
}
+static int bcmgenet_rx_ring_create_pool(struct bcmgenet_priv *priv,
+ struct bcmgenet_rx_ring *ring)
+{
+ struct page_pool_params pp_params = {
+ .order = 0,
+ .flags = PP_FLAG_DMA_MAP | PP_FLAG_DMA_SYNC_DEV,
+ .pool_size = ring->size,
+ .nid = NUMA_NO_NODE,
+ .dev = &priv->pdev->dev,
+ .dma_dir = DMA_FROM_DEVICE,
+ .max_len = RX_BUF_LENGTH,
+ };
+ int err;
+
+ ring->page_pool = page_pool_create(&pp_params);
+ if (IS_ERR(ring->page_pool)) {
+ err = PTR_ERR(ring->page_pool);
+ ring->page_pool = NULL;
+ return err;
+ }
+
+ return 0;
+}
+
/* Initialize a RDMA ring */
static int bcmgenet_init_rx_ring(struct bcmgenet_priv *priv,
unsigned int index, unsigned int size,
@@ -2743,7 +2774,7 @@ static int bcmgenet_init_rx_ring(struct bcmgenet_priv *priv,
{
struct bcmgenet_rx_ring *ring = &priv->rx_rings[index];
u32 words_per_bd = WORDS_PER_BD(priv);
- int ret;
+ int ret, i;
ring->priv = priv;
ring->index = index;
@@ -2754,10 +2785,19 @@ static int bcmgenet_init_rx_ring(struct bcmgenet_priv *priv,
ring->cb_ptr = start_ptr;
ring->end_ptr = end_ptr - 1;
- ret = bcmgenet_alloc_rx_buffers(priv, ring);
+ ret = bcmgenet_rx_ring_create_pool(priv, ring);
if (ret)
return ret;
+ ret = bcmgenet_alloc_rx_buffers(priv, ring);
+ if (ret) {
+ for (i = 0; i < ring->size; i++)
+ bcmgenet_free_rx_cb(ring->cbs + i, ring->page_pool);
+ page_pool_destroy(ring->page_pool);
+ ring->page_pool = NULL;
+ return ret;
+ }
+
bcmgenet_init_dim(ring, bcmgenet_dim_work);
bcmgenet_init_rx_coalesce(ring);
@@ -2951,6 +2991,20 @@ static void bcmgenet_fini_rx_napi(struct bcmgenet_priv *priv)
}
}
+static void bcmgenet_destroy_rx_page_pools(struct bcmgenet_priv *priv)
+{
+ struct bcmgenet_rx_ring *ring;
+ unsigned int i;
+
+ for (i = 0; i <= priv->hw_params->rx_queues; ++i) {
+ ring = &priv->rx_rings[i];
+ if (ring->page_pool) {
+ page_pool_destroy(ring->page_pool);
+ ring->page_pool = NULL;
+ }
+ }
+}
+
/* Initialize Rx queues
*
* Queues 0-15 are priority queues. Hardware Filtering Block (HFB) can be
@@ -3022,6 +3076,7 @@ static void bcmgenet_fini_dma(struct bcmgenet_priv *priv)
}
bcmgenet_free_rx_buffers(priv);
+ bcmgenet_destroy_rx_page_pools(priv);
kfree(priv->rx_cbs);
kfree(priv->tx_cbs);
}
@@ -3100,6 +3155,7 @@ static int bcmgenet_init_dma(struct bcmgenet_priv *priv, bool flush_rx)
if (ret) {
netdev_err(priv->dev, "failed to initialize Rx queues\n");
bcmgenet_free_rx_buffers(priv);
+ bcmgenet_destroy_rx_page_pools(priv);
kfree(priv->rx_cbs);
kfree(priv->tx_cbs);
return ret;
@@ -4021,8 +4077,6 @@ static int bcmgenet_probe(struct platform_device *pdev)
/* Mii wait queue */
init_waitqueue_head(&priv->wq);
- /* Always use RX_BUF_LENGTH (2KB) buffer for all chips */
- priv->rx_buf_len = RX_BUF_LENGTH;
INIT_WORK(&priv->bcmgenet_irq_work, bcmgenet_irq_task);
priv->clk_wol = devm_clk_get_optional(&priv->pdev->dev, "enet-wol");
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.h b/drivers/net/ethernet/broadcom/genet/bcmgenet.h
index 9e4110c7fdf6f..22a958ba99024 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.h
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.h
@@ -15,6 +15,7 @@
#include <linux/phy.h>
#include <linux/dim.h>
#include <linux/ethtool.h>
+#include <net/page_pool/helpers.h>
#include "../unimac.h"
@@ -149,7 +150,6 @@ struct bcmgenet_mib_counters {
u32 rbuf_err_cnt;
u32 mdf_err_cnt;
u32 alloc_rx_buff_failed;
- u32 rx_dma_failed;
u32 tx_dma_failed;
u32 tx_realloc_tsb;
u32 tx_realloc_tsb_failed;
@@ -469,6 +469,7 @@ struct bcmgenet_rx_stats64 {
struct enet_cb {
struct sk_buff *skb;
+ struct page *rx_page;
void __iomem *bd_addr;
DEFINE_DMA_UNMAP_ADDR(dma_addr);
DEFINE_DMA_UNMAP_LEN(dma_len);
@@ -575,6 +576,7 @@ struct bcmgenet_rx_ring {
struct bcmgenet_net_dim dim;
u32 rx_max_coalesced_frames;
u32 rx_coalesce_usecs;
+ struct page_pool *page_pool;
struct bcmgenet_priv *priv;
};
@@ -609,7 +611,6 @@ struct bcmgenet_priv {
void __iomem *rx_bds;
struct enet_cb *rx_cbs;
unsigned int num_rx_bds;
- unsigned int rx_buf_len;
struct bcmgenet_rxnfc_rule rxnfc_rules[MAX_NUM_OF_FS_RULES];
struct list_head rxnfc_list;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 183/438] drop_monitor: synchronize tracepoint unregistration on error path
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (181 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 182/438] pppoatm: ensure a writable skb header and linear data Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 184/438] drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown Greg Kroah-Hartman
` (266 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Hangbin Liu,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 6a038ef2b57922b6d9ca98ddac0df0681849b704 ]
If register_trace_napi_poll() fails in net_dm_trace_on_set(),
unregister_trace_kfree_skb() is called to roll back the kfree_skb
tracepoint registration.
However, tracepoint_synchronize_unregister() is omitted before calling
cancel_work_sync() and module_put(). An in-flight probe executing
concurrently on another CPU could call schedule_work() after
cancel_work_sync() has already returned, leaving a pending work item
scheduled after the module reference is dropped. If the module is then
unloaded, executing the work item triggers a kernel panic.
Add tracepoint_synchronize_unregister() after unregister_trace_kfree_skb()
in the error path, matching net_dm_trace_off_set() and
net_dm_hw_probe_unregister().
Fixes: 7c747838a558 ("drop_monitor: Split tracing enable / disable to different functions")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260910204612.3762015-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index abaf108ac4db8..018d19e3a71de 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -1173,6 +1173,7 @@ static int net_dm_trace_on_set(struct netlink_ext_ack *extack)
err_unregister_trace:
unregister_trace_kfree_skb(ops->kfree_skb_probe, NULL);
+ tracepoint_synchronize_unregister();
err_module_put:
for_each_possible_cpu(cpu) {
struct per_cpu_dm_data *data = &per_cpu(dm_cpu_data, cpu);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 130/398] net: bcmgenet: restore the hardware filters on open
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (128 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 129/398] net: bcmgenet: convert RX path to page_pool Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 131/398] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup Greg Kroah-Hartman
` (272 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Justin Chen,
Florian Fainelli, Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolai Buchwitz <nb@tipi-net.de>
[ Upstream commit 23ca4ddc4fce2c233a49e9fd34d4b5b02bd7324e ]
bcmgenet_hfb_init() runs INIT_LIST_HEAD() on priv->rxnfc_list, which drops
every rule off the list, and bcmgenet_open() calls it on each ifup. Every
rule the user configured is silently lost:
# ethtool -N eth0 flow-type ether dst $MAC action 0
Added rule with ID 0
# ethtool -n eth0 | grep -c Filter:
1
# ip link set eth0 down && ip link set eth0 up
# ethtool -n eth0 | grep -c Filter:
0
Initialise the lists once at probe and restore the rules on open, as
bcmgenet_resume() already does.
Fixes: 3e370952287c ("net: bcmgenet: add support for ethtool rxnfc flows")
Signed-off-by: Nicolai Buchwitz <nb@tipi-net.de>
Reviewed-by: Justin Chen <justin.chen@broadcom.com>
Reviewed-by: Florian Fainelli <florian.fainelli@broadcom.com>
Link: https://patch.msgid.link/20260913190052.939955-1-nb@tipi-net.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/broadcom/genet/bcmgenet.c | 19 +++++++++++++------
1 file changed, 13 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index 7f9d43a75f3bd..41539f9f8061c 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -750,8 +750,17 @@ static void bcmgenet_hfb_init(struct bcmgenet_priv *priv)
INIT_LIST_HEAD(&priv->rxnfc_rules[i].list);
priv->rxnfc_rules[i].state = BCMGENET_RXNFC_STATE_UNUSED;
}
+}
+
+static void bcmgenet_hfb_restore(struct bcmgenet_priv *priv)
+{
+ struct bcmgenet_rxnfc_rule *rule;
bcmgenet_hfb_clear(priv);
+
+ list_for_each_entry(rule, &priv->rxnfc_list, list)
+ if (rule->state != BCMGENET_RXNFC_STATE_UNUSED)
+ bcmgenet_hfb_create_rxnfc_filter(priv, rule);
}
static int bcmgenet_begin(struct net_device *dev)
@@ -3374,8 +3383,8 @@ static int bcmgenet_open(struct net_device *dev)
bcmgenet_set_hw_addr(priv, dev->dev_addr);
- /* HFB init */
- bcmgenet_hfb_init(priv);
+ /* Restore the filters, the MAC was reset above */
+ bcmgenet_hfb_restore(priv);
/* Reinitialize TDMA and RDMA and SW housekeeping */
ret = bcmgenet_init_dma(priv, true);
@@ -4077,6 +4086,7 @@ static int bcmgenet_probe(struct platform_device *pdev)
/* Mii wait queue */
init_waitqueue_head(&priv->wq);
+ bcmgenet_hfb_init(priv);
INIT_WORK(&priv->bcmgenet_irq_work, bcmgenet_irq_task);
priv->clk_wol = devm_clk_get_optional(&priv->pdev->dev, "enet-wol");
@@ -4277,10 +4287,7 @@ static int bcmgenet_resume(struct device *d)
bcmgenet_set_hw_addr(priv, dev->dev_addr);
/* Restore hardware filters */
- bcmgenet_hfb_clear(priv);
- list_for_each_entry(rule, &priv->rxnfc_list, list)
- if (rule->state != BCMGENET_RXNFC_STATE_UNUSED)
- bcmgenet_hfb_create_rxnfc_filter(priv, rule);
+ bcmgenet_hfb_restore(priv);
/* Reinitialize TDMA and RDMA and SW housekeeping */
ret = bcmgenet_init_dma(priv, false);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 184/438] drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (182 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 183/438] drop_monitor: synchronize tracepoint unregistration on error path Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 185/438] drop_monitor: use raw_cpu_ptr() in tracepoint probes Greg Kroah-Hartman
` (265 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit c391a40f71886b28c082b47270f0e856fa3e1150 ]
In drop_monitor teardown paths (net_dm_trace_off_set(),
net_dm_hw_monitor_stop(), and error unwind paths in net_dm_trace_on_set()
and net_dm_hw_monitor_start()), per-CPU timers are stopped using
timer_delete_sync() followed by cancel_work_sync().
However, there is a circular dependency between send_timer and
dm_alert_work:
1) sched_send_work() (timer callback) schedules dm_alert_work.
2) send_dm_alert() / net_dm_hw_summary_work() calls reset_per_cpu_data()
or net_dm_hw_reset_per_cpu_data().
3) If memory allocation fails under memory pressure in the reset
function, it re-arms the timer via mod_timer(&data->send_timer, ...).
If dm_alert_work is running concurrently while timer_delete_sync()
executes on another CPU, an allocation failure in the worker will
re-arm the timer after timer_delete_sync() has already returned.
Once cancel_work_sync() completes and module_put() is called, the timer
remains active in the timer wheel. If the module is then unloaded, the
timer will fire and execute sched_send_work() in freed memory,
triggering a kernel panic / use-after-free.
Switch from timer_delete_sync() to timer_shutdown_sync(). This guarantees
that any in-flight timer handler has finished and prevents subsequent
re-arming attempts from running workers from succeeding. When monitoring
is restarted later, timer_setup() is invoked, which cleanly
re-initializes the timer.
Fixes: 9398e9c0b1d4 ("drop_monitor: Perform cleanup upon probe registration failure")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260910204612.3762015-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index 018d19e3a71de..873155ca72432 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -1083,7 +1083,7 @@ static int net_dm_hw_monitor_start(struct netlink_ext_ack *extack)
struct per_cpu_dm_data *hw_data = &per_cpu(dm_hw_cpu_data, cpu);
struct sk_buff *skb;
- timer_delete_sync(&hw_data->send_timer);
+ timer_shutdown_sync(&hw_data->send_timer);
cancel_work_sync(&hw_data->dm_alert_work);
while ((skb = __skb_dequeue(&hw_data->drop_queue))) {
struct devlink_trap_metadata *hw_metadata;
@@ -1117,7 +1117,7 @@ static void net_dm_hw_monitor_stop(struct netlink_ext_ack *extack)
struct per_cpu_dm_data *hw_data = &per_cpu(dm_hw_cpu_data, cpu);
struct sk_buff *skb;
- timer_delete_sync(&hw_data->send_timer);
+ timer_shutdown_sync(&hw_data->send_timer);
cancel_work_sync(&hw_data->dm_alert_work);
while ((skb = __skb_dequeue(&hw_data->drop_queue))) {
struct devlink_trap_metadata *hw_metadata;
@@ -1179,7 +1179,7 @@ static int net_dm_trace_on_set(struct netlink_ext_ack *extack)
struct per_cpu_dm_data *data = &per_cpu(dm_cpu_data, cpu);
struct sk_buff *skb;
- timer_delete_sync(&data->send_timer);
+ timer_shutdown_sync(&data->send_timer);
cancel_work_sync(&data->dm_alert_work);
while ((skb = __skb_dequeue(&data->drop_queue)))
consume_skb(skb);
@@ -1207,7 +1207,7 @@ static void net_dm_trace_off_set(void)
struct per_cpu_dm_data *data = &per_cpu(dm_cpu_data, cpu);
struct sk_buff *skb;
- timer_delete_sync(&data->send_timer);
+ timer_shutdown_sync(&data->send_timer);
cancel_work_sync(&data->dm_alert_work);
while ((skb = __skb_dequeue(&data->drop_queue)))
consume_skb(skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 131/398] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (129 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 130/398] net: bcmgenet: restore the hardware filters on open Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 132/398] net: fddi: skfp: fix NULL deref when setting the MAC address while down Greg Kroah-Hartman
` (271 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, Jiayuan Chen,
Dong Chenchen, Paolo Abeni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dong Chenchen <dongchenchen2@huawei.com>
[ Upstream commit 2998147b59c9df0a51477c7a6b3d1f0ba3127dd4 ]
When the forward output route cannot be used in icmp_route_lookup(),
it enters the "reverse path" and calls ip_route_input() on fl4_dec.daddr,
the original packet's source address.
ip_route_input() only returns an error for truly invalid packets. For
unreachable addresses it will succeed and return an input route whose
dst.output is set to ip_rt_bug(). The existing check only rejects
RTN_LOCAL routes, so the RTN_UNREACHABLE route types can still be returned
and later used for output, syzkaller triggering a WARN_ON_ONCE()
in ip_rt_bug() as bellow:
------------[ cut here ]------------
WARNING: net/ipv4/route.c:1273 at ip_rt_bug+0x14/0x20
RIP: 0010:ip_rt_bug+0x14/0x20
Call Trace:
ip_push_pending_frames+0xfa/0x100
__icmp_send+0x905/0xf10
ip_options_compile+0xc0/0xd0
ip_rcv_finish_core+0x321/0xae0
ip_rcv+0x1de/0x260
__netif_receive_skb_one_core+0x11a/0x130
netif_receive_skb+0x7b/0x260
tun_get_user+0x11bf/0x1c10
------------[ cut here ]------------
Reject input route that is RTN_UNREACHABLE to fix it. The net warning
is only printed for RTN_LOCAL, as RTN_UNREACHABLE is not the result of
a race condition.
Fixes: 8b7817f3a959 ("[IPSEC]: Add ICMP host relookup support")
Suggested-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Signed-off-by: Dong Chenchen <dongchenchen2@huawei.com>
Link: https://patch.msgid.link/20260910140042.1880242-1-dongchenchen2@huawei.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv4/icmp.c | 17 ++++++++++-------
1 file changed, 10 insertions(+), 7 deletions(-)
diff --git a/net/ipv4/icmp.c b/net/ipv4/icmp.c
index a66e1a7175e90..c59a32160ee6a 100644
--- a/net/ipv4/icmp.c
+++ b/net/ipv4/icmp.c
@@ -572,16 +572,19 @@ static struct rtable *icmp_route_lookup(struct net *net, struct flowi4 *fl4,
skb_dstref_restore(skb_in, orefdst);
/*
- * At this point, fl4_dec.daddr should NOT be local (we
- * checked fl4_dec.saddr above). However, a race condition
- * may occur if the address is added to the interface
- * concurrently. In that case, ip_route_input() returns a
- * LOCAL route with dst.output=ip_rt_bug, which must not
- * be used for output.
+ * fl4_dec.daddr is not expected to be local here, but it can be
+ * added to an interface concurrently, in which case
+ * ip_route_input() returns a LOCAL route. It can also fail to
+ * build a forwarding route towards fl4_dec.daddr, for example,
+ * when forwarding is disabled, and return an UNREACHABLE route.
+ * Both cases will result in a route with dst.output=ip_rt_bug,
+ * which must not be used for output.
*/
- if (!err && rt2 && rt2->rt_type == RTN_LOCAL) {
+ if (!err && rt2 && rt2->rt_type == RTN_LOCAL)
net_warn_ratelimited("detected local route for %pI4 during ICMP sending, src %pI4\n",
&fl4_dec.daddr, &fl4_dec.saddr);
+ if (!err && rt2 &&
+ (rt2->rt_type == RTN_LOCAL || rt2->rt_type == RTN_UNREACHABLE)) {
dst_release(&rt2->dst);
err = -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 185/438] drop_monitor: use raw_cpu_ptr() in tracepoint probes
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (183 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 184/438] drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 186/438] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Greg Kroah-Hartman
` (264 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+dc57fd6722deb17e92af,
Eric Dumazet, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit c19b7d35086b7d240f1ca3088b0079d2bd39ffb9 ]
syzbot reported a preemption warning in sk_skb_reason_drop():
BUG: using smp_processor_id() in preemptible [00000000] code: syz.0.17/5917
caller is net_dm_packet_trace_kfree_skb_hit+0x119/0x350 net/core/drop_monitor.c:519
In net_dm_packet_trace_kfree_skb_hit(), data = this_cpu_ptr(&dm_cpu_data)
is evaluated before spin_lock_irqsave(&data->drop_queue.lock, flags).
When kfree_skb() is called from preemptible context (e.g. process context
during close() on /dev/net/tun), preemption is enabled, triggering the
CONFIG_DEBUG_PREEMPT warning in smp_processor_id().
The same pattern exists in net_dm_hw_trap_summary_probe() and
net_dm_hw_trap_packet_probe() for dm_hw_cpu_data.
This is a false positive because each per-cpu structure is protected
by its own spinlock. If the task migrates to another CPU right after
reading the per-cpu pointer, the lock still safely synchronizes
access to that queue.
Use raw_cpu_ptr() instead of this_cpu_ptr() to silence
CONFIG_DEBUG_PREEMPT without disturbing interrupt state or breaking
PREEMPT_RT locking semantics.
Fixes: ca30707dee2b ("drop_monitor: Add packet alert mode")
Fixes: 5855357cd40e ("drop_monitor: Prepare probe functions for devlink tracepoint")
Reported-by: syzbot+dc57fd6722deb17e92af@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6aa316b2.f81106d8.2ab401.0014.GAE@google.com/
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260910204612.3762015-4-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index 873155ca72432..795c15dd1771a 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -448,7 +448,7 @@ net_dm_hw_trap_summary_probe(void *ignore, const struct devlink *devlink,
if (metadata->trap_type == DEVLINK_TRAP_TYPE_CONTROL)
return;
- hw_data = this_cpu_ptr(&dm_hw_cpu_data);
+ hw_data = raw_cpu_ptr(&dm_hw_cpu_data);
raw_spin_lock_irqsave(&hw_data->lock, flags);
hw_entries = hw_data->hw_entries;
@@ -516,7 +516,7 @@ static void net_dm_packet_trace_kfree_skb_hit(void *ignore,
*/
nskb->tstamp = tstamp;
- data = this_cpu_ptr(&dm_cpu_data);
+ data = raw_cpu_ptr(&dm_cpu_data);
spin_lock_irqsave(&data->drop_queue.lock, flags);
if (skb_queue_len(&data->drop_queue) < net_dm_queue_len)
@@ -983,7 +983,7 @@ net_dm_hw_trap_packet_probe(void *ignore, const struct devlink *devlink,
NET_DM_SKB_CB(nskb)->hw_metadata = n_hw_metadata;
nskb->tstamp = tstamp;
- hw_data = this_cpu_ptr(&dm_hw_cpu_data);
+ hw_data = raw_cpu_ptr(&dm_hw_cpu_data);
spin_lock_irqsave(&hw_data->drop_queue.lock, flags);
if (skb_queue_len(&hw_data->drop_queue) < net_dm_queue_len)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 132/398] net: fddi: skfp: fix NULL deref when setting the MAC address while down
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (130 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 131/398] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 133/398] wifi: brcmfmac: fix lost 802.1x TX completion wakeup Greg Kroah-Hartman
` (270 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hohyun Sim, Paolo Abeni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hohyun Sim <tlaghgus0425@korea.ac.kr>
[ Upstream commit 7c8810c2e69c3d9ca6df870b40ae9218e50b4fb1 ]
skfp_ctl_set_mac_address() calls ResetAdapter() unconditionally, without
checking netif_running(). ResetAdapter() first calls card_stop(), which
sets smc->hw.hw_state to STOPPED, and then mac_drv_clear_tx_queue(),
which walks the two transmit queues:
for (i = QUEUE_S; i <= QUEUE_A0; i++) {
queue = smc->hw.fp.tx[i] ;
...
t = queue->tx_curr_get ;
smc->hw.fp.tx[] is only populated by init_tx(), which is reached from
skfp_open() through init_smt() -> init_fddi_driver() -> init_fplus() ->
init_mac() -> init_tx(). The private area is allocated and zeroed by
alloc_fddidev(), so on an interface that has never been brought up both
queue pointers are still NULL. The hw_state test at the top of
mac_drv_clear_tx_queue() does not catch this, because card_stop() has
just set STOPPED; the function proceeds into the loop and dereferences
NULL. ResetAdapter() does call init_smt() itself, but only after the
queues have been cleared.
Setting the MAC address on a down interface therefore oopses:
ip link set dev fddi0 address 02:00:00:00:00:01
BUG: KASAN: null-ptr-deref in mac_drv_clear_tx_queue+0x68/0x2c0 [skfp]
Read of size 8 at addr 0000000000000010 by task ip/302
Call Trace:
<TASK>
mac_drv_clear_tx_queue+0x68/0x2c0 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
ResetAdapter+0x29/0x100 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
skfp_ctl_set_mac_address+0x57/0x80 [skfp 6c01d4bab63c36978bd0a7d7e90837adb44cc37b]
netif_set_mac_address+0x1e4/0x2c0
do_setlink+0x684/0x2680
</TASK>
Address 0x10 is the offset of tx_curr_get, the third pointer in
struct s_smt_tx_queue, on 64-bit. mac_drv_clear_rx_queue(), which
ResetAdapter() calls immediately afterwards, dereferences
smc->hw.fp.rx[QUEUE_R1] in the same way behind the same ineffective
hw_state test; the transmit queue merely crashes first. Both are
covered by the guard below.
Skip the adapter reset when the interface is down. dev_addr_set() is
left unconditional, so the new address is still recorded in
dev->dev_addr. Nothing is lost by not resetting the adapter here:
skfp_open() deliberately re-reads the factory address on every open,
read_address(smc, NULL);
eth_hw_addr_set(dev, smc->hw.fddi_canon_addr.a);
and the comment above it states this is done to discard exactly such an
address override across a close/open cycle. An address set while the
interface is down could not have survived the following open even
before this change, so the guard removes no working behaviour. Guarding
the hardware side of ndo_set_mac_address() with netif_running() is
established practice; skge_set_mac_address() has done so since commit
2eb3e621c4e0 ("skge: set mac address bonding fix").
Guarding the reset as a whole, rather than NULL-checking the queues, is
also what the rest of the driver expects. After a previous open/close
the queue pointers are stale but non-NULL, so there is no crash, yet
ResetAdapter() goes on to call smt_online() and STI_FBI() ("Enable
Board Interrupts") while skfp_close() has already called free_irq() -
the adapter would be brought back online with no handler installed. The
only other ResetAdapter() caller is skfp_interrupt(), which by
construction runs only while the device is open.
Found by automated driver testing against an emulated SysKonnect FDDI
adapter under a KASAN-enabled 7.0.0 kernel. Triggering it requires
CAP_NET_ADMIN.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: LLM KASAN
Signed-off-by: Hohyun Sim <tlaghgus0425@korea.ac.kr>
Link: https://patch.msgid.link/20260910063743.110747-1-tlaghgus0425@korea.ac.kr
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/fddi/skfp/skfddi.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/fddi/skfp/skfddi.c b/drivers/net/fddi/skfp/skfddi.c
index a273362c9e703..feea7baa48168 100644
--- a/drivers/net/fddi/skfp/skfddi.c
+++ b/drivers/net/fddi/skfp/skfddi.c
@@ -928,7 +928,8 @@ static int skfp_ctl_set_mac_address(struct net_device *dev, void *addr)
dev_addr_set(dev, p_sockaddr->sa_data);
spin_lock_irqsave(&bp->DriverLock, Flags);
- ResetAdapter(smc);
+ if (netif_running(dev))
+ ResetAdapter(smc);
spin_unlock_irqrestore(&bp->DriverLock, Flags);
return 0; /* always return zero */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 186/438] drop_monitor: fix out-of-bounds write in reset_per_cpu_data()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (184 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 185/438] drop_monitor: use raw_cpu_ptr() in tracepoint probes Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 187/438] net: stmmac: do not overwrite phc_index when no PTP clock is registered Greg Kroah-Hartman
` (263 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Hangbin Liu,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 439f392084f8f7f59ab9d47a9579185accefe1d8 ]
In reset_per_cpu_data(), al is computed as:
al = sizeof(struct net_dm_alert_msg);
al += dm_hit_limit * sizeof(struct net_dm_drop_point);
al += sizeof(struct nlattr);
skb = genlmsg_new(al, GFP_KERNEL);
...
nla = nla_reserve(skb, NLA_UNSPEC, sizeof(struct net_dm_alert_msg));
...
msg = nla_data(nla);
memset(msg, 0, al);
Because al includes sizeof(struct nlattr) (the 4-byte attribute header),
genlmsg_new() allocates al bytes of tailroom starting at nla.
However, msg points to nla_data(nla), which is located
sizeof(struct nlattr) bytes past nla. Calling memset(msg, 0, al)
therefore writes al bytes starting from msg, exceeding the allocated
buffer by sizeof(struct nlattr) (4 bytes) and corrupting
skb_shared_info.
Fix this by letting al represent only the payload length, allocating
the skb with genlmsg_new(nla_total_size(al), GFP_KERNEL), and zeroing
al bytes from msg.
Fixes: 683703a26e46 ("drop_monitor: Update netlink protocol to include netlink attribute header in alert message")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260910204612.3762015-5-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index 795c15dd1771a..edc660778408e 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -141,9 +141,8 @@ static struct sk_buff *reset_per_cpu_data(struct per_cpu_dm_data *data)
al = sizeof(struct net_dm_alert_msg);
al += dm_hit_limit * sizeof(struct net_dm_drop_point);
- al += sizeof(struct nlattr);
- skb = genlmsg_new(al, GFP_KERNEL);
+ skb = genlmsg_new(nla_total_size(al), GFP_KERNEL);
if (!skb)
goto err;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 133/398] wifi: brcmfmac: fix lost 802.1x TX completion wakeup
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (131 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 132/398] net: fddi: skfp: fix NULL deref when setting the MAC address while down Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 134/398] net: bridge: mst: move switchdev call outside rcu Greg Kroah-Hartman
` (269 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Arend van Spriel,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 621d90169cef6c8da5b6134db5c0c4e23cdd09ce ]
brcmf_txfinalize() decrements pend_8021x_cnt before a lockless
waitqueue_active() check. atomic_dec() does not order the decrement
against the check.
The waiter can therefore observe a nonzero count while the waker observes
an empty queue, losing the final wakeup and delaying key installation
until the 950 ms timeout.
Add smp_mb__after_atomic() to order the decrement before the queue
check. wait_event_timeout() provides the matching barrier. LKMM confirms
that this forbids the lost-wakeup outcome.
Fixes: 21fff75d2fb6 ("brcmfmac: use wait_event_timeout for 8021x pending count")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260811082702.44521-1-kmehltretter@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
index 169e62b9d7731..048b5d500215e 100644
--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c
@@ -555,6 +555,8 @@ void brcmf_txfinalize(struct brcmf_if *ifp, struct sk_buff *txp, bool success)
if (type == ETH_P_PAE) {
atomic_dec(&ifp->pend_8021x_cnt);
+ /* Order the decrement before waitqueue_active() */
+ smp_mb__after_atomic();
if (waitqueue_active(&ifp->pend_8021x_wait))
wake_up(&ifp->pend_8021x_wait);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 187/438] net: stmmac: do not overwrite phc_index when no PTP clock is registered
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (185 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 186/438] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 188/438] net: bridge: vlan: fix bugs caused by switchdev deletion errors Greg Kroah-Hartman
` (262 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maxime Chevallier, Rahul Rameshbabu,
Lorenzo Bianconi, Gal Pressman, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit f0ef4b1eaed000a304726a43091588e8426ba08a ]
stmmac_get_ts_info() reports phc_index as 0 when hardware timestamping
is supported but no PTP clock has been registered yet (e.g. while the
interface is down). Zero is a valid PHC index and would make userspace
resolve the wrong clock; the absence of a clock should be reported as
-1.
The ethtool core already initializes phc_index to -1 before invoking
the get_ts_info callback (ethtool_init_tsinfo()), so just drop the
erroneous assignment.
Fixes: 9364fa7fcf12 ("net: stmmac: Remove setting of RX software timestamp")
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Reviewed-by: Rahul Rameshbabu <rrameshbabu@nvidia.com>
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Reviewed-by: Gal Pressman <gal@nvidia.com>
Link: https://patch.msgid.link/20260914-stmmac-fix-phc_index-v2-1-bf3d90373fe4@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c
index 92585d27ab883..2a4882f2a498d 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c
@@ -1013,8 +1013,6 @@ static int stmmac_get_ts_info(struct net_device *dev,
if (priv->ptp_clock)
info->phc_index = ptp_clock_index(priv->ptp_clock);
- else
- info->phc_index = 0;
info->tx_types = (1 << HWTSTAMP_TX_OFF) | (1 << HWTSTAMP_TX_ON);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 134/398] net: bridge: mst: move switchdev call outside rcu
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (132 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 133/398] wifi: brcmfmac: fix lost 802.1x TX completion wakeup Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 135/398] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() Greg Kroah-Hartman
` (268 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nikolay Aleksandrov, Ido Schimmel,
Paolo Abeni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nikolay Aleksandrov <razor@blackwall.org>
[ Upstream commit 18a6fe05fb6e18de29fa90d388bb34044114b3d8 ]
This is a follow-up of one of sashiko's pre-existing bug reports.
br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs
while holding rcu_read_lock() which invokes the blocking switchdev
notifier chain and may sleep. Nonzero MSTI changes come from netlink
with rtnl held. Move the switchdev call before entering the rcu section and
assert that rtnl is held.
The call cannot be deferred because netlink needs its error and extack.
Also DSA reads the old bridge MST state during the callback and checks it.
A deferred callback will be late and will see the updated state.
Fixes: 3a7c1661ae13 ("net: bridge: mst: fix vlan use-after-free")
Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260911105021.1385934-1-razor@blackwall.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bridge/br_mst.c | 20 ++++++++++++--------
1 file changed, 12 insertions(+), 8 deletions(-)
diff --git a/net/bridge/br_mst.c b/net/bridge/br_mst.c
index 43a300ae6bfaf..1654efd3045b0 100644
--- a/net/bridge/br_mst.c
+++ b/net/bridge/br_mst.c
@@ -107,21 +107,24 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state,
struct net_bridge_vlan *v;
int err = 0;
- rcu_read_lock();
- vg = nbp_vlan_group_rcu(p);
- if (!vg)
- goto out;
-
/* MSTI 0 (CST) state changes are notified via the regular
- * SWITCHDEV_ATTR_ID_PORT_STP_STATE.
+ * SWITCHDEV_ATTR_ID_PORT_STP_STATE. All other MSTIs are handled via
+ * netlink with RTNL held
*/
if (msti) {
+ ASSERT_RTNL();
+
err = switchdev_port_attr_set(p->dev, &attr, extack);
if (err && err != -EOPNOTSUPP)
goto out;
+ err = 0;
}
- err = 0;
+ rcu_read_lock();
+ vg = nbp_vlan_group_rcu(p);
+ if (!vg)
+ goto out_rcu_unlock;
+
list_for_each_entry_rcu(v, &vg->vlan_list, vlist) {
if (v->brvlan->msti != msti)
continue;
@@ -129,8 +132,9 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state,
br_mst_vlan_set_state(vg, v, state);
}
-out:
+out_rcu_unlock:
rcu_read_unlock();
+out:
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 188/438] net: bridge: vlan: fix bugs caused by switchdev deletion errors
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (186 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 187/438] net: stmmac: do not overwrite phc_index when no PTP clock is registered Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 189/438] netlink: do not free nlk->groups while lockless readers can use it Greg Kroah-Hartman
` (261 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ido Schimmel, Nikolay Aleksandrov,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nikolay Aleksandrov <razor@blackwall.org>
[ Upstream commit 2842ce397dd09882530b42f7fdb0c855767eb24e ]
Allowing switchdev to prevent vlan deletion and error out in __vlan_del
could cause multiple different issues - inconsistent state, memory leaks
when flushing, NULL pointer dereference on bridge error when flushing.
It doesn't make sense to allow it to stop __vlan_del, so log the error
and continue with software vlan deletion. This is also consistent with
8021q behaviour.
Suggested-by: Ido Schimmel <idosch@nvidia.com>
Fixes: bf361ad38165 ("net: bridge: check __vlan_vid_del for error")
Fixes: 5454f5c28eca ("net: bridge: vlan: check for errors from __vlan_del in __vlan_flush")
Fixes: 2594e9064a57 ("bridge: vlan: add per-vlan struct and move to rhashtables")
Fixes: 9c86ce2c1ae3 ("net: bridge: Notify about bridge VLANs")
Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260914105258.3436918-1-razor@blackwall.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bridge/br_vlan.c | 31 ++++++++++++++-----------------
1 file changed, 14 insertions(+), 17 deletions(-)
diff --git a/net/bridge/br_vlan.c b/net/bridge/br_vlan.c
index 1e0e436629ece..92b3cb621a264 100644
--- a/net/bridge/br_vlan.c
+++ b/net/bridge/br_vlan.c
@@ -387,12 +387,12 @@ static int __vlan_add(struct net_bridge_vlan *v, u16 flags,
goto out;
}
-static int __vlan_del(struct net_bridge_vlan *v)
+static void __vlan_del(struct net_bridge_vlan *v)
{
struct net_bridge_vlan *masterv = v;
struct net_bridge_vlan_group *vg;
struct net_bridge_port *p = NULL;
- int err = 0;
+ int err;
if (br_vlan_is_master(v)) {
vg = br_vlan_group(v->br);
@@ -406,12 +406,16 @@ static int __vlan_del(struct net_bridge_vlan *v)
if (p) {
err = __vlan_vid_del(p->dev, p->br, v);
if (err)
- goto out;
+ br_warn(p->br,
+ "port %u(%s) failed to delete vlan %u from switchdev: %pe\n",
+ (unsigned int)p->port_no, p->dev->name,
+ v->vid, ERR_PTR(err));
} else {
err = br_switchdev_port_vlan_del(v->br->dev, v->vid);
if (err && err != -EOPNOTSUPP)
- goto out;
- err = 0;
+ br_warn(v->br,
+ "failed to delete bridge vlan %u from switchdev: %pe\n",
+ v->vid, ERR_PTR(err));
}
if (br_vlan_should_use(v)) {
@@ -431,8 +435,6 @@ static int __vlan_del(struct net_bridge_vlan *v)
}
br_vlan_put_master(masterv);
-out:
- return err;
}
static void __vlan_group_free(struct net_bridge_vlan_group *vg)
@@ -449,7 +451,6 @@ static void __vlan_flush(const struct net_bridge *br,
{
struct net_bridge_vlan *vlan, *tmp;
u16 v_start = 0, v_end = 0;
- int err;
__vlan_delete_pvid(vg, vg->pvid);
list_for_each_entry_safe(vlan, tmp, &vg->vlan_list, vlist) {
@@ -463,13 +464,7 @@ static void __vlan_flush(const struct net_bridge *br,
}
v_end = vlan->vid;
- err = __vlan_del(vlan);
- if (err) {
- br_err(br,
- "port %u(%s) failed to delete vlan %d: %pe\n",
- (unsigned int) p->port_no, p->dev->name,
- vlan->vid, ERR_PTR(err));
- }
+ __vlan_del(vlan);
}
/* notify about the last/whole vlan range */
@@ -837,8 +832,9 @@ int br_vlan_delete(struct net_bridge *br, u16 vid)
br_fdb_delete_by_port(br, NULL, vid, 0);
vlan_tunnel_info_del(vg, v);
+ __vlan_del(v);
- return __vlan_del(v);
+ return 0;
}
void br_vlan_flush(struct net_bridge *br)
@@ -1368,8 +1364,9 @@ int nbp_vlan_delete(struct net_bridge_port *port, u16 vid)
return -ENOENT;
br_fdb_find_delete_local(port->br, port, port->dev->dev_addr, vid);
br_fdb_delete_by_port(port->br, port, vid, 0);
+ __vlan_del(v);
- return __vlan_del(v);
+ return 0;
}
void nbp_vlan_flush(struct net_bridge_port *port)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 135/398] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv().
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (133 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 134/398] net: bridge: mst: move switchdev call outside rcu Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 136/398] tcp: do not let tcp_rmem be set below 4096 Greg Kroah-Hartman
` (267 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Taras Madan, Kuniyuki Iwashima,
Xuanqiang Luo, Eric Dumazet, Paolo Abeni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 8e759cd1f6444a946bd1fd2b2b29eea582eea1d5 ]
tcp_v6_do_rcv() no longer calls skb_clone_and_charge_r() for
TCP_LISTEN since commit 073d89808c06 ("net: fix data-races around
sk->sk_forward_alloc").
However, there is still a small race window between tcp_v6_rcv()
and tcp_v6_do_rcv(), where concurrent close() changes TCP_LISTEN
to TCP_CLOSE, causing skb_clone_and_charge_r() to be called
locklessly and resulting in the splat below. [0]
Let's avoid calling skb_clone_and_charge_r() for TCP_CLOSE as well.
This is fine for non-listeners because tcp_rcv_state_process()
drops skb for TCP_CLOSE and opt_skb was freed immediately anyway.
[0]:
sk->sk_forward_alloc
WARNING: net/ipv4/af_inet.c:162 at inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162, CPU#1: ksoftirqd/1/28
Modules linked in:
CPU: 1 UID: 0 PID: 28 Comm: ksoftirqd/1 Not tainted 7.2.0 #17 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
RIP: 0010:inet_sock_destruct+0x64d/0x810 net/ipv4/af_inet.c:162
Code: 3d 49 ff e9 06 fd ff ff e8 d0 5b 83 f8 90 0f 0b 90 e9 35 fe ff ff e8 c2 5b 83 f8 90 0f 0b 90 e9 c5 fe ff ff e8 b4 5b 83 f8 90 <0f> 0b 90 e9 04 ff ff ff e8 a6 5b 83 f8 90 0f 0b 90 e9 65 fe ff ff
RSP: 0018:ffffc90000677bb8 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffff8880117bde80 RCX: ffffffff8957eb41
RDX: ffff88801dad5d00 RSI: ffffffff8957ec3c RDI: 0000000000000005
RBP: 00000000fffff000 R08: ffffffff8957eb41 R09: 00000000fffff000
R10: 0000000000000005 R11: 0000000000000000 R12: dffffc0000000000
R13: ffff8880117bdf10 R14: ffffffff81c08eb7 R15: 0000000000000003
FS: 0000000000000000(0000) GS:ffff8880d7ae5000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f93a1021138 CR3: 00000000207a9000 CR4: 0000000000350ef0
Call Trace:
<TASK>
__sk_destruct+0x82/0xae0 net/core/sock.c:2356
rcu_do_batch kernel/rcu/tree.c:2645 [inline]
rcu_core+0x59c/0x1100 kernel/rcu/tree.c:2897
handle_softirqs+0x1e4/0x9b0 kernel/softirq.c:622
run_ksoftirqd kernel/softirq.c:1076 [inline]
run_ksoftirqd+0x38/0x60 kernel/softirq.c:1068
smpboot_thread_fn+0x458/0xc80 kernel/smpboot.c:160
kthread+0x396/0x4a0 kernel/kthread.c:436
ret_from_fork+0x8e0/0xe40 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
Fixes: e994b2f0fb92 ("tcp: do not lock listener to process SYN packets")
Reported-by: Taras Madan <tarasmadan@google.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260914011420.115556-1-kuniyu@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/tcp_ipv6.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c
index aca71fbb6c292..761cafdc8d2e8 100644
--- a/net/ipv6/tcp_ipv6.c
+++ b/net/ipv6/tcp_ipv6.c
@@ -1618,7 +1618,8 @@ int tcp_v6_do_rcv(struct sock *sk, struct sk_buff *skb)
by tcp. Feel free to propose better solution.
--ANK (980728)
*/
- if (np->rxopt.all && sk->sk_state != TCP_LISTEN)
+ if (np->rxopt.all &&
+ !((1 << sk->sk_state) & (TCPF_LISTEN | TCPF_CLOSE)))
opt_skb = skb_clone_and_charge_r(skb, sk);
if (sk->sk_state == TCP_ESTABLISHED) { /* Fast path */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 189/438] netlink: do not free nlk->groups while lockless readers can use it
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (187 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 188/438] net: bridge: vlan: fix bugs caused by switchdev deletion errors Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 190/438] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() Greg Kroah-Hartman
` (260 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Burton, Eric Dumazet,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit ceac0de741bfb47ca255eee075257b3bb31f0651 ]
netlink_realloc_groups() uses krealloc() under netlink_table_grab().
Whenever NLGRPSZ(groups) lands in a different kmalloc bucket, the old
bitmap is freed immediately.
Two readers of nlk->groups / nlk->ngroups do not hold the netlink
table lock:
1) sk_diag_dump_groups(). Hashed (bound) sockets are dumped from the
rhashtable walk in __netlink_diag_dump(), which only holds RCU.
Only the mc_list part of the dump takes nl_table_lock.
2) netlink_native_seq_show() (/proc/net/netlink), whose walk has been
lockless since commit 21e4902aea80 ("netlink: Lockless lookup with
RCU grace period in socket release").
Both can read a freed buffer, and sk_diag_dump_groups() can also read
past the end of the old (smaller) buffer if it happens to load the old
@groups pointer together with the new @ngroups value, copying the
result into a NETLINK_DIAG_GROUPS attribute.
This is the same class of bug that commit f773608026ee ("netlink:
access nlk groups safely in netlink bind and getname") fixed for bind()
and getname(); these two readers were missed. Simply grabbing the table
lock in sk_diag_dump_groups() is not an option, because it is also
called with nl_table_lock already held from the mc_list section of the
dump.
Make the lockless readers safe instead:
- Allocate a new bitmap and free the old one after an RCU grace period,
instead of relying on the implicit kfree() done by krealloc().
- Publish @groups before @ngroups, both with release semantics, and have
the lockless readers load @ngroups first. A reader can then never pair
the new (bigger) size with the old (smaller) buffer, and a reader
picking up the new pointer while still seeing the old size is
guaranteed to see the initialized bitmap.
netlink_realloc_groups() is called from process context (bind() and
setsockopt()), so kfree_rcu_mightsleep() can be used, once the table
has been released.
Fixes: 21e4902aea80 ("netlink: Lockless lookup with RCU grace period in socket release")
Fixes: ad202074320c ("netlink: Use rhashtable walk interface in diag dump")
Reported-by: James Burton <jamesburton@meta.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260911160804.917099-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netlink/af_netlink.c | 42 ++++++++++++++++++++++++++++++++--------
net/netlink/diag.c | 20 +++++++++++++++----
2 files changed, 50 insertions(+), 12 deletions(-)
diff --git a/net/netlink/af_netlink.c b/net/netlink/af_netlink.c
index 5202fe0b08671..7288de715341a 100644
--- a/net/netlink/af_netlink.c
+++ b/net/netlink/af_netlink.c
@@ -922,9 +922,9 @@ netlink_update_subscriptions(struct sock *sk, unsigned int subscriptions)
static int netlink_realloc_groups(struct sock *sk)
{
+ unsigned long *new_groups, *old_groups = NULL;
struct netlink_sock *nlk = nlk_sk(sk);
unsigned int groups;
- unsigned long *new_groups;
int err = 0;
netlink_table_grab();
@@ -938,18 +938,37 @@ static int netlink_realloc_groups(struct sock *sk)
if (nlk->ngroups >= groups)
goto out_unlock;
- new_groups = krealloc(nlk->groups, NLGRPSZ(groups), GFP_ATOMIC);
- if (new_groups == NULL) {
+ /* Can not use krealloc(), because the old buffer might be freed
+ * immediately, while lockless readers (netlink diag dump and
+ * /proc/net/netlink) can still be looking at it.
+ */
+ new_groups = kzalloc(NLGRPSZ(groups), GFP_ATOMIC);
+ if (!new_groups) {
err = -ENOMEM;
goto out_unlock;
}
- memset((char *)new_groups + NLGRPSZ(nlk->ngroups), 0,
- NLGRPSZ(groups) - NLGRPSZ(nlk->ngroups));
+ old_groups = nlk->groups;
+ if (old_groups)
+ memcpy(new_groups, old_groups, NLGRPSZ(nlk->ngroups));
+
+ /* Publish the new bitmap and its content: pairs with the address
+ * dependency in lockless readers, which can pick up the new pointer
+ * while still seeing the old (smaller) nlk->ngroups.
+ */
+ smp_store_release(&nlk->groups, new_groups);
+
+ /* Then publish the new size: pairs with smp_load_acquire() from
+ * lockless readers, so that they can not read NLGRPSZ(new ngroups)
+ * bytes from the old buffer.
+ */
+ smp_store_release(&nlk->ngroups, groups);
- nlk->groups = new_groups;
- nlk->ngroups = groups;
out_unlock:
netlink_table_ungrab();
+
+ if (old_groups)
+ kfree_rcu_mightsleep(old_groups);
+
return err;
}
@@ -2705,12 +2724,19 @@ static int netlink_native_seq_show(struct seq_file *seq, void *v)
} else {
struct sock *s = v;
struct netlink_sock *nlk = nlk_sk(s);
+ const unsigned long *groups;
+
+ /* Lockless read : netlink_realloc_groups() can change
+ * nlk->groups under us. The old buffer is freed after an
+ * RCU grace period, and this walk is RCU protected.
+ */
+ groups = READ_ONCE(nlk->groups);
seq_printf(seq, "%pK %-3d %-10u %08x %-8d %-8d %-5d %-8d %-8u %-8llu\n",
s,
s->sk_protocol,
nlk->portid,
- nlk->groups ? (u32)nlk->groups[0] : 0,
+ groups ? (u32)groups[0] : 0,
sk_rmem_alloc_get(s),
sk_wmem_alloc_get(s),
READ_ONCE(nlk->cb_running),
diff --git a/net/netlink/diag.c b/net/netlink/diag.c
index 0b3e021bd0ed2..7979bd9b26060 100644
--- a/net/netlink/diag.c
+++ b/net/netlink/diag.c
@@ -12,12 +12,24 @@
static int sk_diag_dump_groups(struct sock *sk, struct sk_buff *nlskb)
{
struct netlink_sock *nlk = nlk_sk(sk);
-
- if (nlk->groups == NULL)
+ unsigned long *groups;
+ unsigned int ngroups;
+
+ /* Hashed sockets are dumped from the rhashtable walk, which only
+ * holds rcu_read_lock(), while netlink_realloc_groups() can replace
+ * nlk->groups and nlk->ngroups at any time.
+ *
+ * Read nlk->ngroups first : this pairs with smp_store_release()
+ * from netlink_realloc_groups(), so that we can not use the new
+ * (bigger) size with the old (smaller) buffer. The old buffer is
+ * freed after an RCU grace period.
+ */
+ ngroups = smp_load_acquire(&nlk->ngroups);
+ groups = READ_ONCE(nlk->groups);
+ if (!groups)
return 0;
- return nla_put(nlskb, NETLINK_DIAG_GROUPS, NLGRPSZ(nlk->ngroups),
- nlk->groups);
+ return nla_put(nlskb, NETLINK_DIAG_GROUPS, NLGRPSZ(ngroups), groups);
}
static int sk_diag_put_flags(struct sock *sk, struct sk_buff *skb)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 136/398] tcp: do not let tcp_rmem be set below 4096
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (134 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 135/398] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 137/398] ksmbd: return buffer overflow for partial filesystem info Greg Kroah-Hartman
` (266 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Simon Horman,
Paolo Abeni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 83a945a529d6e002dd7339c532288a931f463dba ]
We can hit a division by zero crash in tcp_rcvbuf_grow()
and tcp_rcv_space_adjust():
divide error: 0000 [#1] PREEMPT SMP
RIP: 0010:tcp_rcvbuf_grow+0x187/0x450 net/ipv4/tcp_input.c:939
...
grow = div_u64(((u64)rcvwin << 1) * (newval - oldval), oldval);
The division uses oldval = tp->rcvq_space.space as divisor.
When tp->rcvq_space.space is zero, this leads to a divide-by-zero
exception.
tp->rcvq_space.space is initialized in tcp_init_buffer_space():
tp->rcvq_space.space = min3(tp->rcv_ssthresh, tp->rcv_wnd,
(u32)TCP_INIT_CWND * tp->advmss);
If tcp_rmem[1] is configured to very small values (such as 1),
sk->sk_rcvbuf is initialized to 1. Then tcp_full_space(sk), which
computes (sk->sk_rcvbuf * scaling_ratio) >> 8, truncates to 0.
This sets tp->window_clamp = 0, tp->rcv_ssthresh = 0, and
tp->rcvq_space.space = 0. Later, when data arrives and DRS is invoked,
tcp_rcvbuf_grow() divides by oldval == 0.
Back in 2015, commit b1cb59cf2efe ("net: sysctl_net_core: check SNDBUF
and RCVBUF for min length") ensured that net.core.rmem_default and
net.core.rmem_max cannot be set below SOCK_MIN_RCVBUF. Similarly,
SO_RCVBUF setsockopt enforces max_t(int, val * 2, SOCK_MIN_RCVBUF).
However, net.ipv4.tcp_rmem still had .extra1 = SYSCTL_ONE, allowing
arbitrarily small values.
Because SOCK_MIN_RCVBUF depends on sizeof(struct sk_buff) and cacheline
alignment, its value varies across architectures and configuration options.
Using a fixed constant of 4096 ensures a predictable, architecture-
independent lower bound that is safely above SOCK_MIN_RCVBUF everywhere
and matches the documented 4K default.
Fix this by setting tcp_rmem.extra1 to 4096 and updating the documentation.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260912144848.3448026-1-edumazet@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/networking/ip-sysctl.rst | 2 ++
net/ipv4/sysctl_net_ipv4.c | 4 +++-
2 files changed, 5 insertions(+), 1 deletion(-)
diff --git a/Documentation/networking/ip-sysctl.rst b/Documentation/networking/ip-sysctl.rst
index e13131770fa0c..27a861053b2f5 100644
--- a/Documentation/networking/ip-sysctl.rst
+++ b/Documentation/networking/ip-sysctl.rst
@@ -844,6 +844,8 @@ tcp_rmem - vector of 3 INTEGERs: min, default, max
case this value is ignored.
Default: between 131072 and 32MB, depending on RAM size.
+ Each of the three values cannot be set below 4096.
+
tcp_sack - BOOLEAN
Enable select acknowledgments (SACKS).
diff --git a/net/ipv4/sysctl_net_ipv4.c b/net/ipv4/sysctl_net_ipv4.c
index afcbb9d48cfa2..34a8a932402d8 100644
--- a/net/ipv4/sysctl_net_ipv4.c
+++ b/net/ipv4/sysctl_net_ipv4.c
@@ -49,6 +49,8 @@ static int tcp_plb_max_cong_thresh = 256;
static unsigned int tcp_tw_reuse_delay_max = TCP_PAWS_MSL * MSEC_PER_SEC;
static int tcp_ecn_mode_max = 2;
+static int tcp_min_rcvbuf = 4096;
+
/* obsolete */
static int sysctl_tcp_low_latency __read_mostly;
@@ -1435,7 +1437,7 @@ static struct ctl_table ipv4_net_table[] = {
.maxlen = sizeof(init_net.ipv4.sysctl_tcp_rmem),
.mode = 0644,
.proc_handler = proc_dointvec_minmax,
- .extra1 = SYSCTL_ONE,
+ .extra1 = &tcp_min_rcvbuf,
},
{
.procname = "tcp_comp_sack_delay_ns",
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 190/438] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (188 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 189/438] netlink: do not free nlk->groups while lockless readers can use it Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 191/438] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure Greg Kroah-Hartman
` (259 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Amit Machhiwal, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Amit Machhiwal <amachhiw@linux.ibm.com>
[ Upstream commit 51938dfa8a51a4f85328413fca9b6e21f9d2d088 ]
kvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops
mmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a
reference on the kvm_nested_guest pointer obtained from the IDR. A
concurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race
through kvmhv_flush_nested() -> kvmhv_remove_nested() -> idr_remove /
--refcnt -> kvmhv_release_nested() -> kfree(gp) in that window, leaving
the iterating vCPU with a dangling pointer. The subsequent
mutex_lock(&gp->tlb_lock) and accesses to gp->shadow_pgtable,
gp->shadow_lpid and gp->l1_host all touch freed memory. The free path
is fully L1-controlled.
Fix this by incrementing gp->refcnt inside the loop before dropping
mmu_lock, mirroring what kvmhv_get_nested() does, and releasing the
reference with kvmhv_put_nested() after the per-guest work completes.
This is the same get/put discipline already used at every other
call site that drops mmu_lock while holding a nested-guest pointer.
Fixes: e3b6b4661527 ("KVM: PPC: Book3S HV: Implement H_TLB_INVALIDATE hcall")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kvm/book3s_hv_nested.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/powerpc/kvm/book3s_hv_nested.c b/arch/powerpc/kvm/book3s_hv_nested.c
index 22e6166622556..a6ff42d7666c1 100644
--- a/arch/powerpc/kvm/book3s_hv_nested.c
+++ b/arch/powerpc/kvm/book3s_hv_nested.c
@@ -1204,8 +1204,10 @@ static void kvmhv_emulate_tlbie_all_lpid(struct kvm_vcpu *vcpu, int ric)
spin_lock(&kvm->mmu_lock);
idr_for_each_entry(&kvm->arch.kvm_nested_guest_idr, gp, lpid) {
+ ++gp->refcnt;
spin_unlock(&kvm->mmu_lock);
kvmhv_emulate_tlbie_lpid(vcpu, gp, ric);
+ kvmhv_put_nested(gp);
spin_lock(&kvm->mmu_lock);
}
spin_unlock(&kvm->mmu_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 137/398] ksmbd: return buffer overflow for partial filesystem info
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (135 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 136/398] tcp: do not let tcp_rmem be set below 4096 Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 138/398] ksmbd: fix partial file information responses Greg Kroah-Hartman
` (265 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 0ecd35fac4b4f2828490689b46039744d201dcb0 ]
The query-info buffer check returns STATUS_INFO_LENGTH_MISMATCH for
every output buffer smaller than the complete response. Variable-length
filesystem information instead requires STATUS_BUFFER_OVERFLOW when the
fixed portion fits but the complete data does not.
Pass the fixed size for each filesystem information class to the buffer
checker. Keep INFO_LENGTH_MISMATCH for buffers below that size, and
return BUFFER_OVERFLOW with a response truncated to the requested length
for larger partial buffers.
This fixes smb2.getinfo.qfs_buffercheck.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Stable-dep-of: 9fa26285ae70 ("ksmbd: keep compound responses on query info errors")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 26 +++++++++++++++++++++++++-
1 file changed, 25 insertions(+), 1 deletion(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index cd7bfc73cf087..092788ac01b5d 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -4633,21 +4633,30 @@ int smb2_query_dir(struct ksmbd_work *work)
/**
* buffer_check_err() - helper function to check buffer errors
* @reqOutputBufferLength: max buffer length expected in command response
+ * @fixed_len: minimum fixed response length
* @rsp: query info response buffer contains output buffer length
* @rsp_org: base response buffer pointer in case of chained response
*
* Return: 0 on success, otherwise error
*/
static int buffer_check_err(int reqOutputBufferLength,
+ unsigned int fixed_len,
struct smb2_query_info_rsp *rsp,
void *rsp_org)
{
- if (reqOutputBufferLength < le32_to_cpu(rsp->OutputBufferLength)) {
+ unsigned int output_len = le32_to_cpu(rsp->OutputBufferLength);
+
+ if (reqOutputBufferLength < fixed_len) {
pr_err("Invalid Buffer Size Requested\n");
rsp->hdr.Status = STATUS_INFO_LENGTH_MISMATCH;
*(__be32 *)rsp_org = cpu_to_be32(sizeof(struct smb2_hdr));
return -EINVAL;
}
+
+ if (reqOutputBufferLength < output_len) {
+ rsp->hdr.Status = STATUS_BUFFER_OVERFLOW;
+ rsp->OutputBufferLength = cpu_to_le32(reqOutputBufferLength);
+ }
return 0;
}
@@ -4710,11 +4719,13 @@ static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
case FILE_STANDARD_INFORMATION:
get_standard_info_pipe(rsp, rsp_org);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, rsp_org);
break;
case FILE_INTERNAL_INFORMATION:
get_internal_info_pipe(rsp, id, rsp_org);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, rsp_org);
break;
default:
@@ -5535,6 +5546,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
}
if (!rc)
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, work->response_buf);
ksmbd_fd_put(work, fp);
@@ -5556,6 +5568,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
struct kstatfs stfs;
struct path path;
int rc = 0, len;
+ unsigned int fixed_len = 0;
if (!share->path)
return -EIO;
@@ -5590,6 +5603,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->DeviceCharacteristics |=
cpu_to_le32(FILE_READ_ONLY_DEVICE);
rsp->OutputBufferLength = cpu_to_le32(8);
+ fixed_len = 8;
break;
}
case FS_ATTRIBUTE_INFORMATION:
@@ -5618,6 +5632,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->FileSystemNameLen = cpu_to_le32(len);
sz = sizeof(struct filesystem_attribute_info) + len;
rsp->OutputBufferLength = cpu_to_le32(sz);
+ fixed_len = 16;
break;
}
case FS_VOLUME_INFORMATION:
@@ -5644,6 +5659,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->Reserved = 0;
sz = sizeof(struct filesystem_vol_info) + len;
rsp->OutputBufferLength = cpu_to_le32(sz);
+ fixed_len = 24;
break;
}
case FS_SIZE_INFORMATION:
@@ -5656,6 +5672,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->SectorsPerAllocationUnit = cpu_to_le32(1);
info->BytesPerSector = cpu_to_le32(stfs.f_bsize);
rsp->OutputBufferLength = cpu_to_le32(24);
+ fixed_len = 24;
break;
}
case FS_FULL_SIZE_INFORMATION:
@@ -5671,6 +5688,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->SectorsPerAllocationUnit = cpu_to_le32(1);
info->BytesPerSector = cpu_to_le32(stfs.f_bsize);
rsp->OutputBufferLength = cpu_to_le32(32);
+ fixed_len = 32;
break;
}
case FS_OBJECT_ID_INFORMATION:
@@ -5691,6 +5709,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->extended_info.rel_date = 0;
memcpy(info->extended_info.version_string, "1.1.0", strlen("1.1.0"));
rsp->OutputBufferLength = cpu_to_le32(64);
+ fixed_len = 64;
break;
}
case FS_SECTOR_SIZE_INFORMATION:
@@ -5712,6 +5731,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->ByteOffsetForSectorAlignment = 0;
info->ByteOffsetForPartitionAlignment = 0;
rsp->OutputBufferLength = cpu_to_le32(28);
+ fixed_len = 28;
break;
}
case FS_CONTROL_INFORMATION:
@@ -5732,6 +5752,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->DefaultQuotaLimit = cpu_to_le64(SMB2_NO_FID);
info->Padding = 0;
rsp->OutputBufferLength = cpu_to_le32(48);
+ fixed_len = 48;
break;
}
case FS_POSIX_INFORMATION:
@@ -5752,6 +5773,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
info->TotalFileNodes = cpu_to_le64(stfs.f_files);
info->FreeFileNodes = cpu_to_le64(stfs.f_ffree);
rsp->OutputBufferLength = cpu_to_le32(56);
+ fixed_len = 56;
}
break;
}
@@ -5760,6 +5782,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
return -EOPNOTSUPP;
}
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ fixed_len,
rsp, work->response_buf);
path_put(&path);
@@ -5874,6 +5897,7 @@ static int smb2_get_info_sec(struct ksmbd_work *work,
iov_pin:
rsp->OutputBufferLength = cpu_to_le32(secdesclen);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
+ le32_to_cpu(rsp->OutputBufferLength),
rsp, work->response_buf);
if (rc)
goto err_out;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 191/438] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (189 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 190/438] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 192/438] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba Greg Kroah-Hartman
` (258 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Amit Machhiwal, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Amit Machhiwal <amachhiw@linux.ibm.com>
[ Upstream commit 0a416ee20bcccddf91ca5b63696a23b9d11d73aa ]
In kvmppc_svm_page_in(), if uv_page_in() fails after
kvmppc_uvmem_get_page() has succeeded, the secure device page is never
released. kvmppc_uvmem_get_page() sets a bit in kvmppc_uvmem_bitmap,
allocates a kvmppc_uvmem_page_pvt struct, marks the GFN as
KVMPPC_GFN_UVMEM_PFN, and calls zone_device_page_init() which sets
refcount=1 and locks the page. The subsequent goto out_finalize skips
the *mig.dst assignment, so migrate_vma_finalize() is a no-op for the
page, and none of those resources are ever reclaimed.
Each occurrence permanently consumes one entry from the firmware-bounded
secure memory pool (kvmppc_uvmem_bitmap), leaks pvt, and leaves the GFN
marked as secure — making it unusable for the lifetime of the VM.
The twin __kvmppc_svm_page_out() already handles the analogous uv_page_out()
failure correctly with unlock_page(dpage); __free_page(dpage). Apply
the same pattern here: unlock_page() followed by put_page(), which
chains through free_zone_device_folio() into kvmppc_uvmem_folio_free()
to clear the bitmap bit, free pvt, and reset the GFN state.
Reachable whenever uv_page_in() returns an error (e.g. UV pool
exhaustion) on any POWER9/10 + Ultravisor/PEF system.
Fixes: ca9f4942670c ("KVM: PPC: Book3S HV: Support for running secure guests")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kvm/book3s_hv_uvmem.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/arch/powerpc/kvm/book3s_hv_uvmem.c b/arch/powerpc/kvm/book3s_hv_uvmem.c
index 5fbb95d90e996..463aef870c4eb 100644
--- a/arch/powerpc/kvm/book3s_hv_uvmem.c
+++ b/arch/powerpc/kvm/book3s_hv_uvmem.c
@@ -779,8 +779,11 @@ static int kvmppc_svm_page_in(struct vm_area_struct *vma,
if (spage) {
ret = uv_page_in(kvm->arch.lpid, pfn << page_shift,
gpa, 0, page_shift);
- if (ret)
+ if (ret) {
+ unlock_page(dpage);
+ put_page(dpage);
goto out_finalize;
+ }
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 138/398] ksmbd: fix partial file information responses
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (136 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 137/398] ksmbd: return buffer overflow for partial filesystem info Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 139/398] ksmbd: keep compound responses on query info errors Greg Kroah-Hartman
` (264 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 6b8b79226bc3e0ac3fdd4e91836241af712e8cd1 ]
Variable-length file information handlers use the client output length
while constructing the response. FILE_ALL_INFORMATION can consequently
return -EINVAL before the common buffer check, while stream information
can stop building the complete result too early.
Build the complete response within the available server response buffer
and apply the client output length only when selecting the final status
and transmitted length. Use the protocol-defined fixed sizes for all,
alternate-name, and stream information to distinguish
STATUS_INFO_LENGTH_MISMATCH from STATUS_BUFFER_OVERFLOW.
This fixes smb2.getinfo.qfile_buffercheck.
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Stable-dep-of: 9fa26285ae70 ("ksmbd: keep compound responses on query info errors")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 31 ++++++++++++++++++++-----------
1 file changed, 20 insertions(+), 11 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index 092788ac01b5d..b7fa559d2a339 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -5009,7 +5009,6 @@ static int get_file_all_info(struct ksmbd_work *work,
char *filename;
u64 time;
int ret, buf_free_len, filename_len;
- struct smb2_query_info_req *req = ksmbd_req_buf_next(work);
if (!(fp->daccess & FILE_READ_ATTRIBUTES_LE)) {
ksmbd_debug(SMB, "no right to read the attributes : 0x%x\n",
@@ -5022,10 +5021,9 @@ static int get_file_all_info(struct ksmbd_work *work,
return PTR_ERR(filename);
filename_len = strlen(filename);
- buf_free_len = smb2_calc_max_out_buf_len(work,
+ buf_free_len = smb2_resp_buf_len(work,
offsetof(struct smb2_query_info_rsp, Buffer) +
- offsetof(struct smb2_file_all_info, FileName),
- le32_to_cpu(req->OutputBufferLength));
+ offsetof(struct smb2_file_all_info, FileName));
if (buf_free_len < (filename_len + 1) * 2) {
kfree(filename);
return -EINVAL;
@@ -5118,7 +5116,6 @@ static int get_file_stream_info(struct ksmbd_work *work,
ssize_t xattr_list_len;
int nbytes = 0, streamlen, stream_name_len, next, idx = 0;
int buf_free_len;
- struct smb2_query_info_req *req = ksmbd_req_buf_next(work);
int ret;
ret = vfs_getattr(&fp->filp->f_path, &stat, STATX_BASIC_STATS,
@@ -5128,10 +5125,8 @@ static int get_file_stream_info(struct ksmbd_work *work,
file_info = (struct smb2_file_stream_info *)rsp->Buffer;
- buf_free_len =
- smb2_calc_max_out_buf_len(work,
- offsetof(struct smb2_query_info_rsp, Buffer),
- le32_to_cpu(req->OutputBufferLength));
+ buf_free_len = smb2_resp_buf_len(work,
+ offsetof(struct smb2_query_info_rsp, Buffer));
if (buf_free_len < 0)
goto out;
@@ -5441,6 +5436,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
struct ksmbd_file *fp;
int fileinfoclass = 0;
int rc = 0;
+ unsigned int fixed_len;
unsigned int id = KSMBD_NO_FID, pid = KSMBD_NO_FID;
if (test_share_config_flag(work->tcon->share_conf,
@@ -5544,10 +5540,23 @@ static int smb2_get_info_file(struct ksmbd_work *work,
fileinfoclass);
rc = -EOPNOTSUPP;
}
- if (!rc)
+ if (!rc) {
+ fixed_len = le32_to_cpu(rsp->OutputBufferLength);
+ switch (fileinfoclass) {
+ case FILE_ALL_INFORMATION:
+ fixed_len = FILE_ALL_INFORMATION_SIZE;
+ break;
+ case FILE_ALTERNATE_NAME_INFORMATION:
+ fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
+ break;
+ case FILE_STREAM_INFORMATION:
+ fixed_len = FILE_STREAM_INFORMATION_SIZE;
+ break;
+ }
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
- le32_to_cpu(rsp->OutputBufferLength),
+ fixed_len,
rsp, work->response_buf);
+ }
ksmbd_fd_put(work, fp);
iov_pin_out:
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 192/438] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (190 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 191/438] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 193/438] Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable" Greg Kroah-Hartman
` (257 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Shivaprasad G Bhat, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivaprasad G Bhat <sbhat@linux.ibm.com>
[ Upstream commit 0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71 ]
The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified
IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba().
While doing so, the passed in argument npages is ignored and constant
value '1' is used leaving out a possible overflow as the callers can
legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT
cases.
Fix this by accounting for 'npages', checking for arithmetic overflow,
and verifying that the entire requested range (ioba - offset + npages)
does not exceed the table capacity 'size'.
Fixes: b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Shivaprasad G Bhat <sbhat@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kernel/iommu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/powerpc/kernel/iommu.c b/arch/powerpc/kernel/iommu.c
index ee1b5cb557c9a..1ae8384637b5f 100644
--- a/arch/powerpc/kernel/iommu.c
+++ b/arch/powerpc/kernel/iommu.c
@@ -1076,7 +1076,7 @@ int iommu_tce_check_ioba(unsigned long page_shift,
if (ioba < offset)
return -EINVAL;
- if ((ioba + 1) > (offset + size))
+ if ((ioba + npages < ioba) || (ioba - offset + npages > size))
return -EINVAL;
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 139/398] ksmbd: keep compound responses on query info errors
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (137 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 138/398] ksmbd: fix partial file information responses Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 140/398] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() Greg Kroah-Hartman
` (263 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mobin Aydinfar, ChenXiaoSong,
Namjae Jeon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
[ Upstream commit 9fa26285ae70ac2d3d1b47459a6b4463ab053e1c ]
Do not reset the RFC1002 length of the complete response when a query
info buffer is too small. The current command will add its error response
through ksmbd_iov_pin_rsp(), while resetting the base length can truncate
earlier responses in a compound request.
This lets ksmbd return the earlier responses and the query-info error
response together. Remove the now-unused rsp_org parameter from the pipe
query-info helpers.
Fixes: e2b76ab8b5c9 ("ksmbd: add support for read compound")
Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/smb/server/smb2pdu.c | 31 ++++++++++++-------------------
1 file changed, 12 insertions(+), 19 deletions(-)
diff --git a/fs/smb/server/smb2pdu.c b/fs/smb/server/smb2pdu.c
index b7fa559d2a339..9e42c65139707 100644
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -4635,21 +4635,18 @@ int smb2_query_dir(struct ksmbd_work *work)
* @reqOutputBufferLength: max buffer length expected in command response
* @fixed_len: minimum fixed response length
* @rsp: query info response buffer contains output buffer length
- * @rsp_org: base response buffer pointer in case of chained response
*
* Return: 0 on success, otherwise error
*/
static int buffer_check_err(int reqOutputBufferLength,
unsigned int fixed_len,
- struct smb2_query_info_rsp *rsp,
- void *rsp_org)
+ struct smb2_query_info_rsp *rsp)
{
unsigned int output_len = le32_to_cpu(rsp->OutputBufferLength);
if (reqOutputBufferLength < fixed_len) {
pr_err("Invalid Buffer Size Requested\n");
rsp->hdr.Status = STATUS_INFO_LENGTH_MISMATCH;
- *(__be32 *)rsp_org = cpu_to_be32(sizeof(struct smb2_hdr));
return -EINVAL;
}
@@ -4660,8 +4657,7 @@ static int buffer_check_err(int reqOutputBufferLength,
return 0;
}
-static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp,
- void *rsp_org)
+static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp)
{
struct smb2_file_standard_info *sinfo;
@@ -4676,8 +4672,7 @@ static void get_standard_info_pipe(struct smb2_query_info_rsp *rsp,
cpu_to_le32(sizeof(struct smb2_file_standard_info));
}
-static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num,
- void *rsp_org)
+static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num)
{
struct smb2_file_internal_info *file_info;
@@ -4691,8 +4686,7 @@ static void get_internal_info_pipe(struct smb2_query_info_rsp *rsp, u64 num,
static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
struct smb2_query_info_req *req,
- struct smb2_query_info_rsp *rsp,
- void *rsp_org)
+ struct smb2_query_info_rsp *rsp)
{
u64 id;
int rc;
@@ -4717,16 +4711,16 @@ static int smb2_get_info_file_pipe(struct ksmbd_session *sess,
switch (req->FileInfoClass) {
case FILE_STANDARD_INFORMATION:
- get_standard_info_pipe(rsp, rsp_org);
+ get_standard_info_pipe(rsp);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
le32_to_cpu(rsp->OutputBufferLength),
- rsp, rsp_org);
+ rsp);
break;
case FILE_INTERNAL_INFORMATION:
- get_internal_info_pipe(rsp, id, rsp_org);
+ get_internal_info_pipe(rsp, id);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
le32_to_cpu(rsp->OutputBufferLength),
- rsp, rsp_org);
+ rsp);
break;
default:
ksmbd_debug(SMB, "smb2_info_file_pipe for %u not supported\n",
@@ -5442,8 +5436,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
if (test_share_config_flag(work->tcon->share_conf,
KSMBD_SHARE_FLAG_PIPE)) {
/* smb2 info file called for pipe */
- rc = smb2_get_info_file_pipe(work->sess, req, rsp,
- work->response_buf);
+ rc = smb2_get_info_file_pipe(work->sess, req, rsp);
goto iov_pin_out;
}
@@ -5555,7 +5548,7 @@ static int smb2_get_info_file(struct ksmbd_work *work,
}
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
fixed_len,
- rsp, work->response_buf);
+ rsp);
}
ksmbd_fd_put(work, fp);
@@ -5792,7 +5785,7 @@ static int smb2_get_info_filesystem(struct ksmbd_work *work,
}
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
fixed_len,
- rsp, work->response_buf);
+ rsp);
path_put(&path);
if (!rc)
@@ -5907,7 +5900,7 @@ static int smb2_get_info_sec(struct ksmbd_work *work,
rsp->OutputBufferLength = cpu_to_le32(secdesclen);
rc = buffer_check_err(le32_to_cpu(req->OutputBufferLength),
le32_to_cpu(rsp->OutputBufferLength),
- rsp, work->response_buf);
+ rsp);
if (rc)
goto err_out;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 193/438] Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable"
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (191 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 192/438] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 194/438] futex: Also allocate private hash on vfork() Greg Kroah-Hartman
` (256 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nemesa Garg, Jouni Högander,
Suraj Kandpal, Jani Nikula, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nemesa Garg <nemesa.garg@intel.com>
[ Upstream commit a26204be587c57bd5c54fa513be26c4fd7bf252d ]
This reverts commit 7f1172a2ac0d7e50850785e2e65789c8aac8411a.
This commit replaced the crtc_state->enable_psr2_sel_fetch guard in
icl_plane_disable_sel_fetch_arm() and i9xx_cursor_disable_sel_fetch_arm()
with HAS_PSR2_SEL_FETCH(). This is a display version check and
says nothing about the pipe, so every plane and cursor disable on a
display 12+ platform started writing SEL_FETCH_PLANE_CTL() /
SEL_FETCH_CUR_CTL(), including on pipes that do not implement them.
It shows up as an unclaimed register access on pipes driving HDMI where
selective fetch was never enabled.
The stale selective fetch enable bit that commit addressed is handled
in the next patch.
Fixes: 7f1172a2ac0d ("drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable")
Closes: https://gitlab.freedesktop.org/drm/i915/kernel/-/work_items/16876
Signed-off-by: Nemesa Garg <nemesa.garg@intel.com>
Reviewed-by: Jouni Högander <jouni.hogander@intel.com>
Signed-off-by: Suraj Kandpal <suraj.kandpal@intel.com>
Link: https://patch.msgid.link/20260909110332.3528029-2-nemesa.garg@intel.com
(cherry picked from commit d393529394167e0f5f706657eebe84d8529ce4fc)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/i915/display/intel_cursor.c | 15 +++++----------
.../gpu/drm/i915/display/skl_universal_plane.c | 15 +++++----------
2 files changed, 10 insertions(+), 20 deletions(-)
diff --git a/drivers/gpu/drm/i915/display/intel_cursor.c b/drivers/gpu/drm/i915/display/intel_cursor.c
index 18ef7e64821be..52347668f27d6 100644
--- a/drivers/gpu/drm/i915/display/intel_cursor.c
+++ b/drivers/gpu/drm/i915/display/intel_cursor.c
@@ -530,18 +530,13 @@ static int i9xx_check_cursor(struct intel_crtc_state *crtc_state,
}
static void i9xx_cursor_disable_sel_fetch_arm(struct intel_dsb *dsb,
- struct intel_plane *plane)
+ struct intel_plane *plane,
+ const struct intel_crtc_state *crtc_state)
{
struct intel_display *display = to_intel_display(plane);
enum pipe pipe = plane->pipe;
- /*
- * Clear this whenever the hardware has selective fetch, not just when
- * the current state uses it. The cursor may have been enabled with
- * selective fetch earlier and had its enable bit orphaned when the
- * feature was switched off.
- */
- if (!HAS_PSR2_SEL_FETCH(display))
+ if (!crtc_state->enable_psr2_sel_fetch)
return;
intel_de_write_dsb(display, dsb, SEL_FETCH_CUR_CTL(pipe), 0);
@@ -591,7 +586,7 @@ static void i9xx_cursor_update_sel_fetch_arm(struct intel_dsb *dsb,
if (crtc_state->enable_psr2_su_region_et)
wa_16021440873(dsb, plane, crtc_state, plane_state);
else
- i9xx_cursor_disable_sel_fetch_arm(dsb, plane);
+ i9xx_cursor_disable_sel_fetch_arm(dsb, plane, crtc_state);
}
}
@@ -700,7 +695,7 @@ static void i9xx_cursor_update_arm(struct intel_dsb *dsb,
if (plane_state)
i9xx_cursor_update_sel_fetch_arm(dsb, plane, crtc_state, plane_state);
else
- i9xx_cursor_disable_sel_fetch_arm(dsb, plane);
+ i9xx_cursor_disable_sel_fetch_arm(dsb, plane, crtc_state);
if (plane->cursor.base != base ||
plane->cursor.size != fbc_ctl ||
diff --git a/drivers/gpu/drm/i915/display/skl_universal_plane.c b/drivers/gpu/drm/i915/display/skl_universal_plane.c
index 4369c8eeaac25..164b7d61c9a31 100644
--- a/drivers/gpu/drm/i915/display/skl_universal_plane.c
+++ b/drivers/gpu/drm/i915/display/skl_universal_plane.c
@@ -879,18 +879,13 @@ skl_plane_disable_arm(struct intel_dsb *dsb,
}
static void icl_plane_disable_sel_fetch_arm(struct intel_dsb *dsb,
- struct intel_plane *plane)
+ struct intel_plane *plane,
+ const struct intel_crtc_state *crtc_state)
{
struct intel_display *display = to_intel_display(plane);
enum pipe pipe = plane->pipe;
- /*
- * Clear this whenever the hardware has selective fetch, not just when
- * the current state uses it. The plane may have been enabled with
- * selective fetch earlier and had its enable bit orphaned when the
- * feature was switched off.
- */
- if (!HAS_PSR2_SEL_FETCH(display))
+ if (!crtc_state->enable_psr2_sel_fetch)
return;
intel_de_write_dsb(display, dsb, SEL_FETCH_PLANE_CTL(pipe, plane->id), 0);
@@ -926,7 +921,7 @@ icl_plane_disable_arm(struct intel_dsb *dsb,
skl_write_plane_wm(dsb, plane, crtc_state);
- icl_plane_disable_sel_fetch_arm(dsb, plane);
+ icl_plane_disable_sel_fetch_arm(dsb, plane, crtc_state);
if (plane_has_normalizer(plane))
intel_de_write_dsb(display, dsb,
@@ -1646,7 +1641,7 @@ static void icl_plane_update_sel_fetch_arm(struct intel_dsb *dsb,
intel_de_write_dsb(display, dsb, SEL_FETCH_PLANE_CTL(pipe, plane->id),
SEL_FETCH_PLANE_CTL_ENABLE);
else
- icl_plane_disable_sel_fetch_arm(dsb, plane);
+ icl_plane_disable_sel_fetch_arm(dsb, plane, crtc_state);
}
static void
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 140/398] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (138 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 139/398] ksmbd: keep compound responses on query info errors Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 141/398] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained Greg Kroah-Hartman
` (262 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baineng Shou, Frank Li, Vinod Koul,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baineng Shou <shoubaineng@gmail.com>
[ Upstream commit 075bc7b1d3dde5ed43fbaabbc1a69f09b7fc3a47 ]
In mmp_pdma_prep_slave_sg(), for_each_sg() iterates the scatterlist
putting each entry into 'sg', but the entry length is read from 'sgl'
(the list head) instead of 'sg' (the current entry):
for_each_sg(sgl, sg, sg_len, i) {
addr = sg_dma_address(sg);
avail = sg_dma_len(sgl); /* should be 'sg' */
Consequently 'avail' is always the length of the first entry. For
multi-sg lists this causes out-of-bounds reads when a later entry is
shorter than the first, and silent data loss when it is longer.
Single-sg or uniformly-sized lists happen to mask the issue.
Fixes: c8acd6aa6bed3 ("dmaengine: mmp-pdma support")
Signed-off-by: Baineng Shou <shoubaineng@gmail.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260910021652.1296640-1-shoubaineng@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/mmp_pdma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/mmp_pdma.c b/drivers/dma/mmp_pdma.c
index d12e729ee12c5..bf77bc7d5e388 100644
--- a/drivers/dma/mmp_pdma.c
+++ b/drivers/dma/mmp_pdma.c
@@ -701,7 +701,7 @@ mmp_pdma_prep_slave_sg(struct dma_chan *dchan, struct scatterlist *sgl,
for_each_sg(sgl, sg, sg_len, i) {
addr = sg_dma_address(sg);
- avail = sg_dma_len(sgl);
+ avail = sg_dma_len(sg);
do {
len = min_t(size_t, avail, PDMA_MAX_DESC_BYTES);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 194/438] futex: Also allocate private hash on vfork()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (192 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 193/438] Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable" Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 195/438] drm/xe/i2c: Disable IRQ on unbind Greg Kroah-Hartman
` (255 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jann Horn, Peter Zijlstra (Intel),
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Zijlstra <peterz@infradead.org>
[ Upstream commit b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5 ]
As Jann demonstrated, it is entirely feasible to access the mm through vfork().
Therefore we need to allocate a private hash on vfork() as well as any other
CLONE_VM user.
Specifically, it must be avoided to have (private) futex waiters before
allocating the private hash.
Fixes: ee9dce44362b ("futex: Drop CLONE_THREAD requirement for private default hash alloc")
Reported-by: Jann Horn <jannh@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/20260911090447.GT788244@noisy.programming.kicks-ass.net
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/fork.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/kernel/fork.c b/kernel/fork.c
index 3340dbaf2bb4a..2c88568b0463d 100644
--- a/kernel/fork.c
+++ b/kernel/fork.c
@@ -1977,9 +1977,9 @@ static bool need_futex_hash_allocate_default(u64 clone_flags)
{
/*
* Allocate a default futex hash for any sibling that will
- * share the parent's mm, except vfork.
+ * share the parent's mm.
*/
- return (clone_flags & (CLONE_VM | CLONE_VFORK)) == CLONE_VM;
+ return clone_flags & CLONE_VM;
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 141/398] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (139 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 140/398] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 142/398] Bluetooth: btintel_pcie: validate TX skb length in send_sync Greg Kroah-Hartman
` (261 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b6919040d9958e2fc1ae,
ThangNN99, Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: ThangNN99 <ngocthang2710.1999@gmail.com>
[ Upstream commit 6610c6fe4b8936c232048e6049bf77c70a6f759c ]
hci_send_acl(), hci_send_sco() and hci_send_iso() queue hdev->tx_work
unconditionally. They can run from the L2CAP/SCO/ISO socket send path
while hci_dev_close_sync() is draining hdev->workqueue (HCIDEVDOWN
racing with a socket write). Since that queue_work() is not chained
work from the tx_work worker itself, __queue_work() sees the queue
marked __WQ_DRAINING, warns "cannot queue %ps on wq %s", and drops
the work:
WARNING: CPU: 1 PID: 5985 at kernel/workqueue.c:2352 __queue_work
Call Trace:
queue_work_on
l2cap_chan_send
l2cap_sock_sendmsg
...
hci_dev_close_sync() already sets HCI_CMD_DRAIN_WORKQUEUE before
draining, but only hci_cmd_work() and handle_cmd_cnt_and_timer()
check it before queuing. Route the tx_work producers through the
same guard via a shared hci_sched_tx() helper.
Fixes: 525daaea459f ("Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close")
Reported-by: syzbot+b6919040d9958e2fc1ae@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b6919040d9958e2fc1ae
Signed-off-by: ThangNN99 <ngocthang2710.1999@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/hci_core.c | 17 ++++++++++++++---
1 file changed, 14 insertions(+), 3 deletions(-)
diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
index 447a7ebcdf62f..31c668ad99366 100644
--- a/net/bluetooth/hci_core.c
+++ b/net/bluetooth/hci_core.c
@@ -3273,6 +3273,17 @@ static void hci_queue_acl(struct hci_chan *chan, struct sk_buff_head *queue,
bt_dev_dbg(hdev, "chan %p queued %d", chan, skb_queue_len(queue));
}
+/* Queue hdev->tx_work, unless hdev->workqueue is being drained by
+ * hci_dev_close_sync(), which would otherwise WARN and drop the work.
+ */
+static void hci_sched_tx(struct hci_dev *hdev)
+{
+ rcu_read_lock();
+ if (!hci_dev_test_flag(hdev, HCI_CMD_DRAIN_WORKQUEUE))
+ queue_work(hdev->workqueue, &hdev->tx_work);
+ rcu_read_unlock();
+}
+
void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
{
struct hci_dev *hdev = chan->conn->hdev;
@@ -3281,7 +3292,7 @@ void hci_send_acl(struct hci_chan *chan, struct sk_buff *skb, __u16 flags)
hci_queue_acl(chan, &chan->data_q, skb, flags);
- queue_work(hdev->workqueue, &hdev->tx_work);
+ hci_sched_tx(hdev);
}
/* Send SCO data */
@@ -3306,7 +3317,7 @@ void hci_send_sco(struct hci_conn *conn, struct sk_buff *skb)
bt_dev_dbg(hdev, "hcon %p queued %d", conn,
skb_queue_len(&conn->data_q));
- queue_work(hdev->workqueue, &hdev->tx_work);
+ hci_sched_tx(hdev);
}
/* Send ISO data */
@@ -3377,7 +3388,7 @@ void hci_send_iso(struct hci_conn *conn, struct sk_buff *skb)
hci_queue_iso(conn, &conn->data_q, skb);
- queue_work(hdev->workqueue, &hdev->tx_work);
+ hci_sched_tx(hdev);
}
/* ---- HCI TX task (outgoing data) ---- */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 195/438] drm/xe/i2c: Disable IRQ on unbind
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (193 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 194/438] futex: Also allocate private hash on vfork() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 196/438] btrfs: handle lack of space when cleaning up verity items Greg Kroah-Hartman
` (254 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Raag Jadav, Heikki Krogerus,
Matt Roper, Rodrigo Vivi, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Raag Jadav <raag.jadav@intel.com>
[ Upstream commit f0e9f963a3d209d7dc7ddd61116118ab5da2797d ]
Currently, struct xe_i2c is freed before SGUnit IRQ is disabled in unbind
path, leaving a potential UAF in case I2C IRQ is hit during this small
window. Explicitly disable I2C IRQ in xe_i2c_remove() and fix this.
Fixes: 0bb78ce09926 ("drm/xe/i2c: Wire up reset/postinstall for I2C IRQ")
Signed-off-by: Raag Jadav <raag.jadav@intel.com>
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260911121547.2407261-1-raag.jadav@intel.com
Signed-off-by: Matt Roper <matthew.d.roper@intel.com>
(cherry picked from commit 8ba5c8b8ab3fd362267c11df2cd5a90ee46f6e24)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/xe/xe_i2c.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/gpu/drm/xe/xe_i2c.c b/drivers/gpu/drm/xe/xe_i2c.c
index 5504cd9dd3596..6fce3de272965 100644
--- a/drivers/gpu/drm/xe/xe_i2c.c
+++ b/drivers/gpu/drm/xe/xe_i2c.c
@@ -277,8 +277,10 @@ void xe_i2c_pm_resume(struct xe_device *xe, bool d3cold)
static void xe_i2c_remove(void *data)
{
struct xe_i2c *i2c = data;
+ struct xe_device *xe = tile_to_xe(i2c->mmio->tile);
unsigned int i;
+ xe_i2c_irq_reset(xe);
xe_amc_exit(i2c);
for (i = 0; i < XE_I2C_MAX_CLIENTS; i++) {
@@ -288,6 +290,7 @@ static void xe_i2c_remove(void *data)
bus_unregister_notifier(&i2c_bus_type, &i2c->bus_notifier);
xe_i2c_unregister_adapter(i2c);
+ xe->i2c = NULL;
}
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 142/398] Bluetooth: btintel_pcie: validate TX skb length in send_sync
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (140 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 141/398] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 143/398] Bluetooth: coredump: Quiesce dump work on unregister Greg Kroah-Hartman
` (260 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chandrashekar Devegowda,
Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chandrashekar Devegowda <chandrashekar.devegowda@intel.com>
[ Upstream commit 4b837ebd0ea21ae5cc26f02dc042edc6fe7b46b9 ]
btintel_pcie_prepare_tx() copies skb->len bytes into a fixed
BTINTEL_PCIE_BUFFER_SIZE (4096) DMA slot via an unchecked memcpy.
Oversized packets are currently rejected only in
btintel_pcie_send_frame(); any future caller of
btintel_pcie_send_sync() would silently overflow the DMA buffer.
Add the bounds check in btintel_pcie_send_sync() itself, right
before skb_push() and the DMA copy.
Assisted-by: Copilot:claude-sonnet-5 code-review code-generation
Fixes: 6e65a09f9275 ("Bluetooth: btintel_pcie: Add *setup* function to download firmware")
Signed-off-by: Chandrashekar Devegowda <chandrashekar.devegowda@intel.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btintel_pcie.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c
index 56ba643d5ff7e..90494871e0d37 100644
--- a/drivers/bluetooth/btintel_pcie.c
+++ b/drivers/bluetooth/btintel_pcie.c
@@ -361,6 +361,12 @@ static int btintel_pcie_send_sync(struct btintel_pcie_data *data,
if (tfd_index > txq->count)
return -ERANGE;
+ if (skb->len > BTINTEL_PCIE_BUFFER_SIZE - BTINTEL_PCIE_HCI_TYPE_LEN) {
+ bt_dev_err(hdev, "TX skb too large (%u > %u)", skb->len,
+ BTINTEL_PCIE_BUFFER_SIZE - BTINTEL_PCIE_HCI_TYPE_LEN);
+ return -EMSGSIZE;
+ }
+
/* Firmware raises alive interrupt on HCI_OP_RESET or
* BTINTEL_HCI_OP_RESET
*/
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 196/438] btrfs: handle lack of space when cleaning up verity items
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (194 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 195/438] drm/xe/i2c: Disable IRQ on unbind Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 197/438] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments Greg Kroah-Hartman
` (253 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Daniel Linjama,
David Sterba, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Linjama <daniel@dev.linjama.com>
[ Upstream commit 76bf149cd0298544631e756670b89c399c7acbca ]
When enable_verity() hits the qgroup limit, rollback_verity() needs its
own metadata reservation. When the qgroup limit or lack of space refuses
the rollback, the whole filesystem is forced read-only even though the
qgroup limit was for one subvolume only. Also orphan cleanup at the next
mount fails the same way, so the leftover items are never removed: with
-EDQUOT the subvolume stays unreachable, and with -ENOSPC on a full
filesystem the next read-write mount fails.
Start transactions with btrfs_start_transaction_fallback_global_rsv() in
btrfs_orphan_cleanup(), drop_verity_items() and rollback_verity(). Those
calls only delete items and free the space in the end, so they may use
the global reserve and skip the qgroup limit, which avoids -ENOSPC and
-EDQUOT.
Fixes: 146054090b08 ("btrfs: initial fsverity support")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Daniel Linjama <daniel@dev.linjama.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/inode.c | 3 ++-
fs/btrfs/verity.c | 18 ++++++++++++++++--
2 files changed, 18 insertions(+), 3 deletions(-)
diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c
index 188b4ac9889fc..67f39347acc05 100644
--- a/fs/btrfs/inode.c
+++ b/fs/btrfs/inode.c
@@ -3876,7 +3876,8 @@ int btrfs_orphan_cleanup(struct btrfs_root *root)
if (ret)
goto out;
}
- trans = btrfs_start_transaction(root, 1);
+ /* Only deletes the orphan. */
+ trans = btrfs_start_transaction_fallback_global_rsv(root, 1);
if (IS_ERR(trans)) {
ret = PTR_ERR(trans);
goto out;
diff --git a/fs/btrfs/verity.c b/fs/btrfs/verity.c
index 1133a56c0568b..1f05525386c93 100644
--- a/fs/btrfs/verity.c
+++ b/fs/btrfs/verity.c
@@ -93,6 +93,20 @@ static loff_t merkle_file_pos(const struct inode *inode)
return rounded;
}
+/*
+ * Start a transaction for removing verity items or the verity orphan.
+ *
+ * Like unlink, this only deletes items and frees space in the end, so the
+ * reservation may come from the global reserve when the filesystem is full
+ * (-ENOSPC) and is not subject to the qgroup limit (-EDQUOT). Otherwise a
+ * failed enable could never be cleaned up in either situation.
+ */
+static struct btrfs_trans_handle *start_verity_cleanup_trans(struct btrfs_root *root,
+ unsigned int num_items)
+{
+ return btrfs_start_transaction_fallback_global_rsv(root, num_items);
+}
+
/*
* Drop all the items for this inode with this key_type.
*
@@ -120,7 +134,7 @@ static int drop_verity_items(struct btrfs_inode *inode, u8 key_type)
while (1) {
/* 1 for the item being dropped */
- trans = btrfs_start_transaction(root, 1);
+ trans = start_verity_cleanup_trans(root, 1);
if (IS_ERR(trans))
return PTR_ERR(trans);
@@ -466,7 +480,7 @@ static int rollback_verity(struct btrfs_inode *inode)
* 1 for updating the inode flag
* 1 for deleting the orphan
*/
- trans = btrfs_start_transaction(root, 2);
+ trans = start_verity_cleanup_trans(root, 2);
if (IS_ERR(trans)) {
ret = PTR_ERR(trans);
trans = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 143/398] Bluetooth: coredump: Quiesce dump work on unregister
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (141 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 142/398] Bluetooth: btintel_pcie: validate TX skb length in send_sync Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 144/398] Bluetooth: hci_qca: Refactor HFP hardware offload capability handling Greg Kroah-Hartman
` (259 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+b170dbf55520ebf5969a,
Aby Sam Ross, Tristan Madani, Xiang Mei, Weiming Shi,
Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit d236517c264e41dc09833c708ef23bccb7a91219 ]
hci_devcd_handle_pkt_init() arms dump_timeout and coredump producers
queue dump_rx without holding an hdev reference. Unregister leaves both
works live, so disconnecting during an active dump lets them access hdev
after hci_release_dev() frees it.
Shut down coredump processing during unregister. Close the producer gate
under dump_q.lock before disabling both works, then free the active buffer
and queued packets under hci_dev_lock. Serializing the gate with enqueue
prevents controller-specific workers from adding packets after the final
purge.
Fixes: 9695ef876fd1 ("Bluetooth: Add support for hci devcoredump")
Reported-by: syzbot+b170dbf55520ebf5969a@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=b170dbf55520ebf5969a
Reported-by: Aby Sam Ross <abysamross@gmail.com>
Link: https://lore.kernel.org/r/20260322210849.68743-1-abysamross@gmail.com
Suggested-by: Aby Sam Ross <abysamross@gmail.com>
Reported-by: Tristan Madani <tristan@talencesecurity.com>
Link: https://lore.kernel.org/r/20260814231248.3096377-1-tristmd@gmail.com
Reported-by: Xiang Mei <xmei5@asu.edu>
Assisted-by: OpenAI Codex:gpt-5
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/bluetooth/coredump.h | 2 +
net/bluetooth/coredump.c | 65 +++++++++++++++++++++-----------
net/bluetooth/hci_core.c | 1 +
3 files changed, 47 insertions(+), 21 deletions(-)
diff --git a/include/net/bluetooth/coredump.h b/include/net/bluetooth/coredump.h
index 72f51b587a046..00c12c7ac042f 100644
--- a/include/net/bluetooth/coredump.h
+++ b/include/net/bluetooth/coredump.h
@@ -61,6 +61,7 @@ struct hci_devcoredump {
#ifdef CONFIG_DEV_COREDUMP
void hci_devcd_reset(struct hci_dev *hdev);
+void hci_devcd_shutdown(struct hci_dev *hdev);
void hci_devcd_rx(struct work_struct *work);
void hci_devcd_timeout(struct work_struct *work);
@@ -75,6 +76,7 @@ int hci_devcd_abort(struct hci_dev *hdev);
#else
static inline void hci_devcd_reset(struct hci_dev *hdev) {}
+static inline void hci_devcd_shutdown(struct hci_dev *hdev) {}
static inline void hci_devcd_rx(struct work_struct *work) {}
static inline void hci_devcd_timeout(struct work_struct *work) {}
diff --git a/net/bluetooth/coredump.c b/net/bluetooth/coredump.c
index 720cb79adf964..b15971ad78a8f 100644
--- a/net/bluetooth/coredump.c
+++ b/net/bluetooth/coredump.c
@@ -105,6 +105,22 @@ static void hci_devcd_free(struct hci_dev *hdev)
hci_devcd_reset(hdev);
}
+void hci_devcd_shutdown(struct hci_dev *hdev)
+{
+ unsigned long flags;
+
+ spin_lock_irqsave(&hdev->dump.dump_q.lock, flags);
+ hdev->dump.supported = false;
+ spin_unlock_irqrestore(&hdev->dump.dump_q.lock, flags);
+
+ disable_work_sync(&hdev->dump.dump_rx);
+ disable_delayed_work_sync(&hdev->dump.dump_timeout);
+
+ hci_dev_lock(hdev);
+ hci_devcd_free(hdev);
+ hci_dev_unlock(hdev);
+}
+
/* Call with hci_dev_lock only. */
static int hci_devcd_alloc(struct hci_dev *hdev, u32 size)
{
@@ -444,7 +460,29 @@ EXPORT_SYMBOL(hci_devcd_register);
static inline bool hci_devcd_enabled(struct hci_dev *hdev)
{
- return hdev->dump.supported;
+ return READ_ONCE(hdev->dump.supported);
+}
+
+static int hci_devcd_queue(struct hci_dev *hdev, struct sk_buff *skb)
+{
+ unsigned long flags;
+ int err = 0;
+
+ spin_lock_irqsave(&hdev->dump.dump_q.lock, flags);
+ if (!hdev->dump.supported)
+ err = -EOPNOTSUPP;
+ else
+ __skb_queue_tail(&hdev->dump.dump_q, skb);
+ spin_unlock_irqrestore(&hdev->dump.dump_q.lock, flags);
+
+ if (err) {
+ kfree_skb(skb);
+ return err;
+ }
+
+ queue_work(hdev->workqueue, &hdev->dump.dump_rx);
+
+ return 0;
}
int hci_devcd_init(struct hci_dev *hdev, u32 dump_size)
@@ -461,10 +499,7 @@ int hci_devcd_init(struct hci_dev *hdev, u32 dump_size)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_INIT;
put_unaligned_le32(dump_size, skb_put(skb, 4));
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_init);
@@ -480,10 +515,7 @@ int hci_devcd_append(struct hci_dev *hdev, struct sk_buff *skb)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_SKB;
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_append);
@@ -505,10 +537,7 @@ int hci_devcd_append_pattern(struct hci_dev *hdev, u8 pattern, u32 len)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_PATTERN;
skb_put_data(skb, &p, sizeof(p));
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_append_pattern);
@@ -525,10 +554,7 @@ int hci_devcd_complete(struct hci_dev *hdev)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_COMPLETE;
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_complete);
@@ -545,9 +571,6 @@ int hci_devcd_abort(struct hci_dev *hdev)
hci_dmp_cb(skb)->pkt_type = HCI_DEVCOREDUMP_PKT_ABORT;
- skb_queue_tail(&hdev->dump.dump_q, skb);
- queue_work(hdev->workqueue, &hdev->dump.dump_rx);
-
- return 0;
+ return hci_devcd_queue(hdev, skb);
}
EXPORT_SYMBOL(hci_devcd_abort);
diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c
index 31c668ad99366..c0a8bd7af781e 100644
--- a/net/bluetooth/hci_core.c
+++ b/net/bluetooth/hci_core.c
@@ -2709,6 +2709,7 @@ void hci_unregister_dev(struct hci_dev *hdev)
disable_work_sync(&hdev->error_reset);
disable_delayed_work_sync(&hdev->cmd_timer);
disable_delayed_work_sync(&hdev->ncmd_timer);
+ hci_devcd_shutdown(hdev);
hci_cmd_sync_clear(hdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 197/438] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (195 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 196/438] btrfs: handle lack of space when cleaning up verity items Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 198/438] ASoC: hdmi-codec: Report a change when the channel status moves Greg Kroah-Hartman
` (252 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, kernel test robot, Sasha Levin,
Linus Walleij, Mark Brown
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
[ Upstream commit 11fc0048a6930f4fca44fe3bd16a0023e78846a2 ]
arm allmodconfig fails to build with gcc:
In file included from sound/soc/ux500/ux500_msp_i2s.c:20:
sound/soc/ux500/ux500_msp_i2s.h:151:38: error: suggest parentheses
around arithmetic in operand of '^' [-Werror=parentheses]
sound/soc/ux500/ux500_msp_i2s.c:204:21: note: in expansion of macro
'MSP_TX_CLKPOL_BIT'
cc1: all warnings being treated as errors
The macros never parenthesized their argument:
#define MSP_TX_CLKPOL_BIT(n) ((n & TCKPOL_MASK) << TCKPOL_SHIFT)
That went unnoticed while every caller passed a plain variable, but
configure_protocol() now passes an XOR expression, which binds as
"a ^ (b & MASK)" rather than "(a ^ b) & MASK", and gcc rightly
complains.
No functional change: tx_clk_pol and rx_clk_pol only ever hold
MSP_FALLING_EDGE (0) or MSP_RISING_EDGE (1), and bclk_inverted is a
bool, so masking before or after the XOR gives the same 0/1 result.
Parenthesize the argument anyway - it fixes the build and stops the
macros from silently mis-evaluating a future composite argument.
Fixes: 9ccbacf5a012 ("ASoC: ux500: Validate MSP DAI configuration")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202609051547.G9SJp8UQ-lkp@intel.com/
Assisted-by: LLM
Signed-off-by: Sasha Levin <sashal@kernel.org>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260913173132.1172003-1-sashal@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_i2s.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/sound/soc/ux500/ux500_msp_i2s.h b/sound/soc/ux500/ux500_msp_i2s.h
index 2bf2699bdc49f..c66ef455e1380 100644
--- a/sound/soc/ux500/ux500_msp_i2s.h
+++ b/sound/soc/ux500/ux500_msp_i2s.h
@@ -147,8 +147,8 @@ enum msp_direction {
#define RCKPOL_MASK BIT(0)
#define TCKPOL_MASK BIT(0)
#define SPICKM_MASK (BIT(1) | BIT(0))
-#define MSP_RX_CLKPOL_BIT(n) ((n & RCKPOL_MASK) << RCKPOL_SHIFT)
-#define MSP_TX_CLKPOL_BIT(n) ((n & TCKPOL_MASK) << TCKPOL_SHIFT)
+#define MSP_RX_CLKPOL_BIT(n) (((n) & RCKPOL_MASK) << RCKPOL_SHIFT)
+#define MSP_TX_CLKPOL_BIT(n) (((n) & TCKPOL_MASK) << TCKPOL_SHIFT)
#define P1ELEN_SHIFT 0
#define P1FLEN_SHIFT 3
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 144/398] Bluetooth: hci_qca: Refactor HFP hardware offload capability handling
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (142 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 143/398] Bluetooth: coredump: Quiesce dump work on unregister Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 145/398] Bluetooth: qca: Refactor code on the basis of chipset names Greg Kroah-Hartman
` (258 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Mengshi Wu,
Bartosz Golaszewski, Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mengshi Wu <mengshi.wu@oss.qualcomm.com>
[ Upstream commit 22d893eec0d52fa97d25d3de248285648f26ef68 ]
Replace SoC-specific check with capability-based approach for HFP
hardware offload configuration. Add QCA_CAP_HFP_HW_OFFLOAD capability
flag and support_hfp_hw_offload field to qca_serdev structure. Add
QCA_CAP_HFP_HW_OFFLOAD capability flag to QCA2066 device data
structures.
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Mengshi Wu <mengshi.wu@oss.qualcomm.com>
Acked-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Stable-dep-of: 4e93c65f8782 ("Bluetooth: hci_qca: Do not write to the serial port after it is closed")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/hci_qca.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/drivers/bluetooth/hci_qca.c b/drivers/bluetooth/hci_qca.c
index b510b03dae870..5c03f8f3a53ab 100644
--- a/drivers/bluetooth/hci_qca.c
+++ b/drivers/bluetooth/hci_qca.c
@@ -86,6 +86,7 @@ enum qca_flags {
enum qca_capabilities {
QCA_CAP_WIDEBAND_SPEECH = BIT(0),
QCA_CAP_VALID_LE_STATES = BIT(1),
+ QCA_CAP_HFP_HW_OFFLOAD = BIT(2),
};
/* HCI_IBS transmit side sleep protocol states */
@@ -228,6 +229,7 @@ struct qca_serdev {
u32 init_speed;
u32 oper_speed;
bool bdaddr_property_broken;
+ bool support_hfp_hw_offload;
const char *firmware_name[2];
};
@@ -1915,7 +1917,7 @@ static int qca_setup(struct hci_uart *hu)
const char *rampatch_name = qca_get_rampatch_name(hu);
int ret;
struct qca_btsoc_version ver;
- struct qca_serdev *qcadev;
+ struct qca_serdev *qcadev = serdev_device_get_drvdata(hu->serdev);
const char *soc_name;
ret = qca_check_speeds(hu);
@@ -1979,7 +1981,6 @@ static int qca_setup(struct hci_uart *hu)
case QCA_WCN6750:
case QCA_WCN6855:
case QCA_WCN7850:
- qcadev = serdev_device_get_drvdata(hu->serdev);
if (qcadev->bdaddr_property_broken)
hci_set_quirk(hdev, HCI_QUIRK_BDADDR_PROPERTY_BROKEN);
@@ -2073,7 +2074,7 @@ static int qca_setup(struct hci_uart *hu)
else
hu->hdev->set_bdaddr = qca_set_bdaddr;
- if (soc_type == QCA_QCA2066)
+ if (qcadev->support_hfp_hw_offload)
qca_configure_hfp_offload(hdev);
qca->fw_version = le16_to_cpu(ver.patch_ver);
@@ -2157,7 +2158,8 @@ static const struct qca_device_data qca_soc_data_wcn3998 __maybe_unused = {
static const struct qca_device_data qca_soc_data_qca2066 __maybe_unused = {
.soc_type = QCA_QCA2066,
.num_vregs = 0,
- .capabilities = QCA_CAP_WIDEBAND_SPEECH | QCA_CAP_VALID_LE_STATES,
+ .capabilities = QCA_CAP_WIDEBAND_SPEECH | QCA_CAP_VALID_LE_STATES |
+ QCA_CAP_HFP_HW_OFFLOAD,
};
static const struct qca_device_data qca_soc_data_qca6390 __maybe_unused = {
@@ -2542,6 +2544,9 @@ static int qca_serdev_probe(struct serdev_device *serdev)
if (!(data->capabilities & QCA_CAP_VALID_LE_STATES))
hci_set_quirk(hdev, HCI_QUIRK_BROKEN_LE_STATES);
+
+ if (data->capabilities & QCA_CAP_HFP_HW_OFFLOAD)
+ qcadev->support_hfp_hw_offload = true;
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 198/438] ASoC: hdmi-codec: Report a change when the channel status moves
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (196 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 197/438] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 199/438] ASoC: cs-amp-lib: Prevent NULL pointer if efi variable is zero length Greg Kroah-Hartman
` (251 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Mark Brown,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: HyeongJun An <sammiee5311@gmail.com>
[ Upstream commit c17ae8c26eac16ad244daef44044d714f68a2ddc ]
The put() callback of "IEC958 Playback Default" stores all 24 channel
status bytes and then returns 0. The core notifies userspace only on a
positive return, so a write that changes what the get() callback hands
back is never announced, and a mixer holding the control open keeps
showing the old value.
Compare the stored bytes and return 1 when they move, the way
snd_hda_spdif_default_put() does.
The same shape is in img-spdif-out and uniperif_player.
No board with this codec was to hand. The change is a comparison of
driver state with no hardware behaviour in it, and mixer-test counts the
missing notification as event_missing.
Fixes: 7a8e1d44211e ("ASoC: hdmi-codec: Add iec958 controls")
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Assisted-by: Claude:claude-opus-5
Link: https://patch.msgid.link/20260915092515.2638542-1-sammiee5311@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/hdmi-codec.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/sound/soc/codecs/hdmi-codec.c b/sound/soc/codecs/hdmi-codec.c
index 13ae9e83bc21f..2db9cf8ec6e96 100644
--- a/sound/soc/codecs/hdmi-codec.c
+++ b/sound/soc/codecs/hdmi-codec.c
@@ -425,10 +425,14 @@ static int hdmi_codec_iec958_default_put(struct snd_kcontrol *kcontrol,
struct snd_soc_component *component = snd_kcontrol_chip(kcontrol);
struct hdmi_codec_priv *hcp = snd_soc_component_get_drvdata(component);
+ if (!memcmp(hcp->iec_status, ucontrol->value.iec958.status,
+ sizeof(hcp->iec_status)))
+ return 0;
+
memcpy(hcp->iec_status, ucontrol->value.iec958.status,
sizeof(hcp->iec_status));
- return 0;
+ return 1;
}
static int hdmi_codec_iec958_mask_get(struct snd_kcontrol *kcontrol,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 145/398] Bluetooth: qca: Refactor code on the basis of chipset names
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (143 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 144/398] Bluetooth: hci_qca: Refactor HFP hardware offload capability handling Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 146/398] Bluetooth: qca: enable pwrseq support for WCN39xx devices Greg Kroah-Hartman
` (257 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vivek Sahu, Dmitry Baryshkov,
Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vivek Sahu <vivek.sahu@oss.qualcomm.com>
[ Upstream commit f29bc37dfc4ad7570d78f8cd482d4b83c3caffdf ]
Whenever new chipset support is added to the driver code,
we ended up adding chipset name to the last of the switch case
arising code readability issue because of improper sorting of
the chipset names in various places of the code.
Refactor code such a way that new chipset can be added easily
in the code without compromising code readability.
Signed-off-by: Vivek Sahu <vivek.sahu@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Stable-dep-of: 4e93c65f8782 ("Bluetooth: hci_qca: Do not write to the serial port after it is closed")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btqca.c | 37 +++++++++++++++++++------------------
drivers/bluetooth/hci_qca.c | 30 +++++++++++++++---------------
2 files changed, 34 insertions(+), 33 deletions(-)
diff --git a/drivers/bluetooth/btqca.c b/drivers/bluetooth/btqca.c
index f404eefbfc85b..bdbb5801b2400 100644
--- a/drivers/bluetooth/btqca.c
+++ b/drivers/bluetooth/btqca.c
@@ -818,6 +818,14 @@ int qca_uart_setup(struct hci_dev *hdev, uint8_t baudrate,
snprintf(config.fwname, sizeof(config.fwname), "qca/%s", rampatch_name);
} else {
switch (soc_type) {
+ case QCA_QCA2066:
+ snprintf(config.fwname, sizeof(config.fwname),
+ "qca/hpbtfw%02x.tlv", rom_ver);
+ break;
+ case QCA_QCA6390:
+ snprintf(config.fwname, sizeof(config.fwname),
+ "qca/htbtfw%02x.tlv", rom_ver);
+ break;
case QCA_WCN3950:
snprintf(config.fwname, sizeof(config.fwname),
"qca/cmbtfw%02x.tlv", rom_ver);
@@ -832,14 +840,6 @@ int qca_uart_setup(struct hci_dev *hdev, uint8_t baudrate,
snprintf(config.fwname, sizeof(config.fwname),
"qca/apbtfw%02x.tlv", rom_ver);
break;
- case QCA_QCA2066:
- snprintf(config.fwname, sizeof(config.fwname),
- "qca/hpbtfw%02x.tlv", rom_ver);
- break;
- case QCA_QCA6390:
- snprintf(config.fwname, sizeof(config.fwname),
- "qca/htbtfw%02x.tlv", rom_ver);
- break;
case QCA_WCN6750:
/* Choose mbn file by default.If mbn file is not found
* then choose tlv file
@@ -887,6 +887,16 @@ int qca_uart_setup(struct hci_dev *hdev, uint8_t baudrate,
}
} else {
switch (soc_type) {
+ case QCA_QCA2066:
+ qca_get_nvm_name_by_board(config.fwname,
+ sizeof(config.fwname),
+ "hpnv", soc_type, ver,
+ rom_ver, boardid);
+ break;
+ case QCA_QCA6390:
+ snprintf(config.fwname, sizeof(config.fwname),
+ "qca/htnv%02x.bin", rom_ver);
+ break;
case QCA_WCN3950:
if (le32_to_cpu(ver.soc_id) == QCA_WCN3950_SOC_ID_T)
variant = "t";
@@ -909,15 +919,6 @@ int qca_uart_setup(struct hci_dev *hdev, uint8_t baudrate,
snprintf(config.fwname, sizeof(config.fwname),
"qca/apnv%02x.bin", rom_ver);
break;
- case QCA_QCA2066:
- qca_get_nvm_name_by_board(config.fwname,
- sizeof(config.fwname), "hpnv", soc_type, ver,
- rom_ver, boardid);
- break;
- case QCA_QCA6390:
- snprintf(config.fwname, sizeof(config.fwname),
- "qca/htnv%02x.bin", rom_ver);
- break;
case QCA_WCN6750:
snprintf(config.fwname, sizeof(config.fwname),
"qca/msnv%02x.bin", rom_ver);
@@ -944,9 +945,9 @@ int qca_uart_setup(struct hci_dev *hdev, uint8_t baudrate,
}
switch (soc_type) {
- case QCA_WCN3991:
case QCA_QCA2066:
case QCA_QCA6390:
+ case QCA_WCN3991:
case QCA_WCN6750:
case QCA_WCN6855:
case QCA_WCN7850:
diff --git a/drivers/bluetooth/hci_qca.c b/drivers/bluetooth/hci_qca.c
index 5c03f8f3a53ab..1897d7bf7629a 100644
--- a/drivers/bluetooth/hci_qca.c
+++ b/drivers/bluetooth/hci_qca.c
@@ -1853,6 +1853,7 @@ static int qca_power_on(struct hci_dev *hdev)
return 0;
switch (soc_type) {
+ case QCA_QCA6390:
case QCA_WCN3950:
case QCA_WCN3988:
case QCA_WCN3990:
@@ -1861,7 +1862,6 @@ static int qca_power_on(struct hci_dev *hdev)
case QCA_WCN6750:
case QCA_WCN6855:
case QCA_WCN7850:
- case QCA_QCA6390:
ret = qca_regulator_init(hu);
break;
@@ -2099,6 +2099,18 @@ static const struct hci_uart_proto qca_proto = {
.dequeue = qca_dequeue,
};
+static const struct qca_device_data qca_soc_data_qca2066 __maybe_unused = {
+ .soc_type = QCA_QCA2066,
+ .num_vregs = 0,
+ .capabilities = QCA_CAP_WIDEBAND_SPEECH | QCA_CAP_VALID_LE_STATES |
+ QCA_CAP_HFP_HW_OFFLOAD,
+};
+
+static const struct qca_device_data qca_soc_data_qca6390 __maybe_unused = {
+ .soc_type = QCA_QCA6390,
+ .num_vregs = 0,
+};
+
static const struct qca_device_data qca_soc_data_wcn3950 __maybe_unused = {
.soc_type = QCA_WCN3950,
.vregs = (struct qca_vreg []) {
@@ -2155,18 +2167,6 @@ static const struct qca_device_data qca_soc_data_wcn3998 __maybe_unused = {
.num_vregs = 4,
};
-static const struct qca_device_data qca_soc_data_qca2066 __maybe_unused = {
- .soc_type = QCA_QCA2066,
- .num_vregs = 0,
- .capabilities = QCA_CAP_WIDEBAND_SPEECH | QCA_CAP_VALID_LE_STATES |
- QCA_CAP_HFP_HW_OFFLOAD,
-};
-
-static const struct qca_device_data qca_soc_data_qca6390 __maybe_unused = {
- .soc_type = QCA_QCA6390,
- .num_vregs = 0,
-};
-
static const struct qca_device_data qca_soc_data_wcn6750 __maybe_unused = {
.soc_type = QCA_WCN6750,
.vregs = (struct qca_vreg []) {
@@ -2403,6 +2403,7 @@ static int qca_serdev_probe(struct serdev_device *serdev)
qcadev->btsoc_type = QCA_ROME;
switch (qcadev->btsoc_type) {
+ case QCA_QCA6390:
case QCA_WCN3950:
case QCA_WCN3988:
case QCA_WCN3990:
@@ -2411,7 +2412,6 @@ static int qca_serdev_probe(struct serdev_device *serdev)
case QCA_WCN6750:
case QCA_WCN6855:
case QCA_WCN7850:
- case QCA_QCA6390:
qcadev->bt_power = devm_kzalloc(&serdev->dev,
sizeof(struct qca_power),
GFP_KERNEL);
@@ -2423,9 +2423,9 @@ static int qca_serdev_probe(struct serdev_device *serdev)
}
switch (qcadev->btsoc_type) {
+ case QCA_WCN6750:
case QCA_WCN6855:
case QCA_WCN7850:
- case QCA_WCN6750:
if (!device_property_present(&serdev->dev, "enable-gpios")) {
/*
* Backward compatibility with old DT sources. If the
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 199/438] ASoC: cs-amp-lib: Prevent NULL pointer if efi variable is zero length
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (197 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 198/438] ASoC: hdmi-codec: Report a change when the channel status moves Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 200/438] ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers Greg Kroah-Hartman
` (250 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Fitzgerald, Mark Brown,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Fitzgerald <rf@opensource.cirrus.com>
[ Upstream commit 3482062c786ce4233f8ed3224d824184f53ec154 ]
In cs_amp_alloc_get_efi_variable() the first call to
cs_amp_get_efi_variable() might return EFI_SUCCESS if the variable
exists with zero length. Trap this and return -ENOENT to prevent
returning an unexpected NULL pointer.
The first cs_amp_get_efi_variable() call was assumed to return
EFI_BUFFER_TOO_SMALL if the variable existed, but if instead it
returned EFI_SUCCESS this would be converted to 0 by
cs_amp_convert_efi_status() and then be returned as a NULL pointer.
Fixes: 00fd40bc7acec ("ASoC: cs-amp-lib: Support Dell SSIDExV2 UEFI variable")
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20260914122611.2783563-1-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/cs-amp-lib.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/sound/soc/codecs/cs-amp-lib.c b/sound/soc/codecs/cs-amp-lib.c
index 371e99205b58e..58b06e6878b97 100644
--- a/sound/soc/codecs/cs-amp-lib.c
+++ b/sound/soc/codecs/cs-amp-lib.c
@@ -314,6 +314,8 @@ static void *cs_amp_alloc_get_efi_variable(efi_char16_t *name,
unsigned long size = 0;
status = cs_amp_get_efi_variable(name, guid, NULL, &size, NULL);
+ if (status == EFI_SUCCESS)
+ return ERR_PTR(-ENOENT);
if (status != EFI_BUFFER_TOO_SMALL)
return ERR_PTR(cs_amp_convert_efi_status(status));
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 146/398] Bluetooth: qca: enable pwrseq support for WCN39xx devices
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (144 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 145/398] Bluetooth: qca: Refactor code on the basis of chipset names Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 147/398] Bluetooth: hci_qca: Do not write to the serial port after it is closed Greg Kroah-Hartman
` (256 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski,
Dmitry Baryshkov, Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 9f168e4de5fd43766f6d49b393f445be805c1e05 ]
The WCN39xx family of WiFi/BT chips incorporates a simple PMU, spreading
voltages over internal rails. Implement support for using powersequencer
for this family of QCA devices in addition to using regulators.
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Stable-dep-of: 4e93c65f8782 ("Bluetooth: hci_qca: Do not write to the serial port after it is closed")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/hci_qca.c | 26 ++++++++++++++++++--------
1 file changed, 18 insertions(+), 8 deletions(-)
diff --git a/drivers/bluetooth/hci_qca.c b/drivers/bluetooth/hci_qca.c
index 1897d7bf7629a..8de195c2fc8d6 100644
--- a/drivers/bluetooth/hci_qca.c
+++ b/drivers/bluetooth/hci_qca.c
@@ -2239,6 +2239,18 @@ static void qca_power_shutdown(struct hci_uart *hu)
qcadev = serdev_device_get_drvdata(hu->serdev);
power = qcadev->bt_power;
+ switch (soc_type) {
+ case QCA_WCN3988:
+ case QCA_WCN3990:
+ case QCA_WCN3991:
+ case QCA_WCN3998:
+ host_set_baudrate(hu, 2400);
+ qca_send_power_pulse(hu, false);
+ break;
+ default:
+ break;
+ }
+
if (power && power->pwrseq) {
pwrseq_power_off(power->pwrseq);
set_bit(QCA_BT_OFF, &qca->flags);
@@ -2250,8 +2262,6 @@ static void qca_power_shutdown(struct hci_uart *hu)
case QCA_WCN3990:
case QCA_WCN3991:
case QCA_WCN3998:
- host_set_baudrate(hu, 2400);
- qca_send_power_pulse(hu, false);
qca_regulator_disable(qcadev);
break;
@@ -2423,6 +2433,11 @@ static int qca_serdev_probe(struct serdev_device *serdev)
}
switch (qcadev->btsoc_type) {
+ case QCA_WCN3950:
+ case QCA_WCN3988:
+ case QCA_WCN3990:
+ case QCA_WCN3991:
+ case QCA_WCN3998:
case QCA_WCN6750:
case QCA_WCN6855:
case QCA_WCN7850:
@@ -2447,12 +2462,7 @@ static int qca_serdev_probe(struct serdev_device *serdev)
else
break;
}
- fallthrough;
- case QCA_WCN3950:
- case QCA_WCN3988:
- case QCA_WCN3990:
- case QCA_WCN3991:
- case QCA_WCN3998:
+
qcadev->bt_power->dev = &serdev->dev;
err = qca_init_regulators(qcadev->bt_power, data->vregs,
data->num_vregs);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 200/438] ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (198 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 199/438] ASoC: cs-amp-lib: Prevent NULL pointer if efi variable is zero length Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 201/438] ASoC: sdw_utils: tidyup .count_sidecar Greg Kroah-Hartman
` (249 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vijendar Mukunda,
Mario Limonciello (AMD), Mark Brown, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
[ Upstream commit 29218a4d11a31a8157389bc2b9e62dd768d7ea42 ]
Add a bounds check in create_sdw_dailink() to validate that the
SoundWire link ID derived from link_mask does not exceed the maximum
supported by the platform. If the link ID is out of range or link_mask
is zero, log an error and return -EINVAL to prevent accessing invalid
CPU pin ID tables.
Applied to both acp-sdw-sof-mach.c and acp-sdw-legacy-mach.c.
Fixes: 6d8348ddc56e ("ASoC: amd: acp: refactor SoundWire machine driver code")
Signed-off-by: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Link: https://patch.msgid.link/20260910161728.1452808-2-Vijendar.Mukunda@amd.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/amd/acp/acp-sdw-legacy-mach.c | 10 ++++++++++
sound/soc/amd/acp/acp-sdw-sof-mach.c | 9 +++++++++
2 files changed, 19 insertions(+)
diff --git a/sound/soc/amd/acp/acp-sdw-legacy-mach.c b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
index e8b6819cc4b45..1a6be664be279 100644
--- a/sound/soc/amd/acp/acp-sdw-legacy-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
@@ -205,6 +205,16 @@ static int create_sdw_dailink(struct snd_soc_card *card,
return -EINVAL;
}
+ if (!soc_end->link_mask) {
+ dev_err(dev, "invalid zero link_mask\n");
+ return -EINVAL;
+ }
+ if ((ffs(soc_end->link_mask) - 1) >= amd_ctx->max_sdw_links) {
+ dev_err(dev, "link_id %d exceeds max_sdw_links %d\n",
+ ffs(soc_end->link_mask) - 1, amd_ctx->max_sdw_links);
+ return -EINVAL;
+ }
+
switch (amd_ctx->acp_rev) {
case ACP63_PCI_REV:
ret = get_acp63_cpu_pin_id(ffs(soc_end->link_mask - 1),
diff --git a/sound/soc/amd/acp/acp-sdw-sof-mach.c b/sound/soc/amd/acp/acp-sdw-sof-mach.c
index a423853f3a97d..f66228435984a 100644
--- a/sound/soc/amd/acp/acp-sdw-sof-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-sof-mach.c
@@ -121,6 +121,15 @@ static int create_sdw_dailink(struct snd_soc_card *card,
return -EINVAL;
}
+ if (!sof_end->link_mask) {
+ dev_err(dev, "invalid zero link_mask\n");
+ return -EINVAL;
+ }
+ if ((ffs(sof_end->link_mask) - 1) >= amd_ctx->max_sdw_links) {
+ dev_err(dev, "link_id %d exceeds max_sdw_links %d\n",
+ ffs(sof_end->link_mask) - 1, amd_ctx->max_sdw_links);
+ return -EINVAL;
+ }
switch (amd_ctx->acp_rev) {
case ACP63_PCI_REV:
ret = get_acp63_cpu_pin_id(ffs(sof_end->link_mask - 1),
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 147/398] Bluetooth: hci_qca: Do not write to the serial port after it is closed
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (145 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 146/398] Bluetooth: qca: enable pwrseq support for WCN39xx devices Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 148/398] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() Greg Kroah-Hartman
` (255 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ibrahim Abdelkader, Hans de Goede,
Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ibrahim Abdelkader <iabdelka@qti.qualcomm.com>
[ Upstream commit 4e93c65f87825e1e012bce56615320aeb123815d ]
hci_uart_close() closes the serdev port if HCI_QUIRK_NON_PERSISTENT_SETUP
is set (for example, for the WCN399x family). A failed hci_dev_open_sync()
following a successful qca_setup() calls hdev->close() but not
hdev->shutdown(), so the port is closed while power->vregs_on is left true.
qca_serdev_remove() then passes its power->vregs_on test and calls
qca_power_off(), which writes to the closed port unconditionally.
Seen on a WCN3988 by unbinding the driver after a controller failure. The
trace below is from a 7.0.0 based kernel, where qca_power_off() was still
named qca_power_shutdown():
Unable to handle kernel NULL pointer dereference at virtual address
0000000000000038
Call trace:
tty_set_termios+0x50/0x238 (P)
ttyport_set_baudrate+0x84/0xc0
serdev_device_set_baudrate+0x24/0x40
qca_power_shutdown+0x158/0x1fc [hci_uart]
qca_serdev_remove+0x54/0x68 [hci_uart]
serdev_drv_remove+0x1c/0x2c
device_remove+0x4c/0x80
device_release_driver_internal+0x1cc/0x224
device_driver_detach+0x18/0x24
unbind_store+0xb4/0xc0
Check HCI_UART_PROTO_READY, which hci_uart_close() clears in the same place
it closes the port, before writing to it. The regulator disable is left
unconditional so the controller is still powered down.
The dangling serport->tty that turns this into a use-after-free is
addressed in a separate patch.
Fixes: fa9ad876b8e0 ("Bluetooth: hci_qca: Add support for Qualcomm Bluetooth chip wcn3990")
Signed-off-by: Ibrahim Abdelkader <iabdelka@qti.qualcomm.com>
Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/hci_qca.c | 14 ++++++++++----
1 file changed, 10 insertions(+), 4 deletions(-)
diff --git a/drivers/bluetooth/hci_qca.c b/drivers/bluetooth/hci_qca.c
index 8de195c2fc8d6..cdc51460bd8de 100644
--- a/drivers/bluetooth/hci_qca.c
+++ b/drivers/bluetooth/hci_qca.c
@@ -2221,8 +2221,8 @@ static void qca_power_shutdown(struct hci_uart *hu)
bool sw_ctrl_state;
struct qca_power *power;
- /* From this point we go into power off state. But serial port is
- * still open, stop queueing the IBS data and flush all the buffered
+ /* From this point we go into power off state. But serial port may
+ * still be open, stop queueing the IBS data and flush all the buffered
* data in skb's.
*/
spin_lock_irqsave(&qca->hci_ibs_lock, flags);
@@ -2244,8 +2244,14 @@ static void qca_power_shutdown(struct hci_uart *hu)
case QCA_WCN3990:
case QCA_WCN3991:
case QCA_WCN3998:
- host_set_baudrate(hu, 2400);
- qca_send_power_pulse(hu, false);
+ /* Both of these write to the serial port which may have
+ * already been closed by hci_uart_close(), which closes
+ * the port if HCI_QUIRK_NON_PERSISTENT_SETUP is set.
+ */
+ if (test_bit(HCI_UART_PROTO_READY, &hu->flags)) {
+ host_set_baudrate(hu, 2400);
+ qca_send_power_pulse(hu, false);
+ }
break;
default:
break;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 201/438] ASoC: sdw_utils: tidyup .count_sidecar
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (199 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 200/438] ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 202/438] ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints() Greg Kroah-Hartman
` (248 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuninori Morimoto, Cezary Rojewski,
Mark Brown, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
[ Upstream commit c97f0bf5f705b16d150f2b0d5ce0ee24eee4f68a ]
count_sidecar() is not using *card. Tidyup it.
Current code makes old style / new style conversion difficult.
To make future conversions easier to understand, this patch clean up the
code a little. but no functional change.
Signed-off-by: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Reviewed-by: Cezary Rojewski <cezary.rojewski@intel.com>
Link: https://patch.msgid.link/87jyrlety1.wl-kuninori.morimoto.gx@renesas.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 0b7d55d3a912 ("ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc_sdw_utils.h | 28 ++++++++++----------
sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c | 4 +--
sound/soc/sdw_utils/soc_sdw_utils.c | 2 +-
3 files changed, 16 insertions(+), 18 deletions(-)
diff --git a/include/sound/soc_sdw_utils.h b/include/sound/soc_sdw_utils.h
index 79c21966220b2..443d63dc6ea37 100644
--- a/include/sound/soc_sdw_utils.h
+++ b/include/sound/soc_sdw_utils.h
@@ -44,6 +44,18 @@
struct asoc_sdw_codec_info;
+struct asoc_sdw_mc_private {
+ struct snd_soc_card card;
+ struct snd_soc_jack sdw_headset;
+ struct device *headset_codec_dev; /* only one headset per card */
+ struct device *amp_dev1, *amp_dev2;
+ bool append_dai_type;
+ bool ignore_internal_dmic;
+ void *private;
+ unsigned long mc_quirk;
+ int codec_info_list_count;
+};
+
struct asoc_sdw_dai_info {
const bool direction[2]; /* playback & capture support */
const char *codec_name;
@@ -88,25 +100,13 @@ struct asoc_sdw_codec_info {
int (*codec_card_late_probe)(struct snd_soc_card *card);
- int (*count_sidecar)(struct snd_soc_card *card,
+ int (*count_sidecar)(struct asoc_sdw_mc_private *ctx,
int *num_dais, int *num_devs);
int (*add_sidecar)(struct snd_soc_card *card,
struct snd_soc_dai_link **dai_links,
struct snd_soc_codec_conf **codec_conf);
};
-struct asoc_sdw_mc_private {
- struct snd_soc_card card;
- struct snd_soc_jack sdw_headset;
- struct device *headset_codec_dev; /* only one headset per card */
- struct device *amp_dev1, *amp_dev2;
- bool append_dai_type;
- bool ignore_internal_dmic;
- void *private;
- unsigned long mc_quirk;
- int codec_info_list_count;
-};
-
struct asoc_sdw_endpoint {
struct list_head list;
@@ -235,7 +235,7 @@ int asoc_sdw_es9356_amp_init(struct snd_soc_card *card,
int asoc_sdw_es9356_exit(struct snd_soc_card *card, struct snd_soc_dai_link *dai_link);
/* CS AMP support */
-int asoc_sdw_bridge_cs35l56_count_sidecar(struct snd_soc_card *card,
+int asoc_sdw_bridge_cs35l56_count_sidecar(struct asoc_sdw_mc_private *ctx,
int *num_dais, int *num_devs);
int asoc_sdw_bridge_cs35l56_add_sidecar(struct snd_soc_card *card,
struct snd_soc_dai_link **dai_links,
diff --git a/sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c b/sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c
index e0e32a279787c..129a437ae397e 100644
--- a/sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c
+++ b/sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c
@@ -99,11 +99,9 @@ static const struct snd_soc_dai_link bridge_dai_template = {
SND_SOC_DAILINK_REG(asoc_sdw_bridge_dai),
};
-int asoc_sdw_bridge_cs35l56_count_sidecar(struct snd_soc_card *card,
+int asoc_sdw_bridge_cs35l56_count_sidecar(struct asoc_sdw_mc_private *ctx,
int *num_dais, int *num_devs)
{
- struct asoc_sdw_mc_private *ctx = snd_soc_card_get_drvdata(card);
-
if (ctx->mc_quirk & SOC_SDW_SIDECAR_AMPS) {
(*num_dais)++;
(*num_devs) += ARRAY_SIZE(bridge_cs35l56_name_prefixes);
diff --git a/sound/soc/sdw_utils/soc_sdw_utils.c b/sound/soc/sdw_utils/soc_sdw_utils.c
index ce2a9c28fe1a5..982be8a286133 100644
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -2045,7 +2045,7 @@ int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
ctx->ignore_internal_dmic |= codec_info->ignore_internal_dmic;
if (codec_info->count_sidecar && codec_info->add_sidecar) {
- ret = codec_info->count_sidecar(card, &num_dais, num_devs);
+ ret = codec_info->count_sidecar(ctx, &num_dais, num_devs);
if (ret)
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 148/398] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (146 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 147/398] Bluetooth: hci_qca: Do not write to the serial port after it is closed Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 149/398] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync Greg Kroah-Hartman
` (254 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Upstream commit ca18ee413a7cb6f09885778039225e58bae0d607 ]
iso_get_sock() returns the parent socket with a reference held, which is
dropped by sock_put() once the child socket has been set up. The error
path taken when iso_sock_alloc() fails only calls release_sock() and
returns, leaking the reference and thus the parent socket itself.
Drop the reference on that path as well.
Fixes: fa224d0c094a ("Bluetooth: ISO: Reassociate a socket with an active BIS")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index c30bf48d3858a..83594bb52a14c 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -2160,6 +2160,7 @@ static void iso_conn_ready(struct iso_conn *conn)
BTPROTO_ISO, GFP_ATOMIC, 0);
if (!sk) {
release_sock(parent);
+ sock_put(parent);
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 202/438] ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (200 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 201/438] ASoC: sdw_utils: tidyup .count_sidecar Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 203/438] ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver Greg Kroah-Hartman
` (247 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuninori Morimoto, Cezary Rojewski,
Vijendar Mukunda, Mark Brown, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
[ Upstream commit a1332be2a07090cf422507ec812ce2b9ba0a558a ]
We can avoid to use *card. Tidyup it.
Current code makes old style / new style conversion difficult.
To make future conversions easier to understand, this patch clean up the
code a little. but no functional change.
Signed-off-by: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Reviewed-by: Cezary Rojewski <cezary.rojewski@intel.com>
Reviewed-by: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
Link: https://patch.msgid.link/87ik75etxw.wl-kuninori.morimoto.gx@renesas.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 0b7d55d3a912 ("ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc_sdw_utils.h | 3 ++-
sound/soc/amd/acp/acp-sdw-legacy-mach.c | 2 +-
sound/soc/amd/acp/acp-sdw-sof-mach.c | 2 +-
sound/soc/intel/boards/sof_sdw.c | 2 +-
sound/soc/sdw_utils/soc_sdw_utils.c | 5 ++---
5 files changed, 7 insertions(+), 7 deletions(-)
diff --git a/include/sound/soc_sdw_utils.h b/include/sound/soc_sdw_utils.h
index 443d63dc6ea37..9b28e9aef4f1d 100644
--- a/include/sound/soc_sdw_utils.h
+++ b/include/sound/soc_sdw_utils.h
@@ -182,7 +182,8 @@ struct asoc_sdw_dailink *asoc_sdw_find_dailink(struct asoc_sdw_dailink *dailinks
const struct snd_soc_acpi_endpoint *new);
int asoc_sdw_get_dai_type(u32 type);
-int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
+int asoc_sdw_parse_sdw_endpoints(struct device *dev,
+ struct asoc_sdw_mc_private *ctx,
struct snd_soc_aux_dev *soc_aux,
struct asoc_sdw_dailink *soc_dais,
struct asoc_sdw_endpoint *soc_ends,
diff --git a/sound/soc/amd/acp/acp-sdw-legacy-mach.c b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
index 1a6be664be279..fa31bb848d9df 100644
--- a/sound/soc/amd/acp/acp-sdw-legacy-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
@@ -442,7 +442,7 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
if (!soc_aux)
return -ENOMEM;
- ret = asoc_sdw_parse_sdw_endpoints(card, soc_aux, soc_dais, soc_ends, &num_confs);
+ ret = asoc_sdw_parse_sdw_endpoints(dev, ctx, soc_aux, soc_dais, soc_ends, &num_confs);
if (ret < 0)
return ret;
diff --git a/sound/soc/amd/acp/acp-sdw-sof-mach.c b/sound/soc/amd/acp/acp-sdw-sof-mach.c
index f66228435984a..5d0818ca918a0 100644
--- a/sound/soc/amd/acp/acp-sdw-sof-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-sof-mach.c
@@ -312,7 +312,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
if (!sof_aux)
return -ENOMEM;
- ret = asoc_sdw_parse_sdw_endpoints(card, sof_aux, sof_dais, sof_ends, &num_devs);
+ ret = asoc_sdw_parse_sdw_endpoints(dev, ctx, sof_aux, sof_dais, sof_ends, &num_devs);
if (ret < 0)
return ret;
diff --git a/sound/soc/intel/boards/sof_sdw.c b/sound/soc/intel/boards/sof_sdw.c
index c527d575d1ed6..1013e07052a37 100644
--- a/sound/soc/intel/boards/sof_sdw.c
+++ b/sound/soc/intel/boards/sof_sdw.c
@@ -1288,7 +1288,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
goto err_dai;
}
- ret = asoc_sdw_parse_sdw_endpoints(card, sof_aux, sof_dais, sof_ends, &num_confs);
+ ret = asoc_sdw_parse_sdw_endpoints(dev, ctx, sof_aux, sof_dais, sof_ends, &num_confs);
if (ret < 0)
goto err_end;
diff --git a/sound/soc/sdw_utils/soc_sdw_utils.c b/sound/soc/sdw_utils/soc_sdw_utils.c
index 982be8a286133..befcad08135e7 100644
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -1976,14 +1976,13 @@ static int is_sdca_endpoint_present(struct device *dev,
return ret;
}
-int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
+int asoc_sdw_parse_sdw_endpoints(struct device *dev,
+ struct asoc_sdw_mc_private *ctx,
struct snd_soc_aux_dev *soc_aux,
struct asoc_sdw_dailink *soc_dais,
struct asoc_sdw_endpoint *soc_ends,
int *num_devs)
{
- struct device *dev = card->dev;
- struct asoc_sdw_mc_private *ctx = snd_soc_card_get_drvdata(card);
struct snd_soc_acpi_mach *mach = dev_get_platdata(dev);
struct snd_soc_acpi_mach_params *mach_params = &mach->mach_params;
const struct snd_soc_acpi_link_adr *adr_link;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 149/398] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (147 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 148/398] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 150/398] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events Greg Kroah-Hartman
` (253 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
[ Upstream commit 296e7f3c5071cc02dc22e1566e759179fa1792ae ]
A BIS connection is matched to its parent socket by looking for a
socket in BT_LISTEN state with the same BIG handle:
iso_conn_ready()
if (test_bit(HCI_CONN_BIG_SYNC, &hcon->flags))
parent = iso_get_sock(hdev, &hcon->src, &hcon->dst,
BT_LISTEN, iso_match_big_hcon, hcon);
The socket was only moved to BT_LISTEN after iso_conn_big_sync()
returned, while the LE BIG Create Sync command has already been queued
by then. If the BIG sync is established before the state is updated,
which is easy to hit with an emulated controller as the command may
complete in a few hundred microseconds, no parent is found and the BIS
connections are never notified to the listening socket.
The user space is then left waiting for connections that never arrive,
e.g. bluetoothd never completes a MediaTransport1.Acquire of a
Broadcast Sink transport.
Move the socket to BT_LISTEN before requesting the BIG sync, so the
state is visible by the time the command is queued, and restore the
previous state if the request could not be started. Since the socket is
briefly visible as a listening socket, child sockets may have been
queued in the meantime, so drain the accept queue before restoring the
state: the cleanup paths of BT_CONNECT2/BT_CONNECTED don't do it and the
children would be left with a dangling parent pointer.
Fixes: fbdc4bc47268 ("Bluetooth: ISO: Use defer setup to separate PA sync and BIG sync")
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/iso.c | 52 +++++++++++++++++++++++++++++++++++----------
1 file changed, 41 insertions(+), 11 deletions(-)
diff --git a/net/bluetooth/iso.c b/net/bluetooth/iso.c
index 83594bb52a14c..14f821aa8ac41 100644
--- a/net/bluetooth/iso.c
+++ b/net/bluetooth/iso.c
@@ -764,19 +764,24 @@ static void iso_sock_destruct(struct sock *sk)
skb_queue_purge(&sk->sk_error_queue);
}
-static void iso_sock_cleanup_listen(struct sock *parent)
+/* Close not yet accepted channels */
+static void iso_sock_flush_accept_q(struct sock *parent)
{
struct sock *sk;
- BT_DBG("parent %p", parent);
-
- /* Close not yet accepted channels */
while ((sk = bt_accept_dequeue(parent, NULL))) {
iso_sock_close(sk);
iso_sock_kill(sk);
/* Drop the reference handed back by bt_accept_dequeue(). */
sock_put(sk);
}
+}
+
+static void iso_sock_cleanup_listen(struct sock *parent)
+{
+ BT_DBG("parent %p", parent);
+
+ iso_sock_flush_accept_q(parent);
/* If listening socket has a hcon, properly disconnect it */
if (iso_pi(parent)->conn && iso_pi(parent)->conn->hcon) {
@@ -1616,6 +1621,13 @@ static int iso_sock_recvmsg(struct socket *sock, struct msghdr *msg,
switch (sk->sk_state) {
case BT_CONNECT2:
if (test_bit(BT_SK_PA_SYNC, &pi->flags)) {
+ /* Move to BT_LISTEN before requesting the BIG
+ * sync: the BIS connections are matched to a
+ * parent socket in BT_LISTEN state, and they
+ * may be notified before the request returns.
+ */
+ sk->sk_state = BT_LISTEN;
+
release_sock(sk);
err = iso_conn_big_sync(sk);
lock_sock(sk);
@@ -1624,12 +1636,20 @@ static int iso_sock_recvmsg(struct socket *sock, struct msghdr *msg,
* connection may have been torn down
* meanwhile and iso_chan_del() may have
* already moved the socket to BT_CLOSED.
- * Only move on to BT_LISTEN if the BIG sync
- * was actually started and nothing else has
- * changed the state.
+ * Only move back if the BIG sync could not be
+ * started and nothing else has changed the
+ * state.
*/
- if (!err && sk->sk_state == BT_CONNECT2)
- sk->sk_state = BT_LISTEN;
+ if (err && sk->sk_state == BT_LISTEN) {
+ /* Discard any child socket that may
+ * have been queued while the socket
+ * was in BT_LISTEN, as the cleanup of
+ * BT_CONNECT2 doesn't drain the
+ * accept queue.
+ */
+ iso_sock_flush_accept_q(sk);
+ sk->sk_state = BT_CONNECT2;
+ }
} else {
iso_conn_defer_accept(pi->conn->hcon);
sk->sk_state = BT_CONFIG;
@@ -1639,12 +1659,22 @@ static int iso_sock_recvmsg(struct socket *sock, struct msghdr *msg,
break;
case BT_CONNECTED:
if (test_bit(BT_SK_PA_SYNC, &iso_pi(sk)->flags)) {
+ /* As above, the BIS connections may be
+ * notified before the request returns.
+ */
+ sk->sk_state = BT_LISTEN;
+
release_sock(sk);
err = iso_conn_big_sync(sk);
lock_sock(sk);
- if (!err && sk->sk_state == BT_CONNECTED)
- sk->sk_state = BT_LISTEN;
+ if (err && sk->sk_state == BT_LISTEN) {
+ /* As above, don't leave any child
+ * socket behind in the accept queue.
+ */
+ iso_sock_flush_accept_q(sk);
+ sk->sk_state = BT_CONNECTED;
+ }
early_ret = true;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 203/438] ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (201 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 202/438] ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 204/438] ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID Greg Kroah-Hartman
` (246 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vijendar Mukunda,
Mario Limonciello (AMD), Mark Brown, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
[ Upstream commit 0b7d55d3a91200f2b1ed710f525a944b0a7d6369 ]
num_devs was used both as the endpoint count and as the output for
asoc_sdw_parse_sdw_endpoints(), which overwrites it with the codec
configuration count. Introduce a separate num_confs variable to hold
the codec conf count so the two values remain distinct across
codec_conf allocation and card->num_configs assignment.
Fixes: 6d8348ddc56e ("ASoC: amd: acp: refactor SoundWire machine driver code")
Signed-off-by: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Link: https://patch.msgid.link/20260910161728.1452808-3-Vijendar.Mukunda@amd.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/amd/acp/acp-sdw-sof-mach.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/sound/soc/amd/acp/acp-sdw-sof-mach.c b/sound/soc/amd/acp/acp-sdw-sof-mach.c
index 5d0818ca918a0..f58ef8953dbc2 100644
--- a/sound/soc/amd/acp/acp-sdw-sof-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-sof-mach.c
@@ -286,6 +286,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
int num_devs = 0;
int num_ends = 0;
int num_aux = 0;
+ int num_confs;
int num_links;
int be_id = 0;
int ret;
@@ -296,6 +297,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
return ret;
}
+ num_confs = num_ends;
/* One per DAI link, worst case is a DAI link for every endpoint */
struct asoc_sdw_dailink *sof_dais __free(kfree) =
kzalloc_objs(*sof_dais, num_ends);
@@ -312,7 +314,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
if (!sof_aux)
return -ENOMEM;
- ret = asoc_sdw_parse_sdw_endpoints(dev, ctx, sof_aux, sof_dais, sof_ends, &num_devs);
+ ret = asoc_sdw_parse_sdw_endpoints(dev, ctx, sof_aux, sof_dais, sof_ends, &num_confs);
if (ret < 0)
return ret;
@@ -324,7 +326,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
dev_dbg(dev, "sdw %d, dmic %d", sdw_be_num, dmic_num);
- codec_conf = devm_kcalloc(dev, num_devs, sizeof(*codec_conf), GFP_KERNEL);
+ codec_conf = devm_kcalloc(dev, num_confs, sizeof(*codec_conf), GFP_KERNEL);
if (!codec_conf)
return -ENOMEM;
@@ -335,7 +337,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
return -ENOMEM;
card->codec_conf = codec_conf;
- card->num_configs = num_devs;
+ card->num_configs = num_confs;
card->dai_link = dai_links;
card->num_links = num_links;
card->aux_dev = sof_aux;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 150/398] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (148 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 149/398] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 151/398] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown Greg Kroah-Hartman
` (252 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chris Lu, Luiz Augusto von Dentz,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Lu <chris.lu@mediatek.com>
[ Upstream commit 78b6abd6c7a7591aacdae657f813214dae4fcd3b ]
A too-short BTMTK_WMT_FUNC_CTRL event (WMT header only, no trailing
2-byte status word) is always treated as BTMTK_WMT_ON_UNDONE. This
short form is how firmware acks a plain enable/disable request, and
the actual result is carried in the header's own flag byte (0 =
success), not a separate status word. Decode it from there instead of
assuming failure.
Verified setup on MT7920, MT7921, MT7922 and MT7925: no regression.
Fixes: e3ac0d9f1a20 ("Bluetooth: btmtk: accept too short WMT FUNC_CTRL events")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Chris Lu <chris.lu@mediatek.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btmtk.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btmtk.c b/drivers/bluetooth/btmtk.c
index d1817dd6ab650..c525e2685a861 100644
--- a/drivers/bluetooth/btmtk.c
+++ b/drivers/bluetooth/btmtk.c
@@ -709,7 +709,12 @@ static int btmtk_usb_hci_wmt_sync(struct hci_dev *hdev,
case BTMTK_WMT_FUNC_CTRL:
if (!skb_pull_data(data->evt_skb,
sizeof(wmt_evt_funcc->status))) {
- status = BTMTK_WMT_ON_UNDONE;
+ /* A plain enable/disable request is acked with just
+ * the WMT header and no trailing status word; the
+ * result is carried in the header's own flag byte.
+ */
+ status = wmt_evt->whdr.flag ? BTMTK_WMT_ON_UNDONE :
+ BTMTK_WMT_ON_DONE;
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 204/438] ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (202 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 203/438] ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 205/438] net/sched: codel: bound the dropping loop per dequeue call Greg Kroah-Hartman
` (245 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vijendar Mukunda,
Mario Limonciello (AMD), Mark Brown, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
[ Upstream commit 27098aaf28b96ab4e6891709062c343566d4882b ]
ffs(link_mask - 1) computes ffs on (link_mask - 1) instead of
subtracting 1 from the result of ffs(link_mask). For a typical
power-of-2 link_mask this returns the wrong link ID, causing cpu_pin_id
lookup to select the incorrect SoundWire manager.
Fix the operator precedence to ffs(link_mask) - 1 in both
acp-sdw-sof-mach.c and acp-sdw-legacy-mach.c.
Fixes: 6d8348ddc56e ("ASoC: amd: acp: refactor SoundWire machine driver code")
Signed-off-by: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Link: https://patch.msgid.link/20260910161728.1452808-4-Vijendar.Mukunda@amd.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/amd/acp/acp-sdw-legacy-mach.c | 4 ++--
sound/soc/amd/acp/acp-sdw-sof-mach.c | 4 ++--
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/sound/soc/amd/acp/acp-sdw-legacy-mach.c b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
index fa31bb848d9df..9e3d5d3ed1d75 100644
--- a/sound/soc/amd/acp/acp-sdw-legacy-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
@@ -217,7 +217,7 @@ static int create_sdw_dailink(struct snd_soc_card *card,
switch (amd_ctx->acp_rev) {
case ACP63_PCI_REV:
- ret = get_acp63_cpu_pin_id(ffs(soc_end->link_mask - 1),
+ ret = get_acp63_cpu_pin_id(ffs(soc_end->link_mask) - 1,
*be_id, &cpu_pin_id, dev);
if (ret)
return ret;
@@ -225,7 +225,7 @@ static int create_sdw_dailink(struct snd_soc_card *card,
case ACP70_PCI_REV:
case ACP71_PCI_REV:
case ACP72_PCI_REV:
- ret = get_acp70_cpu_pin_id(ffs(soc_end->link_mask - 1),
+ ret = get_acp70_cpu_pin_id(ffs(soc_end->link_mask) - 1,
*be_id, &cpu_pin_id, dev);
if (ret)
return ret;
diff --git a/sound/soc/amd/acp/acp-sdw-sof-mach.c b/sound/soc/amd/acp/acp-sdw-sof-mach.c
index f58ef8953dbc2..13885ca20168b 100644
--- a/sound/soc/amd/acp/acp-sdw-sof-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-sof-mach.c
@@ -132,7 +132,7 @@ static int create_sdw_dailink(struct snd_soc_card *card,
}
switch (amd_ctx->acp_rev) {
case ACP63_PCI_REV:
- ret = get_acp63_cpu_pin_id(ffs(sof_end->link_mask - 1),
+ ret = get_acp63_cpu_pin_id(ffs(sof_end->link_mask) - 1,
*be_id, &cpu_pin_id, dev);
if (ret)
return ret;
@@ -140,7 +140,7 @@ static int create_sdw_dailink(struct snd_soc_card *card,
case ACP70_PCI_REV:
case ACP71_PCI_REV:
case ACP72_PCI_REV:
- ret = get_acp70_cpu_pin_id(ffs(sof_end->link_mask - 1),
+ ret = get_acp70_cpu_pin_id(ffs(sof_end->link_mask) - 1,
*be_id, &cpu_pin_id, dev);
if (ret)
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 151/398] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (149 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 150/398] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 152/398] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit Greg Kroah-Hartman
` (251 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih,
Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit 7b60ee5f46f2ee329de661f7c68b6818d8136220 ]
In btmtksdio_shutdown(), pm_runtime_get_sync() is called at the
beginning of the function. However, if sending the WMT function
control command fails later, the driver returns early.
It bypasses the corresponding pm_runtime_put_noidle() and
pm_runtime_disable() calls, leaking the PM usage counter and leaving PM
runtime enabled indefinitely.
Fall through to execute the PM runtime cleanup block even if WMT errors.
Fixes: 7f3c563c575e ("Bluetooth: btmtksdio: Add runtime PM support to SDIO based Bluetooth")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btmtksdio.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/bluetooth/btmtksdio.c b/drivers/bluetooth/btmtksdio.c
index f7dcabc11b859..a9ca2d37b8c5a 100644
--- a/drivers/bluetooth/btmtksdio.c
+++ b/drivers/bluetooth/btmtksdio.c
@@ -1245,10 +1245,8 @@ static int btmtksdio_shutdown(struct hci_dev *hdev)
wmt_params.status = NULL;
err = mtk_hci_wmt_sync(hdev, &wmt_params);
- if (err < 0) {
+ if (err < 0)
bt_dev_err(hdev, "Failed to send wmt func ctrl (%d)", err);
- return err;
- }
ignore_wmt_cmd:
pm_runtime_put_noidle(bdev->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 205/438] net/sched: codel: bound the dropping loop per dequeue call
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (203 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 204/438] ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 206/438] net: do not advance stack index from dev_fwd_path() Greg Kroah-Hartman
` (244 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Eric Dumazet, Victor Nogueira,
Jamal Hadi Salim, Toke Høiland-Jørgensen,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
[ Upstream commit 7f4a5ec6258fd7c92633ec4b0493fc51166d9398 ]
The CoDel control law schedules the next drop one interval/sqrt(count)
after the previous drop, using the configured interval
(codel_params.interval). For very small intervals the scheduled step
rounds down to zero, so the dropping loop in codel_dequeue() never
advances and drains the entire backlog under the qdisc lock in one
call - an unprivileged user can trigger a soft lockup this way.
Fix in the shared codel code used by both codel and fq_codel:
1. Make the control-law step at least 1 tick so the dropping loop
always moves forward.
2. Cap the dropping loop at CODEL_MAX_DROPS_PER_DEQUEUE (256) drops
per codel_dequeue() call, resyncing drop_next to now when the cap
is hit: the catch-up owed to the loop grows with the idle gap and
the backlog, which no interval threshold can bound. This is a
deliberate behaviour change after long idle gaps.
The cap applies to fq_codel (4b549a2ef4be) and the mac80211 TXQ path
(fixed interval, cap only).
The target sojourn delay (codel_params.target) is not validated: it
does not feed the control law, so a sub-tick value is aggressive
rather than deadlock-prone.
Conditions to recreate the bug:
- tc qdisc add dev lo root handle 1: tbf rate 1kbit burst 2kb limit 1000000
- tc qdisc add dev lo parent 1:1 handle 10: codel interval 2us target 1ms noecn limit 1000000 (same for fq_codel)
- unpatched kernel: tc accepts it; a UDP flood under the 1kbit tbf
soft-lockups (watchdog: BUG: soft lockup) while one
codel_dequeue() call drops the backlog under the qdisc lock
- patched kernel: same setup, at most 256 drops per dequeue call,
no soft lockup
Testing: claim reproducer and interval 2us/3us variants run clean;
tdc qdisc category passes (see the selftests patch).
Fixes: 76e3cc126bb2 ("codel: Controlled Delay AQM")
Reported-by: Vega <vega@nebusec.ai>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Reviewed-by: Toke Høiland-Jørgensen <toke@toke.dk>
Link: https://patch.msgid.link/QDISC-1L5H.v1.20260912080102@mojatatu.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/codel.h | 5 +++++
include/net/codel_impl.h | 16 +++++++++++++++-
2 files changed, 20 insertions(+), 1 deletion(-)
diff --git a/include/net/codel.h b/include/net/codel.h
index aa80f744826cd..183d43c2bd434 100644
--- a/include/net/codel.h
+++ b/include/net/codel.h
@@ -140,6 +140,11 @@ struct codel_vars {
/* needed shift to get a Q0.32 number from rec_inv_sqrt */
#define REC_INV_SQRT_SHIFT (32 - REC_INV_SQRT_BITS)
+/* Cap on drops per codel_dequeue() call: the loop's work depends on the
+ * idle gap and backlog, both outside our control; resync when exceeded.
+ */
+#define CODEL_MAX_DROPS_PER_DEQUEUE 256
+
/**
* struct codel_stats - contains codel shared variables and stats
* @maxpacket: largest packet we've seen so far
diff --git a/include/net/codel_impl.h b/include/net/codel_impl.h
index 2c1f0ec309e9f..8f26132d45b7f 100644
--- a/include/net/codel_impl.h
+++ b/include/net/codel_impl.h
@@ -93,12 +93,17 @@ static void codel_Newton_step(struct codel_vars *vars)
* CoDel control_law is t + interval/sqrt(count)
* We maintain in rec_inv_sqrt the reciprocal value of sqrt(count) to avoid
* both sqrt() and divide operation.
+ *
+ * Clamp the increment to at least 1 tick: a very small interval (or a
+ * large count) can truncate it to zero, stalling the dropping loop.
*/
static codel_time_t codel_control_law(codel_time_t t,
codel_time_t interval,
u32 rec_inv_sqrt)
{
- return t + reciprocal_scale(interval, rec_inv_sqrt << REC_INV_SQRT_SHIFT);
+ return t + max_t(u32, 1,
+ reciprocal_scale(interval,
+ rec_inv_sqrt << REC_INV_SQRT_SHIFT));
}
static bool codel_should_drop(const struct sk_buff *skb,
@@ -154,6 +159,7 @@ static struct sk_buff *codel_dequeue(void *ctx,
codel_skb_dequeue_t dequeue_func)
{
struct sk_buff *skb = dequeue_func(vars, ctx);
+ unsigned int drops = 0;
codel_time_t now;
bool drop;
@@ -180,6 +186,14 @@ static struct sk_buff *codel_dequeue(void *ctx,
*/
while (vars->dropping &&
codel_time_after_eq(now, vars->drop_next)) {
+ if (++drops > CODEL_MAX_DROPS_PER_DEQUEUE) {
+ /* fell far behind the schedule */
+ WRITE_ONCE(vars->drop_next,
+ codel_control_law(now,
+ params->interval,
+ vars->rec_inv_sqrt));
+ break;
+ }
/* dont care of possible wrap
* since there is no more divide.
*/
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 152/398] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (150 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 151/398] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 153/398] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup Greg Kroah-Hartman
` (250 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sai Teja Aluvala,
Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sai Teja Aluvala <aluvala.sai.teja@intel.com>
[ Upstream commit 2ea5a87a5a7ae58cb2662b8a7d06f209383e1765 ]
btintel_pcie_submit_rx() used frbd_index > rxq->count to guard the
FRBD array access, allowing frbd_index == rxq->count to pass through
and index one element past the end of the array. Change the check to
>= rxq->count so every out-of-range index is rejected.
This issue was reported by Claude Mythos.
Fixes: c2b636b3f788 (Bluetooth: btintel_pcie: Add support for PCIe transport)
Signed-off-by: Sai Teja Aluvala <aluvala.sai.teja@intel.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btintel_pcie.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c
index 90494871e0d37..8d3129aa2a1a3 100644
--- a/drivers/bluetooth/btintel_pcie.c
+++ b/drivers/bluetooth/btintel_pcie.c
@@ -465,7 +465,7 @@ static int btintel_pcie_submit_rx(struct btintel_pcie_data *data)
frbd_index = data->ia.tr_hia[BTINTEL_PCIE_RXQ_NUM];
- if (frbd_index > rxq->count)
+ if (frbd_index >= rxq->count)
return -ERANGE;
/* Prepare for RX submit. It updates the FRBD with the address of DMA
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 206/438] net: do not advance stack index from dev_fwd_path()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (204 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 205/438] net/sched: codel: bound the dropping loop per dequeue call Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 207/438] net: pass dst via net_device_path in dev_fill_forward_path() Greg Kroah-Hartman
` (243 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Pablo Neira Ayuso,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit 5deda60c56eeeab25beb10cf4d48e07587076b11 ]
Update stack index from dev_fill_forward_path() instead, once the
forward path slot has been populated.
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Stable-dep-of: 150dba2c69e9 ("net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/dev.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/net/core/dev.c b/net/core/dev.c
index 74dd9e25f4ff7..e68463e7310a0 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -742,12 +742,10 @@ EXPORT_SYMBOL_GPL(dev_fill_metadata_dst);
static struct net_device_path *dev_fwd_path(struct net_device_path_stack *stack)
{
- int k = stack->num_paths++;
-
- if (k >= NET_DEVICE_PATH_STACK_MAX)
+ if (stack->num_paths + 1 > NET_DEVICE_PATH_STACK_MAX)
return NULL;
- return &stack->path[k];
+ return &stack->path[stack->num_paths];
}
int dev_fill_forward_path(const struct net_device *dev, const u8 *daddr,
@@ -773,6 +771,7 @@ int dev_fill_forward_path(const struct net_device *dev, const u8 *daddr,
if (ret < 0)
return -1;
+ stack->num_paths++;
if (WARN_ON_ONCE(last_dev == ctx.dev))
return -1;
}
@@ -785,6 +784,7 @@ int dev_fill_forward_path(const struct net_device *dev, const u8 *daddr,
return -1;
path->type = DEV_PATH_ETHERNET;
path->dev = ctx.dev;
+ stack->num_paths++;
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 153/398] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (151 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 152/398] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 154/398] af_unix: Unify scc_index when finalising SCC in __unix_walk_scc() Greg Kroah-Hartman
` (249 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+0cece8fa7d83523f47a3,
Juan Perdomo, Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Juan Perdomo <jcperdomo100@gmail.com>
[ Upstream commit 801fb950cae7048eb7d83b18857d1ca37b8cd5a4 ]
rfcomm_sock_cleanup_listen() closes unaccepted child sockets through
rfcomm_sock_close(), which takes the child socket lock before
rfcomm_dlc_close() acquires rfcomm_mutex. The RFCOMM worker takes these
locks in reverse order while handling connections and DLC state changes,
so lockdep reports a possible deadlock.
Close dequeued children without taking their socket lock. The accept queue
owns a reference to each child, and bt_accept_dequeue() locks the child
while unlinking it and clearing its parent pointer.
Dropping the child lock makes it important to prevent a concurrent
rfcomm_connect_ind() from enqueueing a new child after cleanup observes an
empty queue. Set a listening socket to BT_CLOSED while its lock is still
held, before dropping the lock and draining the queue. The state check in
rfcomm_connect_ind() then rejects new children once cleanup starts.
Reported-by: syzbot+0cece8fa7d83523f47a3@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0cece8fa7d83523f47a3
Fixes: b7ce436a5d79 ("Bluetooth: switch to lock_sock in RFCOMM")
Signed-off-by: Juan Perdomo <jcperdomo100@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/bluetooth/rfcomm/sock.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/net/bluetooth/rfcomm/sock.c b/net/bluetooth/rfcomm/sock.c
index 2286efef62f5b..037a7fcab3023 100644
--- a/net/bluetooth/rfcomm/sock.c
+++ b/net/bluetooth/rfcomm/sock.c
@@ -243,9 +243,7 @@ static void __rfcomm_sock_close(struct sock *sk)
*/
static void rfcomm_sock_close(struct sock *sk)
{
- lock_sock(sk);
__rfcomm_sock_close(sk);
- release_sock(sk);
}
static void rfcomm_sock_init(struct sock *sk, struct sock *parent)
@@ -902,6 +900,7 @@ static int rfcomm_sock_compat_ioctl(struct socket *sock, unsigned int cmd, unsig
static int rfcomm_sock_shutdown(struct socket *sock, int how)
{
struct sock *sk = sock->sk;
+ bool cleanup_listen = false;
int err = 0;
BT_DBG("sock %p, sk %p", sock, sk);
@@ -912,9 +911,17 @@ static int rfcomm_sock_shutdown(struct socket *sock, int how)
lock_sock(sk);
if (!sk->sk_shutdown) {
sk->sk_shutdown = SHUTDOWN_MASK;
+ if (sk->sk_state == BT_LISTEN) {
+ /* Block new children before cleaning up without sk lock. */
+ sk->sk_state = BT_CLOSED;
+ cleanup_listen = true;
+ }
release_sock(sk);
- __rfcomm_sock_close(sk);
+ if (cleanup_listen)
+ rfcomm_sock_cleanup_listen(sk);
+ else
+ __rfcomm_sock_close(sk);
lock_sock(sk);
if (sock_flag(sk, SOCK_LINGER) && sk->sk_lingertime &&
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 207/438] net: pass dst via net_device_path in dev_fill_forward_path()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (205 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 206/438] net: do not advance stack index from dev_fwd_path() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 208/438] net: pass net_device_path_ctx to dev_fill_forward_path() Greg Kroah-Hartman
` (242 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Pablo Neira Ayuso,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pablo Neira Ayuso <pablo@netfilter.org>
[ Upstream commit 0ad8404e776698de4dac5cc0df3be68d344e741c ]
Add dst_entry to tunnel device path, this will allow us to remove
a duplicated route lookup.
This is a preparation patch to retrieve the tunnel route directly
from the .fill_forward_path. This new dst_entry in the tunnel will be
used by a follow up patch.
Since dst_release() works fine on NULL interface, this is still
noop until the flowtable starts using this.
Add a new dev_fill_forward_path_release() function to drop the refcount
on the tunnel device route and use it in case of error out. Export it so
to drop the refcount on the tunnel route at a later stage.
Adjust existing drivers that recycle dev_fill_forward_path() to call
dev_fill_forward_path_release() for safety reasons.
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Stable-dep-of: 150dba2c69e9 ("net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/airoha/airoha_ppe.c | 10 ++++--
.../net/ethernet/mediatek/mtk_ppe_offload.c | 10 ++++--
include/linux/netdevice.h | 2 ++
net/core/dev.c | 36 ++++++++++++++++---
4 files changed, 47 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ethernet/airoha/airoha_ppe.c b/drivers/net/ethernet/airoha/airoha_ppe.c
index f6396925722d0..c8fd95e800937 100644
--- a/drivers/net/ethernet/airoha/airoha_ppe.c
+++ b/drivers/net/ethernet/airoha/airoha_ppe.c
@@ -293,14 +293,18 @@ static int airoha_ppe_get_wdma_info(struct net_device *dev, const u8 *addr,
return err;
path = &stack.path[stack.num_paths - 1];
- if (path->type != DEV_PATH_MTK_WDMA)
- return -EINVAL;
+ if (path->type != DEV_PATH_MTK_WDMA) {
+ err = -EINVAL;
+ goto err_out;
+ }
info->idx = path->mtk_wdma.wdma_idx;
info->bss = path->mtk_wdma.bss;
info->wcid = path->mtk_wdma.wcid;
+err_out:
+ dev_fill_forward_path_release(&stack);
- return 0;
+ return err;
}
static int airoha_get_dsa_port(struct net_device **dev)
diff --git a/drivers/net/ethernet/mediatek/mtk_ppe_offload.c b/drivers/net/ethernet/mediatek/mtk_ppe_offload.c
index cc8c4ef8038f3..771d9118f94ad 100644
--- a/drivers/net/ethernet/mediatek/mtk_ppe_offload.c
+++ b/drivers/net/ethernet/mediatek/mtk_ppe_offload.c
@@ -108,16 +108,20 @@ mtk_flow_get_wdma_info(struct net_device *dev, const u8 *addr, struct mtk_wdma_i
return err;
path = &stack.path[stack.num_paths - 1];
- if (path->type != DEV_PATH_MTK_WDMA)
- return -1;
+ if (path->type != DEV_PATH_MTK_WDMA) {
+ err = -EINVAL;
+ goto err_out;
+ }
info->wdma_idx = path->mtk_wdma.wdma_idx;
info->queue = path->mtk_wdma.queue;
info->bss = path->mtk_wdma.bss;
info->wcid = path->mtk_wdma.wcid;
info->amsdu = path->mtk_wdma.amsdu;
+err_out:
+ dev_fill_forward_path_release(&stack);
- return 0;
+ return err;
}
diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h
index 8840b126979ff..d325027b03705 100644
--- a/include/linux/netdevice.h
+++ b/include/linux/netdevice.h
@@ -894,6 +894,7 @@ struct net_device_path {
u8 h_dest[ETH_ALEN];
} encap;
struct {
+ struct dst_entry *dst;
union {
struct in_addr src_v4;
struct in6_addr src_v6;
@@ -3424,6 +3425,7 @@ int dev_get_iflink(const struct net_device *dev);
int dev_fill_metadata_dst(struct net_device *dev, struct sk_buff *skb);
int dev_fill_forward_path(const struct net_device *dev, const u8 *daddr,
struct net_device_path_stack *stack);
+void dev_fill_forward_path_release(struct net_device_path_stack *stack);
struct net_device *dev_get_by_name(struct net *net, const char *name);
struct net_device *dev_get_by_name_rcu(struct net *net, const char *name);
struct net_device *__dev_get_by_name(struct net *net, const char *name);
diff --git a/net/core/dev.c b/net/core/dev.c
index e68463e7310a0..2b493f4c2f0cb 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -748,6 +748,27 @@ static struct net_device_path *dev_fwd_path(struct net_device_path_stack *stack)
return &stack->path[stack->num_paths];
}
+void dev_fill_forward_path_release(struct net_device_path_stack *stack)
+{
+ struct net_device_path *path;
+ int k;
+
+ if (stack->num_paths == 0)
+ return;
+
+ for (k = stack->num_paths - 1; k >= 0; k--) {
+ path = &stack->path[k];
+ switch (path->type) {
+ case DEV_PATH_TUN:
+ dst_release(path->tun.dst);
+ break;
+ default:
+ break;
+ }
+ }
+}
+EXPORT_SYMBOL_GPL(dev_fill_forward_path_release);
+
int dev_fill_forward_path(const struct net_device *dev, const u8 *daddr,
struct net_device_path_stack *stack)
{
@@ -764,16 +785,16 @@ int dev_fill_forward_path(const struct net_device *dev, const u8 *daddr,
last_dev = ctx.dev;
path = dev_fwd_path(stack);
if (!path)
- return -1;
+ goto err_out;
memset(path, 0, sizeof(struct net_device_path));
ret = ctx.dev->netdev_ops->ndo_fill_forward_path(&ctx, path);
if (ret < 0)
- return -1;
+ goto err_out;
stack->num_paths++;
if (WARN_ON_ONCE(last_dev == ctx.dev))
- return -1;
+ goto err_out;
}
if (!ctx.dev)
@@ -781,12 +802,17 @@ int dev_fill_forward_path(const struct net_device *dev, const u8 *daddr,
path = dev_fwd_path(stack);
if (!path)
- return -1;
+ goto err_out;
+
path->type = DEV_PATH_ETHERNET;
path->dev = ctx.dev;
stack->num_paths++;
- return ret;
+ return 0;
+err_out:
+ dev_fill_forward_path_release(stack);
+
+ return -1;
}
EXPORT_SYMBOL_GPL(dev_fill_forward_path);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 154/398] af_unix: Unify scc_index when finalising SCC in __unix_walk_scc().
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (152 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 153/398] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 155/398] pppoatm: ensure a writable skb header and linear data Greg Kroah-Hartman
` (248 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Burton, Kuniyuki Iwashima,
Simon Horman, Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuniyuki Iwashima <kuniyu@google.com>
[ Upstream commit 4a4263dfeabad72f95e8ab6e15146861fa4144dd ]
Commit bfdb01283ee8 ("af_unix: Assign a unique index to SCC.")
changed Tarjan's algorithm to update lowlink with lowlink,
which is called lowpoint (unix_vertex.scc_index).
unix_vertex_dead() assumes all vertices in an SCC share the same
lowpoint, but this is not always true if an SCC has two or more
back edges, depending on the order of DFS.
For example, the graph below has two back edges from B to A
and from C to B.
A --> B --> C
^ | ^ |
`----' `----'
If DFS walks through A -> B -> C -> B (-> C -> B) -> A (-> B -> A),
each index and scc_index will be updated as follows.
A --> B --> C C = (3, 3) (index, scc_index)
B = (2, 2)
A = (1, 1)
A ... B ... C C = (3, 2)<-.
^ | B = (2, 2) -'
`----' A = (1, 1)
A ... B ... C C = (3, 2)
^ | . . B = (2, 1)<-.
`----' .... A = (1, 1) -'
Then, unix_vertex_dead() thinks that B is passed to another
SCC with scc_index 2, and the SCC is not garbage-collected.
This does not happen if DFS walks in a different order below
or starts from B.
1 3
A --> B --> C
^ | ^ |
`----' `----'
2 4
Let's unify scc_index across the SCC when finalising it.
Note that updating v->index was previously done in unix_scc_dead(),
when called from __unix_walk_scc(), just to save one loop. Since
__unix_walk_scc() now iterates over the SCC anyway, the update is
moved back to __unix_walk_scc() and 'fast' argument is dropped.
Fixes: 4090fa373f0e ("af_unix: Replace garbage collection algorithm.")
Reported-by: James Burton <jamesburton@meta.com>
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260912030852.1467872-2-kuniyu@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/unix/garbage.c | 17 ++++++++++-------
1 file changed, 10 insertions(+), 7 deletions(-)
diff --git a/net/unix/garbage.c b/net/unix/garbage.c
index cad17f639b01b..11b75d37ac03a 100644
--- a/net/unix/garbage.c
+++ b/net/unix/garbage.c
@@ -375,7 +375,7 @@ static bool unix_vertex_dead(struct unix_vertex *vertex)
static LIST_HEAD(unix_visited_vertices);
static unsigned long unix_vertex_grouped_index = UNIX_VERTEX_INDEX_MARK2;
-static bool unix_scc_dead(struct list_head *scc, bool fast)
+static bool unix_scc_dead(struct list_head *scc)
{
struct unix_vertex *vertex;
bool scc_dead = true;
@@ -387,10 +387,6 @@ static bool unix_scc_dead(struct list_head *scc, bool fast)
/* Don't restart DFS from this vertex. */
list_move_tail(&vertex->entry, &unix_visited_vertices);
- /* Mark vertex as off-stack for __unix_walk_scc(). */
- if (!fast)
- vertex->index = unix_vertex_grouped_index;
-
if (scc_dead)
scc_dead = unix_vertex_dead(vertex);
}
@@ -522,6 +518,7 @@ static unsigned long __unix_walk_scc(struct unix_vertex *vertex,
}
if (vertex->index == vertex->scc_index) {
+ struct unix_vertex *v;
struct list_head scc;
/* SCC finalised.
@@ -531,7 +528,13 @@ static unsigned long __unix_walk_scc(struct unix_vertex *vertex,
*/
__list_cut_position(&scc, &vertex_stack, &vertex->scc_entry);
- if (unix_scc_dead(&scc, false)) {
+ list_for_each_entry_reverse(v, &scc, scc_entry) {
+ /* Mark vertex as off-stack and assign a unique ID. */
+ v->index = unix_vertex_grouped_index;
+ v->scc_index = vertex->scc_index;
+ }
+
+ if (unix_scc_dead(&scc)) {
unix_collect_skb(&scc, hitlist);
} else {
if (unix_vertex_max_scc_index < vertex->scc_index)
@@ -588,7 +591,7 @@ static void unix_walk_scc_fast(struct sk_buff_head *hitlist)
vertex = list_first_entry(&unix_unvisited_vertices, typeof(*vertex), entry);
list_add(&scc, &vertex->scc_entry);
- if (unix_scc_dead(&scc, true)) {
+ if (unix_scc_dead(&scc)) {
cyclic_sccs--;
unix_collect_skb(&scc, hitlist);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 208/438] net: pass net_device_path_ctx to dev_fill_forward_path()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (206 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 207/438] net: pass dst via net_device_path in dev_fill_forward_path() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 209/438] net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check Greg Kroah-Hartman
` (241 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Simon Horman,
Pablo Neira Ayuso, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit 95133a416809c7e822da4023b7f4193ef2620796 ]
Refactor dev_fill_forward_path() to take a struct net_device_path_ctx
pointer instead of a (dev, daddr) pair, so the caller can build and
populate the context up front and keep it after the forward path walk.
This allows additional fields (e.g. vlan and ether_type) to be carried
in the context and shared with ndo_fill_forward_path implementations,
instead of being reconstructed on the stack inside the core helper.
Update the mtk_ppe_offload, airoha_ppe and nf_flow_table_path callers to
allocate and fill the context before invoking dev_fill_forward_path().
The network topology resolution behaviour is unchanged.
This is a preliminary patch to enable HW flowtable offload for IPv4
over IPv6 tunnels.
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Stable-dep-of: 150dba2c69e9 ("net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/airoha/airoha_ppe.c | 7 ++++++-
.../net/ethernet/mediatek/mtk_ppe_offload.c | 7 ++++++-
include/linux/netdevice.h | 2 +-
net/core/dev.c | 18 +++++++-----------
net/netfilter/nf_flow_table_path.c | 7 ++++++-
5 files changed, 26 insertions(+), 15 deletions(-)
diff --git a/drivers/net/ethernet/airoha/airoha_ppe.c b/drivers/net/ethernet/airoha/airoha_ppe.c
index c8fd95e800937..bc2b4deafd83a 100644
--- a/drivers/net/ethernet/airoha/airoha_ppe.c
+++ b/drivers/net/ethernet/airoha/airoha_ppe.c
@@ -280,14 +280,19 @@ static int airoha_ppe_get_wdma_info(struct net_device *dev, const u8 *addr,
struct airoha_wdma_info *info)
{
struct net_device_path_stack stack;
+ struct net_device_path_ctx ctx = {
+ .dev = dev,
+ };
struct net_device_path *path;
int err;
if (!dev)
return -ENODEV;
+ ether_addr_copy(ctx.daddr, addr);
+
rcu_read_lock();
- err = dev_fill_forward_path(dev, addr, &stack);
+ err = dev_fill_forward_path(&ctx, &stack);
rcu_read_unlock();
if (err)
return err;
diff --git a/drivers/net/ethernet/mediatek/mtk_ppe_offload.c b/drivers/net/ethernet/mediatek/mtk_ppe_offload.c
index 771d9118f94ad..99b28aaa7cc47 100644
--- a/drivers/net/ethernet/mediatek/mtk_ppe_offload.c
+++ b/drivers/net/ethernet/mediatek/mtk_ppe_offload.c
@@ -92,6 +92,9 @@ static int
mtk_flow_get_wdma_info(struct net_device *dev, const u8 *addr, struct mtk_wdma_info *info)
{
struct net_device_path_stack stack;
+ struct net_device_path_ctx ctx = {
+ .dev = dev,
+ };
struct net_device_path *path;
int err;
@@ -101,8 +104,10 @@ mtk_flow_get_wdma_info(struct net_device *dev, const u8 *addr, struct mtk_wdma_i
if (!IS_ENABLED(CONFIG_NET_MEDIATEK_SOC_WED))
return -1;
+ ether_addr_copy(ctx.daddr, addr);
+
rcu_read_lock();
- err = dev_fill_forward_path(dev, addr, &stack);
+ err = dev_fill_forward_path(&ctx, &stack);
rcu_read_unlock();
if (err)
return err;
diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h
index d325027b03705..6a86a211fff57 100644
--- a/include/linux/netdevice.h
+++ b/include/linux/netdevice.h
@@ -3423,7 +3423,7 @@ void dev_remove_offload(struct packet_offload *po);
int dev_get_iflink(const struct net_device *dev);
int dev_fill_metadata_dst(struct net_device *dev, struct sk_buff *skb);
-int dev_fill_forward_path(const struct net_device *dev, const u8 *daddr,
+int dev_fill_forward_path(struct net_device_path_ctx *ctx,
struct net_device_path_stack *stack);
void dev_fill_forward_path_release(struct net_device_path_stack *stack);
struct net_device *dev_get_by_name(struct net *net, const char *name);
diff --git a/net/core/dev.c b/net/core/dev.c
index 2b493f4c2f0cb..679e75d3699ae 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -769,35 +769,31 @@ void dev_fill_forward_path_release(struct net_device_path_stack *stack)
}
EXPORT_SYMBOL_GPL(dev_fill_forward_path_release);
-int dev_fill_forward_path(const struct net_device *dev, const u8 *daddr,
+int dev_fill_forward_path(struct net_device_path_ctx *ctx,
struct net_device_path_stack *stack)
{
const struct net_device *last_dev;
- struct net_device_path_ctx ctx = {
- .dev = dev,
- };
struct net_device_path *path;
int ret = 0;
- memcpy(ctx.daddr, daddr, sizeof(ctx.daddr));
stack->num_paths = 0;
- while (ctx.dev && ctx.dev->netdev_ops->ndo_fill_forward_path) {
- last_dev = ctx.dev;
+ while (ctx->dev && ctx->dev->netdev_ops->ndo_fill_forward_path) {
+ last_dev = ctx->dev;
path = dev_fwd_path(stack);
if (!path)
goto err_out;
memset(path, 0, sizeof(struct net_device_path));
- ret = ctx.dev->netdev_ops->ndo_fill_forward_path(&ctx, path);
+ ret = ctx->dev->netdev_ops->ndo_fill_forward_path(ctx, path);
if (ret < 0)
goto err_out;
stack->num_paths++;
- if (WARN_ON_ONCE(last_dev == ctx.dev))
+ if (WARN_ON_ONCE(last_dev == ctx->dev))
goto err_out;
}
- if (!ctx.dev)
+ if (!ctx->dev)
return ret;
path = dev_fwd_path(stack);
@@ -805,7 +801,7 @@ int dev_fill_forward_path(const struct net_device *dev, const u8 *daddr,
goto err_out;
path->type = DEV_PATH_ETHERNET;
- path->dev = ctx.dev;
+ path->dev = ctx->dev;
stack->num_paths++;
return 0;
diff --git a/net/netfilter/nf_flow_table_path.c b/net/netfilter/nf_flow_table_path.c
index 98c03b487f521..b9df7453f7620 100644
--- a/net/netfilter/nf_flow_table_path.c
+++ b/net/netfilter/nf_flow_table_path.c
@@ -50,6 +50,9 @@ static int nft_dev_fill_forward_path(const struct nf_flow_route *route,
{
const void *daddr = &ct->tuplehash[!dir].tuple.src.u3;
struct net_device *dev = dst_cache->dev;
+ struct net_device_path_ctx ctx = {
+ .dev = dev,
+ };
struct neighbour *n;
u8 nud_state;
@@ -72,7 +75,9 @@ static int nft_dev_fill_forward_path(const struct nf_flow_route *route,
return -1;
out:
- return dev_fill_forward_path(dev, ha, stack);
+ ether_addr_copy(ctx.daddr, ha);
+
+ return dev_fill_forward_path(&ctx, stack);
}
struct nft_forward_info {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 155/398] pppoatm: ensure a writable skb header and linear data
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (153 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 154/398] af_unix: Unify scc_index when finalising SCC in __unix_walk_scc() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 156/398] drop_monitor: synchronize tracepoint unregistration on error path Greg Kroah-Hartman
` (247 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Simon Horman,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit ecc7253683a3c55caa868ce0ee530fcb0044bd3c ]
In pppoatm_send(), LLC encapsulation checks whether there is sufficient
headroom for the 4-byte LLC header, but does not ensure that the skb header
is writable.
Normal transmit packets passing through ppp_start_xmit() have their header
unshared via skb_cow_head(). However, packets can also reach pppoatm_send()
via PPP channel bridging (PPPIOCBRIDGECHAN) without going through
ppp_start_xmit().
Use skb_cow_head() to ensure both sufficient headroom and a writable
header before pushing the LLC header.
While at it:
- Call pskb_may_pull(skb, 1) before inspecting skb->data[0] to prevent
out-of-bounds reads on zero-length or non-linear frames (e.g. from
bridging).
- Defer SC_COMP_PROT protocol compression until after pppoatm_may_send()
succeeds. This eliminates the temporary skb allocation on admission failure
and completely removes the fragile "undo" heuristic at the nospace label,
avoiding any risk of reading uninitialized headroom or performing an
unbalanced skb_push().
Fixes: 4cf476ced45d ("ppp: add PPPIOCBRIDGECHAN and PPPIOCUNBRIDGECHAN ioctls")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260912233048.3977192-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/atm/pppoatm.c | 42 +++++++++++++++++-------------------------
1 file changed, 17 insertions(+), 25 deletions(-)
diff --git a/net/atm/pppoatm.c b/net/atm/pppoatm.c
index 3e4f17d335feb..b668a30b67a8d 100644
--- a/net/atm/pppoatm.c
+++ b/net/atm/pppoatm.c
@@ -292,10 +292,13 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
struct atm_vcc *vcc;
int ret;
+ if (!pskb_may_pull(skb, 1)) {
+ kfree_skb(skb);
+ return DROP_PACKET;
+ }
+
ATM_SKB(skb)->vcc = pvcc->atmvcc;
pr_debug("(skb=0x%p, vcc=0x%p)\n", skb, pvcc->atmvcc);
- if (skb->data[0] == '\0' && (pvcc->flags & SC_COMP_PROT))
- (void) skb_pull(skb, 1);
vcc = ATM_SKB(skb)->vcc;
bh_lock_sock(sk_atm(vcc));
@@ -318,23 +321,13 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
switch (pvcc->encaps) { /* LLC encapsulation needed */
case e_llc:
- if (skb_headroom(skb) < LLC_LEN) {
- struct sk_buff *n;
- n = skb_realloc_headroom(skb, LLC_LEN);
- if (n != NULL &&
- !pppoatm_may_send(pvcc, n->truesize)) {
- kfree_skb(n);
- goto nospace;
- }
- consume_skb(skb);
- skb = n;
- if (skb == NULL) {
- bh_unlock_sock(sk_atm(vcc));
- return DROP_PACKET;
- }
- } else if (!pppoatm_may_send(pvcc, skb->truesize))
+ if (skb_cow_head(skb, LLC_LEN)) {
+ bh_unlock_sock(sk_atm(vcc));
+ kfree_skb(skb);
+ return DROP_PACKET;
+ }
+ if (!pppoatm_may_send(pvcc, skb->truesize))
goto nospace;
- memcpy(skb_push(skb, LLC_LEN), pppllc, LLC_LEN);
break;
case e_vc:
if (!pppoatm_may_send(pvcc, skb->truesize))
@@ -347,6 +340,12 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
return 1;
}
+ if (skb->data[0] == '\0' && (pvcc->flags & SC_COMP_PROT))
+ skb_pull(skb, 1);
+
+ if (pvcc->encaps == e_llc)
+ memcpy(skb_push(skb, LLC_LEN), pppllc, LLC_LEN);
+
atm_account_tx(vcc, skb);
pr_debug("atm_skb(%p)->vcc(%p)->dev(%p)\n",
skb, ATM_SKB(skb)->vcc, ATM_SKB(skb)->vcc->dev);
@@ -356,13 +355,6 @@ static int pppoatm_send(struct ppp_channel *chan, struct sk_buff *skb)
return ret;
nospace:
bh_unlock_sock(sk_atm(vcc));
- /*
- * We don't have space to send this SKB now, but we might have
- * already applied SC_COMP_PROT compression, so may need to undo
- */
- if ((pvcc->flags & SC_COMP_PROT) && skb_headroom(skb) > 0 &&
- skb->data[-1] == '\0')
- (void) skb_push(skb, 1);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 209/438] net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (207 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 208/438] net: pass net_device_path_ctx to dev_fill_forward_path() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 261/398] mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 210/438] net: netsec: fix device_node reference leak on phy_np Greg Kroah-Hartman
` (240 subsequent siblings)
449 siblings, 1 reply; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pablo Neira Ayuso, Farhad Alemi,
Xuanqiang Luo, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Farhad Alemi <farhad.alemi@berkeley.edu>
[ Upstream commit 150dba2c69e93302af24a0c868eebe4871e2e107 ]
ipip_fill_forward_path() and ip6_tnl_fill_forward_path() look up the
route to the tunnel's remote endpoint and set ctx->dev to its device,
which is the tunnel itself when that route resolves back to the tunnel.
dev_fill_forward_path() then makes no progress and trips
WARN_ON_ONCE(last_dev == ctx->dev) as soon as a flowtable tries to
offload a flow through the tunnel. That routing loop is a configuration
any CAP_NET_ADMIN user can set up, and ip_tunnel_xmit() and
ip6_tnl_xmit() already treat it as a tx error, so remove the warning and
just fail the walk, as commit 008e7a7c293b ("net: remove WARN_ON_ONCE
when accessing forward path array") did for the path stack overflow.
Fixes: ab427db17885 ("netfilter: flowtable: Add IPIP rx sw acceleration")
Fixes: d98103575dcd ("netfilter: flowtable: Add IP6IP6 rx sw acceleration")
Closes: https://lore.kernel.org/all/CA+0ovCgaRvbd0Udj70b2xxG8Cx3CaCpNhnf1V4RWQuDveZYZhA@mail.gmail.com/
Suggested-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/CA+0ovCgKDOk+Bg6Gh5Lwx94u_jJjQ30-vY1JcY2BYfhnWJJbPA@mail.gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/dev.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/core/dev.c b/net/core/dev.c
index 679e75d3699ae..ff25e4c71588e 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -789,7 +789,7 @@ int dev_fill_forward_path(struct net_device_path_ctx *ctx,
goto err_out;
stack->num_paths++;
- if (WARN_ON_ONCE(last_dev == ctx->dev))
+ if (last_dev == ctx->dev)
goto err_out;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 156/398] drop_monitor: synchronize tracepoint unregistration on error path
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (154 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 155/398] pppoatm: ensure a writable skb header and linear data Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 157/398] drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown Greg Kroah-Hartman
` (246 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Hangbin Liu,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 6a038ef2b57922b6d9ca98ddac0df0681849b704 ]
If register_trace_napi_poll() fails in net_dm_trace_on_set(),
unregister_trace_kfree_skb() is called to roll back the kfree_skb
tracepoint registration.
However, tracepoint_synchronize_unregister() is omitted before calling
cancel_work_sync() and module_put(). An in-flight probe executing
concurrently on another CPU could call schedule_work() after
cancel_work_sync() has already returned, leaving a pending work item
scheduled after the module reference is dropped. If the module is then
unloaded, executing the work item triggers a kernel panic.
Add tracepoint_synchronize_unregister() after unregister_trace_kfree_skb()
in the error path, matching net_dm_trace_off_set() and
net_dm_hw_probe_unregister().
Fixes: 7c747838a558 ("drop_monitor: Split tracing enable / disable to different functions")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260910204612.3762015-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index a5e75cd04d6ca..172fd2dcbfe93 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -1174,6 +1174,7 @@ static int net_dm_trace_on_set(struct netlink_ext_ack *extack)
err_unregister_trace:
unregister_trace_kfree_skb(ops->kfree_skb_probe, NULL);
+ tracepoint_synchronize_unregister();
err_module_put:
for_each_possible_cpu(cpu) {
struct per_cpu_dm_data *data = &per_cpu(dm_cpu_data, cpu);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 210/438] net: netsec: fix device_node reference leak on phy_np
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (208 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 209/438] net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 211/438] eth: fbnic: ring the doorbell if a burst ends in a drop Greg Kroah-Hartman
` (239 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yige Jiang, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yige Jiang <yigejiang86@gmail.com>
[ Upstream commit 5ae916fabca141b79b32e2e57f3c915c0f1e1b2e ]
netsec_of_probe() takes a reference on the PHY device_node with
of_parse_phandle() and stores it in priv->phy_np, but the driver never
drops it. One device_node reference is leaked per probe, on the success
path as well as on every error path reached after netsec_of_probe().
Neither consumer takes ownership. of_mdio_parse_addr() is a static
inline taking a const struct device_node * that only reads the "reg"
property. of_phy_connect() borrows as well: of_phy_get_and_connect() in
drivers/net/mdio/of_mdio.c brackets its own call with of_node_get() at
:364 and of_node_put() at :373, which would be a double put if
of_phy_connect() consumed the reference.
The node is still in use at netsec_netdev_open() time, where it is
passed to of_phy_connect(), so it has device lifetime. Release it at
the probe error label, which every failure path after the acquire
funnels through, and in netsec_remove(). Both releases precede
free_netdev(), since priv is netdev_priv(ndev). The ACPI probe path
leaves priv->phy_np NULL and of_node_put(NULL) is a no-op.
There is no end-user visible symptom on currently supported platforms:
a device_node is only freed once OF_DYNAMIC is enabled and the node has
been detached, so on a static device tree the imbalance is inert. It is
observable as a refcount that grows across bind/unbind cycles, and would
matter under device tree overlays.
Found by static analysis of reference acquire/release pairing rather
than from a runtime report. No reproducer was produced and the change
has not been runtime tested; it is compile-tested only (arm64,
CONFIG_SNI_NETSEC=m via COMPILE_TEST).
Fixes: 533dd11a12f6 ("net: socionext: Add Synquacer NetSec driver")
Signed-off-by: Yige Jiang <yigejiang86@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260913064102.37452-1-yigejiang86@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/socionext/netsec.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/ethernet/socionext/netsec.c b/drivers/net/ethernet/socionext/netsec.c
index d14a6584473c8..79a0a324c921d 100644
--- a/drivers/net/ethernet/socionext/netsec.c
+++ b/drivers/net/ethernet/socionext/netsec.c
@@ -2149,6 +2149,7 @@ static int netsec_probe(struct platform_device *pdev)
pm_runtime_put_sync(&pdev->dev);
pm_runtime_disable(&pdev->dev);
free_ndev:
+ of_node_put(priv->phy_np);
free_netdev(ndev);
dev_err(&pdev->dev, "init failed\n");
@@ -2166,6 +2167,7 @@ static void netsec_remove(struct platform_device *pdev)
netif_napi_del(&priv->napi);
pm_runtime_disable(&pdev->dev);
+ of_node_put(priv->phy_np);
free_netdev(priv->ndev);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 157/398] drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (155 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 156/398] drop_monitor: synchronize tracepoint unregistration on error path Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 158/398] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Greg Kroah-Hartman
` (245 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit c391a40f71886b28c082b47270f0e856fa3e1150 ]
In drop_monitor teardown paths (net_dm_trace_off_set(),
net_dm_hw_monitor_stop(), and error unwind paths in net_dm_trace_on_set()
and net_dm_hw_monitor_start()), per-CPU timers are stopped using
timer_delete_sync() followed by cancel_work_sync().
However, there is a circular dependency between send_timer and
dm_alert_work:
1) sched_send_work() (timer callback) schedules dm_alert_work.
2) send_dm_alert() / net_dm_hw_summary_work() calls reset_per_cpu_data()
or net_dm_hw_reset_per_cpu_data().
3) If memory allocation fails under memory pressure in the reset
function, it re-arms the timer via mod_timer(&data->send_timer, ...).
If dm_alert_work is running concurrently while timer_delete_sync()
executes on another CPU, an allocation failure in the worker will
re-arm the timer after timer_delete_sync() has already returned.
Once cancel_work_sync() completes and module_put() is called, the timer
remains active in the timer wheel. If the module is then unloaded, the
timer will fire and execute sched_send_work() in freed memory,
triggering a kernel panic / use-after-free.
Switch from timer_delete_sync() to timer_shutdown_sync(). This guarantees
that any in-flight timer handler has finished and prevents subsequent
re-arming attempts from running workers from succeeding. When monitoring
is restarted later, timer_setup() is invoked, which cleanly
re-initializes the timer.
Fixes: 9398e9c0b1d4 ("drop_monitor: Perform cleanup upon probe registration failure")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260910204612.3762015-3-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index 172fd2dcbfe93..b56da4d8c879e 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -1084,7 +1084,7 @@ static int net_dm_hw_monitor_start(struct netlink_ext_ack *extack)
struct per_cpu_dm_data *hw_data = &per_cpu(dm_hw_cpu_data, cpu);
struct sk_buff *skb;
- timer_delete_sync(&hw_data->send_timer);
+ timer_shutdown_sync(&hw_data->send_timer);
cancel_work_sync(&hw_data->dm_alert_work);
while ((skb = __skb_dequeue(&hw_data->drop_queue))) {
struct devlink_trap_metadata *hw_metadata;
@@ -1118,7 +1118,7 @@ static void net_dm_hw_monitor_stop(struct netlink_ext_ack *extack)
struct per_cpu_dm_data *hw_data = &per_cpu(dm_hw_cpu_data, cpu);
struct sk_buff *skb;
- timer_delete_sync(&hw_data->send_timer);
+ timer_shutdown_sync(&hw_data->send_timer);
cancel_work_sync(&hw_data->dm_alert_work);
while ((skb = __skb_dequeue(&hw_data->drop_queue))) {
struct devlink_trap_metadata *hw_metadata;
@@ -1180,7 +1180,7 @@ static int net_dm_trace_on_set(struct netlink_ext_ack *extack)
struct per_cpu_dm_data *data = &per_cpu(dm_cpu_data, cpu);
struct sk_buff *skb;
- timer_delete_sync(&data->send_timer);
+ timer_shutdown_sync(&data->send_timer);
cancel_work_sync(&data->dm_alert_work);
while ((skb = __skb_dequeue(&data->drop_queue)))
consume_skb(skb);
@@ -1208,7 +1208,7 @@ static void net_dm_trace_off_set(void)
struct per_cpu_dm_data *data = &per_cpu(dm_cpu_data, cpu);
struct sk_buff *skb;
- timer_delete_sync(&data->send_timer);
+ timer_shutdown_sync(&data->send_timer);
cancel_work_sync(&data->dm_alert_work);
while ((skb = __skb_dequeue(&data->drop_queue)))
consume_skb(skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 211/438] eth: fbnic: ring the doorbell if a burst ends in a drop
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (209 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 210/438] net: netsec: fix device_node reference leak on phy_np Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 212/438] net: lock the socket in sock_gettstamp() Greg Kroah-Hartman
` (238 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexander Duyck, Simon Horman,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Kicinski <kuba@kernel.org>
[ Upstream commit 490599ab23134962a6d18a024e84541d77bdb999 ]
fbnic_tx_map() skips the doorbell write, and the completion request,
for every packet handed to it with xmit_more set, counting on the
packet which ends the burst to publish them all. When that packet is
dropped instead - skb_put_padto(), skb_cow_head() or a DMA mapping
failure - nothing rings. The descriptors of the preceding packets stay
invisible to the HW until the next transmit on that queue, which for a
burst-then-idle workload may never come.
Remember the meta descriptor of the last packet left without a doorbell
and flush it from the error paths. The completion request has to be set
on that descriptor rather than simply writing the tail, otherwise the HW
would transmit the packets but never report a head, and the ring would
fill up and stall for good.
This is very similar to Joe's recent series of fixes for bnxt.
Not seen in real life, reproduced under QEMU with failure injection.
Fixes: 9a57bacd574b ("eth: fbnic: Add basic Tx handling")
Reviewed-by: Alexander Duyck <alexanderduyck@fb.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915022327.913218-1-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/meta/fbnic/fbnic_txrx.c | 42 +++++++++++++++-----
drivers/net/ethernet/meta/fbnic/fbnic_txrx.h | 9 ++++-
2 files changed, 40 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
index 401f8b8ae1cae..e7918d3f6aba9 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
@@ -311,6 +311,29 @@ fbnic_rx_csum(u64 rcd, struct sk_buff *skb, struct fbnic_ring *rcq,
}
}
+static void fbnic_tx_doorbell(struct fbnic_ring *ring, __le64 *meta)
+{
+ *meta |= cpu_to_le64(FBNIC_TWD_FLAG_REQ_COMPLETION);
+ ring->deferred_meta = -1;
+
+ /* Force DMA writes to flush before writing to tail */
+ dma_wmb();
+
+ writel(ring->tail, ring->doorbell);
+}
+
+/* Packets handed to us with xmit_more set are left in the ring without a
+ * doorbell, and without a completion request, in the expectation that the
+ * packet ending the burst will ring for all of them. If that packet gets
+ * dropped instead we have to ring here, otherwise the descriptors sit in
+ * the ring until the next transmit, which may never come.
+ */
+static void fbnic_tx_flush_doorbell(struct fbnic_ring *ring)
+{
+ if (ring->deferred_meta >= 0)
+ fbnic_tx_doorbell(ring, &ring->desc[ring->deferred_meta]);
+}
+
static bool
fbnic_tx_map(struct fbnic_ring *ring, struct sk_buff *skb, __le64 *meta)
{
@@ -378,14 +401,10 @@ fbnic_tx_map(struct fbnic_ring *ring, struct sk_buff *skb, __le64 *meta)
/* Verify there is room for another packet */
fbnic_maybe_stop_tx(skb->dev, ring, FBNIC_MAX_SKB_DESC);
- if (fbnic_tx_sent_queue(skb, ring)) {
- *meta |= cpu_to_le64(FBNIC_TWD_FLAG_REQ_COMPLETION);
-
- /* Force DMA writes to flush before writing to tail */
- dma_wmb();
-
- writel(tail, ring->doorbell);
- }
+ if (fbnic_tx_sent_queue(skb, ring))
+ fbnic_tx_doorbell(ring, meta);
+ else
+ ring->deferred_meta = meta - ring->desc;
return false;
dma_error:
@@ -425,8 +444,10 @@ fbnic_xmit_frame_ring(struct sk_buff *skb, struct fbnic_ring *ring)
* otherwise try next time
*/
desc_needed = skb_shinfo(skb)->nr_frags + 10;
- if (fbnic_maybe_stop_tx(skb->dev, ring, desc_needed))
+ if (fbnic_maybe_stop_tx(skb->dev, ring, desc_needed)) {
+ fbnic_tx_flush_doorbell(ring);
return NETDEV_TX_BUSY;
+ }
*meta = cpu_to_le64(FBNIC_TWD_FLAG_DEST_MAC);
@@ -447,6 +468,8 @@ fbnic_xmit_frame_ring(struct sk_buff *skb, struct fbnic_ring *ring)
err_free:
dev_kfree_skb_any(skb);
err_count:
+ fbnic_tx_flush_doorbell(ring);
+
u64_stats_update_begin(&ring->stats.syncp);
ring->stats.dropped++;
u64_stats_update_end(&ring->stats.syncp);
@@ -2491,6 +2514,7 @@ static void fbnic_enable_twq0(struct fbnic_ring *twq)
fbnic_ring_wr32(twq, FBNIC_QUEUE_TWQ0_CTL, FBNIC_QUEUE_TWQ_CTL_RESET);
twq->tail = 0;
twq->head = 0;
+ twq->deferred_meta = -1;
/* Store descriptor ring address and size */
fbnic_ring_wr32(twq, FBNIC_QUEUE_TWQ0_BAL, lower_32_bits(twq->dma));
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.h b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.h
index e03c9d2c38dca..f5899446dcc51 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.h
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.h
@@ -128,9 +128,14 @@ struct fbnic_ring {
/* Rx BDQs only */
struct page_pool *page_pool;
- /* Deferred_head is used to cache the head for TWQ1 if
+ /* TWQ0 only, index of the meta descriptor of the last packet
+ * placed in the ring without ringing the doorbell, -1 if the
+ * doorbell is in sync with the tail.
+ */
+ s32 deferred_meta;
+
+ /* TCQ only, used to cache the head for TWQ1 if
* an attempt is made to clean TWQ1 with zero napi_budget.
- * We do not use it for any other ring.
*/
s32 deferred_head;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 158/398] drop_monitor: fix out-of-bounds write in reset_per_cpu_data()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (156 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 157/398] drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 159/398] net: stmmac: do not overwrite phc_index when no PTP clock is registered Greg Kroah-Hartman
` (244 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Hangbin Liu,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 439f392084f8f7f59ab9d47a9579185accefe1d8 ]
In reset_per_cpu_data(), al is computed as:
al = sizeof(struct net_dm_alert_msg);
al += dm_hit_limit * sizeof(struct net_dm_drop_point);
al += sizeof(struct nlattr);
skb = genlmsg_new(al, GFP_KERNEL);
...
nla = nla_reserve(skb, NLA_UNSPEC, sizeof(struct net_dm_alert_msg));
...
msg = nla_data(nla);
memset(msg, 0, al);
Because al includes sizeof(struct nlattr) (the 4-byte attribute header),
genlmsg_new() allocates al bytes of tailroom starting at nla.
However, msg points to nla_data(nla), which is located
sizeof(struct nlattr) bytes past nla. Calling memset(msg, 0, al)
therefore writes al bytes starting from msg, exceeding the allocated
buffer by sizeof(struct nlattr) (4 bytes) and corrupting
skb_shared_info.
Fix this by letting al represent only the payload length, allocating
the skb with genlmsg_new(nla_total_size(al), GFP_KERNEL), and zeroing
al bytes from msg.
Fixes: 683703a26e46 ("drop_monitor: Update netlink protocol to include netlink attribute header in alert message")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Link: https://patch.msgid.link/20260910204612.3762015-5-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/drop_monitor.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c
index b56da4d8c879e..996ae451af628 100644
--- a/net/core/drop_monitor.c
+++ b/net/core/drop_monitor.c
@@ -141,9 +141,8 @@ static struct sk_buff *reset_per_cpu_data(struct per_cpu_dm_data *data)
al = sizeof(struct net_dm_alert_msg);
al += dm_hit_limit * sizeof(struct net_dm_drop_point);
- al += sizeof(struct nlattr);
- skb = genlmsg_new(al, GFP_KERNEL);
+ skb = genlmsg_new(nla_total_size(al), GFP_KERNEL);
if (!skb)
goto err;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 212/438] net: lock the socket in sock_gettstamp()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (210 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 211/438] eth: fbnic: ring the doorbell if a burst ends in a drop Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 213/438] net: ethernet: cortina: Ack RX overrun interrupt correctly Greg Kroah-Hartman
` (237 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jungwoo Lee, Wongi Lee, Eric Dumazet,
Simon Horman, Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 9ed55f3dbef4f4adfe65eb03b0c35c53229a8490 ]
sk->sk_flags must only be changed while holding the socket lock,
because sock_set_flag() and sock_reset_flag() use non atomic
operations (__set_bit() and __clear_bit()).
sock_gettstamp() is one of the last places where a bit of sk->sk_flags
is changed from a syscall without owning the socket lock, through
sock_enable_timestamp(sk, SOCK_TIMESTAMP).
sk_set_memalloc() and sk_clear_memalloc() also change sk->sk_flags
without the socket lock, but their callers (nbd, iscsi_tcp, nvme-tcp,
sunrpc, wireguard) need a careful audit, this will be addressed in a
separate patch.
Jungwoo Lee and Wongi Lee reported an UDP socket use-after-free
caused by this bug: a SIOCGSTAMPNS_NEW ioctl racing with bind()
can cancel the SOCK_RCU_FREE bit that udp_lib_get_port() just set,
because both threads perform a read-modify-write on the same word.
CPU 0 (bind) CPU 1 (SIOCGSTAMPNS_NEW)
-------------------------------- ----------------------------
read sk_flags = F read sk_flags = F
compute F | BIT(SOCK_RCU_FREE) compute F | BIT(SOCK_TIMESTAMP)
store F | BIT(SOCK_RCU_FREE)
sk_add_node_rcu(sk, ...)
store F | BIT(SOCK_TIMESTAMP)
After the lost update, SOCK_RCU_FREE is clear while the socket is
visible to lockless UDP receive lookups. sk_destruct() then frees
the socket immediately instead of waiting for a RCU grace period,
while the receive path still holds a reference-less pointer to it:
BUG: KASAN: slab-use-after-free in ipv4_pktinfo_prepare+0x30/0x410
Read of size 8 at addr ffff888008806610 by task exploit/207
CPU: 0 UID: 1000 PID: 207 Comm: exploit Not tainted 6.12.95+ #1
ipv4_pktinfo_prepare+0x30/0x410
udp_queue_rcv_one_skb+0x51c/0x1180
udp_unicast_rcv_skb+0x109/0x350
ip_protocol_deliver_rcu+0x14b/0x310
ip_local_deliver_finish+0x29d/0x390
ip_local_deliver+0x24d/0x2a0
Only grab the socket lock when SOCK_TIMESTAMP has to be set,
to keep the common case lockless.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Jungwoo Lee <jwlee2217@gmail.com>
Reported-by: Wongi Lee <qw3rtyp0@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915043055.3441600-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/sock.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/net/core/sock.c b/net/core/sock.c
index 1ad41904db25b..5c1a1d1950752 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -3908,7 +3908,14 @@ int sock_gettstamp(struct socket *sock, void __user *userstamp,
struct sock *sk = sock->sk;
struct timespec64 ts;
- sock_enable_timestamp(sk, SOCK_TIMESTAMP);
+ /* sk->sk_flags must only be changed under the socket lock,
+ * because sock_set_flag() uses non atomic operations.
+ */
+ if (!sock_flag(sk, SOCK_TIMESTAMP)) {
+ lock_sock(sk);
+ sock_enable_timestamp(sk, SOCK_TIMESTAMP);
+ release_sock(sk);
+ }
ts = ktime_to_timespec64(sock_read_timestamp(sk));
if (ts.tv_sec == -1)
return -ENOENT;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 159/398] net: stmmac: do not overwrite phc_index when no PTP clock is registered
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (157 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 158/398] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 160/398] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() Greg Kroah-Hartman
` (243 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maxime Chevallier, Rahul Rameshbabu,
Lorenzo Bianconi, Gal Pressman, Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit f0ef4b1eaed000a304726a43091588e8426ba08a ]
stmmac_get_ts_info() reports phc_index as 0 when hardware timestamping
is supported but no PTP clock has been registered yet (e.g. while the
interface is down). Zero is a valid PHC index and would make userspace
resolve the wrong clock; the absence of a clock should be reported as
-1.
The ethtool core already initializes phc_index to -1 before invoking
the get_ts_info callback (ethtool_init_tsinfo()), so just drop the
erroneous assignment.
Fixes: 9364fa7fcf12 ("net: stmmac: Remove setting of RX software timestamp")
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Reviewed-by: Rahul Rameshbabu <rrameshbabu@nvidia.com>
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Reviewed-by: Gal Pressman <gal@nvidia.com>
Link: https://patch.msgid.link/20260914-stmmac-fix-phc_index-v2-1-bf3d90373fe4@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c
index 81d4039e1c082..741e3864f5094 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_ethtool.c
@@ -1059,8 +1059,6 @@ static int stmmac_get_ts_info(struct net_device *dev,
if (priv->ptp_clock)
info->phc_index = ptp_clock_index(priv->ptp_clock);
- else
- info->phc_index = 0;
info->tx_types = (1 << HWTSTAMP_TX_OFF) | (1 << HWTSTAMP_TX_ON);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 213/438] net: ethernet: cortina: Ack RX overrun interrupt correctly
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (211 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 212/438] net: lock the socket in sock_gettstamp() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 214/438] net: stmmac: propagate FPE preemption-class mapping errors Greg Kroah-Hartman
` (236 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linus Walleij, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 1dd85662fee6e2ac580b1c4f9a0c0a7ae6e31f0e ]
The RX overrun interrupt is reported in interrupt status register 4, but
gmac_irq() acknowledges it using the RX descriptor error bit from status
register 0. For GMAC0 this writes the GMAC1 overrun bit, while for GMAC1
the shift leaves no bit in the 32-bit register.
Acknowledge the same per-port RX overrun bit that was detected.
Fixes: 4d5ae32f5e1e ("net: ethernet: Add a driver for Gemini gigabit ethernet")
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260914-b4-gemini-ethernet-fixes-2-v2-1-5ab39a047b90@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cortina/gemini.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/cortina/gemini.c b/drivers/net/ethernet/cortina/gemini.c
index f08de623e6f7c..2dd2fa801829c 100644
--- a/drivers/net/ethernet/cortina/gemini.c
+++ b/drivers/net/ethernet/cortina/gemini.c
@@ -1798,7 +1798,7 @@ static irqreturn_t gmac_irq(int irq, void *data)
if (val & (GMAC0_RX_OVERRUN_INT_BIT << (netdev->dev_id * 8))) {
spin_lock(&geth->irq_lock);
- writel(GMAC0_RXDERR_INT_BIT << (netdev->dev_id * 8),
+ writel(GMAC0_RX_OVERRUN_INT_BIT << (netdev->dev_id * 8),
geth->base + GLOBAL_INTERRUPT_STATUS_4_REG);
u64_stats_update_begin(&port->ir_stats_syncp);
++port->stats.rx_fifo_errors;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 160/398] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (158 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 159/398] net: stmmac: do not overwrite phc_index when no PTP clock is registered Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 161/398] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure Greg Kroah-Hartman
` (242 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Amit Machhiwal, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Amit Machhiwal <amachhiw@linux.ibm.com>
[ Upstream commit 51938dfa8a51a4f85328413fca9b6e21f9d2d088 ]
kvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops
mmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a
reference on the kvm_nested_guest pointer obtained from the IDR. A
concurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race
through kvmhv_flush_nested() -> kvmhv_remove_nested() -> idr_remove /
--refcnt -> kvmhv_release_nested() -> kfree(gp) in that window, leaving
the iterating vCPU with a dangling pointer. The subsequent
mutex_lock(&gp->tlb_lock) and accesses to gp->shadow_pgtable,
gp->shadow_lpid and gp->l1_host all touch freed memory. The free path
is fully L1-controlled.
Fix this by incrementing gp->refcnt inside the loop before dropping
mmu_lock, mirroring what kvmhv_get_nested() does, and releasing the
reference with kvmhv_put_nested() after the per-guest work completes.
This is the same get/put discipline already used at every other
call site that drops mmu_lock while holding a nested-guest pointer.
Fixes: e3b6b4661527 ("KVM: PPC: Book3S HV: Implement H_TLB_INVALIDATE hcall")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kvm/book3s_hv_nested.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/powerpc/kvm/book3s_hv_nested.c b/arch/powerpc/kvm/book3s_hv_nested.c
index 5f8c2321cfb52..7b10caa3424c2 100644
--- a/arch/powerpc/kvm/book3s_hv_nested.c
+++ b/arch/powerpc/kvm/book3s_hv_nested.c
@@ -1204,8 +1204,10 @@ static void kvmhv_emulate_tlbie_all_lpid(struct kvm_vcpu *vcpu, int ric)
spin_lock(&kvm->mmu_lock);
idr_for_each_entry(&kvm->arch.kvm_nested_guest_idr, gp, lpid) {
+ ++gp->refcnt;
spin_unlock(&kvm->mmu_lock);
kvmhv_emulate_tlbie_lpid(vcpu, gp, ric);
+ kvmhv_put_nested(gp);
spin_lock(&kvm->mmu_lock);
}
spin_unlock(&kvm->mmu_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 214/438] net: stmmac: propagate FPE preemption-class mapping errors
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (212 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 213/438] net: ethernet: cortina: Ack RX overrun interrupt correctly Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 215/438] net: prevent torn reads in netdev_tc_txq Greg Kroah-Hartman
` (235 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit 90e4b849dfa6fc8e6c050bcfe1b331b69c015d28 ]
stmmac_fpe_map_preemption_class() dispatches through the
stmmac_do_void_callback() helper, which forces the callback's return
value to 0 whenever the op pointer is populated. As a result the
-EINVAL returned by dwmac5_fpe_map_preemption_class() (e.g. when a
preemptible TC owns more than one TXQ under SP scheduling) is silently
swallowed by every caller.
Switch the dispatch macro to stmmac_do_callback() so the callback's real
result is propagated, and honour it in the taprio and mqprio qdisc
offload.
Note that the taprio "if (ret)" check in tc_taprio_configure() used to
be dead code and now becomes live: a preemptible TC spanning more than
one TXQ under SP scheduling cannot be programmed in hardware, so a
taprio or mqprio configuration that previously returned success while
leaving the preemption-class register unprogrammed now fails with
-EINVAL. For taprio, the failure also runs the disable path, tearing
down the schedule that was just installed; this is the intended
behaviour.
Fixes: 195e4f409a40 ("net: stmmac: support fp parameter of tc-mqprio")
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Link: https://patch.msgid.link/20260911-stmmac-tc_setup_dwmac510_mqprio-error-path-v3-1-a76b1e2547c1@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/hwif.h | 2 +-
.../net/ethernet/stmicro/stmmac/stmmac_tc.c | 19 +++++++++----------
2 files changed, 10 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/hwif.h b/drivers/net/ethernet/stmicro/stmmac/hwif.h
index 04dafec021b4f..9314bcb85c221 100644
--- a/drivers/net/ethernet/stmicro/stmmac/hwif.h
+++ b/drivers/net/ethernet/stmicro/stmmac/hwif.h
@@ -494,7 +494,7 @@ struct stmmac_ops {
#define stmmac_set_arp_offload(__priv, __args...) \
stmmac_do_void_callback(__priv, mac, set_arp_offload, __args)
#define stmmac_fpe_map_preemption_class(__priv, __args...) \
- stmmac_do_void_callback(__priv, mac, fpe_map_preemption_class, __args)
+ stmmac_do_callback(__priv, mac, fpe_map_preemption_class, __args)
/* PTP and HW Timer helpers */
struct stmmac_hwtimestamp {
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
index 14cabe76e53ec..5398616fcdfea 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
@@ -970,7 +970,7 @@ static int tc_taprio_configure(struct stmmac_priv *priv,
struct netlink_ext_ack *extack = qopt->mqprio.extack;
struct timespec64 time, current_time, qopt_time;
ktime_t current_time_ns;
- int i, ret = 0;
+ int err, i, ret = 0;
u64 ctr;
if (qopt->base_time < 0)
@@ -1120,9 +1120,9 @@ static int tc_taprio_configure(struct stmmac_priv *priv,
mutex_unlock(&priv->est_lock);
}
- stmmac_fpe_map_preemption_class(priv, priv->dev, extack, 0);
+ err = stmmac_fpe_map_preemption_class(priv, priv->dev, extack, 0);
- return ret;
+ return qopt->cmd == TAPRIO_CMD_DESTROY ? err : ret;
}
static void tc_taprio_stats(struct stmmac_priv *priv,
@@ -1237,14 +1237,15 @@ static int tc_query_caps(struct stmmac_priv *priv,
}
}
-static void stmmac_reset_tc_mqprio(struct net_device *ndev,
- struct netlink_ext_ack *extack)
+static int stmmac_reset_tc_mqprio(struct net_device *ndev,
+ struct netlink_ext_ack *extack)
{
struct stmmac_priv *priv = netdev_priv(ndev);
netdev_reset_tc(ndev);
netif_set_real_num_tx_queues(ndev, priv->plat->tx_queues_to_use);
- stmmac_fpe_map_preemption_class(priv, ndev, extack, 0);
+
+ return stmmac_fpe_map_preemption_class(priv, ndev, extack, 0);
}
static int tc_setup_dwmac510_mqprio(struct stmmac_priv *priv,
@@ -1257,10 +1258,8 @@ static int tc_setup_dwmac510_mqprio(struct stmmac_priv *priv,
u32 num_tc = qopt->num_tc;
int err;
- if (!num_tc) {
- stmmac_reset_tc_mqprio(ndev, extack);
- return 0;
- }
+ if (!num_tc)
+ return stmmac_reset_tc_mqprio(ndev, extack);
err = netdev_set_num_tc(ndev, num_tc);
if (err)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 161/398] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (159 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 160/398] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 162/398] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba Greg Kroah-Hartman
` (241 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Amit Machhiwal, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Amit Machhiwal <amachhiw@linux.ibm.com>
[ Upstream commit 0a416ee20bcccddf91ca5b63696a23b9d11d73aa ]
In kvmppc_svm_page_in(), if uv_page_in() fails after
kvmppc_uvmem_get_page() has succeeded, the secure device page is never
released. kvmppc_uvmem_get_page() sets a bit in kvmppc_uvmem_bitmap,
allocates a kvmppc_uvmem_page_pvt struct, marks the GFN as
KVMPPC_GFN_UVMEM_PFN, and calls zone_device_page_init() which sets
refcount=1 and locks the page. The subsequent goto out_finalize skips
the *mig.dst assignment, so migrate_vma_finalize() is a no-op for the
page, and none of those resources are ever reclaimed.
Each occurrence permanently consumes one entry from the firmware-bounded
secure memory pool (kvmppc_uvmem_bitmap), leaks pvt, and leaves the GFN
marked as secure — making it unusable for the lifetime of the VM.
The twin __kvmppc_svm_page_out() already handles the analogous uv_page_out()
failure correctly with unlock_page(dpage); __free_page(dpage). Apply
the same pattern here: unlock_page() followed by put_page(), which
chains through free_zone_device_folio() into kvmppc_uvmem_folio_free()
to clear the bitmap bit, free pvt, and reset the GFN state.
Reachable whenever uv_page_in() returns an error (e.g. UV pool
exhaustion) on any POWER9/10 + Ultravisor/PEF system.
Fixes: ca9f4942670c ("KVM: PPC: Book3S HV: Support for running secure guests")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kvm/book3s_hv_uvmem.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/arch/powerpc/kvm/book3s_hv_uvmem.c b/arch/powerpc/kvm/book3s_hv_uvmem.c
index 03f8c34fa0a20..01ab5c653d7c1 100644
--- a/arch/powerpc/kvm/book3s_hv_uvmem.c
+++ b/arch/powerpc/kvm/book3s_hv_uvmem.c
@@ -779,8 +779,11 @@ static int kvmppc_svm_page_in(struct vm_area_struct *vma,
if (spage) {
ret = uv_page_in(kvm->arch.lpid, pfn << page_shift,
gpa, 0, page_shift);
- if (ret)
+ if (ret) {
+ unlock_page(dpage);
+ put_page(dpage);
goto out_finalize;
+ }
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 215/438] net: prevent torn reads in netdev_tc_txq
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (213 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 214/438] net: stmmac: propagate FPE preemption-class mapping errors Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 216/438] net: stmmac: preserve real_num_tx_queues on mqprio setup failure Greg Kroah-Hartman
` (234 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 21ef2d065ad3f0cfbf2ae51260bf962a9fa2c643 ]
netdev_set_tc_queue() (and related helpers/drivers such as
netdev_bind_sb_channel_queue(), netdev_reset_tc(), and
netdev_unbind_sb_channel()) perform separate 16-bit writes to
dev->tc_to_txq[tc].count and dev->tc_to_txq[tc].offset.
Furthermore, memset() in netdev_reset_tc() and
netdev_unbind_sb_channel() provides no guarantee of performing
full 32-bit word stores.
Concurrent lockless readers (e.g. skb_tx_hash(), netdev_txq_to_tc(),
ixgbe_select_queue(), taprio, mqprio, FPE drivers) can observe torn
values where offset and count belong to inconsistent configurations.
Redefine struct netdev_tc_txq to embed count and offset inside a union
with a u32 combined field, allowing atomic manipulation via
READ_ONCE() and WRITE_ONCE().
Update all lockless readers and writers across the kernel to use
READ_ONCE() and WRITE_ONCE() on the combined field.
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260812085440.3917924-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 02fffd1939f6 ("net: stmmac: preserve real_num_tx_queues on mqprio setup failure")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/intel/igc/igc_tsn.c | 6 ++-
drivers/net/ethernet/intel/ixgbe/ixgbe_main.c | 7 +--
.../net/ethernet/mellanox/mlx5/core/en_main.c | 2 +-
drivers/net/ethernet/sfc/falcon/tx.c | 8 +++-
drivers/net/ethernet/sfc/siena/tx.c | 8 +++-
.../net/ethernet/stmicro/stmmac/stmmac_fpe.c | 14 ++++--
include/linux/netdevice.h | 9 +++-
net/core/dev.c | 46 +++++++++++++------
net/sched/sch_mqprio.c | 4 +-
net/sched/sch_mqprio_lib.c | 7 ++-
net/sched/sch_taprio.c | 26 ++++++-----
11 files changed, 94 insertions(+), 43 deletions(-)
diff --git a/drivers/net/ethernet/intel/igc/igc_tsn.c b/drivers/net/ethernet/intel/igc/igc_tsn.c
index 52de2bcbadbec..0c08650d3bb2d 100644
--- a/drivers/net/ethernet/intel/igc/igc_tsn.c
+++ b/drivers/net/ethernet/intel/igc/igc_tsn.c
@@ -183,13 +183,15 @@ static u32 igc_fpe_map_preempt_tc_to_queue(const struct igc_adapter *adapter,
u32 i, queue = 0;
for (i = 0; i < dev->num_tc; i++) {
+ struct netdev_tc_txq res;
u32 offset, count;
if (!(preemptible_tcs & BIT(i)))
continue;
- offset = dev->tc_to_txq[i].offset;
- count = dev->tc_to_txq[i].count;
+ res.combined = READ_ONCE(dev->tc_to_txq[i].combined);
+ offset = res.offset;
+ count = res.count;
queue |= GENMASK(offset + count - 1, offset);
}
diff --git a/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c b/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c
index 8873a8cc4a185..f91856498eb2d 100644
--- a/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c
+++ b/drivers/net/ethernet/intel/ixgbe/ixgbe_main.c
@@ -9273,10 +9273,11 @@ static u16 ixgbe_select_queue(struct net_device *dev, struct sk_buff *skb,
if (sb_dev) {
u8 tc = netdev_get_prio_tc_map(dev, skb->priority);
struct net_device *vdev = sb_dev;
+ struct netdev_tc_txq res;
- txq = vdev->tc_to_txq[tc].offset;
- txq += reciprocal_scale(skb_get_hash(skb),
- vdev->tc_to_txq[tc].count);
+ res.combined = READ_ONCE(vdev->tc_to_txq[tc].combined);
+ txq = res.offset;
+ txq += reciprocal_scale(skb_get_hash(skb), res.count);
return txq;
}
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_main.c b/drivers/net/ethernet/mellanox/mlx5/core/en_main.c
index f0407a850ea82..8634c970cd002 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_main.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_main.c
@@ -3247,7 +3247,7 @@ static int mlx5e_update_tc_and_tx_queues(struct mlx5e_priv *priv)
old_num_txqs = netdev->real_num_tx_queues;
old_ntc = netdev->num_tc ? : 1;
for (i = 0; i < ARRAY_SIZE(old_tc_to_txq); i++)
- old_tc_to_txq[i] = netdev->tc_to_txq[i];
+ old_tc_to_txq[i].combined = READ_ONCE(netdev->tc_to_txq[i].combined);
nch = priv->channels.params.num_channels;
ntc = priv->channels.params.mqprio.num_tc;
diff --git a/drivers/net/ethernet/sfc/falcon/tx.c b/drivers/net/ethernet/sfc/falcon/tx.c
index 9e18aaf44badd..e4d47d26a87a0 100644
--- a/drivers/net/ethernet/sfc/falcon/tx.c
+++ b/drivers/net/ethernet/sfc/falcon/tx.c
@@ -439,8 +439,12 @@ int ef4_setup_tc(struct net_device *net_dev, enum tc_setup_type type,
return 0;
for (tc = 0; tc < num_tc; tc++) {
- net_dev->tc_to_txq[tc].offset = tc * efx->n_tx_channels;
- net_dev->tc_to_txq[tc].count = efx->n_tx_channels;
+ struct netdev_tc_txq res = {
+ .offset = tc * efx->n_tx_channels,
+ .count = efx->n_tx_channels,
+ };
+
+ WRITE_ONCE(net_dev->tc_to_txq[tc].combined, res.combined);
}
if (num_tc > net_dev->num_tc) {
diff --git a/drivers/net/ethernet/sfc/siena/tx.c b/drivers/net/ethernet/sfc/siena/tx.c
index 91e87594ed1ea..1ce98f8fdaf81 100644
--- a/drivers/net/ethernet/sfc/siena/tx.c
+++ b/drivers/net/ethernet/sfc/siena/tx.c
@@ -380,8 +380,12 @@ int efx_siena_setup_tc(struct net_device *net_dev, enum tc_setup_type type,
return 0;
for (tc = 0; tc < num_tc; tc++) {
- net_dev->tc_to_txq[tc].offset = tc * efx->n_tx_channels;
- net_dev->tc_to_txq[tc].count = efx->n_tx_channels;
+ struct netdev_tc_txq res = {
+ .offset = tc * efx->n_tx_channels,
+ .count = efx->n_tx_channels,
+ };
+
+ WRITE_ONCE(net_dev->tc_to_txq[tc].combined, res.combined);
}
net_dev->num_tc = num_tc;
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_fpe.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_fpe.c
index c54c702243517..c889204a7aa5d 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_fpe.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_fpe.c
@@ -217,8 +217,11 @@ int dwmac5_fpe_map_preemption_class(struct net_device *ndev,
* and is direct one-to-one mapping."
*/
for (u32 tc = 0; tc < num_tc; tc++) {
- count = ndev->tc_to_txq[tc].count;
- offset = ndev->tc_to_txq[tc].offset;
+ struct netdev_tc_txq res;
+
+ res.combined = READ_ONCE(ndev->tc_to_txq[tc].combined);
+ count = res.count;
+ offset = res.offset;
if (pclass & BIT(tc))
preemptible_txqs |= GENMASK(offset + count - 1, offset);
@@ -275,8 +278,11 @@ int dwxgmac3_fpe_map_preemption_class(struct net_device *ndev,
* any of the scheduling algorithms."
*/
for (u32 tc = 0; tc < num_tc; tc++) {
- count = ndev->tc_to_txq[tc].count;
- offset = ndev->tc_to_txq[tc].offset;
+ struct netdev_tc_txq res;
+
+ res.combined = READ_ONCE(ndev->tc_to_txq[tc].combined);
+ count = res.count;
+ offset = res.offset;
if (pclass & BIT(tc))
preemptible_txqs |= GENMASK(offset + count - 1, offset);
diff --git a/include/linux/netdevice.h b/include/linux/netdevice.h
index 6a86a211fff57..14bcdcd44d1d5 100644
--- a/include/linux/netdevice.h
+++ b/include/linux/netdevice.h
@@ -832,8 +832,13 @@ struct xps_dev_maps {
#define TC_BITMASK 15
/* HW offloaded queuing disciplines txq count and offset maps */
struct netdev_tc_txq {
- u16 count;
- u16 offset;
+ union {
+ struct {
+ u16 count;
+ u16 offset;
+ };
+ u32 combined;
+ };
};
#if defined(CONFIG_FCOE) || defined(CONFIG_FCOE_MODULE)
diff --git a/net/core/dev.c b/net/core/dev.c
index ff25e4c71588e..65cdaf0c81f71 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -2649,11 +2649,13 @@ EXPORT_SYMBOL_GPL(dev_queue_xmit_nit);
*/
static void netif_setup_tc(struct net_device *dev, unsigned int txq)
{
+ struct netdev_tc_txq res;
int i;
- struct netdev_tc_txq *tc = &dev->tc_to_txq[0];
+
+ res.combined = READ_ONCE(dev->tc_to_txq[0].combined);
/* If TC0 is invalidated disable TC mapping */
- if (tc->offset + tc->count > txq) {
+ if (res.offset + res.count > txq) {
netdev_warn(dev, "Number of in use tx queues changed invalidating tc mappings. Priority traffic classification disabled!\n");
dev->num_tc = 0;
return;
@@ -2663,8 +2665,8 @@ static void netif_setup_tc(struct net_device *dev, unsigned int txq)
for (i = 1; i < TC_BITMASK + 1; i++) {
int q = netdev_get_prio_tc_map(dev, i);
- tc = &dev->tc_to_txq[q];
- if (tc->offset + tc->count > txq) {
+ res.combined = READ_ONCE(dev->tc_to_txq[q].combined);
+ if (res.offset + res.count > txq) {
netdev_warn(dev, "Number of in use tx queues changed. Priority %i to tc mapping %i is no longer valid. Setting map to 0\n",
i, q);
netdev_set_prio_tc_map(dev, i, 0);
@@ -2680,7 +2682,10 @@ int netdev_txq_to_tc(struct net_device *dev, unsigned int txq)
/* walk through the TCs and see if it falls into any of them */
for (i = 0; i < TC_MAX_QUEUE; i++, tc++) {
- if ((txq - tc->offset) < tc->count)
+ struct netdev_tc_txq res;
+
+ res.combined = READ_ONCE(tc->combined);
+ if ((txq - res.offset) < res.count)
return i;
}
@@ -3100,6 +3105,8 @@ static void netdev_unbind_all_sb_channels(struct net_device *dev)
void netdev_reset_tc(struct net_device *dev)
{
+ int i;
+
#ifdef CONFIG_XPS
netif_reset_xps_queues_gt(dev, 0);
#endif
@@ -3107,21 +3114,26 @@ void netdev_reset_tc(struct net_device *dev)
/* Reset TC configuration of device */
dev->num_tc = 0;
- memset(dev->tc_to_txq, 0, sizeof(dev->tc_to_txq));
+ for (i = 0; i < TC_MAX_QUEUE; i++)
+ WRITE_ONCE(dev->tc_to_txq[i].combined, 0);
memset(dev->prio_tc_map, 0, sizeof(dev->prio_tc_map));
}
EXPORT_SYMBOL(netdev_reset_tc);
int netdev_set_tc_queue(struct net_device *dev, u8 tc, u16 count, u16 offset)
{
+ struct netdev_tc_txq res = {
+ .count = count,
+ .offset = offset,
+ };
+
if (tc >= dev->num_tc)
return -EINVAL;
#ifdef CONFIG_XPS
netif_reset_xps_queues(dev, offset, count);
#endif
- dev->tc_to_txq[tc].count = count;
- dev->tc_to_txq[tc].offset = offset;
+ WRITE_ONCE(dev->tc_to_txq[tc].combined, res.combined);
return 0;
}
EXPORT_SYMBOL(netdev_set_tc_queue);
@@ -3145,11 +3157,13 @@ void netdev_unbind_sb_channel(struct net_device *dev,
struct net_device *sb_dev)
{
struct netdev_queue *txq = &dev->_tx[dev->num_tx_queues];
+ int i;
#ifdef CONFIG_XPS
netif_reset_xps_queues_gt(sb_dev, 0);
#endif
- memset(sb_dev->tc_to_txq, 0, sizeof(sb_dev->tc_to_txq));
+ for (i = 0; i < TC_MAX_QUEUE; i++)
+ WRITE_ONCE(sb_dev->tc_to_txq[i].combined, 0);
memset(sb_dev->prio_tc_map, 0, sizeof(sb_dev->prio_tc_map));
while (txq-- != &dev->_tx[0]) {
@@ -3172,8 +3186,12 @@ int netdev_bind_sb_channel_queue(struct net_device *dev,
return -EINVAL;
/* Record the mapping */
- sb_dev->tc_to_txq[tc].count = count;
- sb_dev->tc_to_txq[tc].offset = offset;
+ struct netdev_tc_txq res = {
+ .count = count,
+ .offset = offset,
+ };
+
+ WRITE_ONCE(sb_dev->tc_to_txq[tc].combined, res.combined);
/* Provide a way for Tx queue to find the tc_to_txq map or
* XPS map for itself.
@@ -3539,9 +3557,11 @@ static u16 skb_tx_hash(const struct net_device *dev,
if (dev->num_tc) {
u8 tc = netdev_get_prio_tc_map(dev, skb->priority);
+ struct netdev_tc_txq res;
- qoffset = sb_dev->tc_to_txq[tc].offset;
- qcount = sb_dev->tc_to_txq[tc].count;
+ res.combined = READ_ONCE(sb_dev->tc_to_txq[tc].combined);
+ qoffset = res.offset;
+ qcount = res.count;
if (unlikely(!qcount)) {
net_warn_ratelimited("%s: invalid qcount, qoffset %u for tc %u\n",
sb_dev->name, qoffset, tc);
diff --git a/net/sched/sch_mqprio.c b/net/sched/sch_mqprio.c
index ae991fc25b43f..6ced7008ef5c8 100644
--- a/net/sched/sch_mqprio.c
+++ b/net/sched/sch_mqprio.c
@@ -679,12 +679,14 @@ static int mqprio_dump_class_stats(struct Qdisc *sch, unsigned long cl,
rcu_read_lock();
if (cl >= TC_H_MIN_PRIORITY) {
struct net_device *dev = qdisc_dev(sch);
- struct netdev_tc_txq tc = dev->tc_to_txq[cl & TC_BITMASK];
+ struct netdev_tc_txq tc;
struct gnet_stats_queue qstats = {0};
struct gnet_stats_basic_sync bstats;
u32 qlen = 0;
int i;
+ tc.combined = READ_ONCE(dev->tc_to_txq[cl & TC_BITMASK].combined);
+
gnet_stats_basic_sync_init(&bstats);
for (i = tc.offset; i < tc.offset + tc.count; i++) {
diff --git a/net/sched/sch_mqprio_lib.c b/net/sched/sch_mqprio_lib.c
index b3a5572c167b7..b60e130c70781 100644
--- a/net/sched/sch_mqprio_lib.c
+++ b/net/sched/sch_mqprio_lib.c
@@ -108,8 +108,11 @@ void mqprio_qopt_reconstruct(struct net_device *dev, struct tc_mqprio_qopt *qopt
memcpy(qopt->prio_tc_map, dev->prio_tc_map, sizeof(qopt->prio_tc_map));
for (tc = 0; tc < num_tc; tc++) {
- qopt->count[tc] = dev->tc_to_txq[tc].count;
- qopt->offset[tc] = dev->tc_to_txq[tc].offset;
+ struct netdev_tc_txq res;
+
+ res.combined = READ_ONCE(dev->tc_to_txq[tc].combined);
+ qopt->count[tc] = res.count;
+ qopt->offset[tc] = res.offset;
}
}
EXPORT_SYMBOL_GPL(mqprio_qopt_reconstruct);
diff --git a/net/sched/sch_taprio.c b/net/sched/sch_taprio.c
index 299234a5f0fe6..7d5fe93a4c124 100644
--- a/net/sched/sch_taprio.c
+++ b/net/sched/sch_taprio.c
@@ -762,12 +762,13 @@ static struct sk_buff *taprio_dequeue_from_txq(struct Qdisc *sch, int txq,
static void taprio_next_tc_txq(struct net_device *dev, int tc, int *txq)
{
- int offset = dev->tc_to_txq[tc].offset;
- int count = dev->tc_to_txq[tc].count;
+ struct netdev_tc_txq res;
+
+ res.combined = READ_ONCE(dev->tc_to_txq[tc].combined);
(*txq)++;
- if (*txq == offset + count)
- *txq = offset;
+ if (*txq == res.offset + res.count)
+ *txq = res.offset;
}
/* Prioritize higher traffic classes, and select among TXQs belonging to the
@@ -1441,15 +1442,14 @@ static u32 tc_map_to_queue_mask(struct net_device *dev, u32 tc_mask)
u32 i, queue_mask = 0;
for (i = 0; i < dev->num_tc; i++) {
- u32 offset, count;
+ struct netdev_tc_txq res;
if (!(tc_mask & BIT(i)))
continue;
- offset = dev->tc_to_txq[i].offset;
- count = dev->tc_to_txq[i].count;
+ res.combined = READ_ONCE(dev->tc_to_txq[i].combined);
- queue_mask |= GENMASK(offset + count - 1, offset);
+ queue_mask |= GENMASK(res.offset + res.count - 1, res.offset);
}
return queue_mask;
@@ -1802,10 +1802,14 @@ static int taprio_mqprio_cmp(const struct net_device *dev,
if (!mqprio || mqprio->num_tc != dev->num_tc)
return -1;
- for (i = 0; i < mqprio->num_tc; i++)
- if (dev->tc_to_txq[i].count != mqprio->count[i] ||
- dev->tc_to_txq[i].offset != mqprio->offset[i])
+ for (i = 0; i < mqprio->num_tc; i++) {
+ struct netdev_tc_txq res;
+
+ res.combined = READ_ONCE(dev->tc_to_txq[i].combined);
+ if (res.count != mqprio->count[i] ||
+ res.offset != mqprio->offset[i])
return -1;
+ }
for (i = 0; i <= TC_BITMASK; i++)
if (dev->prio_tc_map[i] != mqprio->prio_tc_map[i])
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 162/398] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (160 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 161/398] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 163/398] futex: Also allocate private hash on vfork() Greg Kroah-Hartman
` (240 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM),
R Nageswara Sastry, Shivaprasad G Bhat, Gautam Menghani,
Madhavan Srinivasan, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivaprasad G Bhat <sbhat@linux.ibm.com>
[ Upstream commit 0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71 ]
The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified
IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba().
While doing so, the passed in argument npages is ignored and constant
value '1' is used leaving out a possible overflow as the callers can
legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT
cases.
Fix this by accounting for 'npages', checking for arithmetic overflow,
and verifying that the entire requested range (ioba - offset + npages)
does not exceed the table capacity 'size'.
Fixes: b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking")
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Signed-off-by: Shivaprasad G Bhat <sbhat@linux.ibm.com>
Signed-off-by: Gautam Menghani <gautam@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kernel/iommu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/powerpc/kernel/iommu.c b/arch/powerpc/kernel/iommu.c
index 244eb4857e7f4..0a7d14f651e8a 100644
--- a/arch/powerpc/kernel/iommu.c
+++ b/arch/powerpc/kernel/iommu.c
@@ -1075,7 +1075,7 @@ int iommu_tce_check_ioba(unsigned long page_shift,
if (ioba < offset)
return -EINVAL;
- if ((ioba + 1) > (offset + size))
+ if ((ioba + npages < ioba) || (ioba - offset + npages > size))
return -EINVAL;
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 216/438] net: stmmac: preserve real_num_tx_queues on mqprio setup failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (214 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 215/438] net: prevent torn reads in netdev_tc_txq Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 217/438] net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() Greg Kroah-Hartman
` (233 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Jakub Kicinski,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit 02fffd1939f6b45892f61822459953ce95e42948 ]
With the FPE preemption-class mapping error now propagated from
stmmac_fpe_map_preemption_class(), tc_setup_dwmac510_mqprio() can fail
on the mapping step. The error path used to call stmmac_reset_tc_mqprio(),
which resets the number of real TX queues to priv->plat->tx_queues_to_use
(the platform maximum), overwriting the value that was active before the
offload was attempted (for example a lower count left over from a previous
mqprio configuration).
The issue can be triggered using the following configuration:
# First mqprio config lowers the hw queue count below the platform
# default (e.g. 8 TX queues).
$tc qdisc add dev eth0 root handle 1: mqprio queues 2@0 2@2
# Replace mqprio configuration with a second one that fails FPE
# preemption-class mapping. stmmac driver resets the real_num_tx_queues
# to the platform maximum, losing the previous configuration.
$tc qdisc replace dev eth0 root handle 2: mqprio queues 2@0 2@2 fp E P
Save ndev->real_num_tx_queues before lowering it and restore it,
together with the TC-to-queue and priority-to-TC mappings, when the FPE
preemption-class mapping fails, instead of resetting the queue count to
the platform maximum.
Note that a failed setup makes the qdisc layer run mqprio_destroy() on
the new qdisc. Because priv->hw_offload is only assigned after
ndo_setup_tc() succeeds, mqprio_destroy() calls netdev_set_num_tc(dev, 0),
so dev->num_tc ends up 0 regardless of the driver-side restore and the
previous qdisc is not reactivated. The restore is still needed to keep
real_num_tx_queues and to avoid leaving the failed configuration's
TC-to-queue and priority-to-TC mappings in place.
Fixes: 195e4f409a40 ("net: stmmac: support fp parameter of tc-mqprio")
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Link: https://patch.msgid.link/20260911-stmmac-tc_setup_dwmac510_mqprio-error-path-v3-2-a76b1e2547c1@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/ethernet/stmicro/stmmac/stmmac_tc.c | 82 ++++++++++++++-----
1 file changed, 62 insertions(+), 20 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
index 5398616fcdfea..42a00446e9b41 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
@@ -1237,6 +1237,30 @@ static int tc_query_caps(struct stmmac_priv *priv,
}
}
+static int stmmac_set_ndev_tcs(struct net_device *ndev, u8 ntc,
+ struct netdev_tc_txq *tc_to_txq)
+{
+ int i, err;
+
+ netdev_reset_tc(ndev);
+ if (!ntc)
+ return 0;
+
+ err = netdev_set_num_tc(ndev, ntc);
+ if (err)
+ return err;
+
+ for (i = 0; i < ntc; i++) {
+ u16 count, offset;
+
+ count = tc_to_txq[i].count;
+ offset = tc_to_txq[i].offset;
+ netdev_set_tc_queue(ndev, i, count, offset);
+ }
+
+ return 0;
+}
+
static int stmmac_reset_tc_mqprio(struct net_device *ndev,
struct netlink_ext_ack *extack)
{
@@ -1251,43 +1275,61 @@ static int stmmac_reset_tc_mqprio(struct net_device *ndev,
static int tc_setup_dwmac510_mqprio(struct stmmac_priv *priv,
struct tc_mqprio_qopt_offload *mqprio)
{
+ unsigned int ndev_num_tx_queues, num_tx_queues = 0;
+ struct netdev_tc_txq ndev_tc_to_txq[TC_MAX_QUEUE];
+ struct netdev_tc_txq tc_to_txq[TC_MAX_QUEUE] = {};
struct netlink_ext_ack *extack = mqprio->extack;
struct tc_mqprio_qopt *qopt = &mqprio->qopt;
- u32 offset, count, num_stack_tx_queues = 0;
struct net_device *ndev = priv->dev;
- u32 num_tc = qopt->num_tc;
- int err;
+ u8 ndev_prio_tc_map[TC_BITMASK + 1];
+ int i, err, ndev_ntc;
- if (!num_tc)
+ if (!qopt->num_tc)
return stmmac_reset_tc_mqprio(ndev, extack);
- err = netdev_set_num_tc(ndev, num_tc);
- if (err)
- return err;
-
- for (u32 tc = 0; tc < num_tc; tc++) {
- offset = qopt->offset[tc];
- count = qopt->count[tc];
- num_stack_tx_queues += count;
+ if (qopt->num_tc > ARRAY_SIZE(tc_to_txq))
+ return -EINVAL;
- err = netdev_set_tc_queue(ndev, tc, count, offset);
- if (err)
- goto err_reset_tc;
+ /* save current tc values for reset */
+ ndev_ntc = netdev_get_num_tc(ndev);
+ for (i = 0; i < ARRAY_SIZE(ndev->tc_to_txq); i++)
+ ndev_tc_to_txq[i].combined =
+ READ_ONCE(ndev->tc_to_txq[i].combined);
+ for (i = 0; i < ARRAY_SIZE(ndev_prio_tc_map); i++)
+ ndev_prio_tc_map[i] = READ_ONCE(ndev->prio_tc_map[i]);
+
+ for (i = 0; i < qopt->num_tc; i++) {
+ tc_to_txq[i] = (struct netdev_tc_txq) {
+ .count = qopt->count[i],
+ .offset = qopt->offset[i],
+ };
+ num_tx_queues += qopt->count[i];
}
- err = netif_set_real_num_tx_queues(ndev, num_stack_tx_queues);
+ err = stmmac_set_ndev_tcs(ndev, qopt->num_tc, tc_to_txq);
+ if (err)
+ goto error_reset_tc;
+
+ ndev_num_tx_queues = ndev->real_num_tx_queues;
+ err = netif_set_real_num_tx_queues(ndev, num_tx_queues);
if (err)
- goto err_reset_tc;
+ goto error_reset_tc;
err = stmmac_fpe_map_preemption_class(priv, ndev, extack,
mqprio->preemptible_tcs);
if (err)
- goto err_reset_tc;
+ goto error_reset_num_tx_queues;
return 0;
-err_reset_tc:
- stmmac_reset_tc_mqprio(ndev, extack);
+error_reset_num_tx_queues:
+ if (netif_set_real_num_tx_queues(ndev, ndev_num_tx_queues))
+ netdev_warn(ndev, "Failed to restore %u TX queues\n",
+ ndev_num_tx_queues);
+error_reset_tc:
+ stmmac_set_ndev_tcs(ndev, ndev_ntc, ndev_tc_to_txq);
+ for (i = 0; i < ARRAY_SIZE(ndev_prio_tc_map); i++)
+ netdev_set_prio_tc_map(ndev, i, ndev_prio_tc_map[i]);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 163/398] futex: Also allocate private hash on vfork()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (161 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 162/398] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 164/398] btrfs: more trivial BTRFS_PATH_AUTO_FREE conversions Greg Kroah-Hartman
` (239 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jann Horn, Peter Zijlstra (Intel),
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Zijlstra <peterz@infradead.org>
[ Upstream commit b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5 ]
As Jann demonstrated, it is entirely feasible to access the mm through vfork().
Therefore we need to allocate a private hash on vfork() as well as any other
CLONE_VM user.
Specifically, it must be avoided to have (private) futex waiters before
allocating the private hash.
Fixes: ee9dce44362b ("futex: Drop CLONE_THREAD requirement for private default hash alloc")
Reported-by: Jann Horn <jannh@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/20260911090447.GT788244@noisy.programming.kicks-ass.net
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/fork.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/kernel/fork.c b/kernel/fork.c
index 295cf8cf719ea..7be5736d44c7f 100644
--- a/kernel/fork.c
+++ b/kernel/fork.c
@@ -1918,9 +1918,9 @@ static bool need_futex_hash_allocate_default(u64 clone_flags)
{
/*
* Allocate a default futex hash for any sibling that will
- * share the parent's mm, except vfork.
+ * share the parent's mm.
*/
- return (clone_flags & (CLONE_VM | CLONE_VFORK)) == CLONE_VM;
+ return clone_flags & CLONE_VM;
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 217/438] net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (215 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 216/438] net: stmmac: preserve real_num_tx_queues on mqprio setup failure Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 218/438] x86/kprobes: Fix crash when probing CS CALL instructions Greg Kroah-Hartman
` (232 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Zahka, Willem de Bruijn,
Jakub Kicinski, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Zahka <daniel.zahka@gmail.com>
[ Upstream commit a41f24c612c3f5139a3143307eb85bbcf1bd4d07 ]
PSP conflicts with TLS ULP in its usage of both skb->decrypted and
sk->sk_validate_xmit_skb().
Make PSP mutually exclusive with TLS ULP, the only other user of either
of these. As other users of skb->decrypted come along, they can be added
to sk_has_decrypt_user(). It would make sense to also assert that
sk->sk_validate_xmit_skb() is also NULL in both of these setup paths for
similar future proofing, but the PSP listener/sk_clone() path is still
broken and it could be seen as a regression to not allow rx assoc to run
on a child of a listener socket with PSP tx assoc state.
Include all TCP ULPs in the sk_has_decrypt_user() check, even though TLS
is the only one that conflicts with PSP via the decrypted bit. This is
intentional because PSP was not designed to be used with ULPs. It is
best to close off surface area that may make bugs reachable, until
someone wishes to design and test an actual user of PSP with ULPs.
Fixes: 6b46ca260e22 ("net: psp: add socket security association code")
Signed-off-by: Daniel Zahka <daniel.zahka@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260915-psp-ktls-fix-v2-1-0eedc3b148ec@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/sock.h | 2 ++
net/core/sock.c | 7 +++++++
net/ipv4/tcp_ulp.c | 4 ++++
net/psp/psp_sock.c | 4 ++++
4 files changed, 17 insertions(+)
diff --git a/include/net/sock.h b/include/net/sock.h
index 51185222aac29..60ea55dc18854 100644
--- a/include/net/sock.h
+++ b/include/net/sock.h
@@ -2312,6 +2312,8 @@ static inline void sk_gso_disable(struct sock *sk)
sk->sk_route_caps &= ~NETIF_F_GSO_MASK;
}
+bool sk_has_decrypt_user(const struct sock *sk);
+
static inline int skb_do_copy_data_nocache(struct sock *sk, struct sk_buff *skb,
struct iov_iter *from, char *to,
int copy, int offset)
diff --git a/net/core/sock.c b/net/core/sock.c
index 5c1a1d1950752..4395509ab9dcd 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -142,6 +142,7 @@
#include <trace/events/sock.h>
+#include <net/psp.h>
#include <net/tcp.h>
#include <net/busy_poll.h>
#include <net/phonet/phonet.h>
@@ -2667,6 +2668,12 @@ void sk_setup_caps(struct sock *sk, struct dst_entry *dst)
}
EXPORT_SYMBOL_GPL(sk_setup_caps);
+bool sk_has_decrypt_user(const struct sock *sk)
+{
+ return psp_sk_assoc(sk) ||
+ (sk_is_inet(sk) && inet_csk_has_ulp(sk)); /* for tls */
+}
+
/*
* Simple resource managers for sockets.
*/
diff --git a/net/ipv4/tcp_ulp.c b/net/ipv4/tcp_ulp.c
index 2aa442128630e..b58045df101e5 100644
--- a/net/ipv4/tcp_ulp.c
+++ b/net/ipv4/tcp_ulp.c
@@ -136,6 +136,10 @@ static int __tcp_set_ulp(struct sock *sk, const struct tcp_ulp_ops *ulp_ops)
if (icsk->icsk_ulp_ops)
goto out_err;
+ err = -EINVAL;
+ if (sk_has_decrypt_user(sk))
+ goto out_err;
+
if (sk->sk_socket)
clear_bit(SOCK_SUPPORT_ZC, &sk->sk_socket->flags);
diff --git a/net/psp/psp_sock.c b/net/psp/psp_sock.c
index 07dc4cf741f33..ce423d14ad267 100644
--- a/net/psp/psp_sock.c
+++ b/net/psp/psp_sock.c
@@ -143,6 +143,10 @@ int psp_sock_assoc_set_rx(struct sock *sk, struct psp_assoc *pas,
NL_SET_ERR_MSG(extack, "Socket already has PSP state");
err = -EBUSY;
goto exit_unlock;
+ } else if (sk_has_decrypt_user(sk)) {
+ NL_SET_ERR_MSG(extack, "Socket has incompatible state");
+ err = -EINVAL;
+ goto exit_unlock;
}
refcount_inc(&pas->refcnt);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 164/398] btrfs: more trivial BTRFS_PATH_AUTO_FREE conversions
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (162 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 163/398] futex: Also allocate private hash on vfork() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 165/398] btrfs: handle lack of space when cleaning up verity items Greg Kroah-Hartman
` (238 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sun YangKai, David Sterba,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sun YangKai <sunk67188@gmail.com>
[ Upstream commit 7fc35cc559cb64221a7fb1d2cf48cda8fd31fc9e ]
Convert more of the trivial pattern for the auto freeing of btrfs_path
with goto -> return conversions where applicable.
Signed-off-by: Sun YangKai <sunk67188@gmail.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Stable-dep-of: 76bf149cd029 ("btrfs: handle lack of space when cleaning up verity items")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/uuid-tree.c | 120 ++++++++++++---------------------
fs/btrfs/verity.c | 29 +++-----
fs/btrfs/volumes.c | 153 ++++++++++++++++---------------------------
fs/btrfs/xattr.c | 36 ++++------
4 files changed, 119 insertions(+), 219 deletions(-)
diff --git a/fs/btrfs/uuid-tree.c b/fs/btrfs/uuid-tree.c
index 146d78fac8f83..a3c244ff3a0c5 100644
--- a/fs/btrfs/uuid-tree.c
+++ b/fs/btrfs/uuid-tree.c
@@ -27,32 +27,26 @@ static int btrfs_uuid_tree_lookup(struct btrfs_root *uuid_root, const u8 *uuid,
u8 type, u64 subid)
{
int ret;
- struct btrfs_path *path = NULL;
+ BTRFS_PATH_AUTO_FREE(path);
struct extent_buffer *eb;
int slot;
u32 item_size;
unsigned long offset;
struct btrfs_key key;
- if (WARN_ON_ONCE(!uuid_root)) {
- ret = -ENOENT;
- goto out;
- }
+ if (WARN_ON_ONCE(!uuid_root))
+ return -ENOENT;
path = btrfs_alloc_path();
- if (!path) {
- ret = -ENOMEM;
- goto out;
- }
+ if (!path)
+ return -ENOMEM;
btrfs_uuid_to_key(uuid, type, &key);
ret = btrfs_search_slot(NULL, uuid_root, &key, path, 0, 0);
- if (ret < 0) {
- goto out;
- } else if (ret > 0) {
- ret = -ENOENT;
- goto out;
- }
+ if (ret < 0)
+ return ret;
+ if (ret > 0)
+ return -ENOENT;
eb = path->nodes[0];
slot = path->slots[0];
@@ -64,7 +58,7 @@ static int btrfs_uuid_tree_lookup(struct btrfs_root *uuid_root, const u8 *uuid,
btrfs_warn(uuid_root->fs_info,
"uuid item with illegal size %lu!",
(unsigned long)item_size);
- goto out;
+ return ret;
}
while (item_size) {
__le64 data;
@@ -78,8 +72,6 @@ static int btrfs_uuid_tree_lookup(struct btrfs_root *uuid_root, const u8 *uuid,
item_size -= sizeof(data);
}
-out:
- btrfs_free_path(path);
return ret;
}
@@ -89,7 +81,7 @@ int btrfs_uuid_tree_add(struct btrfs_trans_handle *trans, const u8 *uuid, u8 typ
struct btrfs_fs_info *fs_info = trans->fs_info;
struct btrfs_root *uuid_root = fs_info->uuid_root;
int ret;
- struct btrfs_path *path = NULL;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_key key;
struct extent_buffer *eb;
int slot;
@@ -100,18 +92,14 @@ int btrfs_uuid_tree_add(struct btrfs_trans_handle *trans, const u8 *uuid, u8 typ
if (ret != -ENOENT)
return ret;
- if (WARN_ON_ONCE(!uuid_root)) {
- ret = -EINVAL;
- goto out;
- }
+ if (WARN_ON_ONCE(!uuid_root))
+ return -EINVAL;
btrfs_uuid_to_key(uuid, type, &key);
path = btrfs_alloc_path();
- if (!path) {
- ret = -ENOMEM;
- goto out;
- }
+ if (!path)
+ return -ENOMEM;
ret = btrfs_insert_empty_item(trans, uuid_root, path, &key,
sizeof(subid_le));
@@ -134,15 +122,12 @@ int btrfs_uuid_tree_add(struct btrfs_trans_handle *trans, const u8 *uuid, u8 typ
btrfs_warn(fs_info,
"insert uuid item failed %d (0x%016llx, 0x%016llx) type %u!",
ret, key.objectid, key.offset, type);
- goto out;
+ return ret;
}
- ret = 0;
subid_le = cpu_to_le64(subid_cpu);
write_extent_buffer(eb, &subid_le, offset, sizeof(subid_le));
-out:
- btrfs_free_path(path);
- return ret;
+ return 0;
}
int btrfs_uuid_tree_remove(struct btrfs_trans_handle *trans, const u8 *uuid, u8 type,
@@ -151,7 +136,7 @@ int btrfs_uuid_tree_remove(struct btrfs_trans_handle *trans, const u8 *uuid, u8
struct btrfs_fs_info *fs_info = trans->fs_info;
struct btrfs_root *uuid_root = fs_info->uuid_root;
int ret;
- struct btrfs_path *path = NULL;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_key key;
struct extent_buffer *eb;
int slot;
@@ -161,29 +146,23 @@ int btrfs_uuid_tree_remove(struct btrfs_trans_handle *trans, const u8 *uuid, u8
unsigned long move_src;
unsigned long move_len;
- if (WARN_ON_ONCE(!uuid_root)) {
- ret = -EINVAL;
- goto out;
- }
+ if (WARN_ON_ONCE(!uuid_root))
+ return -EINVAL;
btrfs_uuid_to_key(uuid, type, &key);
path = btrfs_alloc_path();
- if (!path) {
- ret = -ENOMEM;
- goto out;
- }
+ if (!path)
+ return -ENOMEM;
ret = btrfs_search_slot(trans, uuid_root, &key, path, -1, 1);
if (ret < 0) {
btrfs_warn(fs_info, "error %d while searching for uuid item!",
ret);
- goto out;
- }
- if (ret > 0) {
- ret = -ENOENT;
- goto out;
+ return ret;
}
+ if (ret > 0)
+ return -ENOENT;
eb = path->nodes[0];
slot = path->slots[0];
@@ -192,8 +171,7 @@ int btrfs_uuid_tree_remove(struct btrfs_trans_handle *trans, const u8 *uuid, u8
if (!IS_ALIGNED(item_size, sizeof(u64))) {
btrfs_warn(fs_info, "uuid item with illegal size %lu!",
(unsigned long)item_size);
- ret = -ENOENT;
- goto out;
+ return -ENOENT;
}
while (item_size) {
__le64 read_subid;
@@ -205,16 +183,12 @@ int btrfs_uuid_tree_remove(struct btrfs_trans_handle *trans, const u8 *uuid, u8
item_size -= sizeof(read_subid);
}
- if (!item_size) {
- ret = -ENOENT;
- goto out;
- }
+ if (!item_size)
+ return -ENOENT;
item_size = btrfs_item_size(eb, slot);
- if (item_size == sizeof(subid)) {
- ret = btrfs_del_item(trans, uuid_root, path);
- goto out;
- }
+ if (item_size == sizeof(subid))
+ return btrfs_del_item(trans, uuid_root, path);
move_dst = offset;
move_src = offset + sizeof(subid);
@@ -222,9 +196,7 @@ int btrfs_uuid_tree_remove(struct btrfs_trans_handle *trans, const u8 *uuid, u8
memmove_extent_buffer(eb, move_dst, move_src, move_len);
btrfs_truncate_item(trans, path, item_size - sizeof(subid), 1);
-out:
- btrfs_free_path(path);
- return ret;
+ return 0;
}
/*
@@ -331,7 +303,7 @@ int btrfs_uuid_tree_iterate(struct btrfs_fs_info *fs_info)
{
struct btrfs_root *root = fs_info->uuid_root;
struct btrfs_key key;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
int ret = 0;
struct extent_buffer *leaf;
int slot;
@@ -339,10 +311,8 @@ int btrfs_uuid_tree_iterate(struct btrfs_fs_info *fs_info)
unsigned long offset;
path = btrfs_alloc_path();
- if (!path) {
- ret = -ENOMEM;
- goto out;
- }
+ if (!path)
+ return -ENOMEM;
key.objectid = 0;
key.type = 0;
@@ -350,17 +320,15 @@ int btrfs_uuid_tree_iterate(struct btrfs_fs_info *fs_info)
again_search_slot:
ret = btrfs_search_forward(root, &key, path, BTRFS_OLDEST_GENERATION);
- if (ret) {
- if (ret > 0)
- ret = 0;
- goto out;
- }
+ if (ret < 0)
+ return ret;
+ if (ret > 0)
+ return 0;
while (1) {
- if (btrfs_fs_closing(fs_info)) {
- ret = -EINTR;
- goto out;
- }
+ if (btrfs_fs_closing(fs_info))
+ return -EINTR;
+
cond_resched();
leaf = path->nodes[0];
slot = path->slots[0];
@@ -391,7 +359,7 @@ int btrfs_uuid_tree_iterate(struct btrfs_fs_info *fs_info)
ret = btrfs_check_uuid_tree_entry(fs_info, uuid,
key.type, subid_cpu);
if (ret < 0)
- goto out;
+ return ret;
if (ret > 0) {
btrfs_release_path(path);
ret = btrfs_uuid_iter_rem(root, uuid, key.type,
@@ -407,7 +375,7 @@ int btrfs_uuid_tree_iterate(struct btrfs_fs_info *fs_info)
goto again_search_slot;
}
if (ret < 0 && ret != -ENOENT)
- goto out;
+ return ret;
key.offset++;
goto again_search_slot;
}
@@ -424,8 +392,6 @@ int btrfs_uuid_tree_iterate(struct btrfs_fs_info *fs_info)
break;
}
-out:
- btrfs_free_path(path);
return ret;
}
diff --git a/fs/btrfs/verity.c b/fs/btrfs/verity.c
index 7fc30a58d8d9c..1c8c782307939 100644
--- a/fs/btrfs/verity.c
+++ b/fs/btrfs/verity.c
@@ -109,7 +109,7 @@ static int drop_verity_items(struct btrfs_inode *inode, u8 key_type)
{
struct btrfs_trans_handle *trans;
struct btrfs_root *root = inode->root;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_key key;
int count = 0;
int ret;
@@ -121,10 +121,8 @@ static int drop_verity_items(struct btrfs_inode *inode, u8 key_type)
while (1) {
/* 1 for the item being dropped */
trans = btrfs_start_transaction(root, 1);
- if (IS_ERR(trans)) {
- ret = PTR_ERR(trans);
- goto out;
- }
+ if (IS_ERR(trans))
+ return PTR_ERR(trans);
/*
* Walk backwards through all the items until we find one that
@@ -143,7 +141,7 @@ static int drop_verity_items(struct btrfs_inode *inode, u8 key_type)
path->slots[0]--;
} else if (ret < 0) {
btrfs_end_transaction(trans);
- goto out;
+ return ret;
}
btrfs_item_key_to_cpu(path->nodes[0], &key, path->slots[0]);
@@ -161,17 +159,14 @@ static int drop_verity_items(struct btrfs_inode *inode, u8 key_type)
ret = btrfs_del_items(trans, root, path, path->slots[0], 1);
if (ret) {
btrfs_end_transaction(trans);
- goto out;
+ return ret;
}
count++;
btrfs_release_path(path);
btrfs_end_transaction(trans);
}
- ret = count;
btrfs_end_transaction(trans);
-out:
- btrfs_free_path(path);
- return ret;
+ return count;
}
/*
@@ -217,7 +212,7 @@ static int write_key_bytes(struct btrfs_inode *inode, u8 key_type, u64 offset,
const char *src, u64 len)
{
struct btrfs_trans_handle *trans;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_root *root = inode->root;
struct extent_buffer *leaf;
struct btrfs_key key;
@@ -233,10 +228,8 @@ static int write_key_bytes(struct btrfs_inode *inode, u8 key_type, u64 offset,
while (len > 0) {
/* 1 for the new item being inserted */
trans = btrfs_start_transaction(root, 1);
- if (IS_ERR(trans)) {
- ret = PTR_ERR(trans);
- break;
- }
+ if (IS_ERR(trans))
+ return PTR_ERR(trans);
key.objectid = btrfs_ino(inode);
key.type = key_type;
@@ -267,7 +260,6 @@ static int write_key_bytes(struct btrfs_inode *inode, u8 key_type, u64 offset,
btrfs_end_transaction(trans);
}
- btrfs_free_path(path);
return ret;
}
@@ -296,7 +288,7 @@ static int write_key_bytes(struct btrfs_inode *inode, u8 key_type, u64 offset,
static int read_key_bytes(struct btrfs_inode *inode, u8 key_type, u64 offset,
char *dest, u64 len, struct folio *dest_folio)
{
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_root *root = inode->root;
struct extent_buffer *leaf;
struct btrfs_key key;
@@ -404,7 +396,6 @@ static int read_key_bytes(struct btrfs_inode *inode, u8 key_type, u64 offset,
}
}
out:
- btrfs_free_path(path);
if (!ret)
ret = copied;
return ret;
diff --git a/fs/btrfs/volumes.c b/fs/btrfs/volumes.c
index 792818b66dc4b..b4404d09a4892 100644
--- a/fs/btrfs/volumes.c
+++ b/fs/btrfs/volumes.c
@@ -1809,7 +1809,7 @@ static int find_free_dev_extent(struct btrfs_device *device, u64 num_bytes,
struct btrfs_root *root = fs_info->dev_root;
struct btrfs_key key;
struct btrfs_dev_extent *dev_extent;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
u64 search_start;
u64 hole_size;
u64 max_hole_start;
@@ -1936,7 +1936,6 @@ static int find_free_dev_extent(struct btrfs_device *device, u64 num_bytes,
"max_hole_start=%llu max_hole_size=%llu search_end=%llu",
max_hole_start, max_hole_size, search_end);
out:
- btrfs_free_path(path);
*start = max_hole_start;
if (len)
*len = max_hole_size;
@@ -1950,7 +1949,7 @@ static int btrfs_free_dev_extent(struct btrfs_trans_handle *trans,
struct btrfs_fs_info *fs_info = device->fs_info;
struct btrfs_root *root = fs_info->dev_root;
int ret;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_key key;
struct btrfs_key found_key;
struct extent_buffer *leaf = NULL;
@@ -1969,7 +1968,7 @@ static int btrfs_free_dev_extent(struct btrfs_trans_handle *trans,
ret = btrfs_previous_item(root, path, key.objectid,
BTRFS_DEV_EXTENT_KEY);
if (ret)
- goto out;
+ return ret;
leaf = path->nodes[0];
btrfs_item_key_to_cpu(leaf, &found_key, path->slots[0]);
extent = btrfs_item_ptr(leaf, path->slots[0],
@@ -1984,7 +1983,7 @@ static int btrfs_free_dev_extent(struct btrfs_trans_handle *trans,
extent = btrfs_item_ptr(leaf, path->slots[0],
struct btrfs_dev_extent);
} else {
- goto out;
+ return ret;
}
*dev_extent_len = btrfs_dev_extent_length(leaf, extent);
@@ -1992,8 +1991,6 @@ static int btrfs_free_dev_extent(struct btrfs_trans_handle *trans,
ret = btrfs_del_item(trans, root, path);
if (ret == 0)
set_bit(BTRFS_TRANS_HAVE_FREE_BGS, &trans->transaction->flags);
-out:
- btrfs_free_path(path);
return ret;
}
@@ -2021,7 +2018,7 @@ static noinline int find_next_devid(struct btrfs_fs_info *fs_info,
int ret;
struct btrfs_key key;
struct btrfs_key found_key;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
path = btrfs_alloc_path();
if (!path)
@@ -2033,13 +2030,12 @@ static noinline int find_next_devid(struct btrfs_fs_info *fs_info,
ret = btrfs_search_slot(NULL, fs_info->chunk_root, &key, path, 0, 0);
if (ret < 0)
- goto error;
+ return ret;
if (unlikely(ret == 0)) {
/* Corruption */
btrfs_err(fs_info, "corrupted chunk tree devid -1 matched");
- ret = -EUCLEAN;
- goto error;
+ return -EUCLEAN;
}
ret = btrfs_previous_item(fs_info->chunk_root, path,
@@ -2052,10 +2048,7 @@ static noinline int find_next_devid(struct btrfs_fs_info *fs_info,
path->slots[0]);
*devid_ret = found_key.offset + 1;
}
- ret = 0;
-error:
- btrfs_free_path(path);
- return ret;
+ return 0;
}
/*
@@ -2066,7 +2059,7 @@ static int btrfs_add_dev_item(struct btrfs_trans_handle *trans,
struct btrfs_device *device)
{
int ret;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_dev_item *dev_item;
struct extent_buffer *leaf;
struct btrfs_key key;
@@ -2085,7 +2078,7 @@ static int btrfs_add_dev_item(struct btrfs_trans_handle *trans,
&key, sizeof(*dev_item));
btrfs_trans_release_chunk_metadata(trans);
if (ret)
- goto out;
+ return ret;
leaf = path->nodes[0];
dev_item = btrfs_item_ptr(leaf, path->slots[0], struct btrfs_dev_item);
@@ -2111,10 +2104,7 @@ static int btrfs_add_dev_item(struct btrfs_trans_handle *trans,
write_extent_buffer(leaf, trans->fs_info->fs_devices->metadata_uuid,
ptr, BTRFS_FSID_SIZE);
- ret = 0;
-out:
- btrfs_free_path(path);
- return ret;
+ return 0;
}
/*
@@ -2141,7 +2131,7 @@ static int btrfs_rm_dev_item(struct btrfs_trans_handle *trans,
{
struct btrfs_root *root = device->fs_info->chunk_root;
int ret;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_key key;
path = btrfs_alloc_path();
@@ -2155,16 +2145,12 @@ static int btrfs_rm_dev_item(struct btrfs_trans_handle *trans,
btrfs_reserve_chunk_metadata(trans, false);
ret = btrfs_search_slot(trans, root, &key, path, -1, 1);
btrfs_trans_release_chunk_metadata(trans);
- if (ret) {
- if (ret > 0)
- ret = -ENOENT;
- goto out;
- }
+ if (ret > 0)
+ return -ENOENT;
+ if (ret < 0)
+ return ret;
- ret = btrfs_del_item(trans, root, path);
-out:
- btrfs_free_path(path);
- return ret;
+ return btrfs_del_item(trans, root, path);
}
/*
@@ -2748,7 +2734,7 @@ static int btrfs_finish_sprout(struct btrfs_trans_handle *trans)
BTRFS_DEV_LOOKUP_ARGS(args);
struct btrfs_fs_info *fs_info = trans->fs_info;
struct btrfs_root *root = fs_info->chunk_root;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct extent_buffer *leaf;
struct btrfs_dev_item *dev_item;
struct btrfs_device *device;
@@ -2770,7 +2756,7 @@ static int btrfs_finish_sprout(struct btrfs_trans_handle *trans)
ret = btrfs_search_slot(trans, root, &key, path, 0, 1);
btrfs_trans_release_chunk_metadata(trans);
if (ret < 0)
- goto error;
+ return ret;
leaf = path->nodes[0];
next_slot:
@@ -2779,7 +2765,7 @@ static int btrfs_finish_sprout(struct btrfs_trans_handle *trans)
if (ret > 0)
break;
if (ret < 0)
- goto error;
+ return ret;
leaf = path->nodes[0];
btrfs_item_key_to_cpu(leaf, &key, path->slots[0]);
btrfs_release_path(path);
@@ -2810,10 +2796,7 @@ static int btrfs_finish_sprout(struct btrfs_trans_handle *trans)
path->slots[0]++;
goto next_slot;
}
- ret = 0;
-error:
- btrfs_free_path(path);
- return ret;
+ return 0;
}
int btrfs_init_new_device(struct btrfs_fs_info *fs_info, const char *device_path)
@@ -3072,7 +3055,7 @@ static noinline int btrfs_update_device(struct btrfs_trans_handle *trans,
struct btrfs_device *device)
{
int ret;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_root *root = device->fs_info->chunk_root;
struct btrfs_dev_item *dev_item;
struct extent_buffer *leaf;
@@ -3088,12 +3071,10 @@ static noinline int btrfs_update_device(struct btrfs_trans_handle *trans,
ret = btrfs_search_slot(trans, root, &key, path, 0, 1);
if (ret < 0)
- goto out;
+ return ret;
- if (ret > 0) {
- ret = -ENOENT;
- goto out;
- }
+ if (ret > 0)
+ return -ENOENT;
leaf = path->nodes[0];
dev_item = btrfs_item_ptr(leaf, path->slots[0], struct btrfs_dev_item);
@@ -3107,8 +3088,6 @@ static noinline int btrfs_update_device(struct btrfs_trans_handle *trans,
btrfs_device_get_disk_total_bytes(device));
btrfs_set_device_bytes_used(leaf, dev_item,
btrfs_device_get_bytes_used(device));
-out:
- btrfs_free_path(path);
return ret;
}
@@ -3161,7 +3140,7 @@ static int btrfs_free_chunk(struct btrfs_trans_handle *trans, u64 chunk_offset)
struct btrfs_fs_info *fs_info = trans->fs_info;
struct btrfs_root *root = fs_info->chunk_root;
int ret;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_key key;
path = btrfs_alloc_path();
@@ -3174,23 +3153,21 @@ static int btrfs_free_chunk(struct btrfs_trans_handle *trans, u64 chunk_offset)
ret = btrfs_search_slot(trans, root, &key, path, -1, 1);
if (ret < 0)
- goto out;
- else if (unlikely(ret > 0)) { /* Logic error or corruption */
+ return ret;
+ if (unlikely(ret > 0)) {
+ /* Logic error or corruption */
btrfs_err(fs_info, "failed to lookup chunk %llu when freeing",
chunk_offset);
btrfs_abort_transaction(trans, -ENOENT);
- ret = -EUCLEAN;
- goto out;
+ return -EUCLEAN;
}
ret = btrfs_del_item(trans, root, path);
if (unlikely(ret < 0)) {
btrfs_err(fs_info, "failed to delete chunk %llu item", chunk_offset);
btrfs_abort_transaction(trans, ret);
- goto out;
+ return ret;
}
-out:
- btrfs_free_path(path);
return ret;
}
@@ -3627,7 +3604,7 @@ int btrfs_relocate_chunk(struct btrfs_fs_info *fs_info, u64 chunk_offset,
static int btrfs_relocate_sys_chunks(struct btrfs_fs_info *fs_info)
{
struct btrfs_root *chunk_root = fs_info->chunk_root;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct extent_buffer *leaf;
struct btrfs_chunk *chunk;
struct btrfs_key key;
@@ -3651,7 +3628,7 @@ static int btrfs_relocate_sys_chunks(struct btrfs_fs_info *fs_info)
ret = btrfs_search_slot(NULL, chunk_root, &key, path, 0, 0);
if (ret < 0) {
mutex_unlock(&fs_info->reclaim_bgs_lock);
- goto error;
+ return ret;
}
if (unlikely(ret == 0)) {
/*
@@ -3661,9 +3638,8 @@ static int btrfs_relocate_sys_chunks(struct btrfs_fs_info *fs_info)
* offset (one less than the previous one, wrong
* alignment and size).
*/
- ret = -EUCLEAN;
mutex_unlock(&fs_info->reclaim_bgs_lock);
- goto error;
+ return -EUCLEAN;
}
ret = btrfs_previous_item(chunk_root, path, key.objectid,
@@ -3671,7 +3647,7 @@ static int btrfs_relocate_sys_chunks(struct btrfs_fs_info *fs_info)
if (ret)
mutex_unlock(&fs_info->reclaim_bgs_lock);
if (ret < 0)
- goto error;
+ return ret;
if (ret > 0)
break;
@@ -3705,8 +3681,6 @@ static int btrfs_relocate_sys_chunks(struct btrfs_fs_info *fs_info)
} else if (WARN_ON(failed && retried)) {
ret = -ENOSPC;
}
-error:
- btrfs_free_path(path);
return ret;
}
@@ -4844,7 +4818,7 @@ int btrfs_recover_balance(struct btrfs_fs_info *fs_info)
struct btrfs_balance_control *bctl;
struct btrfs_balance_item *item;
struct btrfs_disk_balance_args disk_bargs;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct extent_buffer *leaf;
struct btrfs_key key;
int ret;
@@ -4859,17 +4833,14 @@ int btrfs_recover_balance(struct btrfs_fs_info *fs_info)
ret = btrfs_search_slot(NULL, fs_info->tree_root, &key, path, 0, 0);
if (ret < 0)
- goto out;
+ return ret;
if (ret > 0) { /* ret = -ENOENT; */
- ret = 0;
- goto out;
+ return 0;
}
bctl = kzalloc(sizeof(*bctl), GFP_NOFS);
- if (!bctl) {
- ret = -ENOMEM;
- goto out;
- }
+ if (!bctl)
+ return -ENOMEM;
leaf = path->nodes[0];
item = btrfs_item_ptr(leaf, path->slots[0], struct btrfs_balance_item);
@@ -4906,8 +4877,6 @@ int btrfs_recover_balance(struct btrfs_fs_info *fs_info)
fs_info->balance_ctl = bctl;
spin_unlock(&fs_info->balance_lock);
mutex_unlock(&fs_info->balance_mutex);
-out:
- btrfs_free_path(path);
return ret;
}
@@ -7593,7 +7562,7 @@ static void readahead_tree_node_children(struct extent_buffer *node)
int btrfs_read_chunk_tree(struct btrfs_fs_info *fs_info)
{
struct btrfs_root *root = fs_info->chunk_root;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct extent_buffer *leaf;
struct btrfs_key key;
struct btrfs_key found_key;
@@ -7710,8 +7679,6 @@ int btrfs_read_chunk_tree(struct btrfs_fs_info *fs_info)
ret = 0;
error:
mutex_unlock(&uuid_mutex);
-
- btrfs_free_path(path);
return ret;
}
@@ -7811,7 +7778,7 @@ int btrfs_init_dev_stats(struct btrfs_fs_info *fs_info)
{
struct btrfs_fs_devices *fs_devices = fs_info->fs_devices, *seed_devs;
struct btrfs_device *device;
- struct btrfs_path *path = NULL;
+ BTRFS_PATH_AUTO_FREE(path);
int ret = 0;
path = btrfs_alloc_path();
@@ -7833,8 +7800,6 @@ int btrfs_init_dev_stats(struct btrfs_fs_info *fs_info)
}
out:
mutex_unlock(&fs_devices->device_list_mutex);
-
- btrfs_free_path(path);
return ret;
}
@@ -7843,7 +7808,7 @@ static int update_dev_stat_item(struct btrfs_trans_handle *trans,
{
struct btrfs_fs_info *fs_info = trans->fs_info;
struct btrfs_root *dev_root = fs_info->dev_root;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_key key;
struct extent_buffer *eb;
struct btrfs_dev_stats_item *ptr;
@@ -7862,7 +7827,7 @@ static int update_dev_stat_item(struct btrfs_trans_handle *trans,
btrfs_warn(fs_info,
"error %d while searching for dev_stats item for device %s",
ret, btrfs_dev_name(device));
- goto out;
+ return ret;
}
if (ret == 0 &&
@@ -7873,7 +7838,7 @@ static int update_dev_stat_item(struct btrfs_trans_handle *trans,
btrfs_warn(fs_info,
"delete too small dev_stats item for device %s failed %d",
btrfs_dev_name(device), ret);
- goto out;
+ return ret;
}
ret = 1;
}
@@ -7887,7 +7852,7 @@ static int update_dev_stat_item(struct btrfs_trans_handle *trans,
btrfs_warn(fs_info,
"insert dev_stats item for device %s failed %d",
btrfs_dev_name(device), ret);
- goto out;
+ return ret;
}
}
@@ -7896,8 +7861,6 @@ static int update_dev_stat_item(struct btrfs_trans_handle *trans,
for (i = 0; i < BTRFS_DEV_STAT_VALUES_MAX; i++)
btrfs_set_dev_stats_value(eb, ptr, i,
btrfs_dev_stat_read(device, i));
-out:
- btrfs_free_path(path);
return ret;
}
@@ -8188,7 +8151,7 @@ static int verify_chunk_dev_extent_mapping(struct btrfs_fs_info *fs_info)
*/
int btrfs_verify_dev_extents(struct btrfs_fs_info *fs_info)
{
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct btrfs_root *root = fs_info->dev_root;
struct btrfs_key key;
u64 prev_devid = 0;
@@ -8219,17 +8182,15 @@ int btrfs_verify_dev_extents(struct btrfs_fs_info *fs_info)
path->reada = READA_FORWARD;
ret = btrfs_search_slot(NULL, root, &key, path, 0, 0);
if (ret < 0)
- goto out;
+ return ret;
if (path->slots[0] >= btrfs_header_nritems(path->nodes[0])) {
ret = btrfs_next_leaf(root, path);
if (ret < 0)
- goto out;
+ return ret;
/* No dev extents at all? Not good */
- if (unlikely(ret > 0)) {
- ret = -EUCLEAN;
- goto out;
- }
+ if (unlikely(ret > 0))
+ return -EUCLEAN;
}
while (1) {
struct extent_buffer *leaf = path->nodes[0];
@@ -8255,20 +8216,19 @@ int btrfs_verify_dev_extents(struct btrfs_fs_info *fs_info)
btrfs_err(fs_info,
"dev extent devid %llu physical offset %llu overlap with previous dev extent end %llu",
devid, physical_offset, prev_dev_ext_end);
- ret = -EUCLEAN;
- goto out;
+ return -EUCLEAN;
}
ret = verify_one_dev_extent(fs_info, chunk_offset, devid,
physical_offset, physical_len);
if (ret < 0)
- goto out;
+ return ret;
prev_devid = devid;
prev_dev_ext_end = physical_offset + physical_len;
ret = btrfs_next_item(root, path);
if (ret < 0)
- goto out;
+ return ret;
if (ret > 0) {
ret = 0;
break;
@@ -8276,10 +8236,7 @@ int btrfs_verify_dev_extents(struct btrfs_fs_info *fs_info)
}
/* Ensure all chunks have corresponding dev extents */
- ret = verify_chunk_dev_extent_mapping(fs_info);
-out:
- btrfs_free_path(path);
- return ret;
+ return verify_chunk_dev_extent_mapping(fs_info);
}
/*
diff --git a/fs/btrfs/xattr.c b/fs/btrfs/xattr.c
index b6e91e8fb7e38..ab55d10bd71fd 100644
--- a/fs/btrfs/xattr.c
+++ b/fs/btrfs/xattr.c
@@ -29,9 +29,8 @@ int btrfs_getxattr(const struct inode *inode, const char *name,
{
struct btrfs_dir_item *di;
struct btrfs_root *root = BTRFS_I(inode)->root;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
struct extent_buffer *leaf;
- int ret = 0;
unsigned long data_ptr;
path = btrfs_alloc_path();
@@ -41,26 +40,19 @@ int btrfs_getxattr(const struct inode *inode, const char *name,
/* lookup the xattr by name */
di = btrfs_lookup_xattr(NULL, root, path, btrfs_ino(BTRFS_I(inode)),
name, strlen(name), 0);
- if (!di) {
- ret = -ENODATA;
- goto out;
- } else if (IS_ERR(di)) {
- ret = PTR_ERR(di);
- goto out;
- }
+ if (!di)
+ return -ENODATA;
+ if (IS_ERR(di))
+ return PTR_ERR(di);
leaf = path->nodes[0];
/* if size is 0, that means we want the size of the attr */
- if (!size) {
- ret = btrfs_dir_data_len(leaf, di);
- goto out;
- }
+ if (!size)
+ return btrfs_dir_data_len(leaf, di);
/* now get the data out of our dir_item */
- if (btrfs_dir_data_len(leaf, di) > size) {
- ret = -ERANGE;
- goto out;
- }
+ if (btrfs_dir_data_len(leaf, di) > size)
+ return -ERANGE;
/*
* The way things are packed into the leaf is like this
@@ -73,11 +65,7 @@ int btrfs_getxattr(const struct inode *inode, const char *name,
btrfs_dir_name_len(leaf, di));
read_extent_buffer(leaf, buffer, data_ptr,
btrfs_dir_data_len(leaf, di));
- ret = btrfs_dir_data_len(leaf, di);
-
-out:
- btrfs_free_path(path);
- return ret;
+ return btrfs_dir_data_len(leaf, di);
}
int btrfs_setxattr(struct btrfs_trans_handle *trans, struct inode *inode,
@@ -277,7 +265,7 @@ ssize_t btrfs_listxattr(struct dentry *dentry, char *buffer, size_t size)
struct btrfs_key key;
struct inode *inode = d_inode(dentry);
struct btrfs_root *root = BTRFS_I(inode)->root;
- struct btrfs_path *path;
+ BTRFS_PATH_AUTO_FREE(path);
int iter_ret = 0;
int ret = 0;
size_t total_size = 0, size_left = size;
@@ -353,8 +341,6 @@ ssize_t btrfs_listxattr(struct dentry *dentry, char *buffer, size_t size)
else
ret = total_size;
- btrfs_free_path(path);
-
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 218/438] x86/kprobes: Fix crash when probing CS CALL instructions
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (216 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 217/438] net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 219/438] net: macb: fix ordering around PTP timestamp read Greg Kroah-Hartman
` (231 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google), Jinke Han,
Ingo Molnar, Yafang Shao, Borislav Petkov, Peter Zijlstra,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jinke Han <jinkehan@didiglobal.com>
[ Upstream commit a5f7a5bb3b7f28ba7e4fa246775b29a0e5537255 ]
When using eBPF to probe CS CALL instructions within a function,
a crash can be triggered.
The eBPF tool probes offset 257 of the __hrtimer_run_queues()
function:
<__hrtimer_run_queues+249>: nopl 0x0(%rax,%rax,1)
<__hrtimer_run_queues+254>: mov %r14,%rdi
<__hrtimer_run_queues+257>: cs call <__x86_indirect_thunk_r12>
<__hrtimer_run_queues+263>: mov %eax,%r12d
<__hrtimer_run_queues+266>: xchg %ax,%ax
<__hrtimer_run_queues+268>: mov %r13,%rdi
Which triggers this crash:
BUG: unable to handle page fault for address: 00000000000f41c9
#PF: supervisor write access in kernel mode
#PF: error_code(0x0002) - not-present page
PGD 0 P4D 0
Oops: 0002 [#1] SMP NOPTI
CPU: 1 PID: 0 Comm: swapper/1 Kdump: loaded Tainted: P
RIP: 0010:__hrtimer_run_queues+0x106/0x230
Note that __hrtimer_run_queues+0x106 is __hrtimer_run_queues+262, which is
at the 6th byte of the above CS CALL instruction. Since the CS CALL
instruction occupies 6 bytes, the exception occurred in the middle of that
call instruction.
The root cause is that when using eBPF tools to probe in the middle of a
function, a kprobe with INT3 is used as the underlying implementation.
During single-step emulation of the original CALL instruction,
int3_emulate_call() assumes that the probed CALL instruction is 5 bytes
long. However, the actual CS-prefixed CALL instruction occupies 6 bytes,
so it constructs an incorrect exception return address. When the CPU
returns from the kprobe handler, the next instruction to be executed is at
the address of the last byte of that CS CALL instruction. Coincidentally,
starting from that address, the CPU fetches and decodes a completely
different instruction, which ultimately triggers a kernel crash.
Fix the issue by using the actual instruction length obtained from
the instruction decoder when constructing the exception return
address, rather than relying on the hardcoded CALL_INSN_SIZE macro.
[ mingo: Refined the changelog ]
Fixes: 6256e668b7af ("x86/kprobes: Use int3 instead of debug trap for single-step")
Suggested-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Jinke Han <jinkehan@didiglobal.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Acked-by: Yafang Shao <laoar.shao@gmail.com>
Acked-by: Borislav Petkov <bp@alien8.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Link: https://patch.msgid.link/20260908073742.GA10517@didi-ThinkCentre-M920t-N000
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/include/asm/text-patching.h | 4 ++--
arch/x86/kernel/alternative.c | 6 ++++--
arch/x86/kernel/kprobes/core.c | 5 ++---
3 files changed, 8 insertions(+), 7 deletions(-)
diff --git a/arch/x86/include/asm/text-patching.h b/arch/x86/include/asm/text-patching.h
index f2d142a0a862e..ea09381070e82 100644
--- a/arch/x86/include/asm/text-patching.h
+++ b/arch/x86/include/asm/text-patching.h
@@ -164,9 +164,9 @@ unsigned long int3_emulate_pop(struct pt_regs *regs)
}
static __always_inline
-void int3_emulate_call(struct pt_regs *regs, unsigned long func)
+void int3_emulate_call(struct pt_regs *regs, unsigned long ip, unsigned long func)
{
- int3_emulate_push(regs, regs->ip - INT3_INSN_SIZE + CALL_INSN_SIZE);
+ int3_emulate_push(regs, ip);
int3_emulate_jmp(regs, func);
}
diff --git a/arch/x86/kernel/alternative.c b/arch/x86/kernel/alternative.c
index b0b576ab2fa6e..f24d7e911d3e5 100644
--- a/arch/x86/kernel/alternative.c
+++ b/arch/x86/kernel/alternative.c
@@ -2319,6 +2319,7 @@ int3_exception_notify(struct notifier_block *self, unsigned long val, void *data
unsigned long selftest = (unsigned long)&int3_selftest_asm;
struct die_args *args = data;
struct pt_regs *regs = args->regs;
+ unsigned long ip;
OPTIMIZER_HIDE_VAR(selftest);
@@ -2331,7 +2332,8 @@ int3_exception_notify(struct notifier_block *self, unsigned long val, void *data
if (regs->ip - INT3_INSN_SIZE != selftest)
return NOTIFY_DONE;
- int3_emulate_call(regs, (unsigned long)&int3_selftest_callee);
+ ip = regs->ip - INT3_INSN_SIZE + CALL_INSN_SIZE;
+ int3_emulate_call(regs, ip, (unsigned long)&int3_selftest_callee);
return NOTIFY_STOP;
}
@@ -2929,7 +2931,7 @@ noinstr int smp_text_poke_int3_handler(struct pt_regs *regs)
break;
case CALL_INSN_OPCODE:
- int3_emulate_call(regs, (long)ip + tpl->disp);
+ int3_emulate_call(regs, (long)ip, (long)ip + tpl->disp);
break;
case JMP32_INSN_OPCODE:
diff --git a/arch/x86/kernel/kprobes/core.c b/arch/x86/kernel/kprobes/core.c
index c1fac3a9fecc2..03d2710ec3021 100644
--- a/arch/x86/kernel/kprobes/core.c
+++ b/arch/x86/kernel/kprobes/core.c
@@ -510,10 +510,9 @@ NOKPROBE_SYMBOL(kprobe_emulate_ret);
static void kprobe_emulate_call(struct kprobe *p, struct pt_regs *regs)
{
- unsigned long func = regs->ip - INT3_INSN_SIZE + p->ainsn.size;
+ unsigned long ip = regs->ip - INT3_INSN_SIZE + p->ainsn.size;
- func += p->ainsn.rel32;
- int3_emulate_call(regs, func);
+ int3_emulate_call(regs, ip, ip + p->ainsn.rel32);
}
NOKPROBE_SYMBOL(kprobe_emulate_call);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 165/398] btrfs: handle lack of space when cleaning up verity items
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (163 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 164/398] btrfs: more trivial BTRFS_PATH_AUTO_FREE conversions Greg Kroah-Hartman
@ 2026-09-23 14:03 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 166/398] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments Greg Kroah-Hartman
` (237 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:03 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Daniel Linjama,
David Sterba, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Linjama <daniel@dev.linjama.com>
[ Upstream commit 76bf149cd0298544631e756670b89c399c7acbca ]
When enable_verity() hits the qgroup limit, rollback_verity() needs its
own metadata reservation. When the qgroup limit or lack of space refuses
the rollback, the whole filesystem is forced read-only even though the
qgroup limit was for one subvolume only. Also orphan cleanup at the next
mount fails the same way, so the leftover items are never removed: with
-EDQUOT the subvolume stays unreachable, and with -ENOSPC on a full
filesystem the next read-write mount fails.
Start transactions with btrfs_start_transaction_fallback_global_rsv() in
btrfs_orphan_cleanup(), drop_verity_items() and rollback_verity(). Those
calls only delete items and free the space in the end, so they may use
the global reserve and skip the qgroup limit, which avoids -ENOSPC and
-EDQUOT.
Fixes: 146054090b08 ("btrfs: initial fsverity support")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Daniel Linjama <daniel@dev.linjama.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/inode.c | 3 ++-
fs/btrfs/verity.c | 18 ++++++++++++++++--
2 files changed, 18 insertions(+), 3 deletions(-)
diff --git a/fs/btrfs/inode.c b/fs/btrfs/inode.c
index 3023e1b504b96..6ab593b893198 100644
--- a/fs/btrfs/inode.c
+++ b/fs/btrfs/inode.c
@@ -3789,7 +3789,8 @@ int btrfs_orphan_cleanup(struct btrfs_root *root)
if (ret)
goto out;
}
- trans = btrfs_start_transaction(root, 1);
+ /* Only deletes the orphan. */
+ trans = btrfs_start_transaction_fallback_global_rsv(root, 1);
if (IS_ERR(trans)) {
ret = PTR_ERR(trans);
goto out;
diff --git a/fs/btrfs/verity.c b/fs/btrfs/verity.c
index 1c8c782307939..43433577076b7 100644
--- a/fs/btrfs/verity.c
+++ b/fs/btrfs/verity.c
@@ -93,6 +93,20 @@ static loff_t merkle_file_pos(const struct inode *inode)
return rounded;
}
+/*
+ * Start a transaction for removing verity items or the verity orphan.
+ *
+ * Like unlink, this only deletes items and frees space in the end, so the
+ * reservation may come from the global reserve when the filesystem is full
+ * (-ENOSPC) and is not subject to the qgroup limit (-EDQUOT). Otherwise a
+ * failed enable could never be cleaned up in either situation.
+ */
+static struct btrfs_trans_handle *start_verity_cleanup_trans(struct btrfs_root *root,
+ unsigned int num_items)
+{
+ return btrfs_start_transaction_fallback_global_rsv(root, num_items);
+}
+
/*
* Drop all the items for this inode with this key_type.
*
@@ -120,7 +134,7 @@ static int drop_verity_items(struct btrfs_inode *inode, u8 key_type)
while (1) {
/* 1 for the item being dropped */
- trans = btrfs_start_transaction(root, 1);
+ trans = start_verity_cleanup_trans(root, 1);
if (IS_ERR(trans))
return PTR_ERR(trans);
@@ -466,7 +480,7 @@ static int rollback_verity(struct btrfs_inode *inode)
* 1 for updating the inode flag
* 1 for deleting the orphan
*/
- trans = btrfs_start_transaction(root, 2);
+ trans = start_verity_cleanup_trans(root, 2);
if (IS_ERR(trans)) {
ret = PTR_ERR(trans);
trans = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 219/438] net: macb: fix ordering around PTP timestamp read
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (217 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 7.2 218/438] x86/kprobes: Fix crash when probing CS CALL instructions Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 220/438] net: mvpp2: prevent buffer overflow in page_pool allocation Greg Kroah-Hartman
` (230 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Théo Lebrun,
James Clark, Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Clark <jjc@jclark.com>
[ Upstream commit 9ca4ba24259183ce15665be86b2956cd896c4687 ]
PTP_SYS_OFFSET_EXTENDED returns system timestamps that do not correctly
bracket the PHC register read on MACB/GEM. On a Raspberry Pi 5, the
returned interval can be as short as 37 ns, while an ordered register
read takes approximately 1 us. This biases the midpoint used by phc2sys,
causing CLOCK_REALTIME to run approximately 0.5 us ahead when synchronized
to the PHC.
gem_tsu_get_time() reads the nanoseconds register using the driver's
relaxed MMIO accessor. On weakly ordered systems, the subsequent system
timestamp can be taken before the register read completes. The internal
smp_rmb() in the pre-timestamp path also does not guarantee ordering
against the subsequent MMIO read.
Add rmb() before and after the bracketed nanoseconds read in both the
normal and seconds rollover paths so the system timestamps bracket the
PHC read. Adding the post-read barrier increases the minimum interval on
the same Raspberry Pi 5 to approximately 1 us.
Fixes: e51bb5c2784c ("net: macb: ptp: Switch to gettimex64() interface")
Tested-by: Nicolai Buchwitz <nb@tipi-net.de> # Raspberry Pi CM5, min bracket 37 ns -> 981 ns
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Reviewed-by: Théo Lebrun <theo.lebrun@bootlin.com>
Assisted-by: LLM
Signed-off-by: James Clark <jjc@jclark.com>
Link: https://patch.msgid.link/20260915045823.76100-1-jjc@jclark.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cadence/macb_ptp.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/net/ethernet/cadence/macb_ptp.c b/drivers/net/ethernet/cadence/macb_ptp.c
index 6d91663899886..14ae57fa00cba 100644
--- a/drivers/net/ethernet/cadence/macb_ptp.c
+++ b/drivers/net/ethernet/cadence/macb_ptp.c
@@ -50,7 +50,12 @@ static int gem_tsu_get_time(struct ptp_clock_info *ptp, struct timespec64 *ts,
spin_lock_irqsave(&bp->tsu_clk_lock, flags);
ptp_read_system_prets(sts);
+ /* explicit barriers are needed because gem_readl() is relaxed */
+ if (sts)
+ rmb();
first = gem_readl(bp, TN);
+ if (sts)
+ rmb();
ptp_read_system_postts(sts);
secl = gem_readl(bp, TSL);
sech = gem_readl(bp, TSH);
@@ -62,7 +67,11 @@ static int gem_tsu_get_time(struct ptp_clock_info *ptp, struct timespec64 *ts,
* (assume all done within 1s)
*/
ptp_read_system_prets(sts);
+ if (sts)
+ rmb();
ts->tv_nsec = gem_readl(bp, TN);
+ if (sts)
+ rmb();
ptp_read_system_postts(sts);
secl = gem_readl(bp, TSL);
sech = gem_readl(bp, TSH);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 166/398] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (164 preceding siblings ...)
2026-09-23 14:03 ` [PATCH 6.18 165/398] btrfs: handle lack of space when cleaning up verity items Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 167/398] ASoC: hdmi-codec: Report a change when the channel status moves Greg Kroah-Hartman
` (236 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, kernel test robot, Sasha Levin,
Linus Walleij, Mark Brown
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
[ Upstream commit 11fc0048a6930f4fca44fe3bd16a0023e78846a2 ]
arm allmodconfig fails to build with gcc:
In file included from sound/soc/ux500/ux500_msp_i2s.c:20:
sound/soc/ux500/ux500_msp_i2s.h:151:38: error: suggest parentheses
around arithmetic in operand of '^' [-Werror=parentheses]
sound/soc/ux500/ux500_msp_i2s.c:204:21: note: in expansion of macro
'MSP_TX_CLKPOL_BIT'
cc1: all warnings being treated as errors
The macros never parenthesized their argument:
#define MSP_TX_CLKPOL_BIT(n) ((n & TCKPOL_MASK) << TCKPOL_SHIFT)
That went unnoticed while every caller passed a plain variable, but
configure_protocol() now passes an XOR expression, which binds as
"a ^ (b & MASK)" rather than "(a ^ b) & MASK", and gcc rightly
complains.
No functional change: tx_clk_pol and rx_clk_pol only ever hold
MSP_FALLING_EDGE (0) or MSP_RISING_EDGE (1), and bclk_inverted is a
bool, so masking before or after the XOR gives the same 0/1 result.
Parenthesize the argument anyway - it fixes the build and stops the
macros from silently mis-evaluating a future composite argument.
Fixes: 9ccbacf5a012 ("ASoC: ux500: Validate MSP DAI configuration")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202609051547.G9SJp8UQ-lkp@intel.com/
Assisted-by: LLM
Signed-off-by: Sasha Levin <sashal@kernel.org>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260913173132.1172003-1-sashal@kernel.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/ux500/ux500_msp_i2s.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/sound/soc/ux500/ux500_msp_i2s.h b/sound/soc/ux500/ux500_msp_i2s.h
index 2bf2699bdc49f..c66ef455e1380 100644
--- a/sound/soc/ux500/ux500_msp_i2s.h
+++ b/sound/soc/ux500/ux500_msp_i2s.h
@@ -147,8 +147,8 @@ enum msp_direction {
#define RCKPOL_MASK BIT(0)
#define TCKPOL_MASK BIT(0)
#define SPICKM_MASK (BIT(1) | BIT(0))
-#define MSP_RX_CLKPOL_BIT(n) ((n & RCKPOL_MASK) << RCKPOL_SHIFT)
-#define MSP_TX_CLKPOL_BIT(n) ((n & TCKPOL_MASK) << TCKPOL_SHIFT)
+#define MSP_RX_CLKPOL_BIT(n) (((n) & RCKPOL_MASK) << RCKPOL_SHIFT)
+#define MSP_TX_CLKPOL_BIT(n) (((n) & TCKPOL_MASK) << TCKPOL_SHIFT)
#define P1ELEN_SHIFT 0
#define P1FLEN_SHIFT 3
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 220/438] net: mvpp2: prevent buffer overflow in page_pool allocation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (218 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 219/438] net: macb: fix ordering around PTP timestamp read Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 221/438] net: skbuff: do not leave stale header offsets after pskb_carve() Greg Kroah-Hartman
` (229 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitriy Okunev, Paolo Abeni,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitriy Okunev <dokunevdmitriy@gmail.com>
[ Upstream commit 14cb1e7702e5cb3c58888f6aed498381a73927d2 ]
The per‑processor buffering scheme is supported only if the
number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8).
This is already checked in mvpp2_probe() during the initial
activation of percpu_pools.
However, mvpp2_change_mtu() may later call
mvpp2_bm_switch_buffers(priv, true) without this check, which can
lead to an out-of-bounds access in the priv->page_pool array in
mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ
entries, and mvpp2_get_nrxqs() may return exactly that value. The
per-CPU scheme then doubles it to nrxqs * 2, exceeding the array
bounds.
Check that the hardware version is MVPP22 or newer and that the
number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS
before switching to per-CPU mode.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: 7d04b0b13b11 ("mvpp2: percpu buffers")
Signed-off-by: Dmitriy Okunev <dokunevdmitriy@gmail.com>
Link: https://patch.msgid.link/20260914091557.71769-1-dokunevdmitriy@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
index ccc24a1301f22..848ee655c6ea6 100644
--- a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
+++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
@@ -5086,7 +5086,8 @@ static int mvpp2_change_mtu(struct net_device *dev, int mtu)
netdev_warn(dev, "mtu %d too high, switching to shared buffers", mtu);
mvpp2_bm_switch_buffers(priv, false);
}
- } else {
+ } else if (priv->hw_version >= MVPP22 &&
+ mvpp2_get_nrxqs(priv) * 2 <= MVPP2_BM_MAX_POOLS) {
bool jumbo = false;
int i;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 167/398] ASoC: hdmi-codec: Report a change when the channel status moves
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (165 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 166/398] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 168/398] ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers Greg Kroah-Hartman
` (235 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: HyeongJun An <sammiee5311@gmail.com>
[ Upstream commit c17ae8c26eac16ad244daef44044d714f68a2ddc ]
The put() callback of "IEC958 Playback Default" stores all 24 channel
status bytes and then returns 0. The core notifies userspace only on a
positive return, so a write that changes what the get() callback hands
back is never announced, and a mixer holding the control open keeps
showing the old value.
Compare the stored bytes and return 1 when they move, the way
snd_hda_spdif_default_put() does.
The same shape is in img-spdif-out and uniperif_player.
No board with this codec was to hand. The change is a comparison of
driver state with no hardware behaviour in it, and mixer-test counts the
missing notification as event_missing.
Fixes: 7a8e1d44211e ("ASoC: hdmi-codec: Add iec958 controls")
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Assisted-by: Claude:claude-opus-5
Link: https://patch.msgid.link/20260915092515.2638542-1-sammiee5311@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/hdmi-codec.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/sound/soc/codecs/hdmi-codec.c b/sound/soc/codecs/hdmi-codec.c
index e1933f733af10..df32032e631fc 100644
--- a/sound/soc/codecs/hdmi-codec.c
+++ b/sound/soc/codecs/hdmi-codec.c
@@ -425,10 +425,14 @@ static int hdmi_codec_iec958_default_put(struct snd_kcontrol *kcontrol,
struct snd_soc_component *component = snd_kcontrol_chip(kcontrol);
struct hdmi_codec_priv *hcp = snd_soc_component_get_drvdata(component);
+ if (!memcmp(hcp->iec_status, ucontrol->value.iec958.status,
+ sizeof(hcp->iec_status)))
+ return 0;
+
memcpy(hcp->iec_status, ucontrol->value.iec958.status,
sizeof(hcp->iec_status));
- return 0;
+ return 1;
}
static int hdmi_codec_iec958_mask_get(struct snd_kcontrol *kcontrol,
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 221/438] net: skbuff: do not leave stale header offsets after pskb_carve()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (219 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 220/438] net: mvpp2: prevent buffer overflow in page_pool allocation Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 222/438] drm/amdgpu: check ras and obj before dereference Greg Kroah-Hartman
` (228 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+586af68eb819833c2d91,
Xuanqiang Luo, Allison Henderson, rds-devel, Eric Dumazet,
Xuanqiang Luo, Paolo Abeni, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit a5117e1eccac6ee3bd4aed7cacf8ebcb6b3eb309 ]
pskb_carve_inside_header() and pskb_carve_inside_nonlinear() remove
the first bytes of a packet and reallocate skb->head.
All the headers that were present before the operation are gone,
but both functions call skb_headers_offset_update(skb, 0), which
is a no-op : skb->mac_header, skb->network_header,
skb->transport_header and skb->csum_start keep their old values and
now describe bytes which are no longer there.
Both helpers size the new head from the old skb_end_offset(), so the
stale offsets still land inside the new allocation. They point past
skb_tail_pointer() though, to bytes that were never initialized.
pskb_carve_inside_nonlinear() is the worst case, because it leaves a
zombie skb with an empty linear part (skb->data ==
skb_tail_pointer(skb), skb_headlen(skb) == 0), while
skb_mac_header_was_set() is still true and skb->mac_header is way
ahead of skb->data.
The only user of pskb_extract() is rds_tcp_data_recv(), and the
carved skb is queued on tinc->ti_skb_list. When the RDS incoming
message is released, rds_tcp_inc_free() calls skb_queue_purge(),
which frees the skbs with SKB_DROP_REASON_QUEUE_PURGE. This is
visible from drop_monitor, which then tries to pull back to the
(bogus) mac header :
skbuff: __skb_pull(len=234)
skb len=6968 data_len=6968 headroom=0 headlen=0 tailroom=0
end-tail=384 mac=(234,14) mac_len=14 net=(248,40) trans=288
shinfo(txflags=0 nr_frags=1 gso(size=1428 type=16 segs=5))
csum(0x100120 start=288 offset=16 ip_summed=3 complete_sw=0 valid=1 level=0)
hash(0x7b446c6c sw=0 l4=1) proto=0x86dd pkttype=0 iif=60
kernel BUG at ./include/linux/skbuff.h:2847!
Add skb_carve_reset_headers() to mark the mac and transport headers
as not set, reset the network header, clear skb->mac_len, and drop
a now meaningless CHECKSUM_PARTIAL (csum_start no longer describes
anything).
Invalidate the inner offsets as well. Unlike mac_header and
transport_header they have no "unset" sentinel, so a leftover
non-zero value still looks like a real header. Zero
skb->inner_mac_header, skb->inner_network_header,
skb->inner_transport_header, skb->inner_protocol and
skb->encapsulation, so that all the header state is invalidated in
one place.
v2: fixed an inaccurate changelog. The stale offsets stay inside the
new skb->head, which is never smaller than the old one, they
simply point past skb_tail_pointer() to bytes that are gone.
Thanks to Xuanqiang Luo for insisting on this.
Also invalidate the inner header state, as suggested by the
netdev AI review :
https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260911114922.621937-1-edumazet%40google.com
Fixes: 6fa01ccd8830 ("skbuff: Add pskb_extract() helper function")
Reported-by: syzbot+586af68eb819833c2d91@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6aa3e9d3.f2639fcc.29487d.0028.GAE@google.com/
Cc: Xuanqiang Luo <xuanqiang.luo@linux.dev>
Cc: Allison Henderson <achender@kernel.org>
Cc: rds-devel@oss.oracle.com
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260915130423.3956471-1-edumazet@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/skbuff.c | 32 ++++++++++++++++++++++++++++++--
1 file changed, 30 insertions(+), 2 deletions(-)
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 0e964c67a7213..c485be081aeaa 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -6820,6 +6820,34 @@ struct sk_buff *alloc_skb_with_frags(unsigned long header_len,
}
EXPORT_SYMBOL(alloc_skb_with_frags);
+/* pskb_carve_inside_header() and pskb_carve_inside_nonlinear()
+ * remove the first bytes of a packet and reallocate skb->head.
+ *
+ * Whatever headers were present before the operation are gone,
+ * we must not leave stale offsets, otherwise users of this skb
+ * (skb_dump(), drop_monitor, taps, ...) would read or pull garbage.
+ */
+static void skb_carve_reset_headers(struct sk_buff *skb)
+{
+ skb_unset_mac_header(skb);
+ skb_unset_transport_header(skb);
+ skb_reset_network_header(skb);
+ skb->mac_len = 0;
+
+ /* Inner offsets have no "unset" marker, zero them so that
+ * skb_inner_network_header_was_set() becomes false and no
+ * consumer mistakes them for a real (and long gone) header.
+ */
+ skb->inner_mac_header = 0;
+ skb->inner_network_header = 0;
+ skb->inner_transport_header = 0;
+ skb->inner_protocol = 0;
+ skb->encapsulation = 0;
+
+ if (skb->ip_summed == CHECKSUM_PARTIAL)
+ skb->ip_summed = CHECKSUM_NONE;
+}
+
/* carve out the first off bytes from skb when off < headlen */
static int pskb_carve_inside_header(struct sk_buff *skb, const u32 off,
const int headlen, gfp_t gfp_mask)
@@ -6875,7 +6903,7 @@ static int pskb_carve_inside_header(struct sk_buff *skb, const u32 off,
skb->head_frag = 0;
skb_set_end_offset(skb, size);
skb_set_tail_pointer(skb, skb_headlen(skb));
- skb_headers_offset_update(skb, 0);
+ skb_carve_reset_headers(skb);
skb->cloned = 0;
skb->hdr_len = 0;
skb->nohdr = 0;
@@ -7015,7 +7043,7 @@ static int pskb_carve_inside_nonlinear(struct sk_buff *skb, const u32 off,
skb->data = data;
skb_set_end_offset(skb, size);
skb_reset_tail_pointer(skb);
- skb_headers_offset_update(skb, 0);
+ skb_carve_reset_headers(skb);
skb->cloned = 0;
skb->hdr_len = 0;
skb->nohdr = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 168/398] ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (166 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 167/398] ASoC: hdmi-codec: Report a change when the channel status moves Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 169/398] ASoC: sdw_utils: Add codec_conf for every DAI Greg Kroah-Hartman
` (234 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vijendar Mukunda,
Mario Limonciello (AMD), Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
[ Upstream commit 29218a4d11a31a8157389bc2b9e62dd768d7ea42 ]
Add a bounds check in create_sdw_dailink() to validate that the
SoundWire link ID derived from link_mask does not exceed the maximum
supported by the platform. If the link ID is out of range or link_mask
is zero, log an error and return -EINVAL to prevent accessing invalid
CPU pin ID tables.
Applied to both acp-sdw-sof-mach.c and acp-sdw-legacy-mach.c.
Fixes: 6d8348ddc56e ("ASoC: amd: acp: refactor SoundWire machine driver code")
Signed-off-by: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Link: https://patch.msgid.link/20260910161728.1452808-2-Vijendar.Mukunda@amd.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/amd/acp/acp-sdw-legacy-mach.c | 10 ++++++++++
sound/soc/amd/acp/acp-sdw-sof-mach.c | 9 +++++++++
2 files changed, 19 insertions(+)
diff --git a/sound/soc/amd/acp/acp-sdw-legacy-mach.c b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
index ac955a9b51dc3..09387accd1269 100644
--- a/sound/soc/amd/acp/acp-sdw-legacy-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
@@ -189,6 +189,16 @@ static int create_sdw_dailink(struct snd_soc_card *card,
return -EINVAL;
}
+ if (!soc_end->link_mask) {
+ dev_err(dev, "invalid zero link_mask\n");
+ return -EINVAL;
+ }
+ if ((ffs(soc_end->link_mask) - 1) >= amd_ctx->max_sdw_links) {
+ dev_err(dev, "link_id %d exceeds max_sdw_links %d\n",
+ ffs(soc_end->link_mask) - 1, amd_ctx->max_sdw_links);
+ return -EINVAL;
+ }
+
switch (amd_ctx->acp_rev) {
case ACP63_PCI_REV:
ret = get_acp63_cpu_pin_id(ffs(soc_end->link_mask - 1),
diff --git a/sound/soc/amd/acp/acp-sdw-sof-mach.c b/sound/soc/amd/acp/acp-sdw-sof-mach.c
index 14d6e31d50408..d365c51bb99c1 100644
--- a/sound/soc/amd/acp/acp-sdw-sof-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-sof-mach.c
@@ -121,6 +121,15 @@ static int create_sdw_dailink(struct snd_soc_card *card,
return -EINVAL;
}
+ if (!sof_end->link_mask) {
+ dev_err(dev, "invalid zero link_mask\n");
+ return -EINVAL;
+ }
+ if ((ffs(sof_end->link_mask) - 1) >= amd_ctx->max_sdw_links) {
+ dev_err(dev, "link_id %d exceeds max_sdw_links %d\n",
+ ffs(sof_end->link_mask) - 1, amd_ctx->max_sdw_links);
+ return -EINVAL;
+ }
switch (amd_ctx->acp_rev) {
case ACP63_PCI_REV:
ret = get_acp63_cpu_pin_id(ffs(sof_end->link_mask - 1),
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 222/438] drm/amdgpu: check ras and obj before dereference
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (220 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 221/438] net: skbuff: do not leave stale header offsets after pskb_carve() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 223/438] drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates Greg Kroah-Hartman
` (227 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tao Zhou, Dmitriy Chumachenko,
Alex Deucher, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitriy Chumachenko <Dmitry.Chumachenko@cyberprotect.ru>
[ Upstream commit 723d4dc628d764b19cf9efca14b82cca5ff020c9 ]
nbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences ras and obj
without checking either for NULL. Both amdgpu_ras_get_context() and
amdgpu_ras_find_obj() can return NULL, e.g. during the window between
adev->nbio.ras being set (early in amdgpu_ras_init(), by design, to
enable the fatal-error interrupt as soon as possible) and the PCIE_BIF
ras object actually being created in RAS late_init. Any interrupt in that
window crashes in hard-IRQ context.
This is analogous to commit d190b459b2a4 ("drm/amdgpu: the warning
dereferencing obj for nbio_v7_4"), which fixed the same issue in the
nbio_v7_4 handler.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: 7692e1ee2446 ("drm/amdgpu: add RAS fatal error handler for NBIO v7.9")
Reviewed-by: Tao Zhou <tao.zhou1@amd.com>
Signed-off-by: Dmitriy Chumachenko <Dmitry.Chumachenko@cyberprotect.ru>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit c7071767a50a32ed727cf800ac84372429e3b4b3)
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c b/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c
index bdfd2917e3cab..def02993b7cfd 100644
--- a/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c
+++ b/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c
@@ -535,7 +535,7 @@ static void nbio_v7_9_handle_ras_controller_intr_no_bifring(struct amdgpu_device
RAS_CNTLR_INTERRUPT_CLEAR, 1);
WREG32_SOC15(NBIO, 0, regBIF_BX0_BIF_DOORBELL_INT_CNTL, bif_doorbell_intr_cntl);
- if (!ras->disable_ras_err_cnt_harvest) {
+ if (ras && !ras->disable_ras_err_cnt_harvest && obj) {
/*
* clear error status after ras_controller_intr
* according to hw team and count ue number
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 169/398] ASoC: sdw_utils: Add codec_conf for every DAI
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (167 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 168/398] ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 170/398] ASoC: intel: sof_sdw: Add ability to have auxiliary devices Greg Kroah-Hartman
` (233 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bard Liao, Charles Keepax,
Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Keepax <ckeepax@opensource.cirrus.com>
[ Upstream commit 26ee34d2f5c7fba968fcc2f1fd94110e1c1660db ]
The assumption so far is that all the DAI links for a given audio part
would be on the same device. However, as SDCA implements each audio
function on a separate auxiliary driver this will no longer be true.
This means it is necessary to add additional codec_conf structures to
get the prefix for an audio part to apply to all the auxiliary drivers
that make up that part.
Reviewed-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Link: https://patch.msgid.link/20251127163426.2500633-4-ckeepax@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 0b7d55d3a912 ("ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/amd/acp/acp-sdw-legacy-mach.c | 9 ++++++---
sound/soc/intel/boards/sof_sdw.c | 9 ++++++---
sound/soc/sdw_utils/soc_sdw_utils.c | 19 ++++++++++---------
3 files changed, 22 insertions(+), 15 deletions(-)
diff --git a/sound/soc/amd/acp/acp-sdw-legacy-mach.c b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
index 09387accd1269..b8a509bbf99a6 100644
--- a/sound/soc/amd/acp/acp-sdw-legacy-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
@@ -399,6 +399,7 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
struct snd_soc_dai_link *dai_links;
int num_devs = 0;
int num_ends = 0;
+ int num_confs;
int num_links;
int be_id = 0;
int ret;
@@ -409,6 +410,8 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
return ret;
}
+ num_confs = num_ends;
+
/* One per DAI link, worst case is a DAI link for every endpoint */
soc_dais = kcalloc(num_ends, sizeof(*soc_dais), GFP_KERNEL);
if (!soc_dais)
@@ -419,7 +422,7 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
if (!soc_ends)
return -ENOMEM;
- ret = asoc_sdw_parse_sdw_endpoints(card, soc_dais, soc_ends, &num_devs);
+ ret = asoc_sdw_parse_sdw_endpoints(card, soc_dais, soc_ends, &num_confs);
if (ret < 0)
return ret;
@@ -431,7 +434,7 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
dev_dbg(dev, "sdw %d, dmic %d", sdw_be_num, dmic_num);
- codec_conf = devm_kcalloc(dev, num_devs, sizeof(*codec_conf), GFP_KERNEL);
+ codec_conf = devm_kcalloc(dev, num_confs, sizeof(*codec_conf), GFP_KERNEL);
if (!codec_conf)
return -ENOMEM;
@@ -442,7 +445,7 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
return -ENOMEM;
card->codec_conf = codec_conf;
- card->num_configs = num_devs;
+ card->num_configs = num_confs;
card->dai_link = dai_links;
card->num_links = num_links;
diff --git a/sound/soc/intel/boards/sof_sdw.c b/sound/soc/intel/boards/sof_sdw.c
index ffa6e2ad73f75..4c2d6a5ede3ff 100644
--- a/sound/soc/intel/boards/sof_sdw.c
+++ b/sound/soc/intel/boards/sof_sdw.c
@@ -1168,6 +1168,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
struct asoc_sdw_dailink *sof_dais;
int num_devs = 0;
int num_ends = 0;
+ int num_confs;
struct snd_soc_dai_link *dai_links;
int num_links;
int be_id = 0;
@@ -1181,6 +1182,8 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
return ret;
}
+ num_confs = num_ends;
+
/*
* One per DAI link, worst case is a DAI link for every endpoint, also
* add one additional to act as a terminator such that code can iterate
@@ -1197,7 +1200,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
goto err_dai;
}
- ret = asoc_sdw_parse_sdw_endpoints(card, sof_dais, sof_ends, &num_devs);
+ ret = asoc_sdw_parse_sdw_endpoints(card, sof_dais, sof_ends, &num_confs);
if (ret < 0)
goto err_end;
@@ -1245,7 +1248,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
sdw_be_num, ssp_num, dmic_num,
intel_ctx->hdmi.idisp_codec ? hdmi_num : 0, bt_num);
- codec_conf = devm_kcalloc(dev, num_devs, sizeof(*codec_conf), GFP_KERNEL);
+ codec_conf = devm_kcalloc(dev, num_confs, sizeof(*codec_conf), GFP_KERNEL);
if (!codec_conf) {
ret = -ENOMEM;
goto err_end;
@@ -1260,7 +1263,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
}
card->codec_conf = codec_conf;
- card->num_configs = num_devs;
+ card->num_configs = num_confs;
card->dai_link = dai_links;
card->num_links = num_links;
diff --git a/sound/soc/sdw_utils/soc_sdw_utils.c b/sound/soc/sdw_utils/soc_sdw_utils.c
index 2c5c370503675..9dac810ccc611 100644
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -1387,15 +1387,6 @@ int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
ctx->ignore_internal_dmic |= codec_info->ignore_internal_dmic;
- codec_name = asoc_sdw_get_codec_name(dev, codec_info, adr_link, i);
- if (!codec_name)
- return -ENOMEM;
-
- dev_dbg(dev, "Adding prefix %s for %s\n",
- adr_dev->name_prefix, codec_name);
-
- soc_end->name_prefix = adr_dev->name_prefix;
-
if (codec_info->count_sidecar && codec_info->add_sidecar) {
ret = codec_info->count_sidecar(card, &num_dais, num_devs);
if (ret)
@@ -1483,6 +1474,16 @@ int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
num_link_dailinks += !!list_empty(&soc_dai->endpoints);
list_add_tail(&soc_end->list, &soc_dai->endpoints);
+ codec_name = asoc_sdw_get_codec_name(dev, codec_info,
+ adr_link, i);
+ if (!codec_name)
+ return -ENOMEM;
+
+ dev_dbg(dev, "Adding prefix %s for %s\n",
+ adr_dev->name_prefix, codec_name);
+
+ soc_end->name_prefix = adr_dev->name_prefix;
+
soc_end->link_mask = adr_link->mask;
soc_end->codec_name = codec_name;
soc_end->codec_info = codec_info;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 223/438] drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (221 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 222/438] drm/amdgpu: check ras and obj before dereference Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 224/438] btrfs: abort transaction on failure to update inode for hole punching and reflinking Greg Kroah-Hartman
` (226 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Francis Marlou Pacaro, Leo Li,
Alex Deucher, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Francis Marlou Pacaro <pacaro.francis.marlou.n@gmail.com>
[ Upstream commit 2ac2fe765ef475f409616ac0b57c4a3922749b0f ]
dcn30_apply_idle_power_optimizations() derives the MALL frame cache
hysteresis timer with
tmr_delay = (uint32_t)(div_u64(..., denom) - 64LL);
div_u64() returns a u64, so when the quotient is smaller than 64 the
subtraction wraps instead of going negative and tmr_delay ends up huge.
The loop that follows tries to squeeze it into the 6 bit register field
by doubling denom, but that only makes the quotient smaller, so tmr_delay
can never converge. tmr_scale is bumped past 3 and the function gives up
with
/* Delay exceeds range of hysteresis timer */
ASSERT(false);
even though the requested delay is too *short* to encode, not too long.
With mall_additional_timer_percent left at its default of 0, the quotient
drops below 64 once the refresh rate used for the calculation goes above
~243 Hz. Every DCN 3.0 display above that loses MALL static screen
entirely and splats a WARN once per boot. Reproduced on Navi 23
(RX 6600) driving 1920x1080, resetting /sys/kernel/debug/clear_warn_once
between modes:
refresh MALL ASSERT
144 Hz enabled no
240 Hz enabled no
280 Hz skipped yes
360 Hz skipped yes
Commit 3bb68cec4db8 ("drm/amd/display: Add Overflow check to skip MALL")
already covered the other end of the range, where a large stutter period
makes the delay too long to encode. Cover the short end by clamping to
0, which selects the shortest hysteresis the register can express,
65.28us * 64 = ~4.18ms. That is marginally longer than what the formula
asks for at these refresh rates, and erring long is the safe direction:
it only delays MALL entry, it can never enter early.
The numerator does not change between iterations, only denom does, so
compute it once and keep both call sites inside 100 columns.
The genuinely out of range case at very low refresh rates still reaches
the ASSERT, which is where it belongs.
Fixes: 52f2e83e2fe5 ("drm/amdgpu/display: add MALL support (v2)")
Signed-off-by: Francis Marlou Pacaro <pacaro.francis.marlou.n@gmail.com>
Reviewed-by: Leo Li <sunpeng.li@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 387550e53e1405f1f960b62b22f8783db17c8e1d)
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../gpu/drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
diff --git a/drivers/gpu/drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c b/drivers/gpu/drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c
index 2d3587a31bc8b..2ecd3a4068c03 100644
--- a/drivers/gpu/drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c
+++ b/drivers/gpu/drm/amd/display/dc/hwss/dcn30/dcn30_hwseq.c
@@ -1058,10 +1058,12 @@ bool dcn30_apply_idle_power_optimizations(struct dc *dc, bool enable)
*/
unsigned int denom = refresh_hz * 6528;
unsigned int stutter_period = dc->current_state->perf_params.stutter_period_us;
+ uint64_t num = (1000000LL + 2 * stutter_period * refresh_hz) *
+ (100LL + dc->debug.mall_additional_timer_percent);
+ uint64_t tmr_ticks;
- tmr_delay = (uint32_t)(div_u64(((1000000LL + 2 * stutter_period * refresh_hz) *
- (100LL + dc->debug.mall_additional_timer_percent) + denom - 1),
- denom) - 64LL);
+ tmr_ticks = div_u64(num + denom - 1, denom);
+ tmr_delay = tmr_ticks > 64 ? (uint32_t)(tmr_ticks - 64) : 0;
/* In some cases the stutter period is really big (tiny modes) in these
* cases MALL cant be enabled, So skip these cases to avoid a ASSERT()
@@ -1083,9 +1085,8 @@ bool dcn30_apply_idle_power_optimizations(struct dc *dc, bool enable)
}
denom *= 2;
- tmr_delay = (uint32_t)(div_u64(((1000000LL + 2 * stutter_period * refresh_hz) *
- (100LL + dc->debug.mall_additional_timer_percent) + denom - 1),
- denom) - 64LL);
+ tmr_ticks = div_u64(num + denom - 1, denom);
+ tmr_delay = tmr_ticks > 64 ? (uint32_t)(tmr_ticks - 64) : 0;
}
/* Copy HW cursor */
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 170/398] ASoC: intel: sof_sdw: Add ability to have auxiliary devices
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (168 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 169/398] ASoC: sdw_utils: Add codec_conf for every DAI Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 171/398] ASoC: sdw_utils: tidyup .count_sidecar Greg Kroah-Hartman
` (232 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bard Liao, Charles Keepax,
Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Keepax <ckeepax@opensource.cirrus.com>
[ Upstream commit c66297d09e1a5813eb743bae8cda4e115b8a5c56 ]
Currently the sof_sdw machine driver assumes that all devices involved
in the sound card are connected through a DAI link. However for SDCA
devices we still want the HID (Human Interface Device, used for jack
buttons) to be part of the sound card, but it contains no DAI links.
Add support into the machine driver to specify a list of auxiliary
devices to merged into the card.
Reviewed-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Link: https://patch.msgid.link/20251127163426.2500633-6-ckeepax@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 0b7d55d3a912 ("ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc_sdw_utils.h | 11 ++++++++++-
sound/soc/amd/acp/acp-sdw-legacy-mach.c | 12 ++++++++++--
sound/soc/amd/acp/acp-sdw-sof-mach.c | 12 ++++++++++--
sound/soc/intel/boards/sof_sdw.c | 14 ++++++++++++--
sound/soc/sdw_utils/soc_sdw_utils.c | 23 ++++++++++++++++++++---
5 files changed, 62 insertions(+), 10 deletions(-)
diff --git a/include/sound/soc_sdw_utils.h b/include/sound/soc_sdw_utils.h
index 3c5e9b2af7f1a..7badbd1d32319 100644
--- a/include/sound/soc_sdw_utils.h
+++ b/include/sound/soc_sdw_utils.h
@@ -13,6 +13,7 @@
#include <sound/soc-acpi.h>
#define SOC_SDW_MAX_DAI_NUM 8
+#define SOC_SDW_MAX_AUX_NUM 2
#define SOC_SDW_MAX_NO_PROPS 2
#define SOC_SDW_JACK_JDSRC(quirk) ((quirk) & GENMASK(3, 0))
@@ -64,6 +65,10 @@ struct asoc_sdw_dai_info {
bool quirk_exclude;
};
+struct asoc_sdw_aux_info {
+ const char *codec_name;
+};
+
struct asoc_sdw_codec_info {
const int part_id;
const int version_id;
@@ -74,6 +79,8 @@ struct asoc_sdw_codec_info {
const struct snd_soc_ops *ops;
struct asoc_sdw_dai_info dais[SOC_SDW_MAX_DAI_NUM];
const int dai_num;
+ struct asoc_sdw_aux_info auxs[SOC_SDW_MAX_AUX_NUM];
+ const int aux_num;
int (*codec_card_late_probe)(struct snd_soc_card *card);
@@ -164,12 +171,14 @@ int asoc_sdw_init_simple_dai_link(struct device *dev, struct snd_soc_dai_link *d
int no_pcm, int (*init)(struct snd_soc_pcm_runtime *rtd),
const struct snd_soc_ops *ops);
-int asoc_sdw_count_sdw_endpoints(struct snd_soc_card *card, int *num_devs, int *num_ends);
+int asoc_sdw_count_sdw_endpoints(struct snd_soc_card *card,
+ int *num_devs, int *num_ends, int *num_aux);
struct asoc_sdw_dailink *asoc_sdw_find_dailink(struct asoc_sdw_dailink *dailinks,
const struct snd_soc_acpi_endpoint *new);
int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
+ struct snd_soc_aux_dev *soc_aux,
struct asoc_sdw_dailink *soc_dais,
struct asoc_sdw_endpoint *soc_ends,
int *num_devs);
diff --git a/sound/soc/amd/acp/acp-sdw-legacy-mach.c b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
index b8a509bbf99a6..5a62e4a116311 100644
--- a/sound/soc/amd/acp/acp-sdw-legacy-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
@@ -395,16 +395,18 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
struct snd_soc_acpi_mach_params *mach_params = &mach->mach_params;
struct asoc_sdw_endpoint *soc_ends __free(kfree) = NULL;
struct asoc_sdw_dailink *soc_dais __free(kfree) = NULL;
+ struct snd_soc_aux_dev *soc_aux;
struct snd_soc_codec_conf *codec_conf;
struct snd_soc_dai_link *dai_links;
int num_devs = 0;
int num_ends = 0;
+ int num_aux = 0;
int num_confs;
int num_links;
int be_id = 0;
int ret;
- ret = asoc_sdw_count_sdw_endpoints(card, &num_devs, &num_ends);
+ ret = asoc_sdw_count_sdw_endpoints(card, &num_devs, &num_ends, &num_aux);
if (ret < 0) {
dev_err(dev, "failed to count devices/endpoints: %d\n", ret);
return ret;
@@ -422,7 +424,11 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
if (!soc_ends)
return -ENOMEM;
- ret = asoc_sdw_parse_sdw_endpoints(card, soc_dais, soc_ends, &num_confs);
+ soc_aux = devm_kcalloc(dev, num_aux, sizeof(*soc_aux), GFP_KERNEL);
+ if (!soc_aux)
+ return -ENOMEM;
+
+ ret = asoc_sdw_parse_sdw_endpoints(card, soc_aux, soc_dais, soc_ends, &num_confs);
if (ret < 0)
return ret;
@@ -448,6 +454,8 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
card->num_configs = num_confs;
card->dai_link = dai_links;
card->num_links = num_links;
+ card->aux_dev = soc_aux;
+ card->num_aux_devs = num_aux;
/* SDW */
if (sdw_be_num) {
diff --git a/sound/soc/amd/acp/acp-sdw-sof-mach.c b/sound/soc/amd/acp/acp-sdw-sof-mach.c
index d365c51bb99c1..9213f2b1208cb 100644
--- a/sound/soc/amd/acp/acp-sdw-sof-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-sof-mach.c
@@ -282,15 +282,17 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
struct snd_soc_acpi_mach_params *mach_params = &mach->mach_params;
struct asoc_sdw_endpoint *sof_ends __free(kfree) = NULL;
struct asoc_sdw_dailink *sof_dais __free(kfree) = NULL;
+ struct snd_soc_aux_dev *sof_aux;
struct snd_soc_codec_conf *codec_conf;
struct snd_soc_dai_link *dai_links;
int num_devs = 0;
int num_ends = 0;
+ int num_aux = 0;
int num_links;
int be_id = 0;
int ret;
- ret = asoc_sdw_count_sdw_endpoints(card, &num_devs, &num_ends);
+ ret = asoc_sdw_count_sdw_endpoints(card, &num_devs, &num_ends, &num_aux);
if (ret < 0) {
dev_err(dev, "failed to count devices/endpoints: %d\n", ret);
return ret;
@@ -306,7 +308,11 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
if (!sof_ends)
return -ENOMEM;
- ret = asoc_sdw_parse_sdw_endpoints(card, sof_dais, sof_ends, &num_devs);
+ sof_aux = devm_kcalloc(dev, num_aux, sizeof(*sof_aux), GFP_KERNEL);
+ if (!sof_aux)
+ return -ENOMEM;
+
+ ret = asoc_sdw_parse_sdw_endpoints(card, sof_aux, sof_dais, sof_ends, &num_devs);
if (ret < 0)
return ret;
@@ -332,6 +338,8 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
card->num_configs = num_devs;
card->dai_link = dai_links;
card->num_links = num_links;
+ card->aux_dev = sof_aux;
+ card->num_aux_devs = num_aux;
/* SDW */
if (sdw_be_num) {
diff --git a/sound/soc/intel/boards/sof_sdw.c b/sound/soc/intel/boards/sof_sdw.c
index 4c2d6a5ede3ff..0be07ea03f512 100644
--- a/sound/soc/intel/boards/sof_sdw.c
+++ b/sound/soc/intel/boards/sof_sdw.c
@@ -1166,8 +1166,10 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
struct asoc_sdw_codec_info *ssp_info;
struct asoc_sdw_endpoint *sof_ends;
struct asoc_sdw_dailink *sof_dais;
+ struct snd_soc_aux_dev *sof_aux;
int num_devs = 0;
int num_ends = 0;
+ int num_aux = 0;
int num_confs;
struct snd_soc_dai_link *dai_links;
int num_links;
@@ -1176,7 +1178,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
unsigned long ssp_mask;
int ret;
- ret = asoc_sdw_count_sdw_endpoints(card, &num_devs, &num_ends);
+ ret = asoc_sdw_count_sdw_endpoints(card, &num_devs, &num_ends, &num_aux);
if (ret < 0) {
dev_err(dev, "failed to count devices/endpoints: %d\n", ret);
return ret;
@@ -1200,7 +1202,13 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
goto err_dai;
}
- ret = asoc_sdw_parse_sdw_endpoints(card, sof_dais, sof_ends, &num_confs);
+ sof_aux = devm_kcalloc(dev, num_aux, sizeof(*sof_aux), GFP_KERNEL);
+ if (!sof_aux) {
+ ret = -ENOMEM;
+ goto err_dai;
+ }
+
+ ret = asoc_sdw_parse_sdw_endpoints(card, sof_aux, sof_dais, sof_ends, &num_confs);
if (ret < 0)
goto err_end;
@@ -1266,6 +1274,8 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
card->num_configs = num_confs;
card->dai_link = dai_links;
card->num_links = num_links;
+ card->aux_dev = sof_aux;
+ card->num_aux_devs = num_aux;
/* SDW */
if (sdw_be_num) {
diff --git a/sound/soc/sdw_utils/soc_sdw_utils.c b/sound/soc/sdw_utils/soc_sdw_utils.c
index 9dac810ccc611..80f24a2296f03 100644
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -1196,7 +1196,8 @@ int asoc_sdw_init_simple_dai_link(struct device *dev, struct snd_soc_dai_link *d
}
EXPORT_SYMBOL_NS(asoc_sdw_init_simple_dai_link, "SND_SOC_SDW_UTILS");
-int asoc_sdw_count_sdw_endpoints(struct snd_soc_card *card, int *num_devs, int *num_ends)
+int asoc_sdw_count_sdw_endpoints(struct snd_soc_card *card,
+ int *num_devs, int *num_ends, int *num_aux)
{
struct device *dev = card->dev;
struct snd_soc_acpi_mach *mach = dev_get_platdata(dev);
@@ -1207,8 +1208,18 @@ int asoc_sdw_count_sdw_endpoints(struct snd_soc_card *card, int *num_devs, int *
for (adr_link = mach_params->links; adr_link->num_adr; adr_link++) {
*num_devs += adr_link->num_adr;
- for (i = 0; i < adr_link->num_adr; i++)
- *num_ends += adr_link->adr_d[i].num_endpoints;
+ for (i = 0; i < adr_link->num_adr; i++) {
+ const struct snd_soc_acpi_adr_device *adr_dev = &adr_link->adr_d[i];
+ struct asoc_sdw_codec_info *codec_info;
+
+ *num_ends += adr_dev->num_endpoints;
+
+ codec_info = asoc_sdw_find_codec_info_part(adr_dev->adr);
+ if (!codec_info)
+ return -EINVAL;
+
+ *num_aux += codec_info->aux_num;
+ }
}
dev_dbg(dev, "Found %d devices with %d endpoints\n", *num_devs, *num_ends);
@@ -1346,6 +1357,7 @@ static int is_sdca_endpoint_present(struct device *dev,
}
int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
+ struct snd_soc_aux_dev *soc_aux,
struct asoc_sdw_dailink *soc_dais,
struct asoc_sdw_endpoint *soc_ends,
int *num_devs)
@@ -1385,6 +1397,11 @@ int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
if (!codec_info)
return -EINVAL;
+ for (j = 0; j < codec_info->aux_num; j++) {
+ soc_aux->dlc.name = codec_info->auxs[j].codec_name;
+ soc_aux++;
+ }
+
ctx->ignore_internal_dmic |= codec_info->ignore_internal_dmic;
if (codec_info->count_sidecar && codec_info->add_sidecar) {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 224/438] btrfs: abort transaction on failure to update inode for hole punching and reflinking
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (222 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 223/438] drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 225/438] btrfs: check if there is space for chunk item when validating sys chunk array Greg Kroah-Hartman
` (225 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Filipe Manana,
David Sterba, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit 97fcd34aa9fd73cefe3120ac9a82ca9d7763922f ]
If we fail to update the inode we error out without aborting the
transaction, which can result in a persistent inconsistency if after
the failure the transaction is committed, as we have dropped file
extent items from a range and either punched a hole or insert a new file
extent item for that range (for reflinks).
So add the missing transaction abort.
Fixes: 2aaa66558172 ("Btrfs: add hole punching")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/file.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/btrfs/file.c b/fs/btrfs/file.c
index f949805f2c3ef..d892683927149 100644
--- a/fs/btrfs/file.c
+++ b/fs/btrfs/file.c
@@ -2513,8 +2513,10 @@ int btrfs_replace_file_extents(struct btrfs_inode *inode,
inode_set_ctime_current(&inode->vfs_inode));
ret = btrfs_update_inode(trans, inode);
- if (ret)
+ if (unlikely(ret)) {
+ btrfs_abort_transaction(trans, ret);
break;
+ }
btrfs_end_transaction(trans);
btrfs_btree_balance_dirty(fs_info);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 171/398] ASoC: sdw_utils: tidyup .count_sidecar
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (169 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 170/398] ASoC: intel: sof_sdw: Add ability to have auxiliary devices Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 172/398] ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints() Greg Kroah-Hartman
` (231 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuninori Morimoto, Cezary Rojewski,
Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
[ Upstream commit c97f0bf5f705b16d150f2b0d5ce0ee24eee4f68a ]
count_sidecar() is not using *card. Tidyup it.
Current code makes old style / new style conversion difficult.
To make future conversions easier to understand, this patch clean up the
code a little. but no functional change.
Signed-off-by: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Reviewed-by: Cezary Rojewski <cezary.rojewski@intel.com>
Link: https://patch.msgid.link/87jyrlety1.wl-kuninori.morimoto.gx@renesas.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 0b7d55d3a912 ("ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc_sdw_utils.h | 28 ++++++++++----------
sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c | 4 +--
sound/soc/sdw_utils/soc_sdw_utils.c | 2 +-
3 files changed, 16 insertions(+), 18 deletions(-)
diff --git a/include/sound/soc_sdw_utils.h b/include/sound/soc_sdw_utils.h
index 7badbd1d32319..f27019f1b4e51 100644
--- a/include/sound/soc_sdw_utils.h
+++ b/include/sound/soc_sdw_utils.h
@@ -44,6 +44,18 @@
struct asoc_sdw_codec_info;
+struct asoc_sdw_mc_private {
+ struct snd_soc_card card;
+ struct snd_soc_jack sdw_headset;
+ struct device *headset_codec_dev; /* only one headset per card */
+ struct device *amp_dev1, *amp_dev2;
+ bool append_dai_type;
+ bool ignore_internal_dmic;
+ void *private;
+ unsigned long mc_quirk;
+ int codec_info_list_count;
+};
+
struct asoc_sdw_dai_info {
const bool direction[2]; /* playback & capture support */
const char *dai_name;
@@ -84,25 +96,13 @@ struct asoc_sdw_codec_info {
int (*codec_card_late_probe)(struct snd_soc_card *card);
- int (*count_sidecar)(struct snd_soc_card *card,
+ int (*count_sidecar)(struct asoc_sdw_mc_private *ctx,
int *num_dais, int *num_devs);
int (*add_sidecar)(struct snd_soc_card *card,
struct snd_soc_dai_link **dai_links,
struct snd_soc_codec_conf **codec_conf);
};
-struct asoc_sdw_mc_private {
- struct snd_soc_card card;
- struct snd_soc_jack sdw_headset;
- struct device *headset_codec_dev; /* only one headset per card */
- struct device *amp_dev1, *amp_dev2;
- bool append_dai_type;
- bool ignore_internal_dmic;
- void *private;
- unsigned long mc_quirk;
- int codec_info_list_count;
-};
-
struct asoc_sdw_endpoint {
struct list_head list;
@@ -219,7 +219,7 @@ int asoc_sdw_cs42l43_spk_init(struct snd_soc_card *card,
bool playback);
/* CS AMP support */
-int asoc_sdw_bridge_cs35l56_count_sidecar(struct snd_soc_card *card,
+int asoc_sdw_bridge_cs35l56_count_sidecar(struct asoc_sdw_mc_private *ctx,
int *num_dais, int *num_devs);
int asoc_sdw_bridge_cs35l56_add_sidecar(struct snd_soc_card *card,
struct snd_soc_dai_link **dai_links,
diff --git a/sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c b/sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c
index c7e55f4433514..8f189025c20cc 100644
--- a/sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c
+++ b/sound/soc/sdw_utils/soc_sdw_bridge_cs35l56.c
@@ -104,11 +104,9 @@ static const struct snd_soc_dai_link bridge_dai_template = {
SND_SOC_DAILINK_REG(asoc_sdw_bridge_dai),
};
-int asoc_sdw_bridge_cs35l56_count_sidecar(struct snd_soc_card *card,
+int asoc_sdw_bridge_cs35l56_count_sidecar(struct asoc_sdw_mc_private *ctx,
int *num_dais, int *num_devs)
{
- struct asoc_sdw_mc_private *ctx = snd_soc_card_get_drvdata(card);
-
if (ctx->mc_quirk & SOC_SDW_SIDECAR_AMPS) {
(*num_dais)++;
(*num_devs) += ARRAY_SIZE(bridge_cs35l56_name_prefixes);
diff --git a/sound/soc/sdw_utils/soc_sdw_utils.c b/sound/soc/sdw_utils/soc_sdw_utils.c
index 80f24a2296f03..7336375cd386d 100644
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -1405,7 +1405,7 @@ int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
ctx->ignore_internal_dmic |= codec_info->ignore_internal_dmic;
if (codec_info->count_sidecar && codec_info->add_sidecar) {
- ret = codec_info->count_sidecar(card, &num_dais, num_devs);
+ ret = codec_info->count_sidecar(ctx, &num_dais, num_devs);
if (ret)
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 225/438] btrfs: check if there is space for chunk item when validating sys chunk array
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (223 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 224/438] btrfs: abort transaction on failure to update inode for hole punching and reflinking Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 226/438] perf: Fix null pointer access in is_include_guest_event() Greg Kroah-Hartman
` (224 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Filipe Manana,
David Sterba, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit aeab4c62875748ecfd390a47ac1d91ea7c9a6abb ]
We checked if have enough remaining space for a key before dereferencing a
key, but we then dereference a chunk item, to get the number of stripes,
without checking if there is space for the item. So add a check to see if
there is enough space for a chunk item before dereferencing the item to
extract the stripe count.
Fixes: 2a9bb78cfd36 ("btrfs: validate system chunk array at btrfs_validate_super()")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/disk-io.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c
index de6e23b88b406..12b771bda43aa 100644
--- a/fs/btrfs/disk-io.c
+++ b/fs/btrfs/disk-io.c
@@ -2358,6 +2358,10 @@ static int validate_sys_chunk_array(const struct btrfs_fs_info *fs_info,
key.type, cur);
return -EUCLEAN;
}
+
+ if (unlikely(cur + sizeof(*chunk) > sys_array_size))
+ goto short_read;
+
chunk = (struct btrfs_chunk *)(sb->sys_chunk_array + cur);
num_stripes = btrfs_stack_chunk_num_stripes(chunk);
if (unlikely(cur + btrfs_chunk_item_size(num_stripes) > sys_array_size))
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 172/398] ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (170 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 171/398] ASoC: sdw_utils: tidyup .count_sidecar Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 173/398] ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver Greg Kroah-Hartman
` (230 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuninori Morimoto, Cezary Rojewski,
Vijendar Mukunda, Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
[ Upstream commit a1332be2a07090cf422507ec812ce2b9ba0a558a ]
We can avoid to use *card. Tidyup it.
Current code makes old style / new style conversion difficult.
To make future conversions easier to understand, this patch clean up the
code a little. but no functional change.
Signed-off-by: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Reviewed-by: Cezary Rojewski <cezary.rojewski@intel.com>
Reviewed-by: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
Link: https://patch.msgid.link/87ik75etxw.wl-kuninori.morimoto.gx@renesas.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 0b7d55d3a912 ("ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/sound/soc_sdw_utils.h | 3 ++-
sound/soc/amd/acp/acp-sdw-legacy-mach.c | 2 +-
sound/soc/amd/acp/acp-sdw-sof-mach.c | 2 +-
sound/soc/intel/boards/sof_sdw.c | 2 +-
sound/soc/sdw_utils/soc_sdw_utils.c | 5 ++---
5 files changed, 7 insertions(+), 7 deletions(-)
diff --git a/include/sound/soc_sdw_utils.h b/include/sound/soc_sdw_utils.h
index f27019f1b4e51..ea8b8adf33b7f 100644
--- a/include/sound/soc_sdw_utils.h
+++ b/include/sound/soc_sdw_utils.h
@@ -177,7 +177,8 @@ int asoc_sdw_count_sdw_endpoints(struct snd_soc_card *card,
struct asoc_sdw_dailink *asoc_sdw_find_dailink(struct asoc_sdw_dailink *dailinks,
const struct snd_soc_acpi_endpoint *new);
-int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
+int asoc_sdw_parse_sdw_endpoints(struct device *dev,
+ struct asoc_sdw_mc_private *ctx,
struct snd_soc_aux_dev *soc_aux,
struct asoc_sdw_dailink *soc_dais,
struct asoc_sdw_endpoint *soc_ends,
diff --git a/sound/soc/amd/acp/acp-sdw-legacy-mach.c b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
index 5a62e4a116311..1eebdaa2f80b9 100644
--- a/sound/soc/amd/acp/acp-sdw-legacy-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
@@ -428,7 +428,7 @@ static int soc_card_dai_links_create(struct snd_soc_card *card)
if (!soc_aux)
return -ENOMEM;
- ret = asoc_sdw_parse_sdw_endpoints(card, soc_aux, soc_dais, soc_ends, &num_confs);
+ ret = asoc_sdw_parse_sdw_endpoints(dev, ctx, soc_aux, soc_dais, soc_ends, &num_confs);
if (ret < 0)
return ret;
diff --git a/sound/soc/amd/acp/acp-sdw-sof-mach.c b/sound/soc/amd/acp/acp-sdw-sof-mach.c
index 9213f2b1208cb..616cf0f763529 100644
--- a/sound/soc/amd/acp/acp-sdw-sof-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-sof-mach.c
@@ -312,7 +312,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
if (!sof_aux)
return -ENOMEM;
- ret = asoc_sdw_parse_sdw_endpoints(card, sof_aux, sof_dais, sof_ends, &num_devs);
+ ret = asoc_sdw_parse_sdw_endpoints(dev, ctx, sof_aux, sof_dais, sof_ends, &num_devs);
if (ret < 0)
return ret;
diff --git a/sound/soc/intel/boards/sof_sdw.c b/sound/soc/intel/boards/sof_sdw.c
index 0be07ea03f512..e27bfc0196d7b 100644
--- a/sound/soc/intel/boards/sof_sdw.c
+++ b/sound/soc/intel/boards/sof_sdw.c
@@ -1208,7 +1208,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
goto err_dai;
}
- ret = asoc_sdw_parse_sdw_endpoints(card, sof_aux, sof_dais, sof_ends, &num_confs);
+ ret = asoc_sdw_parse_sdw_endpoints(dev, ctx, sof_aux, sof_dais, sof_ends, &num_confs);
if (ret < 0)
goto err_end;
diff --git a/sound/soc/sdw_utils/soc_sdw_utils.c b/sound/soc/sdw_utils/soc_sdw_utils.c
index 7336375cd386d..8729e00826959 100644
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -1356,14 +1356,13 @@ static int is_sdca_endpoint_present(struct device *dev,
return ret;
}
-int asoc_sdw_parse_sdw_endpoints(struct snd_soc_card *card,
+int asoc_sdw_parse_sdw_endpoints(struct device *dev,
+ struct asoc_sdw_mc_private *ctx,
struct snd_soc_aux_dev *soc_aux,
struct asoc_sdw_dailink *soc_dais,
struct asoc_sdw_endpoint *soc_ends,
int *num_devs)
{
- struct device *dev = card->dev;
- struct asoc_sdw_mc_private *ctx = snd_soc_card_get_drvdata(card);
struct snd_soc_acpi_mach *mach = dev_get_platdata(dev);
struct snd_soc_acpi_mach_params *mach_params = &mach->mach_params;
const struct snd_soc_acpi_link_adr *adr_link;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 226/438] perf: Fix null pointer access in is_include_guest_event()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (224 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 225/438] btrfs: check if there is space for chunk item when validating sys chunk array Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 227/438] sched/core: Avoid false migration warning for proxy donors Greg Kroah-Hartman
` (223 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vinay Belgaumkar,
Peter Zijlstra (Intel), Dapeng Mi, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vinay Belgaumkar <vinay.belgaumkar@intel.com>
[ Upstream commit 88aed0422f39b22406f35f1e758cea25e7bbcfb5 ]
A typical module unload occurring event when there is an active perf
connection leads to freeing of the pmu pointer. The call log is something
like:
..
__pmu_detach_event
pmu_detach_event
pmu_detach_events
perf_pmu_unregister
..
__pmu_detach_event() sets event->pmu to null. When the perf connection
finally is closed, the following stack trace is observed:
Oops: general protection fault, kernel NULL pointer dereference
...
RIP: 0010:_free_event+0x3e/0x370
...
Call Trace:
...
perf_event_release_kernel+0x260/0x2d0
perf_release+0x12/0x20
A call to mediated_pmu_unaccount_event() inside _free_event() is the root
cause of this crash. Adding a check inside is_include_guest_event() ensures
we don't accidentally access a null pmu ptr. In addition to this, we will
now call mediated_pmu_unaccount_event() before clearing the pmu ptr so that
nr_include_guest_events counts are maintained correctly.
Fixes: eff95e170275 ("perf: Add APIs to create/release mediated guest vPMUs")
Assisted-by: Claude:Claude-Sonnet-5
Signed-off-by: Vinay Belgaumkar <vinay.belgaumkar@intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260904181625.1394082-1-vinay.belgaumkar@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/events/core.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/kernel/events/core.c b/kernel/events/core.c
index bd8c1acf59e2e..60e60809bedc7 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -6350,6 +6350,9 @@ static DEFINE_MUTEX(perf_mediated_pmu_mutex);
/* !exclude_guest event of PMU with PERF_PMU_CAP_MEDIATED_VPMU */
static inline bool is_include_guest_event(struct perf_event *event)
{
+ if (!event->pmu)
+ return false;
+
if ((event->pmu->capabilities & PERF_PMU_CAP_MEDIATED_VPMU) &&
!event->attr.exclude_guest)
return true;
@@ -12977,6 +12980,7 @@ static void __pmu_detach_event(struct pmu *pmu, struct perf_event *event,
exclusive_event_destroy(event);
module_put(pmu->module);
+ mediated_pmu_unaccount_event(event);
event->pmu = NULL; /* force fault instead of UAF */
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 173/398] ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (171 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 172/398] ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 174/398] ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID Greg Kroah-Hartman
` (229 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vijendar Mukunda,
Mario Limonciello (AMD), Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
[ Upstream commit 0b7d55d3a91200f2b1ed710f525a944b0a7d6369 ]
num_devs was used both as the endpoint count and as the output for
asoc_sdw_parse_sdw_endpoints(), which overwrites it with the codec
configuration count. Introduce a separate num_confs variable to hold
the codec conf count so the two values remain distinct across
codec_conf allocation and card->num_configs assignment.
Fixes: 6d8348ddc56e ("ASoC: amd: acp: refactor SoundWire machine driver code")
Signed-off-by: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Link: https://patch.msgid.link/20260910161728.1452808-3-Vijendar.Mukunda@amd.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/amd/acp/acp-sdw-sof-mach.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/sound/soc/amd/acp/acp-sdw-sof-mach.c b/sound/soc/amd/acp/acp-sdw-sof-mach.c
index 616cf0f763529..5eeadeaf6453d 100644
--- a/sound/soc/amd/acp/acp-sdw-sof-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-sof-mach.c
@@ -288,6 +288,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
int num_devs = 0;
int num_ends = 0;
int num_aux = 0;
+ int num_confs;
int num_links;
int be_id = 0;
int ret;
@@ -298,6 +299,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
return ret;
}
+ num_confs = num_ends;
/* One per DAI link, worst case is a DAI link for every endpoint */
sof_dais = kcalloc(num_ends, sizeof(*sof_dais), GFP_KERNEL);
if (!sof_dais)
@@ -312,7 +314,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
if (!sof_aux)
return -ENOMEM;
- ret = asoc_sdw_parse_sdw_endpoints(dev, ctx, sof_aux, sof_dais, sof_ends, &num_devs);
+ ret = asoc_sdw_parse_sdw_endpoints(dev, ctx, sof_aux, sof_dais, sof_ends, &num_confs);
if (ret < 0)
return ret;
@@ -324,7 +326,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
dev_dbg(dev, "sdw %d, dmic %d", sdw_be_num, dmic_num);
- codec_conf = devm_kcalloc(dev, num_devs, sizeof(*codec_conf), GFP_KERNEL);
+ codec_conf = devm_kcalloc(dev, num_confs, sizeof(*codec_conf), GFP_KERNEL);
if (!codec_conf)
return -ENOMEM;
@@ -335,7 +337,7 @@ static int sof_card_dai_links_create(struct snd_soc_card *card)
return -ENOMEM;
card->codec_conf = codec_conf;
- card->num_configs = num_devs;
+ card->num_configs = num_confs;
card->dai_link = dai_links;
card->num_links = num_links;
card->aux_dev = sof_aux;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 227/438] sched/core: Avoid false migration warning for proxy donors
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (225 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 226/438] perf: Fix null pointer access in is_include_guest_event() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 228/438] x86/fred: Reconstruct the #GP context for rejected INT instructions Greg Kroah-Hartman
` (222 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrea Righi, Peter Zijlstra (Intel),
John Stultz, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrea Righi <arighi@nvidia.com>
[ Upstream commit fe3c73d7bc769e7afc252f867a3421fe168b898d ]
Proxy execution can move a blocked donor's scheduling context to the
lock owner's CPU even when the donor is migration-disabled. The donor
does not execute there, and its original execution CPU remains recorded
in wake_cpu.
set_task_cpu() warns unconditionally for migration-disabled tasks, so a
subsequent proxy migration or the wakeup path returning the donor home
triggers a false positive: moving a blocked scheduling context does not
violate the migration-disabled execution context.
For example, creating a mutex owner on CPU1 and a migration-disabled
waiter on CPU0 can trigger the following warning:
proxy_migrate_repro: donor blocking on CPU0 with migration disabled
proxy_migrate_repro: donor moved from CPU0 to CPU1
WARNING: kernel/sched/core.c:3389 at set_task_cpu+0x1d3/0x280
...
Call Trace:
try_to_wake_up+0x43f/0x780
__mutex_unlock_slowpath+0x330/0x540
owner_fn+0x9f/0xc0 [proxy_migrate_repro]
...
proxy_migrate_repro: donor woke on CPU0, task_cpu=0
proxy_migrate_repro: completed
Exclude blocked proxy donors from the warning. The proxy wakeup path
restores an executable placement before clearing the blocked state.
Fixes: b049b81bdff6 ("sched: Handle blocked-waiter migration (and return migration)")
Signed-off-by: Andrea Righi <arighi@nvidia.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Acked-by: John Stultz <jstultz@google.com>
Link: https://patch.msgid.link/20260915184101.2621252-1-arighi@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/sched/core.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/kernel/sched/core.c b/kernel/sched/core.c
index 35d647c8c3683..3d6c55598726f 100644
--- a/kernel/sched/core.c
+++ b/kernel/sched/core.c
@@ -3352,6 +3352,8 @@ void relax_compatible_cpus_allowed_ptr(struct task_struct *p)
void set_task_cpu(struct task_struct *p, unsigned int new_cpu)
{
unsigned int state = READ_ONCE(p->__state);
+ bool proxy_migrated = sched_proxy_exec() && p->is_blocked &&
+ task_cpu(p) != p->wake_cpu;
/*
* We should never call set_task_cpu() on a blocked task,
@@ -3387,7 +3389,12 @@ void set_task_cpu(struct task_struct *p, unsigned int new_cpu)
*/
WARN_ON_ONCE(!cpu_online(new_cpu));
- WARN_ON_ONCE(is_migration_disabled(p));
+ /*
+ * Proxy execution can move a blocked task's scheduling context to any
+ * CPU without moving its migration-disabled execution context. The
+ * wakeup path will return the task to a CPU where it can execute.
+ */
+ WARN_ON_ONCE(is_migration_disabled(p) && !proxy_migrated);
trace_sched_migrate_task(p, new_cpu);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 174/398] ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (172 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 173/398] ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 175/398] net: netsec: fix device_node reference leak on phy_np Greg Kroah-Hartman
` (228 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vijendar Mukunda,
Mario Limonciello (AMD), Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
[ Upstream commit 27098aaf28b96ab4e6891709062c343566d4882b ]
ffs(link_mask - 1) computes ffs on (link_mask - 1) instead of
subtracting 1 from the result of ffs(link_mask). For a typical
power-of-2 link_mask this returns the wrong link ID, causing cpu_pin_id
lookup to select the incorrect SoundWire manager.
Fix the operator precedence to ffs(link_mask) - 1 in both
acp-sdw-sof-mach.c and acp-sdw-legacy-mach.c.
Fixes: 6d8348ddc56e ("ASoC: amd: acp: refactor SoundWire machine driver code")
Signed-off-by: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Link: https://patch.msgid.link/20260910161728.1452808-4-Vijendar.Mukunda@amd.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/amd/acp/acp-sdw-legacy-mach.c | 4 ++--
sound/soc/amd/acp/acp-sdw-sof-mach.c | 4 ++--
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/sound/soc/amd/acp/acp-sdw-legacy-mach.c b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
index 1eebdaa2f80b9..53567fdf3e2d6 100644
--- a/sound/soc/amd/acp/acp-sdw-legacy-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-legacy-mach.c
@@ -201,7 +201,7 @@ static int create_sdw_dailink(struct snd_soc_card *card,
switch (amd_ctx->acp_rev) {
case ACP63_PCI_REV:
- ret = get_acp63_cpu_pin_id(ffs(soc_end->link_mask - 1),
+ ret = get_acp63_cpu_pin_id(ffs(soc_end->link_mask) - 1,
*be_id, &cpu_pin_id, dev);
if (ret)
return ret;
@@ -209,7 +209,7 @@ static int create_sdw_dailink(struct snd_soc_card *card,
case ACP70_PCI_REV:
case ACP71_PCI_REV:
case ACP72_PCI_REV:
- ret = get_acp70_cpu_pin_id(ffs(soc_end->link_mask - 1),
+ ret = get_acp70_cpu_pin_id(ffs(soc_end->link_mask) - 1,
*be_id, &cpu_pin_id, dev);
if (ret)
return ret;
diff --git a/sound/soc/amd/acp/acp-sdw-sof-mach.c b/sound/soc/amd/acp/acp-sdw-sof-mach.c
index 5eeadeaf6453d..4081cccb9050c 100644
--- a/sound/soc/amd/acp/acp-sdw-sof-mach.c
+++ b/sound/soc/amd/acp/acp-sdw-sof-mach.c
@@ -132,7 +132,7 @@ static int create_sdw_dailink(struct snd_soc_card *card,
}
switch (amd_ctx->acp_rev) {
case ACP63_PCI_REV:
- ret = get_acp63_cpu_pin_id(ffs(sof_end->link_mask - 1),
+ ret = get_acp63_cpu_pin_id(ffs(sof_end->link_mask) - 1,
*be_id, &cpu_pin_id, dev);
if (ret)
return ret;
@@ -140,7 +140,7 @@ static int create_sdw_dailink(struct snd_soc_card *card,
case ACP70_PCI_REV:
case ACP71_PCI_REV:
case ACP72_PCI_REV:
- ret = get_acp70_cpu_pin_id(ffs(sof_end->link_mask - 1),
+ ret = get_acp70_cpu_pin_id(ffs(sof_end->link_mask) - 1,
*be_id, &cpu_pin_id, dev);
if (ret)
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 228/438] x86/fred: Reconstruct the #GP context for rejected INT instructions
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (226 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 227/438] sched/core: Avoid false migration warning for proxy donors Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 229/438] Input: eeti_ts - publish the OF module alias Greg Kroah-Hartman
` (221 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paul Gofman, Matthew Schwartz,
Peter Zijlstra (Intel), H. Peter Anvin, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthew Schwartz <matthew.schwartz@linux.dev>
[ Upstream commit 93f53499d0b945e8ae447f497faf743d60069f61 ]
FRED event delivery does not use the IDT, so the gate DPL check that
rejects a user INT n falls to software (Intel FRED specification [1],
section 8.3). fred_intx() rejects the same vectors as IDT delivery, but
reports a zero error code and the IP after the INT. This breaks the
signal ABI. Wine uses the error code to recognize INT 0x2d, so the
changed context turns a handled breakpoint into an access violation in
Elden Ring.
Rewind IP using the instruction length in the augmented SS and
synthesize the IDT selector error code, (vector << 3) | 2. Set RF in the
saved flags, as the CPU does for a #GP fault. Section 5.2.1 defines the
saved vector, instruction length and RF state. The supplied length
handles prefixes without reading user memory. Limit the changes to
already-rejected software interrupts, preserving the accepted INT3, INT4
and enabled INT80 paths and hardware exceptions. With IA32 emulation
disabled, INT 0x80 now reports the same #GP as the DPL 0 gate IDT
installs there. The rewound IP also stops fixup_iopl_exception() from
inspecting the byte after the INT.
Also clear the software event flag. Section 6.2.3 specifies that ERETU
with this flag and TF set traps before executing any user instruction. A
tracer that suppresses SIGSEGV and resumes with TF set expects the next
instruction to run first, as after IRET. The sigreturn path clears the
same flag for this reason in prevent_single_step_upon_eretu().
[1] Intel Flexible Return and Event Delivery (FRED) Specification,
revision 9.0 (346446-009US), sections 5.2.1, 6.2.3 and 8.3.
Fixes: 14619d912b65 ("x86/fred: FRED entry/exit and dispatch code")
Closes: https://gitlab.freedesktop.org/mesa/mesa/-/work_items/15745
Closes: https://gitlab.freedesktop.org/mesa/mesa/-/work_items/16132
Reported-by: Paul Gofman <pgofman@codeweavers.com>
Signed-off-by: Matthew Schwartz <matthew.schwartz@linux.dev>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: H. Peter Anvin <hpa@zytor.com>
Link: https://cdrdv2.intel.com/v1/dl/getContent/678938 # [1]
Link: https://patch.msgid.link/20260917230907.2080792-2-matthew.schwartz@linux.dev
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/entry/entry_fred.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/arch/x86/entry/entry_fred.c b/arch/x86/entry/entry_fred.c
index fb3594ddf731f..854899bfec5d9 100644
--- a/arch/x86/entry/entry_fred.c
+++ b/arch/x86/entry/entry_fred.c
@@ -10,6 +10,7 @@
#include <asm/desc.h>
#include <asm/fred.h>
#include <asm/idtentry.h>
+#include <asm/processor-flags.h>
#include <asm/syscall.h>
#include <asm/trapnr.h>
#include <asm/traps.h>
@@ -71,7 +72,15 @@ static noinstr void fred_intx(struct pt_regs *regs)
#endif
default:
- return exc_general_protection(regs, 0);
+ /*
+ * Reconstruct the #GP fault state that IDT delivery would produce.
+ * Clear the software event flag so ERETU with TF set does not trap
+ * before the resumed instruction. See prevent_single_step_upon_eretu().
+ */
+ regs->ip -= regs->fred_ss.insnlen;
+ regs->flags |= X86_EFLAGS_RF;
+ regs->fred_ss.swevent = 0;
+ return exc_general_protection(regs, (regs->fred_ss.vector << 3) | 2);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 175/398] net: netsec: fix device_node reference leak on phy_np
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (173 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 174/398] ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 177/398] net: lock the socket in sock_gettstamp() Greg Kroah-Hartman
` (227 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yige Jiang, Simon Horman,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yige Jiang <yigejiang86@gmail.com>
[ Upstream commit 5ae916fabca141b79b32e2e57f3c915c0f1e1b2e ]
netsec_of_probe() takes a reference on the PHY device_node with
of_parse_phandle() and stores it in priv->phy_np, but the driver never
drops it. One device_node reference is leaked per probe, on the success
path as well as on every error path reached after netsec_of_probe().
Neither consumer takes ownership. of_mdio_parse_addr() is a static
inline taking a const struct device_node * that only reads the "reg"
property. of_phy_connect() borrows as well: of_phy_get_and_connect() in
drivers/net/mdio/of_mdio.c brackets its own call with of_node_get() at
:364 and of_node_put() at :373, which would be a double put if
of_phy_connect() consumed the reference.
The node is still in use at netsec_netdev_open() time, where it is
passed to of_phy_connect(), so it has device lifetime. Release it at
the probe error label, which every failure path after the acquire
funnels through, and in netsec_remove(). Both releases precede
free_netdev(), since priv is netdev_priv(ndev). The ACPI probe path
leaves priv->phy_np NULL and of_node_put(NULL) is a no-op.
There is no end-user visible symptom on currently supported platforms:
a device_node is only freed once OF_DYNAMIC is enabled and the node has
been detached, so on a static device tree the imbalance is inert. It is
observable as a refcount that grows across bind/unbind cycles, and would
matter under device tree overlays.
Found by static analysis of reference acquire/release pairing rather
than from a runtime report. No reproducer was produced and the change
has not been runtime tested; it is compile-tested only (arm64,
CONFIG_SNI_NETSEC=m via COMPILE_TEST).
Fixes: 533dd11a12f6 ("net: socionext: Add Synquacer NetSec driver")
Signed-off-by: Yige Jiang <yigejiang86@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260913064102.37452-1-yigejiang86@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/socionext/netsec.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/ethernet/socionext/netsec.c b/drivers/net/ethernet/socionext/netsec.c
index ee890de69ffe7..a432eb354049c 100644
--- a/drivers/net/ethernet/socionext/netsec.c
+++ b/drivers/net/ethernet/socionext/netsec.c
@@ -2149,6 +2149,7 @@ static int netsec_probe(struct platform_device *pdev)
pm_runtime_put_sync(&pdev->dev);
pm_runtime_disable(&pdev->dev);
free_ndev:
+ of_node_put(priv->phy_np);
free_netdev(ndev);
dev_err(&pdev->dev, "init failed\n");
@@ -2166,6 +2167,7 @@ static void netsec_remove(struct platform_device *pdev)
netif_napi_del(&priv->napi);
pm_runtime_disable(&pdev->dev);
+ of_node_put(priv->phy_np);
free_netdev(priv->ndev);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 229/438] Input: eeti_ts - publish the OF module alias
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (227 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 228/438] x86/fred: Reconstruct the #GP context for rejected INT instructions Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 230/438] hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler Greg Kroah-Hartman
` (220 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, hpp.iscas, Dmitry Torokhov,
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: hpp.iscas <hppiscas@163.com>
[ Upstream commit a52ae68a937efc353251aec27fc995ff66cbe1ca ]
The EETI driver matches eeti,exc3000-i2c Device Tree clients, but only
publishes the legacy eeti_ts I2C ID. The I2C core emits an OF modalias
for a Device Tree client.
Publish the existing OF match table within its CONFIG_OF guard.
Fixes: e32d7f1b246c ("Input: eeti - add device tree matching table")
Signed-off-by: hpp.iscas <hppiscas@163.com>
Link: https://patch.msgid.link/20260905134004.66336-1-hppiscas@163.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/input/touchscreen/eeti_ts.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/input/touchscreen/eeti_ts.c b/drivers/input/touchscreen/eeti_ts.c
index b12602bc368ef..b870a939508bb 100644
--- a/drivers/input/touchscreen/eeti_ts.c
+++ b/drivers/input/touchscreen/eeti_ts.c
@@ -276,6 +276,7 @@ static const struct of_device_id of_eeti_ts_match[] = {
{ .compatible = "eeti,exc3000-i2c", },
{ }
};
+MODULE_DEVICE_TABLE(of, of_eeti_ts_match);
#endif
static struct i2c_driver eeti_ts_driver = {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 176/398] eth: fbnic: ring the doorbell if a burst ends in a drop
2026-09-23 14:02 ` [PATCH 7.2 124/438] ntfs: propagate folio errors Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
0 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexander Duyck, Simon Horman,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Kicinski <kuba@kernel.org>
[ Upstream commit 490599ab23134962a6d18a024e84541d77bdb999 ]
fbnic_tx_map() skips the doorbell write, and the completion request,
for every packet handed to it with xmit_more set, counting on the
packet which ends the burst to publish them all. When that packet is
dropped instead - skb_put_padto(), skb_cow_head() or a DMA mapping
failure - nothing rings. The descriptors of the preceding packets stay
invisible to the HW until the next transmit on that queue, which for a
burst-then-idle workload may never come.
Remember the meta descriptor of the last packet left without a doorbell
and flush it from the error paths. The completion request has to be set
on that descriptor rather than simply writing the tail, otherwise the HW
would transmit the packets but never report a head, and the ring would
fill up and stall for good.
This is very similar to Joe's recent series of fixes for bnxt.
Not seen in real life, reproduced under QEMU with failure injection.
Fixes: 9a57bacd574b ("eth: fbnic: Add basic Tx handling")
Reviewed-by: Alexander Duyck <alexanderduyck@fb.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915022327.913218-1-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/meta/fbnic/fbnic_txrx.c | 42 +++++++++++++++-----
drivers/net/ethernet/meta/fbnic/fbnic_txrx.h | 9 ++++-
2 files changed, 40 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
index dbe0855ecb575..0ea861ff40f56 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.c
@@ -311,6 +311,29 @@ fbnic_rx_csum(u64 rcd, struct sk_buff *skb, struct fbnic_ring *rcq,
}
}
+static void fbnic_tx_doorbell(struct fbnic_ring *ring, __le64 *meta)
+{
+ *meta |= cpu_to_le64(FBNIC_TWD_FLAG_REQ_COMPLETION);
+ ring->deferred_meta = -1;
+
+ /* Force DMA writes to flush before writing to tail */
+ dma_wmb();
+
+ writel(ring->tail, ring->doorbell);
+}
+
+/* Packets handed to us with xmit_more set are left in the ring without a
+ * doorbell, and without a completion request, in the expectation that the
+ * packet ending the burst will ring for all of them. If that packet gets
+ * dropped instead we have to ring here, otherwise the descriptors sit in
+ * the ring until the next transmit, which may never come.
+ */
+static void fbnic_tx_flush_doorbell(struct fbnic_ring *ring)
+{
+ if (ring->deferred_meta >= 0)
+ fbnic_tx_doorbell(ring, &ring->desc[ring->deferred_meta]);
+}
+
static bool
fbnic_tx_map(struct fbnic_ring *ring, struct sk_buff *skb, __le64 *meta)
{
@@ -378,14 +401,10 @@ fbnic_tx_map(struct fbnic_ring *ring, struct sk_buff *skb, __le64 *meta)
/* Verify there is room for another packet */
fbnic_maybe_stop_tx(skb->dev, ring, FBNIC_MAX_SKB_DESC);
- if (fbnic_tx_sent_queue(skb, ring)) {
- *meta |= cpu_to_le64(FBNIC_TWD_FLAG_REQ_COMPLETION);
-
- /* Force DMA writes to flush before writing to tail */
- dma_wmb();
-
- writel(tail, ring->doorbell);
- }
+ if (fbnic_tx_sent_queue(skb, ring))
+ fbnic_tx_doorbell(ring, meta);
+ else
+ ring->deferred_meta = meta - ring->desc;
return false;
dma_error:
@@ -425,8 +444,10 @@ fbnic_xmit_frame_ring(struct sk_buff *skb, struct fbnic_ring *ring)
* otherwise try next time
*/
desc_needed = skb_shinfo(skb)->nr_frags + 10;
- if (fbnic_maybe_stop_tx(skb->dev, ring, desc_needed))
+ if (fbnic_maybe_stop_tx(skb->dev, ring, desc_needed)) {
+ fbnic_tx_flush_doorbell(ring);
return NETDEV_TX_BUSY;
+ }
*meta = cpu_to_le64(FBNIC_TWD_FLAG_DEST_MAC);
@@ -447,6 +468,8 @@ fbnic_xmit_frame_ring(struct sk_buff *skb, struct fbnic_ring *ring)
err_free:
dev_kfree_skb_any(skb);
err_count:
+ fbnic_tx_flush_doorbell(ring);
+
u64_stats_update_begin(&ring->stats.syncp);
ring->stats.dropped++;
u64_stats_update_end(&ring->stats.syncp);
@@ -2473,6 +2496,7 @@ static void fbnic_enable_twq0(struct fbnic_ring *twq)
fbnic_ring_wr32(twq, FBNIC_QUEUE_TWQ0_CTL, FBNIC_QUEUE_TWQ_CTL_RESET);
twq->tail = 0;
twq->head = 0;
+ twq->deferred_meta = -1;
/* Store descriptor ring address and size */
fbnic_ring_wr32(twq, FBNIC_QUEUE_TWQ0_BAL, lower_32_bits(twq->dma));
diff --git a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.h b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.h
index f2ee2cbf3486b..643e7d3ddb543 100644
--- a/drivers/net/ethernet/meta/fbnic/fbnic_txrx.h
+++ b/drivers/net/ethernet/meta/fbnic/fbnic_txrx.h
@@ -128,9 +128,14 @@ struct fbnic_ring {
/* Rx BDQs only */
struct page_pool *page_pool;
- /* Deferred_head is used to cache the head for TWQ1 if
+ /* TWQ0 only, index of the meta descriptor of the last packet
+ * placed in the ring without ringing the doorbell, -1 if the
+ * doorbell is in sync with the tail.
+ */
+ s32 deferred_meta;
+
+ /* TCQ only, used to cache the head for TWQ1 if
* an attempt is made to clean TWQ1 with zero napi_budget.
- * We do not use it for any other ring.
*/
s32 deferred_head;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 230/438] hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (228 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 229/438] Input: eeti_ts - publish the OF module alias Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 231/438] hwmon: (hp-wmi-sensors) Improve raw WMI string handling Greg Kroah-Hartman
` (219 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko AI review, Cong Nguyen,
Guenter Roeck, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cong Nguyen <congnt264@gmail.com>
[ Upstream commit bdf5f731957de48acada392f28e82bc019713adb ]
fan_alarm_irq_handler() always schedules alarm_work but returns IRQ_NONE,
so the kernel treats every alarm interrupt as unhandled. On a shared
line that risks the whole line being disabled as spurious.
v1 just fixed that, but it was still IRQF_SHARED, and always returning
IRQ_HANDLED there defeats spurious-interrupt detection for the line --
if the interrupt ever fires without a real event, nothing catches it,
and a fault could spin the CPU in the handler.
Sashiko flagged this in v1, and Guenter confirmed: this interrupt must
not be shared. So v2 drops IRQF_SHARED too.
Fixes: d6fe1360f42e ("hwmon: add generic GPIO fan driver")
Reported-by: Sashiko AI review <sashiko-bot@kernel.org>
Link: https://lore.kernel.org/r/20260901160931.DD3811F00A3D@smtp.kernel.org
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Link: https://patch.msgid.link/20260914104136.1797979-1-congnt264@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/gpio-fan.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/hwmon/gpio-fan.c b/drivers/hwmon/gpio-fan.c
index df8bd97076050..3f78375eeb448 100644
--- a/drivers/hwmon/gpio-fan.c
+++ b/drivers/hwmon/gpio-fan.c
@@ -68,7 +68,7 @@ static irqreturn_t fan_alarm_irq_handler(int irq, void *dev_id)
schedule_work(&fan_data->alarm_work);
- return IRQ_NONE;
+ return IRQ_HANDLED;
}
static ssize_t fan1_alarm_show(struct device *dev,
@@ -103,7 +103,7 @@ static int fan_alarm_init(struct gpio_fan_data *fan_data)
irq_set_irq_type(alarm_irq, IRQ_TYPE_EDGE_BOTH);
return devm_request_irq(dev, alarm_irq, fan_alarm_irq_handler,
- IRQF_SHARED, "GPIO fan alarm", fan_data);
+ 0, "GPIO fan alarm", fan_data);
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 177/398] net: lock the socket in sock_gettstamp()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (174 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 175/398] net: netsec: fix device_node reference leak on phy_np Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 178/398] net: ethernet: cortina: Ack RX overrun interrupt correctly Greg Kroah-Hartman
` (226 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jungwoo Lee, Wongi Lee, Eric Dumazet,
Simon Horman, Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit 9ed55f3dbef4f4adfe65eb03b0c35c53229a8490 ]
sk->sk_flags must only be changed while holding the socket lock,
because sock_set_flag() and sock_reset_flag() use non atomic
operations (__set_bit() and __clear_bit()).
sock_gettstamp() is one of the last places where a bit of sk->sk_flags
is changed from a syscall without owning the socket lock, through
sock_enable_timestamp(sk, SOCK_TIMESTAMP).
sk_set_memalloc() and sk_clear_memalloc() also change sk->sk_flags
without the socket lock, but their callers (nbd, iscsi_tcp, nvme-tcp,
sunrpc, wireguard) need a careful audit, this will be addressed in a
separate patch.
Jungwoo Lee and Wongi Lee reported an UDP socket use-after-free
caused by this bug: a SIOCGSTAMPNS_NEW ioctl racing with bind()
can cancel the SOCK_RCU_FREE bit that udp_lib_get_port() just set,
because both threads perform a read-modify-write on the same word.
CPU 0 (bind) CPU 1 (SIOCGSTAMPNS_NEW)
-------------------------------- ----------------------------
read sk_flags = F read sk_flags = F
compute F | BIT(SOCK_RCU_FREE) compute F | BIT(SOCK_TIMESTAMP)
store F | BIT(SOCK_RCU_FREE)
sk_add_node_rcu(sk, ...)
store F | BIT(SOCK_TIMESTAMP)
After the lost update, SOCK_RCU_FREE is clear while the socket is
visible to lockless UDP receive lookups. sk_destruct() then frees
the socket immediately instead of waiting for a RCU grace period,
while the receive path still holds a reference-less pointer to it:
BUG: KASAN: slab-use-after-free in ipv4_pktinfo_prepare+0x30/0x410
Read of size 8 at addr ffff888008806610 by task exploit/207
CPU: 0 UID: 1000 PID: 207 Comm: exploit Not tainted 6.12.95+ #1
ipv4_pktinfo_prepare+0x30/0x410
udp_queue_rcv_one_skb+0x51c/0x1180
udp_unicast_rcv_skb+0x109/0x350
ip_protocol_deliver_rcu+0x14b/0x310
ip_local_deliver_finish+0x29d/0x390
ip_local_deliver+0x24d/0x2a0
Only grab the socket lock when SOCK_TIMESTAMP has to be set,
to keep the common case lockless.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Jungwoo Lee <jwlee2217@gmail.com>
Reported-by: Wongi Lee <qw3rtyp0@gmail.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260915043055.3441600-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/sock.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/net/core/sock.c b/net/core/sock.c
index 1b64ac35073db..a0288a3618193 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -3783,7 +3783,14 @@ int sock_gettstamp(struct socket *sock, void __user *userstamp,
struct sock *sk = sock->sk;
struct timespec64 ts;
- sock_enable_timestamp(sk, SOCK_TIMESTAMP);
+ /* sk->sk_flags must only be changed under the socket lock,
+ * because sock_set_flag() uses non atomic operations.
+ */
+ if (!sock_flag(sk, SOCK_TIMESTAMP)) {
+ lock_sock(sk);
+ sock_enable_timestamp(sk, SOCK_TIMESTAMP);
+ release_sock(sk);
+ }
ts = ktime_to_timespec64(sock_read_timestamp(sk));
if (ts.tv_sec == -1)
return -ENOENT;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 231/438] hwmon: (hp-wmi-sensors) Improve raw WMI string handling
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (229 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 230/438] hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 232/438] watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
` (218 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Muhammad Bilal, James Seo,
Guenter Roeck, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Seo <james@equiv.tech>
[ Upstream commit 92b68492eae701e5b0e9d142ffe229921af7b1fa ]
Commit c9ba59258094 ("hwmon: (hp-wmi-sensors) Fix failure to load on
EliteDesk 800 G6") left out some logic for recognizing raw WMI
strings in check_numeric_sensor_wobj(). This issue was reported by a
user along with an incomplete and unsuitable proposed solution [1].
Add the missing logic and properly remedy the issue. Also slightly
refactor how raw WMI strings are recognized elsewhere to make the
intent that they should be treated as regular ACPI strings clearer.
Reported-by: Muhammad Bilal <meatuni001@gmail.com>
Link: https://lore.kernel.org/linux-hwmon/20260916002907.161210-1-meatuni001@gmail.com/ [1]
Fixes: c9ba59258094 ("hwmon: (hp-wmi-sensors) Fix failure to load on EliteDesk 800 G6")
Signed-off-by: James Seo <james@equiv.tech>
Link: https://patch.msgid.link/20260916221912.434119-5-james@equiv.tech
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/hp-wmi-sensors.c | 30 ++++++++++++++++++++++--------
1 file changed, 22 insertions(+), 8 deletions(-)
diff --git a/drivers/hwmon/hp-wmi-sensors.c b/drivers/hwmon/hp-wmi-sensors.c
index 03c684ba83bd6..cb2eb9bd278a2 100644
--- a/drivers/hwmon/hp-wmi-sensors.c
+++ b/drivers/hwmon/hp-wmi-sensors.c
@@ -526,14 +526,12 @@ static int check_wobj(const union acpi_object *wobj,
for (prop = 0; prop <= last_prop; prop++) {
type = elements[prop].type;
valid_type = property_map[prop];
- if (type != valid_type) {
- if (type == ACPI_TYPE_BUFFER &&
- valid_type == ACPI_TYPE_STRING &&
- is_raw_wmi_string(elements[prop].buffer.pointer,
- elements[prop].buffer.length))
- continue;
+ if (type == ACPI_TYPE_BUFFER &&
+ is_raw_wmi_string(elements[prop].buffer.pointer,
+ elements[prop].buffer.length))
+ type = ACPI_TYPE_STRING;
+ if (type != valid_type)
return -EINVAL;
- }
}
return 0;
@@ -579,6 +577,7 @@ static int check_numeric_sensor_wobj(const union acpi_object *wobj,
int prop = HP_WMI_PROPERTY_NAME;
acpi_object_type valid_type;
union acpi_object *elements;
+ union acpi_object *element;
u32 elem_count;
int last_prop;
bool is_new;
@@ -602,13 +601,20 @@ static int check_numeric_sensor_wobj(const union acpi_object *wobj,
elem_count > HP_WMI_MAX_PROPERTIES)
return -EINVAL;
- type = elements[HP_WMI_PROPERTY_SIZE].type;
+ element = &elements[HP_WMI_PROPERTY_SIZE];
+ type = element->type;
switch (type) {
case ACPI_TYPE_INTEGER:
is_new = true;
last_prop = HP_WMI_PROPERTY_RATE_UNITS;
break;
+ case ACPI_TYPE_BUFFER:
+ if (!is_raw_wmi_string(element->buffer.pointer,
+ element->buffer.length))
+ return -EINVAL;
+ fallthrough;
+
case ACPI_TYPE_STRING:
is_new = false;
last_prop = HP_WMI_PROPERTY_CURRENT_READING;
@@ -631,6 +637,10 @@ static int check_numeric_sensor_wobj(const union acpi_object *wobj,
for (i = 0; i < elem_count && prop <= last_prop; i++, prop++) {
type = elements[i].type;
valid_type = hp_wmi_property_map[prop];
+ if (type == ACPI_TYPE_BUFFER &&
+ is_raw_wmi_string(elements[i].buffer.pointer,
+ elements[i].buffer.length))
+ type = ACPI_TYPE_STRING;
if (type != valid_type)
return -EINVAL;
@@ -651,6 +661,10 @@ static int check_numeric_sensor_wobj(const union acpi_object *wobj,
/* PossibleStates[0] has already been type-checked. */
for (j = 0; i + 1 < elem_count && j + 1 < count; j++) {
type = elements[++i].type;
+ if (type == ACPI_TYPE_BUFFER &&
+ is_raw_wmi_string(elements[i].buffer.pointer,
+ elements[i].buffer.length))
+ type = ACPI_TYPE_STRING;
if (type != valid_type)
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 178/398] net: ethernet: cortina: Ack RX overrun interrupt correctly
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (175 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 177/398] net: lock the socket in sock_gettstamp() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 179/398] net: stmmac: propagate FPE preemption-class mapping errors Greg Kroah-Hartman
` (225 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linus Walleij, Jakub Kicinski,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 1dd85662fee6e2ac580b1c4f9a0c0a7ae6e31f0e ]
The RX overrun interrupt is reported in interrupt status register 4, but
gmac_irq() acknowledges it using the RX descriptor error bit from status
register 0. For GMAC0 this writes the GMAC1 overrun bit, while for GMAC1
the shift leaves no bit in the 32-bit register.
Acknowledge the same per-port RX overrun bit that was detected.
Fixes: 4d5ae32f5e1e ("net: ethernet: Add a driver for Gemini gigabit ethernet")
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260914-b4-gemini-ethernet-fixes-2-v2-1-5ab39a047b90@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cortina/gemini.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/cortina/gemini.c b/drivers/net/ethernet/cortina/gemini.c
index 3215d26aa2d39..fddb068cc13c8 100644
--- a/drivers/net/ethernet/cortina/gemini.c
+++ b/drivers/net/ethernet/cortina/gemini.c
@@ -1799,7 +1799,7 @@ static irqreturn_t gmac_irq(int irq, void *data)
if (val & (GMAC0_RX_OVERRUN_INT_BIT << (netdev->dev_id * 8))) {
spin_lock(&geth->irq_lock);
- writel(GMAC0_RXDERR_INT_BIT << (netdev->dev_id * 8),
+ writel(GMAC0_RX_OVERRUN_INT_BIT << (netdev->dev_id * 8),
geth->base + GLOBAL_INTERRUPT_STATUS_4_REG);
u64_stats_update_begin(&port->ir_stats_syncp);
++port->stats.rx_fifo_errors;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 232/438] watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (230 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 231/438] hwmon: (hp-wmi-sensors) Improve raw WMI string handling Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 233/438] Input: xpad - add support for Victrix Pro BFG Controller Greg Kroah-Hartman
` (217 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Li Jun, Guenter Roeck, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Jun <lijun01@kylinos.cn>
[ Upstream commit 5071122bf5a628494db16d98d253f622a5aab074 ]
da9062_wdt_suspend() and da9062_wdt_resume() only check watchdog_active(),
when the watchdog is left running by the driver sets
WDOG_HW_RUNNING in da9062_wdt_probe() but userspace never opens the
device, so WDOG_ACTIVE remains cleared, the wdt_disable() will not be
executed in da9062_wdt_suspend. In this case, the suspend callback is
a no-op and the watchdog keeps counting during system suspend,
leading to an unexpected system reset.
Check WDOG_HW_RUNNING and wdt->wdd,can fix this issue.
Fixes: f6c98b08381c7 ("watchdog: da9062: add power management ops")
Cs: stable@vger.kernel.org
Signed-off-by: Li Jun <lijun01@kylinos.cn>
Link: https://patch.msgid.link/20260914062353.582205-1-lijun01@kylinos.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/watchdog/da9062_wdt.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/watchdog/da9062_wdt.c b/drivers/watchdog/da9062_wdt.c
index 426962547df16..4d558652e9e71 100644
--- a/drivers/watchdog/da9062_wdt.c
+++ b/drivers/watchdog/da9062_wdt.c
@@ -256,7 +256,7 @@ static int __maybe_unused da9062_wdt_suspend(struct device *dev)
if (!wdt->use_sw_pm)
return 0;
- if (watchdog_active(wdd))
+ if (watchdog_active(wdd) || watchdog_hw_running(wdd))
return da9062_wdt_stop(wdd);
return 0;
@@ -270,7 +270,7 @@ static int __maybe_unused da9062_wdt_resume(struct device *dev)
if (!wdt->use_sw_pm)
return 0;
- if (watchdog_active(wdd))
+ if (watchdog_active(wdd) || watchdog_hw_running(wdd))
return da9062_wdt_start(wdd);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 179/398] net: stmmac: propagate FPE preemption-class mapping errors
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (176 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 178/398] net: ethernet: cortina: Ack RX overrun interrupt correctly Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 180/398] net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() Greg Kroah-Hartman
` (224 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Jakub Kicinski,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
[ Upstream commit 90e4b849dfa6fc8e6c050bcfe1b331b69c015d28 ]
stmmac_fpe_map_preemption_class() dispatches through the
stmmac_do_void_callback() helper, which forces the callback's return
value to 0 whenever the op pointer is populated. As a result the
-EINVAL returned by dwmac5_fpe_map_preemption_class() (e.g. when a
preemptible TC owns more than one TXQ under SP scheduling) is silently
swallowed by every caller.
Switch the dispatch macro to stmmac_do_callback() so the callback's real
result is propagated, and honour it in the taprio and mqprio qdisc
offload.
Note that the taprio "if (ret)" check in tc_taprio_configure() used to
be dead code and now becomes live: a preemptible TC spanning more than
one TXQ under SP scheduling cannot be programmed in hardware, so a
taprio or mqprio configuration that previously returned success while
leaving the preemption-class register unprogrammed now fails with
-EINVAL. For taprio, the failure also runs the disable path, tearing
down the schedule that was just installed; this is the intended
behaviour.
Fixes: 195e4f409a40 ("net: stmmac: support fp parameter of tc-mqprio")
Signed-off-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
Link: https://patch.msgid.link/20260911-stmmac-tc_setup_dwmac510_mqprio-error-path-v3-1-a76b1e2547c1@oss.qualcomm.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/hwif.h | 2 +-
.../net/ethernet/stmicro/stmmac/stmmac_tc.c | 19 +++++++++----------
2 files changed, 10 insertions(+), 11 deletions(-)
diff --git a/drivers/net/ethernet/stmicro/stmmac/hwif.h b/drivers/net/ethernet/stmicro/stmmac/hwif.h
index 14dbe0685997d..75e915e86c789 100644
--- a/drivers/net/ethernet/stmicro/stmmac/hwif.h
+++ b/drivers/net/ethernet/stmicro/stmmac/hwif.h
@@ -490,7 +490,7 @@ struct stmmac_ops {
#define stmmac_set_arp_offload(__priv, __args...) \
stmmac_do_void_callback(__priv, mac, set_arp_offload, __args)
#define stmmac_fpe_map_preemption_class(__priv, __args...) \
- stmmac_do_void_callback(__priv, mac, fpe_map_preemption_class, __args)
+ stmmac_do_callback(__priv, mac, fpe_map_preemption_class, __args)
/* PTP and HW Timer helpers */
struct stmmac_hwtimestamp {
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
index 0119b4b89fc0a..49161241d0328 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_tc.c
@@ -970,7 +970,7 @@ static int tc_taprio_configure(struct stmmac_priv *priv,
struct netlink_ext_ack *extack = qopt->mqprio.extack;
struct timespec64 time, current_time, qopt_time;
ktime_t current_time_ns;
- int i, ret = 0;
+ int err, i, ret = 0;
u64 ctr;
if (qopt->base_time < 0)
@@ -1120,9 +1120,9 @@ static int tc_taprio_configure(struct stmmac_priv *priv,
mutex_unlock(&priv->est_lock);
}
- stmmac_fpe_map_preemption_class(priv, priv->dev, extack, 0);
+ err = stmmac_fpe_map_preemption_class(priv, priv->dev, extack, 0);
- return ret;
+ return qopt->cmd == TAPRIO_CMD_DESTROY ? err : ret;
}
static void tc_taprio_stats(struct stmmac_priv *priv,
@@ -1237,14 +1237,15 @@ static int tc_query_caps(struct stmmac_priv *priv,
}
}
-static void stmmac_reset_tc_mqprio(struct net_device *ndev,
- struct netlink_ext_ack *extack)
+static int stmmac_reset_tc_mqprio(struct net_device *ndev,
+ struct netlink_ext_ack *extack)
{
struct stmmac_priv *priv = netdev_priv(ndev);
netdev_reset_tc(ndev);
netif_set_real_num_tx_queues(ndev, priv->plat->tx_queues_to_use);
- stmmac_fpe_map_preemption_class(priv, ndev, extack, 0);
+
+ return stmmac_fpe_map_preemption_class(priv, ndev, extack, 0);
}
static int tc_setup_dwmac510_mqprio(struct stmmac_priv *priv,
@@ -1257,10 +1258,8 @@ static int tc_setup_dwmac510_mqprio(struct stmmac_priv *priv,
u32 num_tc = qopt->num_tc;
int err;
- if (!num_tc) {
- stmmac_reset_tc_mqprio(ndev, extack);
- return 0;
- }
+ if (!num_tc)
+ return stmmac_reset_tc_mqprio(ndev, extack);
err = netdev_set_num_tc(ndev, num_tc);
if (err)
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 233/438] Input: xpad - add support for Victrix Pro BFG Controller
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (231 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 232/438] watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 234/438] Input: xpad - add support for Azeron devices Greg Kroah-Hartman
` (216 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Erich Sartison, Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Erich Sartison <byt.es@mailbox.org>
commit 971fa7ea8621e123feb9c8d7dc61be1c656bd945 upstream.
The controller doesn't currently work via USB-cable.
Signed-off-by: Erich Sartison <byt.es@mailbox.org>
Link: https://patch.msgid.link/20260903103137.630170-1-byt.es@mailbox.org
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -227,6 +227,7 @@ static const struct xpad_device {
{ 0x0e6f, 0x0213, "Afterglow Gamepad for Xbox 360", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x021f, "Rock Candy Gamepad for Xbox 360", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x0246, "Rock Candy Gamepad for Xbox One 2015", 0, XTYPE_XBOXONE },
+ { 0x0e6f, 0x024c, "PDP Victrix Pro BFG Wired Controller for Xbox", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a0, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a1, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a2, "PDP Wired Controller for Xbox One - Crimson Red", 0, XTYPE_XBOXONE },
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 180/398] net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (177 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 179/398] net: stmmac: propagate FPE preemption-class mapping errors Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 181/398] x86/alternative: Refactor INT3 call emulation selftest Greg Kroah-Hartman
` (223 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Zahka, Willem de Bruijn,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Zahka <daniel.zahka@gmail.com>
[ Upstream commit a41f24c612c3f5139a3143307eb85bbcf1bd4d07 ]
PSP conflicts with TLS ULP in its usage of both skb->decrypted and
sk->sk_validate_xmit_skb().
Make PSP mutually exclusive with TLS ULP, the only other user of either
of these. As other users of skb->decrypted come along, they can be added
to sk_has_decrypt_user(). It would make sense to also assert that
sk->sk_validate_xmit_skb() is also NULL in both of these setup paths for
similar future proofing, but the PSP listener/sk_clone() path is still
broken and it could be seen as a regression to not allow rx assoc to run
on a child of a listener socket with PSP tx assoc state.
Include all TCP ULPs in the sk_has_decrypt_user() check, even though TLS
is the only one that conflicts with PSP via the decrypted bit. This is
intentional because PSP was not designed to be used with ULPs. It is
best to close off surface area that may make bugs reachable, until
someone wishes to design and test an actual user of PSP with ULPs.
Fixes: 6b46ca260e22 ("net: psp: add socket security association code")
Signed-off-by: Daniel Zahka <daniel.zahka@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260915-psp-ktls-fix-v2-1-0eedc3b148ec@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/sock.h | 2 ++
net/core/sock.c | 7 +++++++
net/ipv4/tcp_ulp.c | 4 ++++
net/psp/psp_sock.c | 4 ++++
4 files changed, 17 insertions(+)
diff --git a/include/net/sock.h b/include/net/sock.h
index 9e13e1233e417..fb91d72a955dd 100644
--- a/include/net/sock.h
+++ b/include/net/sock.h
@@ -2260,6 +2260,8 @@ static inline void sk_gso_disable(struct sock *sk)
sk->sk_route_caps &= ~NETIF_F_GSO_MASK;
}
+bool sk_has_decrypt_user(const struct sock *sk);
+
static inline int skb_do_copy_data_nocache(struct sock *sk, struct sk_buff *skb,
struct iov_iter *from, char *to,
int copy, int offset)
diff --git a/net/core/sock.c b/net/core/sock.c
index a0288a3618193..0d5f167e6ce69 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -142,6 +142,7 @@
#include <trace/events/sock.h>
+#include <net/psp.h>
#include <net/tcp.h>
#include <net/busy_poll.h>
#include <net/phonet/phonet.h>
@@ -2635,6 +2636,12 @@ void sk_setup_caps(struct sock *sk, struct dst_entry *dst)
}
EXPORT_SYMBOL_GPL(sk_setup_caps);
+bool sk_has_decrypt_user(const struct sock *sk)
+{
+ return psp_sk_assoc(sk) ||
+ (sk_is_inet(sk) && inet_csk_has_ulp(sk)); /* for tls */
+}
+
/*
* Simple resource managers for sockets.
*/
diff --git a/net/ipv4/tcp_ulp.c b/net/ipv4/tcp_ulp.c
index 2aa442128630e..b58045df101e5 100644
--- a/net/ipv4/tcp_ulp.c
+++ b/net/ipv4/tcp_ulp.c
@@ -136,6 +136,10 @@ static int __tcp_set_ulp(struct sock *sk, const struct tcp_ulp_ops *ulp_ops)
if (icsk->icsk_ulp_ops)
goto out_err;
+ err = -EINVAL;
+ if (sk_has_decrypt_user(sk))
+ goto out_err;
+
if (sk->sk_socket)
clear_bit(SOCK_SUPPORT_ZC, &sk->sk_socket->flags);
diff --git a/net/psp/psp_sock.c b/net/psp/psp_sock.c
index a931d825d1cc4..0fcc60c92c329 100644
--- a/net/psp/psp_sock.c
+++ b/net/psp/psp_sock.c
@@ -143,6 +143,10 @@ int psp_sock_assoc_set_rx(struct sock *sk, struct psp_assoc *pas,
NL_SET_ERR_MSG(extack, "Socket already has PSP state");
err = -EBUSY;
goto exit_unlock;
+ } else if (sk_has_decrypt_user(sk)) {
+ NL_SET_ERR_MSG(extack, "Socket has incompatible state");
+ err = -EINVAL;
+ goto exit_unlock;
}
refcount_inc(&pas->refcnt);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 234/438] Input: xpad - add support for Azeron devices
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (232 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 233/438] Input: xpad - add support for Victrix Pro BFG Controller Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 235/438] Input: xpad - fix PDP Marvel Xbox 360 controller Greg Kroah-Hartman
` (215 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Roberts Kursitis, Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Roberts Kursitis <roberts.kursitis@azeron.eu>
commit cba76c0f47af1a389d718c5bb69e75cbd67bba98 upstream.
Azeron controllers (Cyro, Cyborg, Classic/Compact, Cyro Lefty,
Cyborg II and Keyzen) present a standard Xbox 360 controller
interface, so they work with the existing xpad driver once their
USB IDs are added.
The 0x16d0 vendor ID is a shared block, but this is safe because
xpad only binds interfaces that match the Xbox 360 signature.
Tested with an Azeron Keyzen.
Signed-off-by: Roberts Kursitis <roberts.kursitis@azeron.eu>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260906143040.162418-1-roberts.kursitis@azeron.eu
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -293,6 +293,12 @@ static const struct xpad_device {
{ 0x1689, 0xfd00, "Razer Onza Tournament Edition", 0, XTYPE_XBOX360 },
{ 0x1689, 0xfd01, "Razer Onza Classic Edition", 0, XTYPE_XBOX360 },
{ 0x1689, 0xfe00, "Razer Sabertooth", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1103, "Azeron Cyro", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x113c, "Azeron Cyborg", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1192, "Azeron Classic/Compact", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1212, "Azeron Cyro Lefty", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x12f7, "Azeron Cyborg II", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x13ea, "Azeron Keyzen", 0, XTYPE_XBOX360 },
{ 0x17ef, 0x6182, "Lenovo Legion Controller for Windows", 0, XTYPE_XBOX360 },
{ 0x1949, 0x041a, "Amazon Game Controller", 0, XTYPE_XBOX360 },
{ 0x1a86, 0xe310, "Legion Go S", 0, XTYPE_XBOX360 },
@@ -535,6 +541,7 @@ static const struct usb_device_id xpad_t
XPAD_XBOX360_VENDOR(0x15e4), /* Numark Xbox 360 controllers */
XPAD_XBOX360_VENDOR(0x162e), /* Joytech Xbox 360 controllers */
XPAD_XBOX360_VENDOR(0x1689), /* Razer Onza */
+ XPAD_XBOX360_VENDOR(0x16d0), /* Azeron controllers */
XPAD_XBOX360_VENDOR(0x17ef), /* Lenovo */
XPAD_XBOX360_VENDOR(0x1949), /* Amazon controllers */
XPAD_XBOX360_VENDOR(0x1a86), /* Nanjing Qinheng Microelectronics (WCH) */
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 181/398] x86/alternative: Refactor INT3 call emulation selftest
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (178 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 180/398] net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 182/398] x86/kprobes: Fix crash when probing CS CALL instructions Greg Kroah-Hartman
` (222 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Petr Mladek, Joe Lawrence,
Josh Poimboeuf, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Josh Poimboeuf <jpoimboe@kernel.org>
[ Upstream commit 3049fc4b5f1d2320a84e2902b3ac5a735f60ca04 ]
The INT3 call emulation selftest is a bit fragile as it relies on the
compiler not inserting any extra instructions before the
int3_selftest_ip() definition.
Also, the int3_selftest_ip() symbol overlaps with the int3_selftest
symbol(), which can confuse objtool.
Fix those issues by slightly reworking the functionality and moving
int3_selftest_ip() to a separate asm function. While at it, improve the
naming.
Acked-by: Petr Mladek <pmladek@suse.com>
Tested-by: Joe Lawrence <joe.lawrence@redhat.com>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Stable-dep-of: a5f7a5bb3b7f ("x86/kprobes: Fix crash when probing CS CALL instructions")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/kernel/alternative.c | 51 +++++++++++++++++++----------------
1 file changed, 28 insertions(+), 23 deletions(-)
diff --git a/arch/x86/kernel/alternative.c b/arch/x86/kernel/alternative.c
index 109a285cca514..4917d2843feb4 100644
--- a/arch/x86/kernel/alternative.c
+++ b/arch/x86/kernel/alternative.c
@@ -2266,21 +2266,34 @@ int alternatives_text_reserved(void *start, void *end)
* See entry_{32,64}.S for more details.
*/
-/*
- * We define the int3_magic() function in assembly to control the calling
- * convention such that we can 'call' it from assembly.
- */
+extern void int3_selftest_asm(unsigned int *ptr);
-extern void int3_magic(unsigned int *ptr); /* defined in asm */
+asm (
+" .pushsection .init.text, \"ax\", @progbits\n"
+" .type int3_selftest_asm, @function\n"
+"int3_selftest_asm:\n"
+ ANNOTATE_NOENDBR
+ /*
+ * INT3 padded with NOP to CALL_INSN_SIZE. The INT3 triggers an
+ * exception, then the int3_exception_nb notifier emulates a call to
+ * int3_selftest_callee().
+ */
+" int3; nop; nop; nop; nop\n"
+ ASM_RET
+" .size int3_selftest_asm, . - int3_selftest_asm\n"
+" .popsection\n"
+);
+
+extern void int3_selftest_callee(unsigned int *ptr);
asm (
" .pushsection .init.text, \"ax\", @progbits\n"
-" .type int3_magic, @function\n"
-"int3_magic:\n"
+" .type int3_selftest_callee, @function\n"
+"int3_selftest_callee:\n"
ANNOTATE_NOENDBR
-" movl $1, (%" _ASM_ARG1 ")\n"
+" movl $0x1234, (%" _ASM_ARG1 ")\n"
ASM_RET
-" .size int3_magic, .-int3_magic\n"
+" .size int3_selftest_callee, . - int3_selftest_callee\n"
" .popsection\n"
);
@@ -2289,7 +2302,7 @@ extern void int3_selftest_ip(void); /* defined in asm below */
static int __init
int3_exception_notify(struct notifier_block *self, unsigned long val, void *data)
{
- unsigned long selftest = (unsigned long)&int3_selftest_ip;
+ unsigned long selftest = (unsigned long)&int3_selftest_asm;
struct die_args *args = data;
struct pt_regs *regs = args->regs;
@@ -2304,7 +2317,7 @@ int3_exception_notify(struct notifier_block *self, unsigned long val, void *data
if (regs->ip - INT3_INSN_SIZE != selftest)
return NOTIFY_DONE;
- int3_emulate_call(regs, (unsigned long)&int3_magic);
+ int3_emulate_call(regs, (unsigned long)&int3_selftest_callee);
return NOTIFY_STOP;
}
@@ -2320,19 +2333,11 @@ static noinline void __init int3_selftest(void)
BUG_ON(register_die_notifier(&int3_exception_nb));
/*
- * Basically: int3_magic(&val); but really complicated :-)
- *
- * INT3 padded with NOP to CALL_INSN_SIZE. The int3_exception_nb
- * notifier above will emulate CALL for us.
+ * Basically: int3_selftest_callee(&val); but really complicated :-)
*/
- asm volatile ("int3_selftest_ip:\n\t"
- ANNOTATE_NOENDBR
- " int3; nop; nop; nop; nop\n\t"
- : ASM_CALL_CONSTRAINT
- : __ASM_SEL_RAW(a, D) (&val)
- : "memory");
-
- BUG_ON(val != 1);
+ int3_selftest_asm(&val);
+
+ BUG_ON(val != 0x1234);
unregister_die_notifier(&int3_exception_nb);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 235/438] Input: xpad - fix PDP Marvel Xbox 360 controller
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (233 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 234/438] Input: xpad - add support for Azeron devices Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 236/438] 9p: Fix v9fs_issue_write() to update i_size and remote_i_size Greg Kroah-Hartman
` (214 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jeremy Nyberg, Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeremy Nyberg <slickstretch3.0@gmail.com>
commit 7bc369cb3d3f3656eb77285628ee264264d28ad4 upstream.
The PDP Marvel Xbox 360 controller with USB ID 0e6f:0147 is
incorrectly classified as an Xbox One controller.
With the current XTYPE_XBOXONE classification, the controller is
detected but produces no input, while its four player LEDs continue
blinking indefinitely.
Classify USB ID 0e6f:0147 as an Xbox 360 controller instead.
Tested on a PDP Marvel Xbox 360 controller with USB ID 0e6f:0147.
All inputs register correctly and the player LED indicates the
current player.
Fixes: c225370e01b8 ("Input: xpad - sync supported devices with 360Controller")
Cc: stable@vger.kernel.org
Signed-off-by: Jeremy Nyberg <SlickStretch3.0@gmail.com>
Link: https://patch.msgid.link/20260910071627.236014-1-SlickStretch3.0@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -215,7 +215,7 @@ static const struct xpad_device {
{ 0x0e6f, 0x0139, "Afterglow Prismatic Wired Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x013a, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x0146, "Rock Candy Wired Controller for Xbox One", 0, XTYPE_XBOXONE },
- { 0x0e6f, 0x0147, "PDP Marvel Xbox One Controller", 0, XTYPE_XBOXONE },
+ { 0x0e6f, 0x0147, "PDP Marvel Xbox 360 Controller", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x015c, "PDP Xbox One Arcade Stick", MAP_TRIGGERS_TO_BUTTONS, XTYPE_XBOXONE },
{ 0x0e6f, 0x015d, "PDP Mirror's Edge Official Wired Controller for Xbox One", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x0161, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 182/398] x86/kprobes: Fix crash when probing CS CALL instructions
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (179 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 181/398] x86/alternative: Refactor INT3 call emulation selftest Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 183/398] net: macb: fix ordering around PTP timestamp read Greg Kroah-Hartman
` (221 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google), Jinke Han,
Ingo Molnar, Yafang Shao, Borislav Petkov, Peter Zijlstra,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jinke Han <jinkehan@didiglobal.com>
[ Upstream commit a5f7a5bb3b7f28ba7e4fa246775b29a0e5537255 ]
When using eBPF to probe CS CALL instructions within a function,
a crash can be triggered.
The eBPF tool probes offset 257 of the __hrtimer_run_queues()
function:
<__hrtimer_run_queues+249>: nopl 0x0(%rax,%rax,1)
<__hrtimer_run_queues+254>: mov %r14,%rdi
<__hrtimer_run_queues+257>: cs call <__x86_indirect_thunk_r12>
<__hrtimer_run_queues+263>: mov %eax,%r12d
<__hrtimer_run_queues+266>: xchg %ax,%ax
<__hrtimer_run_queues+268>: mov %r13,%rdi
Which triggers this crash:
BUG: unable to handle page fault for address: 00000000000f41c9
#PF: supervisor write access in kernel mode
#PF: error_code(0x0002) - not-present page
PGD 0 P4D 0
Oops: 0002 [#1] SMP NOPTI
CPU: 1 PID: 0 Comm: swapper/1 Kdump: loaded Tainted: P
RIP: 0010:__hrtimer_run_queues+0x106/0x230
Note that __hrtimer_run_queues+0x106 is __hrtimer_run_queues+262, which is
at the 6th byte of the above CS CALL instruction. Since the CS CALL
instruction occupies 6 bytes, the exception occurred in the middle of that
call instruction.
The root cause is that when using eBPF tools to probe in the middle of a
function, a kprobe with INT3 is used as the underlying implementation.
During single-step emulation of the original CALL instruction,
int3_emulate_call() assumes that the probed CALL instruction is 5 bytes
long. However, the actual CS-prefixed CALL instruction occupies 6 bytes,
so it constructs an incorrect exception return address. When the CPU
returns from the kprobe handler, the next instruction to be executed is at
the address of the last byte of that CS CALL instruction. Coincidentally,
starting from that address, the CPU fetches and decodes a completely
different instruction, which ultimately triggers a kernel crash.
Fix the issue by using the actual instruction length obtained from
the instruction decoder when constructing the exception return
address, rather than relying on the hardcoded CALL_INSN_SIZE macro.
[ mingo: Refined the changelog ]
Fixes: 6256e668b7af ("x86/kprobes: Use int3 instead of debug trap for single-step")
Suggested-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Jinke Han <jinkehan@didiglobal.com>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Reviewed-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Acked-by: Yafang Shao <laoar.shao@gmail.com>
Acked-by: Borislav Petkov <bp@alien8.de>
Cc: Peter Zijlstra <peterz@infradead.org>
Link: https://patch.msgid.link/20260908073742.GA10517@didi-ThinkCentre-M920t-N000
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/include/asm/text-patching.h | 4 ++--
arch/x86/kernel/alternative.c | 6 ++++--
arch/x86/kernel/kprobes/core.c | 5 ++---
3 files changed, 8 insertions(+), 7 deletions(-)
diff --git a/arch/x86/include/asm/text-patching.h b/arch/x86/include/asm/text-patching.h
index f2d142a0a862e..ea09381070e82 100644
--- a/arch/x86/include/asm/text-patching.h
+++ b/arch/x86/include/asm/text-patching.h
@@ -164,9 +164,9 @@ unsigned long int3_emulate_pop(struct pt_regs *regs)
}
static __always_inline
-void int3_emulate_call(struct pt_regs *regs, unsigned long func)
+void int3_emulate_call(struct pt_regs *regs, unsigned long ip, unsigned long func)
{
- int3_emulate_push(regs, regs->ip - INT3_INSN_SIZE + CALL_INSN_SIZE);
+ int3_emulate_push(regs, ip);
int3_emulate_jmp(regs, func);
}
diff --git a/arch/x86/kernel/alternative.c b/arch/x86/kernel/alternative.c
index 4917d2843feb4..9c980b4f1943b 100644
--- a/arch/x86/kernel/alternative.c
+++ b/arch/x86/kernel/alternative.c
@@ -2305,6 +2305,7 @@ int3_exception_notify(struct notifier_block *self, unsigned long val, void *data
unsigned long selftest = (unsigned long)&int3_selftest_asm;
struct die_args *args = data;
struct pt_regs *regs = args->regs;
+ unsigned long ip;
OPTIMIZER_HIDE_VAR(selftest);
@@ -2317,7 +2318,8 @@ int3_exception_notify(struct notifier_block *self, unsigned long val, void *data
if (regs->ip - INT3_INSN_SIZE != selftest)
return NOTIFY_DONE;
- int3_emulate_call(regs, (unsigned long)&int3_selftest_callee);
+ ip = regs->ip - INT3_INSN_SIZE + CALL_INSN_SIZE;
+ int3_emulate_call(regs, ip, (unsigned long)&int3_selftest_callee);
return NOTIFY_STOP;
}
@@ -2889,7 +2891,7 @@ noinstr int smp_text_poke_int3_handler(struct pt_regs *regs)
break;
case CALL_INSN_OPCODE:
- int3_emulate_call(regs, (long)ip + tpl->disp);
+ int3_emulate_call(regs, (long)ip, (long)ip + tpl->disp);
break;
case JMP32_INSN_OPCODE:
diff --git a/arch/x86/kernel/kprobes/core.c b/arch/x86/kernel/kprobes/core.c
index 3863d7709386f..95ab48b3b0f89 100644
--- a/arch/x86/kernel/kprobes/core.c
+++ b/arch/x86/kernel/kprobes/core.c
@@ -511,10 +511,9 @@ NOKPROBE_SYMBOL(kprobe_emulate_ret);
static void kprobe_emulate_call(struct kprobe *p, struct pt_regs *regs)
{
- unsigned long func = regs->ip - INT3_INSN_SIZE + p->ainsn.size;
+ unsigned long ip = regs->ip - INT3_INSN_SIZE + p->ainsn.size;
- func += p->ainsn.rel32;
- int3_emulate_call(regs, func);
+ int3_emulate_call(regs, ip, ip + p->ainsn.rel32);
}
NOKPROBE_SYMBOL(kprobe_emulate_call);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 236/438] 9p: Fix v9fs_issue_write() to update i_size and remote_i_size
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (234 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 235/438] Input: xpad - fix PDP Marvel Xbox 360 controller Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 237/438] ALSA: core: Fix potential UAF after asynchronous card release Greg Kroah-Hartman
` (213 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Mulqueen, David Howells,
Dominique Martinet
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
commit c60ae98c5aa64021751b38ab1313b19d620bf640 upstream.
Fix v9fs_issue_write() to update i_size and remote_i_size to the new size
of the server file if we made it larger, using the start fpos and the count
returned by p9_client_write() to calculate the new minimum file size.
This assumes that if the 9P server makes a short write (say it hits
ENOSPC), a reduced count is returned.
Fixes: 5fb70e7275a6 ("netfs, 9p: Implement helpers for new write code")
Reported-by: Michael Mulqueen <mike@method-b.uk>
Closes: https://lore.kernel.org/r/fbb9e395-1e07-4212-8f70-23f3cd498074@method-b.uk/
Cc: stable@vger.kernel.org
Signed-off-by: David Howells <dhowells@redhat.com>
Message-ID: <2226525.1789118704@warthog.procyon.org.uk>
Signed-off-by: Dominique Martinet <asmadeus@codewreck.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/9p/vfs_addr.c | 28 +++++++++++++++++++++++++++-
1 file changed, 27 insertions(+), 1 deletion(-)
--- a/fs/9p/vfs_addr.c
+++ b/fs/9p/vfs_addr.c
@@ -54,11 +54,37 @@ static void v9fs_begin_writeback(struct
static void v9fs_issue_write(struct netfs_io_subrequest *subreq)
{
struct p9_fid *fid = subreq->rreq->netfs_priv;
+ struct inode *inode = subreq->rreq->inode;
+ struct netfs_inode *ictx = netfs_inode(inode);
int err, len;
len = p9_client_write(fid, subreq->start, &subreq->io_iter, &err);
- if (len > 0)
+ if (len > 0) {
+ uoff_t end = subreq->start + len, i_size, remote, zp;
+ bool set = false;
+
+ spin_lock(&inode->i_lock);
+
+ /* We can read the sizes directly as we hold i_lock. */
+ i_size = inode->i_size;
+ remote = ictx->_remote_i_size;
+ zp = ictx->_zero_point;
+
+ if (end > i_size) {
+ i_size = end;
+ set = true;
+ }
+ if (end > remote) {
+ remote = end;
+ set = true;
+ }
+
+ if (set)
+ netfs_write_sizes(inode, i_size, remote, zp);
+ spin_unlock(&inode->i_lock);
+
__set_bit(NETFS_SREQ_MADE_PROGRESS, &subreq->flags);
+ }
netfs_write_subrequest_terminated(subreq, len ?: err);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 183/398] net: macb: fix ordering around PTP timestamp read
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (180 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 182/398] x86/kprobes: Fix crash when probing CS CALL instructions Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 184/398] net: mvpp2: prevent buffer overflow in page_pool allocation Greg Kroah-Hartman
` (220 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicolai Buchwitz, Théo Lebrun,
James Clark, Paolo Abeni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Clark <jjc@jclark.com>
[ Upstream commit 9ca4ba24259183ce15665be86b2956cd896c4687 ]
PTP_SYS_OFFSET_EXTENDED returns system timestamps that do not correctly
bracket the PHC register read on MACB/GEM. On a Raspberry Pi 5, the
returned interval can be as short as 37 ns, while an ordered register
read takes approximately 1 us. This biases the midpoint used by phc2sys,
causing CLOCK_REALTIME to run approximately 0.5 us ahead when synchronized
to the PHC.
gem_tsu_get_time() reads the nanoseconds register using the driver's
relaxed MMIO accessor. On weakly ordered systems, the subsequent system
timestamp can be taken before the register read completes. The internal
smp_rmb() in the pre-timestamp path also does not guarantee ordering
against the subsequent MMIO read.
Add rmb() before and after the bracketed nanoseconds read in both the
normal and seconds rollover paths so the system timestamps bracket the
PHC read. Adding the post-read barrier increases the minimum interval on
the same Raspberry Pi 5 to approximately 1 us.
Fixes: e51bb5c2784c ("net: macb: ptp: Switch to gettimex64() interface")
Tested-by: Nicolai Buchwitz <nb@tipi-net.de> # Raspberry Pi CM5, min bracket 37 ns -> 981 ns
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Reviewed-by: Théo Lebrun <theo.lebrun@bootlin.com>
Assisted-by: LLM
Signed-off-by: James Clark <jjc@jclark.com>
Link: https://patch.msgid.link/20260915045823.76100-1-jjc@jclark.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/cadence/macb_ptp.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/net/ethernet/cadence/macb_ptp.c b/drivers/net/ethernet/cadence/macb_ptp.c
index d961a5faf355d..97b72f633d3bc 100644
--- a/drivers/net/ethernet/cadence/macb_ptp.c
+++ b/drivers/net/ethernet/cadence/macb_ptp.c
@@ -48,7 +48,12 @@ static int gem_tsu_get_time(struct ptp_clock_info *ptp, struct timespec64 *ts,
spin_lock_irqsave(&bp->tsu_clk_lock, flags);
ptp_read_system_prets(sts);
+ /* explicit barriers are needed because gem_readl() is relaxed */
+ if (sts)
+ rmb();
first = gem_readl(bp, TN);
+ if (sts)
+ rmb();
ptp_read_system_postts(sts);
secl = gem_readl(bp, TSL);
sech = gem_readl(bp, TSH);
@@ -60,7 +65,11 @@ static int gem_tsu_get_time(struct ptp_clock_info *ptp, struct timespec64 *ts,
* (assume all done within 1s)
*/
ptp_read_system_prets(sts);
+ if (sts)
+ rmb();
ts->tv_nsec = gem_readl(bp, TN);
+ if (sts)
+ rmb();
ptp_read_system_postts(sts);
secl = gem_readl(bp, TSL);
sech = gem_readl(bp, TSH);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 237/438] ALSA: core: Fix potential UAF after asynchronous card release
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (235 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 236/438] 9p: Fix v9fs_issue_write() to update i_size and remote_i_size Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 238/438] ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity Greg Kroah-Hartman
` (212 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Farhad Alemi, Takashi Iwai
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit fd95e68df6fe66344161a1329cbe5e5805e7b704 upstream.
Usually a sound driver releases the resources assigned to the card via
snd_card_free(), and it synchronizes with the whole release procedure.
However, when the card is released asynchronously via
snd_card_free_when_closed() like USB-audio driver, the situation is
slightly different; although the snd_card_disconnect() call at the
disconnection guarantees that any newer accesses will be gated, the
in-flight tasks might be still accessing to the underlying card->dev
device even after the disconnection, which would cause a
use-after-free in the end, as reported by fuzzers.
For addressing the bug above, this patch takes the refcount of
card->dev at initialization of the card object, and releases at its
destructor. This assures the availability of the card->dev in its
whole lifecycle.
Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Closes: https://lore.kernel.org/CA+0ovChexj4TrZL_2iG_P0WBEbZc5+73GfB3DkciQi=R8pZOnA@mail.gmail.com
Closes: https://lore.kernel.org/CA+0ovCgQUQNN=Z1tJTouiCsDaXR5M-3-SQEGk-cpPXQkM5Xh+w@mail.gmail.com
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20260912162150.455144-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/core/init.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/sound/core/init.c
+++ b/sound/core/init.c
@@ -310,7 +310,7 @@ static int snd_card_init(struct snd_card
kfree(card); /* manually free here, as no destructor called */
return err;
}
- card->dev = parent;
+ card->dev = get_device(parent);
card->number = idx;
WARN_ON(IS_MODULE(CONFIG_SND) && !module);
card->module = module;
@@ -601,6 +601,7 @@ static int snd_card_do_free(struct snd_c
dev_warn(card->dev, "unable to free card info\n");
/* Not fatal error */
}
+ put_device(card->dev);
if (card->release_completion)
complete(card->release_completion);
if (!managed)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 184/398] net: mvpp2: prevent buffer overflow in page_pool allocation
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (181 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 183/398] net: macb: fix ordering around PTP timestamp read Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 185/398] net: skbuff: do not leave stale header offsets after pskb_carve() Greg Kroah-Hartman
` (219 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitriy Okunev, Paolo Abeni,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitriy Okunev <dokunevdmitriy@gmail.com>
[ Upstream commit 14cb1e7702e5cb3c58888f6aed498381a73927d2 ]
The per‑processor buffering scheme is supported only if the
number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8).
This is already checked in mvpp2_probe() during the initial
activation of percpu_pools.
However, mvpp2_change_mtu() may later call
mvpp2_bm_switch_buffers(priv, true) without this check, which can
lead to an out-of-bounds access in the priv->page_pool array in
mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ
entries, and mvpp2_get_nrxqs() may return exactly that value. The
per-CPU scheme then doubles it to nrxqs * 2, exceeding the array
bounds.
Check that the hardware version is MVPP22 or newer and that the
number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS
before switching to per-CPU mode.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: 7d04b0b13b11 ("mvpp2: percpu buffers")
Signed-off-by: Dmitriy Okunev <dokunevdmitriy@gmail.com>
Link: https://patch.msgid.link/20260914091557.71769-1-dokunevdmitriy@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
index 79f8e0abfdbfd..17ce1dfcccd1a 100644
--- a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
+++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c
@@ -5088,7 +5088,8 @@ static int mvpp2_change_mtu(struct net_device *dev, int mtu)
netdev_warn(dev, "mtu %d too high, switching to shared buffers", mtu);
mvpp2_bm_switch_buffers(priv, false);
}
- } else {
+ } else if (priv->hw_version >= MVPP22 &&
+ mvpp2_get_nrxqs(priv) * 2 <= MVPP2_BM_MAX_POOLS) {
bool jumbo = false;
int i;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 238/438] ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (236 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 237/438] ALSA: core: Fix potential UAF after asynchronous card release Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 239/438] ALSA: virtio: reset device before deleting virtqueues Greg Kroah-Hartman
` (211 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+8eacd4fa193b1b28, Xiang Mei,
Takashi Iwai
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
commit 76a986c980bb502c7688d605ac7a67fd257a9a1b upstream.
data_ep_set_params() allocates each data URB for exactly u->packets
isochronous frames, so urb->iso_frame_desc[] has u->packets slots and
ctx->packets is the driver's only record of that limit. For an implicit
feedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the
sync source's packet count, which is calculated independently from the
capture endpoint's parameters. When that count is larger,
prepare_playback_urb() and prepare_silent_urb() can write
iso_frame_desc[] past the allocation; their existing bounds limit payload
bytes, not the descriptor index.
The reproducer uses a high-speed UAC2 device declaring bInterval 1 for
implicit feedback capture (8 packets) and bInterval 4 for playback
(1 packet). On the first capture completion after the stream starts, it
accesses seven descriptors spanning 112 bytes beyond the one-packet URB:
BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560)
Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178
prepare_playback_urb (sound/usb/pcm.c:1560)
prepare_outbound_urb (sound/usb/endpoint.c:340)
snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501)
snd_complete_urb (sound/usb/endpoint.c:1834)
__usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107)
kthread (kernel/kthread.c:436)
The buggy address belongs to the object at ffff88801e696a00
which belongs to the cache kmalloc-256 of size 256
The buggy address is located 0 bytes to the right of
allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0)
Record the allocated packet count per endpoint and clamp both the adopted
count and the packet-size copy to it. Fold the Format Type II delimiter
into urb_packs before the allocation loop so the recorded limit matches
every URB.
Fixes: cf044e441902 ("ALSA: usb-audio: Update the number of packets properly at receiving")
Reported-by: co+8eacd4fa193b1b28@bugs.sh
Closes: https://lore.kernel.org/all/22xPn8drvIUtYgVeQnBiNqXuevOTpBAjepLz%40bugs.sh/
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Link: https://patch.msgid.link/20260912200530.1955491-1-xmei5@asu.edu
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/card.h | 1 +
sound/usb/endpoint.c | 12 +++++++-----
2 files changed, 8 insertions(+), 5 deletions(-)
--- a/sound/usb/card.h
+++ b/sound/usb/card.h
@@ -116,6 +116,7 @@ struct snd_usb_endpoint {
unsigned int phase; /* phase accumulator */
unsigned int maxpacksize; /* max packet size in bytes */
unsigned int maxframesize; /* max packet size in frames */
+ unsigned int max_urb_packs; /* packets allocated per data URB */
unsigned int max_urb_frames; /* max URB size in frames */
unsigned int curpacksize; /* current packet size in bytes (for capture) */
unsigned int curframesize; /* current packet size in frames (for capture) */
--- a/sound/usb/endpoint.c
+++ b/sound/usb/endpoint.c
@@ -492,9 +492,10 @@ int snd_usb_queue_pending_output_urbs(st
/* copy over the length information */
if (implicit_fb) {
- ctx->packets = packet->packets;
+ ctx->packets = min_t(int, packet->packets,
+ ep->max_urb_packs);
memcpy(ctx->packet_size, packet->packet_size,
- packet->packets * sizeof(packet->packet_size[0]));
+ ctx->packets * sizeof(packet->packet_size[0]));
}
/* call the data handler to fill in playback data */
@@ -1239,15 +1240,16 @@ static int data_ep_set_params(struct snd
ep->nurbs = min(max_urbs, urbs_per_period * ep->cur_buffer_periods);
}
+ if (fmt->fmt_type == UAC_FORMAT_TYPE_II)
+ urb_packs++; /* for transfer delimiter */
+ ep->max_urb_packs = urb_packs;
+
/* allocate and initialize data urbs */
for (i = 0; i < ep->nurbs; i++) {
struct snd_urb_ctx *u = &ep->urb[i];
u->index = i;
u->ep = ep;
u->packets = urb_packs;
-
- if (fmt->fmt_type == UAC_FORMAT_TYPE_II)
- u->packets++; /* for transfer delimiter */
u->buffer_size = maxsize * u->packets;
u->urb = usb_alloc_urb(u->packets, GFP_KERNEL);
if (!u->urb)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 185/398] net: skbuff: do not leave stale header offsets after pskb_carve()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (182 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 184/398] net: mvpp2: prevent buffer overflow in page_pool allocation Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 186/398] drm/amdgpu: check ras and obj before dereference Greg Kroah-Hartman
` (218 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+586af68eb819833c2d91,
Xuanqiang Luo, Allison Henderson, rds-devel, Eric Dumazet,
Xuanqiang Luo, Paolo Abeni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Dumazet <edumazet@google.com>
[ Upstream commit a5117e1eccac6ee3bd4aed7cacf8ebcb6b3eb309 ]
pskb_carve_inside_header() and pskb_carve_inside_nonlinear() remove
the first bytes of a packet and reallocate skb->head.
All the headers that were present before the operation are gone,
but both functions call skb_headers_offset_update(skb, 0), which
is a no-op : skb->mac_header, skb->network_header,
skb->transport_header and skb->csum_start keep their old values and
now describe bytes which are no longer there.
Both helpers size the new head from the old skb_end_offset(), so the
stale offsets still land inside the new allocation. They point past
skb_tail_pointer() though, to bytes that were never initialized.
pskb_carve_inside_nonlinear() is the worst case, because it leaves a
zombie skb with an empty linear part (skb->data ==
skb_tail_pointer(skb), skb_headlen(skb) == 0), while
skb_mac_header_was_set() is still true and skb->mac_header is way
ahead of skb->data.
The only user of pskb_extract() is rds_tcp_data_recv(), and the
carved skb is queued on tinc->ti_skb_list. When the RDS incoming
message is released, rds_tcp_inc_free() calls skb_queue_purge(),
which frees the skbs with SKB_DROP_REASON_QUEUE_PURGE. This is
visible from drop_monitor, which then tries to pull back to the
(bogus) mac header :
skbuff: __skb_pull(len=234)
skb len=6968 data_len=6968 headroom=0 headlen=0 tailroom=0
end-tail=384 mac=(234,14) mac_len=14 net=(248,40) trans=288
shinfo(txflags=0 nr_frags=1 gso(size=1428 type=16 segs=5))
csum(0x100120 start=288 offset=16 ip_summed=3 complete_sw=0 valid=1 level=0)
hash(0x7b446c6c sw=0 l4=1) proto=0x86dd pkttype=0 iif=60
kernel BUG at ./include/linux/skbuff.h:2847!
Add skb_carve_reset_headers() to mark the mac and transport headers
as not set, reset the network header, clear skb->mac_len, and drop
a now meaningless CHECKSUM_PARTIAL (csum_start no longer describes
anything).
Invalidate the inner offsets as well. Unlike mac_header and
transport_header they have no "unset" sentinel, so a leftover
non-zero value still looks like a real header. Zero
skb->inner_mac_header, skb->inner_network_header,
skb->inner_transport_header, skb->inner_protocol and
skb->encapsulation, so that all the header state is invalidated in
one place.
v2: fixed an inaccurate changelog. The stale offsets stay inside the
new skb->head, which is never smaller than the old one, they
simply point past skb_tail_pointer() to bytes that are gone.
Thanks to Xuanqiang Luo for insisting on this.
Also invalidate the inner header state, as suggested by the
netdev AI review :
https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260911114922.621937-1-edumazet%40google.com
Fixes: 6fa01ccd8830 ("skbuff: Add pskb_extract() helper function")
Reported-by: syzbot+586af68eb819833c2d91@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/6aa3e9d3.f2639fcc.29487d.0028.GAE@google.com/
Cc: Xuanqiang Luo <xuanqiang.luo@linux.dev>
Cc: Allison Henderson <achender@kernel.org>
Cc: rds-devel@oss.oracle.com
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260915130423.3956471-1-edumazet@google.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/core/skbuff.c | 32 ++++++++++++++++++++++++++++++--
1 file changed, 30 insertions(+), 2 deletions(-)
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 0324292309921..594764eab40dc 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -6766,6 +6766,34 @@ struct sk_buff *alloc_skb_with_frags(unsigned long header_len,
}
EXPORT_SYMBOL(alloc_skb_with_frags);
+/* pskb_carve_inside_header() and pskb_carve_inside_nonlinear()
+ * remove the first bytes of a packet and reallocate skb->head.
+ *
+ * Whatever headers were present before the operation are gone,
+ * we must not leave stale offsets, otherwise users of this skb
+ * (skb_dump(), drop_monitor, taps, ...) would read or pull garbage.
+ */
+static void skb_carve_reset_headers(struct sk_buff *skb)
+{
+ skb_unset_mac_header(skb);
+ skb_unset_transport_header(skb);
+ skb_reset_network_header(skb);
+ skb->mac_len = 0;
+
+ /* Inner offsets have no "unset" marker, zero them so that
+ * skb_inner_network_header_was_set() becomes false and no
+ * consumer mistakes them for a real (and long gone) header.
+ */
+ skb->inner_mac_header = 0;
+ skb->inner_network_header = 0;
+ skb->inner_transport_header = 0;
+ skb->inner_protocol = 0;
+ skb->encapsulation = 0;
+
+ if (skb->ip_summed == CHECKSUM_PARTIAL)
+ skb->ip_summed = CHECKSUM_NONE;
+}
+
/* carve out the first off bytes from skb when off < headlen */
static int pskb_carve_inside_header(struct sk_buff *skb, const u32 off,
const int headlen, gfp_t gfp_mask)
@@ -6821,7 +6849,7 @@ static int pskb_carve_inside_header(struct sk_buff *skb, const u32 off,
skb->head_frag = 0;
skb_set_end_offset(skb, size);
skb_set_tail_pointer(skb, skb_headlen(skb));
- skb_headers_offset_update(skb, 0);
+ skb_carve_reset_headers(skb);
skb->cloned = 0;
skb->hdr_len = 0;
skb->nohdr = 0;
@@ -6961,7 +6989,7 @@ static int pskb_carve_inside_nonlinear(struct sk_buff *skb, const u32 off,
skb->data = data;
skb_set_end_offset(skb, size);
skb_reset_tail_pointer(skb);
- skb_headers_offset_update(skb, 0);
+ skb_carve_reset_headers(skb);
skb->cloned = 0;
skb->hdr_len = 0;
skb->nohdr = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 239/438] ALSA: virtio: reset device before deleting virtqueues
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (237 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 238/438] ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 240/438] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type Greg Kroah-Hartman
` (210 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Takashi Iwai
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <oss.patchbox@gmail.com>
commit 6c05d00af307560e6a9f1631d6270d3df5aa2272 upstream.
virtsnd_remove() and virtsnd_freeze() delete the virtqueues before
resetting the device. del_vqs() frees the vring backing, but does not
provide a generic device quiesce operation. In particular, modern
virtio-pci keeps enabled queues active until the device is reset.
Reset the device before deleting the virtqueues so it can no longer
access the vring memory when that memory is released. This also covers
probe failures after DRIVER_OK, which unwind through virtsnd_remove().
Fixes: de3a9980d8c3 ("ALSA: virtio: add virtio sound driver")
Fixes: 575483e90a32 ("ALSA: virtio: introduce device suspend/resume support")
Cc: stable@vger.kernel.org
Signed-off-by: Yuho Choi <oss.patchbox@gmail.com>
Link: https://patch.msgid.link/20260911031121.1542502-1-oss.patchbox@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/virtio/virtio_card.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/sound/virtio/virtio_card.c
+++ b/sound/virtio/virtio_card.c
@@ -354,8 +354,8 @@ static void virtsnd_remove(struct virtio
if (snd->card)
snd_card_free(snd->card);
- vdev->config->del_vqs(vdev);
virtio_reset_device(vdev);
+ vdev->config->del_vqs(vdev);
for (i = 0; snd->substreams && i < snd->nsubstreams; ++i) {
struct virtio_pcm_substream *vss = &snd->substreams[i];
@@ -383,8 +383,8 @@ static int virtsnd_freeze(struct virtio_
virtsnd_disable_event_vq(snd);
virtsnd_ctl_msg_cancel_all(snd);
- vdev->config->del_vqs(vdev);
virtio_reset_device(vdev);
+ vdev->config->del_vqs(vdev);
for (i = 0; i < snd->nsubstreams; ++i)
cancel_work_sync(&snd->substreams[i].elapsed_period);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 186/398] drm/amdgpu: check ras and obj before dereference
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (183 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 185/398] net: skbuff: do not leave stale header offsets after pskb_carve() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 187/398] btrfs: abort transaction on failure to update inode for hole punching and reflinking Greg Kroah-Hartman
` (217 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tao Zhou, Dmitriy Chumachenko,
Alex Deucher, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitriy Chumachenko <Dmitry.Chumachenko@cyberprotect.ru>
[ Upstream commit 723d4dc628d764b19cf9efca14b82cca5ff020c9 ]
nbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences ras and obj
without checking either for NULL. Both amdgpu_ras_get_context() and
amdgpu_ras_find_obj() can return NULL, e.g. during the window between
adev->nbio.ras being set (early in amdgpu_ras_init(), by design, to
enable the fatal-error interrupt as soon as possible) and the PCIE_BIF
ras object actually being created in RAS late_init. Any interrupt in that
window crashes in hard-IRQ context.
This is analogous to commit d190b459b2a4 ("drm/amdgpu: the warning
dereferencing obj for nbio_v7_4"), which fixed the same issue in the
nbio_v7_4 handler.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: 7692e1ee2446 ("drm/amdgpu: add RAS fatal error handler for NBIO v7.9")
Reviewed-by: Tao Zhou <tao.zhou1@amd.com>
Signed-off-by: Dmitriy Chumachenko <Dmitry.Chumachenko@cyberprotect.ru>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit c7071767a50a32ed727cf800ac84372429e3b4b3)
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c b/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c
index 1c22bc11c1f85..a71ad237972ce 100644
--- a/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c
+++ b/drivers/gpu/drm/amd/amdgpu/nbio_v7_9.c
@@ -533,7 +533,7 @@ static void nbio_v7_9_handle_ras_controller_intr_no_bifring(struct amdgpu_device
RAS_CNTLR_INTERRUPT_CLEAR, 1);
WREG32_SOC15(NBIO, 0, regBIF_BX0_BIF_DOORBELL_INT_CNTL, bif_doorbell_intr_cntl);
- if (!ras->disable_ras_err_cnt_harvest) {
+ if (ras && !ras->disable_ras_err_cnt_harvest && obj) {
/*
* clear error status after ras_controller_intr
* according to hw team and count ue number
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 240/438] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (238 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 239/438] ALSA: virtio: reset device before deleting virtqueues Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 241/438] cgroup: Avoid iteration of dying tasks with zero refcount Greg Kroah-Hartman
` (209 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiangshan Yi, Pierre-Louis Bossart,
Mark Brown
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiangshan Yi <yijiangshan@kylinos.cn>
commit 03a5699a0a04309c597683967aaaf25d1e555ea2 upstream.
stream_config is not initialized before being passed to
sdw_stream_add_slave(). The type field may contain garbage and is
later copied to stream->type by sdw_config_stream().
Zero-initialize stream_config so type defaults to SDW_STREAM_PCM.
While at it, use snd_sdw_params_to_config() helper instead of
open-coding the same logic.
Fixes: 63a511284c9e ("ASoC: rt712-sdca: Add RT712 SDCA driver for Mic topology")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260914104712.379574-1-yijiangshan@kylinos.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/codecs/rt712-sdca-dmic.c | 14 +++++---------
1 file changed, 5 insertions(+), 9 deletions(-)
--- a/sound/soc/codecs/rt712-sdca-dmic.c
+++ b/sound/soc/codecs/rt712-sdca-dmic.c
@@ -13,6 +13,7 @@
#include <sound/core.h>
#include <sound/pcm.h>
#include <sound/pcm_params.h>
+#include <sound/sdw.h>
#include <sound/tlv.h>
#include "rt712-sdca.h"
#include "rt712-sdca-dmic.h"
@@ -632,10 +633,10 @@ static int rt712_sdca_dmic_hw_params(str
{
struct snd_soc_component *component = dai->component;
struct rt712_sdca_dmic_priv *rt712 = snd_soc_component_get_drvdata(component);
- struct sdw_stream_config stream_config;
+ struct sdw_stream_config stream_config = {0};
struct sdw_port_config port_config;
struct sdw_stream_runtime *sdw_stream;
- int retval, num_channels;
+ int retval;
unsigned int sampling_rate;
dev_dbg(dai->dev, "%s %s", __func__, dai->name);
@@ -647,13 +648,8 @@ static int rt712_sdca_dmic_hw_params(str
if (!rt712->slave)
return -EINVAL;
- stream_config.frame_rate = params_rate(params);
- stream_config.ch_count = params_channels(params);
- stream_config.bps = snd_pcm_format_width(params_format(params));
- stream_config.direction = SDW_DATA_DIR_TX;
-
- num_channels = params_channels(params);
- port_config.ch_mask = GENMASK(num_channels - 1, 0);
+ /* SoundWire specific configuration */
+ snd_sdw_params_to_config(substream, params, &stream_config, &port_config);
port_config.num = 2;
retval = sdw_stream_add_slave(rt712->slave, &stream_config,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 187/398] btrfs: abort transaction on failure to update inode for hole punching and reflinking
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (184 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 186/398] drm/amdgpu: check ras and obj before dereference Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 188/398] btrfs: check if there is space for chunk item when validating sys chunk array Greg Kroah-Hartman
` (216 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Filipe Manana,
David Sterba, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit 97fcd34aa9fd73cefe3120ac9a82ca9d7763922f ]
If we fail to update the inode we error out without aborting the
transaction, which can result in a persistent inconsistency if after
the failure the transaction is committed, as we have dropped file
extent items from a range and either punched a hole or insert a new file
extent item for that range (for reflinks).
So add the missing transaction abort.
Fixes: 2aaa66558172 ("Btrfs: add hole punching")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/file.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/btrfs/file.c b/fs/btrfs/file.c
index a15062f976ba3..19f0f9df038cc 100644
--- a/fs/btrfs/file.c
+++ b/fs/btrfs/file.c
@@ -2498,8 +2498,10 @@ int btrfs_replace_file_extents(struct btrfs_inode *inode,
inode_set_ctime_current(&inode->vfs_inode));
ret = btrfs_update_inode(trans, inode);
- if (ret)
+ if (unlikely(ret)) {
+ btrfs_abort_transaction(trans, ret);
break;
+ }
btrfs_end_transaction(trans);
btrfs_btree_balance_dirty(fs_info);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 241/438] cgroup: Avoid iteration of dying tasks with zero refcount
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (239 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 240/438] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 242/438] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY Greg Kroah-Hartman
` (208 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Noah Elias Feldt,
Salvatore Bonaccorso, Michal Koutný, Tejun Heo
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michal Koutný <mkoutny@suse.com>
commit 057dac23d329d5c5ed62352f2659a39fd46c6d4a upstream.
The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from
cgroup_task_release() to cgroup_task_free()") extended the lifetime of
tasks on the dying_tasks list.
The iterators have provision to go through dying_tasks because of
dying threadgroup leaders or explicit CSS_TASK_ITER_WITH_DEAD, however,
it was expected that such tasks can obtain a new reference (that is
possible before cgroup_task_release()/put_task_struct_rcu_user()).
The tasks after cgroup_task_release() and before cgroup_task_free()
are subject to race when they may or may not have ->usage count > 0.
The race window is between css_task_iter_next() invocations
when css_set_lock is released and we may arrive at a new ->task_pos.
The iterator should not attempt to resurrect tasks whose ->usage count
dropped to zero. (When that happens, __put_task_struct_rcu_cb() is
already imminent and the returned task_struct would could be used
after free.)
As for the fix, we cannot simply check the signal->live count of a task
on the dying list because that won't distinguish regular zombies waiting
to be reaped from RCU remnant tasks that are going to be free'd.
Therefore add an extra check to rule out ->usage==0 tasks from any
iteration.
The repeat: loop in css_task_iter_advance() doesn't consider ->usage
count, so add a new loop to css_task_iter_next() to skip de-used tasks
on the dying_list.
Rough illustration of the possible race
R (reader of cgroup.procs) T (thread) L (group leader)
--------------------------------- -------------------------------- --------------------------------
L exits, signal->live > 0
cgroup_task_dead(L)
css_set_skip_task_iters() // skips only cset->tasks
list_add_tail(&L->cg_list, &cset->dying_tasks)
css_task_iter_next()
take css_set_lock
css_task_iter_advance()
leader && signal->live != 0
=> it->task_pos = &L->cg_list
release css_set_lock
T exits
--signal->live == 0
cgroup_task_dead(T) // css_set_lock
release_task(T)
cgroup_task_release(T)
release_task(L) // zap_leader
cgroup_task_release(L)
put_task_struct_rcu_user(L)
...RCU...
put_task_struct(L)
L->usage = 0
/* L still on dying_tasks */
...RCU...
__put_task_struct(L)
css_task_iter_next() // another iteration
take css_set_lock
it->task_pos = &L->cg_list
get_task_struct(L)
=> addition on 0
drop css_set_lock
cgroup_task_free(L)
css_set_skip_task_iters() // dying skip comes too late
free_task(L)
cgroup_procs_show()
task_pid_vnr(L)
Fixes: 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup_task_release() to cgroup_task_free()")
Cc: stable@vger.kernel.org # v6.19+
Link: https://lists.debian.org/debian-kernel/2026/08/msg00220.html
Reported-by: Noah Elias Feldt <N.Feldt@mittwald.de>
Reported-by: Salvatore Bonaccorso <carnil@debian.org>
Tested-by: Salvatore Bonaccorso <carnil@debian.org>
Signed-off-by: Michal Koutný <mkoutny@suse.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/cgroup/cgroup.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
--- a/kernel/cgroup/cgroup.c
+++ b/kernel/cgroup/cgroup.c
@@ -5228,10 +5228,13 @@ struct task_struct *css_task_iter_next(s
if (it->flags & CSS_TASK_ITER_SKIPPED)
css_task_iter_advance(it);
- if (it->task_pos) {
+ while (it->task_pos && !it->cur_task) {
it->cur_task = list_entry(it->task_pos, struct task_struct,
cg_list);
- get_task_struct(it->cur_task);
+ /* a task on dying_tasks with zero refcount is only valid for
+ * RCU readers, not even interesting for
+ * CSS_TASK_ITER_WITH_DEAD, find another one */
+ it->cur_task = tryget_task_struct(it->cur_task);
css_task_iter_advance(it);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 188/398] btrfs: check if there is space for chunk item when validating sys chunk array
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (185 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 187/398] btrfs: abort transaction on failure to update inode for hole punching and reflinking Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 189/398] x86/fred: Reconstruct the #GP context for rejected INT instructions Greg Kroah-Hartman
` (215 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Filipe Manana,
David Sterba, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit aeab4c62875748ecfd390a47ac1d91ea7c9a6abb ]
We checked if have enough remaining space for a key before dereferencing a
key, but we then dereference a chunk item, to get the number of stripes,
without checking if there is space for the item. So add a check to see if
there is enough space for a chunk item before dereferencing the item to
extract the stripe count.
Fixes: 2a9bb78cfd36 ("btrfs: validate system chunk array at btrfs_validate_super()")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/disk-io.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/fs/btrfs/disk-io.c b/fs/btrfs/disk-io.c
index 8863479a19d3e..5396f900d5f12 100644
--- a/fs/btrfs/disk-io.c
+++ b/fs/btrfs/disk-io.c
@@ -2338,6 +2338,10 @@ static int validate_sys_chunk_array(const struct btrfs_fs_info *fs_info,
key.type, cur);
return -EUCLEAN;
}
+
+ if (unlikely(cur + sizeof(*chunk) > sys_array_size))
+ goto short_read;
+
chunk = (struct btrfs_chunk *)(sb->sys_chunk_array + cur);
num_stripes = btrfs_stack_chunk_num_stripes(chunk);
if (unlikely(cur + btrfs_chunk_item_size(num_stripes) > sys_array_size))
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 242/438] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (240 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 241/438] cgroup: Avoid iteration of dying tasks with zero refcount Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 243/438] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources() Greg Kroah-Hartman
` (207 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Roland Waltersson, Damien Le Moal,
Niklas Cassel
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Cassel <cassel@kernel.org>
commit 82e47533221d4746947b74d2e79a478c36c6433a upstream.
A user reported that commit 105c42566a55 ("ata: ahci: force 32-bit DMA for
JMicron JMB582/JMB585") made the JMicron JMB585 unusable on his board.
The failure is seen as soon as the ahci driver is probed, and booting with
iommu=off does not solve the problem.
Looking at the AHCI specification, PxCLBU and PxFBU are both read only '0'
for HBAs that do not support 64-bit addressing.
For HBAs that do support 64-bit addressing, the registers are read write,
with a reset value that is Implementation Specific.
When using the AHCI_HFLAG_32BIT_ONLY flag, the HBA does support 64-bit
addressing, and a 32-bit DMA mask is set by simply clearing HOST_CAP_64.
Thus, in this case, we need to explicitly clear the registers to 0.
Fixes: 105c42566a55 ("ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585")
Fixes: c7a42156d99b ("ahci: disable 64bit dma on sb600")
Cc: stable@vger.kernel.org
Reported-by: Roland Waltersson <roland.waltersson@netinsight.net>
Closes: https://lore.kernel.org/linux-ide/IA0PR17MB668730A4ECCD65F7A1DC3EDC9EB62@IA0PR17MB6687.namprd17.prod.outlook.com/
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://lore.kernel.org/r/20260904134310.1465051-2-cassel@kernel.org
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libahci.c | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
--- a/drivers/ata/libahci.c
+++ b/drivers/ata/libahci.c
@@ -744,15 +744,28 @@ void ahci_start_fis_rx(struct ata_port *
struct ahci_port_priv *pp = ap->private_data;
u32 tmp;
- /* set FIS registers */
+ /*
+ * On HBAs that only support 32-bit addressing PxCLBU is read only '0'.
+ * When applying the AHCI_HFLAG_32BIT_ONLY quirk, PxCLBU is RW, and the
+ * reset value is Implementation Specific, so we need to clear it to 0.
+ */
if (hpriv->cap & HOST_CAP_64)
writel((pp->cmd_slot_dma >> 16) >> 16,
port_mmio + PORT_LST_ADDR_HI);
+ else if (hpriv->flags & AHCI_HFLAG_32BIT_ONLY)
+ writel(0, port_mmio + PORT_LST_ADDR_HI);
writel(pp->cmd_slot_dma & 0xffffffff, port_mmio + PORT_LST_ADDR);
+ /*
+ * On HBAs that only support 32-bit addressing PxFBU is read only '0'.
+ * When applying the AHCI_HFLAG_32BIT_ONLY quirk, PxFBU is RW, and the
+ * reset value is Implementation Specific, so we need to clear it to 0.
+ */
if (hpriv->cap & HOST_CAP_64)
writel((pp->rx_fis_dma >> 16) >> 16,
port_mmio + PORT_FIS_ADDR_HI);
+ else if (hpriv->flags & AHCI_HFLAG_32BIT_ONLY)
+ writel(0, port_mmio + PORT_FIS_ADDR_HI);
writel(pp->rx_fis_dma & 0xffffffff, port_mmio + PORT_FIS_ADDR);
/* enable FIS reception */
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 189/398] x86/fred: Reconstruct the #GP context for rejected INT instructions
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (186 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 188/398] btrfs: check if there is space for chunk item when validating sys chunk array Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 190/398] Input: eeti_ts - publish the OF module alias Greg Kroah-Hartman
` (214 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paul Gofman, Matthew Schwartz,
Peter Zijlstra (Intel), H. Peter Anvin, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Matthew Schwartz <matthew.schwartz@linux.dev>
[ Upstream commit 93f53499d0b945e8ae447f497faf743d60069f61 ]
FRED event delivery does not use the IDT, so the gate DPL check that
rejects a user INT n falls to software (Intel FRED specification [1],
section 8.3). fred_intx() rejects the same vectors as IDT delivery, but
reports a zero error code and the IP after the INT. This breaks the
signal ABI. Wine uses the error code to recognize INT 0x2d, so the
changed context turns a handled breakpoint into an access violation in
Elden Ring.
Rewind IP using the instruction length in the augmented SS and
synthesize the IDT selector error code, (vector << 3) | 2. Set RF in the
saved flags, as the CPU does for a #GP fault. Section 5.2.1 defines the
saved vector, instruction length and RF state. The supplied length
handles prefixes without reading user memory. Limit the changes to
already-rejected software interrupts, preserving the accepted INT3, INT4
and enabled INT80 paths and hardware exceptions. With IA32 emulation
disabled, INT 0x80 now reports the same #GP as the DPL 0 gate IDT
installs there. The rewound IP also stops fixup_iopl_exception() from
inspecting the byte after the INT.
Also clear the software event flag. Section 6.2.3 specifies that ERETU
with this flag and TF set traps before executing any user instruction. A
tracer that suppresses SIGSEGV and resumes with TF set expects the next
instruction to run first, as after IRET. The sigreturn path clears the
same flag for this reason in prevent_single_step_upon_eretu().
[1] Intel Flexible Return and Event Delivery (FRED) Specification,
revision 9.0 (346446-009US), sections 5.2.1, 6.2.3 and 8.3.
Fixes: 14619d912b65 ("x86/fred: FRED entry/exit and dispatch code")
Closes: https://gitlab.freedesktop.org/mesa/mesa/-/work_items/15745
Closes: https://gitlab.freedesktop.org/mesa/mesa/-/work_items/16132
Reported-by: Paul Gofman <pgofman@codeweavers.com>
Signed-off-by: Matthew Schwartz <matthew.schwartz@linux.dev>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: H. Peter Anvin <hpa@zytor.com>
Link: https://cdrdv2.intel.com/v1/dl/getContent/678938 # [1]
Link: https://patch.msgid.link/20260917230907.2080792-2-matthew.schwartz@linux.dev
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/entry/entry_fred.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/arch/x86/entry/entry_fred.c b/arch/x86/entry/entry_fred.c
index 9f50f0c1c00f5..c43c750fa26dc 100644
--- a/arch/x86/entry/entry_fred.c
+++ b/arch/x86/entry/entry_fred.c
@@ -10,6 +10,7 @@
#include <asm/desc.h>
#include <asm/fred.h>
#include <asm/idtentry.h>
+#include <asm/processor-flags.h>
#include <asm/syscall.h>
#include <asm/trapnr.h>
#include <asm/traps.h>
@@ -71,7 +72,15 @@ static noinstr void fred_intx(struct pt_regs *regs)
#endif
default:
- return exc_general_protection(regs, 0);
+ /*
+ * Reconstruct the #GP fault state that IDT delivery would produce.
+ * Clear the software event flag so ERETU with TF set does not trap
+ * before the resumed instruction. See prevent_single_step_upon_eretu().
+ */
+ regs->ip -= regs->fred_ss.insnlen;
+ regs->flags |= X86_EFLAGS_RF;
+ regs->fred_ss.swevent = 0;
+ return exc_general_protection(regs, (regs->fred_ss.vector << 3) | 2);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 243/438] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (241 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 242/438] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 244/438] cifs: Fix server use-after-free in cifs_chan_skip_or_disable() Greg Kroah-Hartman
` (206 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wentao Liang, Damien Le Moal,
Niklas Cassel
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 0d1cb83337f13af082afb68b28d3fdfe29cde7fb upstream.
of_find_device_by_node() takes a reference on the port platform device,
which is only used to look up its port regulator and is never released,
neither on success nor on the error paths. Drop the reference with
put_device() once the regulator has been obtained, which covers both the
success and error paths.
Fixes: c7d7ddee7e24 ("ata: libahci: Allow using multiple regulators")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://lore.kernel.org/r/20260915065933.1733061-1-vulab@iscas.ac.cn
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libahci_platform.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/ata/libahci_platform.c
+++ b/drivers/ata/libahci_platform.c
@@ -620,10 +620,10 @@ struct ahci_host_priv *ahci_platform_get
of_platform_device_create(child, NULL, NULL);
port_dev = of_find_device_by_node(child);
-
if (port_dev) {
rc = ahci_platform_get_regulator(hpriv, port,
&port_dev->dev);
+ put_device(&port_dev->dev);
if (rc == -EPROBE_DEFER)
goto err_out;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 190/398] Input: eeti_ts - publish the OF module alias
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (187 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 189/398] x86/fred: Reconstruct the #GP context for rejected INT instructions Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 191/398] hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler Greg Kroah-Hartman
` (213 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, hpp.iscas, Dmitry Torokhov,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: hpp.iscas <hppiscas@163.com>
[ Upstream commit a52ae68a937efc353251aec27fc995ff66cbe1ca ]
The EETI driver matches eeti,exc3000-i2c Device Tree clients, but only
publishes the legacy eeti_ts I2C ID. The I2C core emits an OF modalias
for a Device Tree client.
Publish the existing OF match table within its CONFIG_OF guard.
Fixes: e32d7f1b246c ("Input: eeti - add device tree matching table")
Signed-off-by: hpp.iscas <hppiscas@163.com>
Link: https://patch.msgid.link/20260905134004.66336-1-hppiscas@163.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/input/touchscreen/eeti_ts.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/input/touchscreen/eeti_ts.c b/drivers/input/touchscreen/eeti_ts.c
index 87eb18977b71a..50f150d82f29d 100644
--- a/drivers/input/touchscreen/eeti_ts.c
+++ b/drivers/input/touchscreen/eeti_ts.c
@@ -283,6 +283,7 @@ static const struct of_device_id of_eeti_ts_match[] = {
{ .compatible = "eeti,exc3000-i2c", },
{ }
};
+MODULE_DEVICE_TABLE(of, of_eeti_ts_match);
#endif
static struct i2c_driver eeti_ts_driver = {
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 244/438] cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (242 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 243/438] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 245/438] exec: Cleanup POSIX timers right after de_thread() Greg Kroah-Hartman
` (205 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 717e0a25036b6c92cecace30913b2d874a4c22b8 upstream.
When a secondary channel is no longer supported by the server,
cifs_chan_skip_or_disable() drops the channel reference with
cifs_put_tcp_session() and then continues to use the server pointer by
calling cifs_signal_cifsd_for_reconnect() on it and reading its
primary_server pointer. cifs_put_tcp_session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs_put_tcp_session()) can be freed before they are signaled for
reconnect.
Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs_put_tcp_session().
Fixes: f591062bdbf4 ("cifs: handle servers that still advertise multichannel after disabling")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2pdu.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
--- a/fs/smb/client/smb2pdu.c
+++ b/fs/smb/client/smb2pdu.c
@@ -189,18 +189,19 @@ cifs_chan_skip_or_disable(struct cifs_se
spin_unlock(&ses->chan_lock);
/*
- * the above reference of server by channel
- * needs to be dropped without holding chan_lock
- * as cifs_put_tcp_session takes a higher lock
- * i.e. cifs_tcp_ses_lock
+ * signal the channel and its primary server to
+ * reconnect before dropping the above reference of
+ * server by channel, which is done without holding
+ * chan_lock as cifs_put_tcp_session takes a higher
+ * lock i.e. cifs_tcp_ses_lock
*/
- cifs_put_tcp_session(server, from_reconnect);
-
cifs_signal_cifsd_for_reconnect(server, false);
/* mark primary server as needing reconnect */
pserver = server->primary_server;
cifs_signal_cifsd_for_reconnect(pserver, false);
+
+ cifs_put_tcp_session(server, from_reconnect);
skip_terminate:
return -EHOSTDOWN;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 191/398] hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (188 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 190/398] Input: eeti_ts - publish the OF module alias Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 192/398] hwmon: (hp-wmi-sensors) Improve raw WMI string handling Greg Kroah-Hartman
` (212 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko AI review, Cong Nguyen,
Guenter Roeck, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cong Nguyen <congnt264@gmail.com>
[ Upstream commit bdf5f731957de48acada392f28e82bc019713adb ]
fan_alarm_irq_handler() always schedules alarm_work but returns IRQ_NONE,
so the kernel treats every alarm interrupt as unhandled. On a shared
line that risks the whole line being disabled as spurious.
v1 just fixed that, but it was still IRQF_SHARED, and always returning
IRQ_HANDLED there defeats spurious-interrupt detection for the line --
if the interrupt ever fires without a real event, nothing catches it,
and a fault could spin the CPU in the handler.
Sashiko flagged this in v1, and Guenter confirmed: this interrupt must
not be shared. So v2 drops IRQF_SHARED too.
Fixes: d6fe1360f42e ("hwmon: add generic GPIO fan driver")
Reported-by: Sashiko AI review <sashiko-bot@kernel.org>
Link: https://lore.kernel.org/r/20260901160931.DD3811F00A3D@smtp.kernel.org
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Link: https://patch.msgid.link/20260914104136.1797979-1-congnt264@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/gpio-fan.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/hwmon/gpio-fan.c b/drivers/hwmon/gpio-fan.c
index ea5ca2dea2a99..1dfc02df9bbb0 100644
--- a/drivers/hwmon/gpio-fan.c
+++ b/drivers/hwmon/gpio-fan.c
@@ -68,7 +68,7 @@ static irqreturn_t fan_alarm_irq_handler(int irq, void *dev_id)
schedule_work(&fan_data->alarm_work);
- return IRQ_NONE;
+ return IRQ_HANDLED;
}
static ssize_t fan1_alarm_show(struct device *dev,
@@ -103,7 +103,7 @@ static int fan_alarm_init(struct gpio_fan_data *fan_data)
irq_set_irq_type(alarm_irq, IRQ_TYPE_EDGE_BOTH);
return devm_request_irq(dev, alarm_irq, fan_alarm_irq_handler,
- IRQF_SHARED, "GPIO fan alarm", fan_data);
+ 0, "GPIO fan alarm", fan_data);
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 245/438] exec: Cleanup POSIX timers right after de_thread()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (243 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 244/438] cifs: Fix server use-after-free in cifs_chan_skip_or_disable() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 246/438] fs/dax: check zero or empty entry before converting xarray entry Greg Kroah-Hartman
` (204 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hyunwoo Kim, Thomas Gleixner,
Kijo Park, Oleg Nesterov, Frederic Weisbecker
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hyunwoo Kim <imv4bel@gmail.com>
commit acb03d3881818581052924a9bbbe92b8741ed448 upstream.
A per-thread CPU timer holds a reference to the PID of the thread it is
attached to and, while it is armed, its node is queued in that thread's
posix_cputimers. The task is looked up by that PID.
When a non-leader thread exec()s, de_thread() changes which task owns
that PID. pid_task(timer->it.cpu.pid, PIDTYPE_PID) then returns NULL,
but the node is still queued on tsk, which is alive. timer_lock_sighand()
takes a failed lookup to mean that the node is already dequeued, so it
has nothing to undo.
begin_new_exec() calls posix_cpu_timers_exit(me) right after
exec_task_namespaces() and that removes the leftover node, so the state
normally stays invisible. But bprm->point_of_no_return is set before
de_thread(), so if unshare_files(), set_mm_exe_file(), exec_mmap() or
exec_task_namespaces() fails, the task dies before it gets there.
exit_itimers() then frees the k_itimer while its node is still queued,
and reaping tsk later erases that freed node from the rbtree.
In short:
the non-leader thread B the parent
timer_create(CLOCK_THREAD_CPUTIME_ID)
timer_settime()
arm_timer() // the node is queued on B
execve()
de_thread(B)
exchange_tids(B, leader) // B's PID now belongs to the leader
release_task(leader)
__exit_signal(leader)
posix_cpu_timers_exit(leader) // cleans leader's queue, not B's
__unhash_process(leader) // that PID has no task anymore
exec_mmap()
mmap_read_lock_killable(old_mm)
kill(B, SIGKILL)
// -EINTR
get_signal()
do_exit()
exit_itimers()
posix_timer_delete()
posix_cpu_timer_del()
posix_timer_unhash_and_free() // freed while still queued
wait4()
release_task(B)
posix_cpu_timers_exit(B)
cleanup_timerqueue()
timerqueue_del() // use-after-free
Move the POSIX timer cleanup right after de_thread() before any of the
later failure conditions brings the task into do_exit().
[ tglx: Move the cleanup right after de_thread() ]
Fixes: 55e8c8eb2c7b ("posix-cpu-timers: Store a reference to a pid not a task")
Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Kijo Park <red993688@gmail.com>
Reviewed-by: Oleg Nesterov <oleg@redhat.com>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/ao7Q8miiuLAPVnWv@v4bel
Link: https://patch.msgid.link/20260911090541.627712075@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/exec.c | 29 +++++++++++++++++++++--------
1 file changed, 21 insertions(+), 8 deletions(-)
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -1104,6 +1104,17 @@ void __set_task_comm(struct task_struct
perf_event_comm(tsk, exec);
}
+static void posixtimer_exec(struct task_struct *me)
+{
+#ifdef CONFIG_POSIX_TIMERS
+ spin_lock_irq(&me->sighand->siglock);
+ posix_cpu_timers_exit(me);
+ spin_unlock_irq(&me->sighand->siglock);
+ exit_itimers(me);
+ flush_itimer_signals();
+#endif
+}
+
/*
* Calling this is the point of no return. None of the failures will be
* seen by userspace since either the process is already taking a fatal
@@ -1137,6 +1148,16 @@ int begin_new_exec(struct linux_binprm *
retval = de_thread(me);
if (retval)
goto out;
+
+ /*
+ * This must be done here to ensure that POSIX CPU timers which were
+ * armed on the current task are dequeued from me::posix_cputimers.
+ * Otherwise in case of a TID switch the deletion of the related POSIX
+ * timer would not remove an enqueued timer because the TID lookup
+ * of the old TID fails.
+ */
+ posixtimer_exec(me);
+
/* see the comment in check_unsafe_exec() */
current->fs->in_exec = 0;
/*
@@ -1191,14 +1212,6 @@ int begin_new_exec(struct linux_binprm *
if (retval)
goto out_unlock;
-#ifdef CONFIG_POSIX_TIMERS
- spin_lock_irq(&me->sighand->siglock);
- posix_cpu_timers_exit(me);
- spin_unlock_irq(&me->sighand->siglock);
- exit_itimers(me);
- flush_itimer_signals();
-#endif
-
/*
* Make the signal table private.
*/
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 192/398] hwmon: (hp-wmi-sensors) Improve raw WMI string handling
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (189 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 191/398] hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 193/398] watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
` (211 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Muhammad Bilal, James Seo,
Guenter Roeck, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Seo <james@equiv.tech>
[ Upstream commit 92b68492eae701e5b0e9d142ffe229921af7b1fa ]
Commit c9ba59258094 ("hwmon: (hp-wmi-sensors) Fix failure to load on
EliteDesk 800 G6") left out some logic for recognizing raw WMI
strings in check_numeric_sensor_wobj(). This issue was reported by a
user along with an incomplete and unsuitable proposed solution [1].
Add the missing logic and properly remedy the issue. Also slightly
refactor how raw WMI strings are recognized elsewhere to make the
intent that they should be treated as regular ACPI strings clearer.
Reported-by: Muhammad Bilal <meatuni001@gmail.com>
Link: https://lore.kernel.org/linux-hwmon/20260916002907.161210-1-meatuni001@gmail.com/ [1]
Fixes: c9ba59258094 ("hwmon: (hp-wmi-sensors) Fix failure to load on EliteDesk 800 G6")
Signed-off-by: James Seo <james@equiv.tech>
Link: https://patch.msgid.link/20260916221912.434119-5-james@equiv.tech
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwmon/hp-wmi-sensors.c | 30 ++++++++++++++++++++++--------
1 file changed, 22 insertions(+), 8 deletions(-)
diff --git a/drivers/hwmon/hp-wmi-sensors.c b/drivers/hwmon/hp-wmi-sensors.c
index 03c684ba83bd6..cb2eb9bd278a2 100644
--- a/drivers/hwmon/hp-wmi-sensors.c
+++ b/drivers/hwmon/hp-wmi-sensors.c
@@ -526,14 +526,12 @@ static int check_wobj(const union acpi_object *wobj,
for (prop = 0; prop <= last_prop; prop++) {
type = elements[prop].type;
valid_type = property_map[prop];
- if (type != valid_type) {
- if (type == ACPI_TYPE_BUFFER &&
- valid_type == ACPI_TYPE_STRING &&
- is_raw_wmi_string(elements[prop].buffer.pointer,
- elements[prop].buffer.length))
- continue;
+ if (type == ACPI_TYPE_BUFFER &&
+ is_raw_wmi_string(elements[prop].buffer.pointer,
+ elements[prop].buffer.length))
+ type = ACPI_TYPE_STRING;
+ if (type != valid_type)
return -EINVAL;
- }
}
return 0;
@@ -579,6 +577,7 @@ static int check_numeric_sensor_wobj(const union acpi_object *wobj,
int prop = HP_WMI_PROPERTY_NAME;
acpi_object_type valid_type;
union acpi_object *elements;
+ union acpi_object *element;
u32 elem_count;
int last_prop;
bool is_new;
@@ -602,13 +601,20 @@ static int check_numeric_sensor_wobj(const union acpi_object *wobj,
elem_count > HP_WMI_MAX_PROPERTIES)
return -EINVAL;
- type = elements[HP_WMI_PROPERTY_SIZE].type;
+ element = &elements[HP_WMI_PROPERTY_SIZE];
+ type = element->type;
switch (type) {
case ACPI_TYPE_INTEGER:
is_new = true;
last_prop = HP_WMI_PROPERTY_RATE_UNITS;
break;
+ case ACPI_TYPE_BUFFER:
+ if (!is_raw_wmi_string(element->buffer.pointer,
+ element->buffer.length))
+ return -EINVAL;
+ fallthrough;
+
case ACPI_TYPE_STRING:
is_new = false;
last_prop = HP_WMI_PROPERTY_CURRENT_READING;
@@ -631,6 +637,10 @@ static int check_numeric_sensor_wobj(const union acpi_object *wobj,
for (i = 0; i < elem_count && prop <= last_prop; i++, prop++) {
type = elements[i].type;
valid_type = hp_wmi_property_map[prop];
+ if (type == ACPI_TYPE_BUFFER &&
+ is_raw_wmi_string(elements[i].buffer.pointer,
+ elements[i].buffer.length))
+ type = ACPI_TYPE_STRING;
if (type != valid_type)
return -EINVAL;
@@ -651,6 +661,10 @@ static int check_numeric_sensor_wobj(const union acpi_object *wobj,
/* PossibleStates[0] has already been type-checked. */
for (j = 0; i + 1 < elem_count && j + 1 < count; j++) {
type = elements[++i].type;
+ if (type == ACPI_TYPE_BUFFER &&
+ is_raw_wmi_string(elements[i].buffer.pointer,
+ elements[i].buffer.length))
+ type = ACPI_TYPE_STRING;
if (type != valid_type)
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 246/438] fs/dax: check zero or empty entry before converting xarray entry
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (244 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 245/438] exec: Cleanup POSIX timers right after de_thread() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 247/438] PCI: imx6: Move clock enable after core reset assertion Greg Kroah-Hartman
` (203 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Seunguk Shin, Jan Kara,
Alistair Popple, Kiara Grouwstra, Al Viro, Christian Brauner,
Matthew Wilcox (Oracle), Andrew Morton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Seunguk Shin <seunguk.shin@arm.com>
commit 8e2b8614039853e68d5338e37821e8bcee9fc05f upstream.
Calling dax_to_folio() with empty entry causes kernel panic below when
booting a VM with DAX enabled storage.
This patch checks empty entry before calling dax_to_folio() on
dax_associate_entry(), dax_disassociate_entry(), and dax_busy_page().
Commit 98c183a4fccf ("fs/dax: don't disassociate zero page entries") added
guards in the associate and disassociate paths, but the guards still come
after dax_to_folio(), and dax_busy_page() still has the same problem.
[ 0.737679] EXT4-fs (pmem0p1): mounted filesystem 79676804-7c8b-491a-b2a6-9bae3c72af70 ro with ordered data mode. Quota mode: disabled.
[ 0.737891] VFS: Mounted root (ext4 filesystem) readonly on device 259:1.
[ 0.739119] devtmpfs: mounted
[ 0.739476] Freeing unused kernel memory: 1920K
[ 0.740156] Run /sbin/init as init process
[ 0.740229] with arguments:
[ 0.740286] /sbin/init
[ 0.740321] with environment:
[ 0.740369] HOME=/
[ 0.740400] TERM=linux
[ 0.743162] Unable to handle kernel paging request at virtual address fffffdffbf000008
[ 0.743285] Mem abort info:
[ 0.743316] ESR = 0x0000000096000006
[ 0.743371] EC = 0x25: DABT (current EL), IL = 32 bits
[ 0.743444] SET = 0, FnV = 0
[ 0.743489] EA = 0, S1PTW = 0
[ 0.743545] FSC = 0x06: level 2 translation fault
[ 0.743610] Data abort info:
[ 0.743656] ISV = 0, ISS = 0x00000006, ISS2 = 0x00000000
[ 0.743720] CM = 0, WnR = 0, TnD = 0, TagAccess = 0
[ 0.743785] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
[ 0.743848] swapper pgtable: 4k pages, 48-bit VAs, pgdp=00000000b9d17000
[ 0.743931] [fffffdffbf000008] pgd=10000000bfa3d403, p4d=10000000bfa3d403, pud=1000000040bfe403, pmd=0000000000000000
[ 0.744070] Internal error: Oops: 0000000096000006 [#1] SMP
[ 0.748888] CPU: 0 UID: 0 PID: 1 Comm: init Not tainted 6.18.4 #1 NONE
[ 0.749421] pstate: 004000c5 (nzcv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 0.749969] pc : dax_disassociate_entry.constprop.0+0x20/0x50
[ 0.750444] lr : dax_insert_entry+0xcc/0x408
[ 0.750802] sp : ffff80008000b9e0
[ 0.751083] x29: ffff80008000b9e0 x28: 0000000000000000 x27: 0000000000000000
[ 0.751682] x26: 0000000001963d01 x25: ffff0000004f7d90 x24: 0000000000000000
[ 0.752264] x23: 0000000000000000 x22: ffff80008000bcc8 x21: 0000000000000011
[ 0.752836] x20: ffff80008000ba90 x19: 0000000001963d01 x18: 0000000000000000
[ 0.753407] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000
[ 0.753970] x14: ffffbf3154b9ae70 x13: 0000000000000000 x12: ffffbf3154b9ae70
[ 0.754548] x11: ffffffffffffffff x10: 0000000000000000 x9 : 0000000000000000
[ 0.755122] x8 : 000000000000000d x7 : 000000000000001f x6 : 0000000000000000
[ 0.755707] x5 : 0000000000000000 x4 : 0000000000000000 x3 : fffffdffc0000000
[ 0.756287] x2 : 0000000000000008 x1 : 0000000040000000 x0 : fffffdffbf000000
[ 0.756871] Call trace:
[ 0.757107] dax_disassociate_entry.constprop.0+0x20/0x50 (P)
[ 0.757592] dax_iomap_pte_fault+0x4fc/0x808
[ 0.757951] dax_iomap_fault+0x28/0x30
[ 0.758258] ext4_dax_huge_fault+0x80/0x2dc
[ 0.758594] ext4_dax_fault+0x10/0x3c
[ 0.758892] __do_fault+0x38/0x12c
[ 0.759175] __handle_mm_fault+0x530/0xcf0
[ 0.759518] handle_mm_fault+0xe4/0x230
[ 0.759833] do_page_fault+0x17c/0x4dc
[ 0.760144] do_translation_fault+0x30/0x38
[ 0.760483] do_mem_abort+0x40/0x8c
[ 0.760771] el0_ia+0x4c/0x170
[ 0.761032] el0t_64_sync_handler+0xd8/0xdc
[ 0.761371] el0t_64_sync+0x168/0x16c
[ 0.761677] Code: f9453021 f2dfbfe3 cb813080 8b001860 (f9400401)
[ 0.762168] ---[ end trace 0000000000000000 ]---
[ 0.762550] note: init[1] exited with irqs disabled
[ 0.762631] Kernel panic - not syncing: Attempted to kill init! exitcode=0x0000000b
Link: https://lore.kernel.org/m2y0enxtzk.fsf@arm.com
Fixes: 38607c62b34b ("fs/dax: properly refcount fs dax pages")
Signed-off-by: Seunguk Shin <seunguk.shin@arm.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Reviewed-by: Alistair Popple <apopple@nvidia.com>
Reported-by: Kiara Grouwstra <cinereal@riseup.net>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/dax.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
--- a/fs/dax.c
+++ b/fs/dax.c
@@ -480,11 +480,12 @@ static void dax_associate_entry(void *en
unsigned long address, bool shared)
{
unsigned long size = dax_entry_size(entry), index;
- struct folio *folio = dax_to_folio(entry);
+ struct folio *folio;
if (dax_is_zero_entry(entry) || dax_is_empty_entry(entry))
return;
+ folio = dax_to_folio(entry);
index = linear_page_index(vma, address & ~(size - 1));
if (shared && (folio->mapping || dax_folio_is_shared(folio))) {
if (folio->mapping)
@@ -505,21 +506,23 @@ static void dax_associate_entry(void *en
static void dax_disassociate_entry(void *entry, struct address_space *mapping,
bool trunc)
{
- struct folio *folio = dax_to_folio(entry);
+ struct folio *folio;
if (dax_is_zero_entry(entry) || dax_is_empty_entry(entry))
return;
+ folio = dax_to_folio(entry);
dax_folio_put(folio);
}
static struct page *dax_busy_page(void *entry)
{
- struct folio *folio = dax_to_folio(entry);
+ struct folio *folio;
if (dax_is_zero_entry(entry) || dax_is_empty_entry(entry))
return NULL;
+ folio = dax_to_folio(entry);
if (folio_ref_count(folio) - folio_mapcount(folio))
return &folio->page;
else
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 193/398] watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (190 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 192/398] hwmon: (hp-wmi-sensors) Improve raw WMI string handling Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 194/398] ACPI: processor: Update cpuidle driver check in __acpi_processor_start() Greg Kroah-Hartman
` (210 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Li Jun, Guenter Roeck, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Jun <lijun01@kylinos.cn>
[ Upstream commit 5071122bf5a628494db16d98d253f622a5aab074 ]
da9062_wdt_suspend() and da9062_wdt_resume() only check watchdog_active(),
when the watchdog is left running by the driver sets
WDOG_HW_RUNNING in da9062_wdt_probe() but userspace never opens the
device, so WDOG_ACTIVE remains cleared, the wdt_disable() will not be
executed in da9062_wdt_suspend. In this case, the suspend callback is
a no-op and the watchdog keeps counting during system suspend,
leading to an unexpected system reset.
Check WDOG_HW_RUNNING and wdt->wdd,can fix this issue.
Fixes: f6c98b08381c7 ("watchdog: da9062: add power management ops")
Cs: stable@vger.kernel.org
Signed-off-by: Li Jun <lijun01@kylinos.cn>
Link: https://patch.msgid.link/20260914062353.582205-1-lijun01@kylinos.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/watchdog/da9062_wdt.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/watchdog/da9062_wdt.c b/drivers/watchdog/da9062_wdt.c
index 426962547df16..4d558652e9e71 100644
--- a/drivers/watchdog/da9062_wdt.c
+++ b/drivers/watchdog/da9062_wdt.c
@@ -256,7 +256,7 @@ static int __maybe_unused da9062_wdt_suspend(struct device *dev)
if (!wdt->use_sw_pm)
return 0;
- if (watchdog_active(wdd))
+ if (watchdog_active(wdd) || watchdog_hw_running(wdd))
return da9062_wdt_stop(wdd);
return 0;
@@ -270,7 +270,7 @@ static int __maybe_unused da9062_wdt_resume(struct device *dev)
if (!wdt->use_sw_pm)
return 0;
- if (watchdog_active(wdd))
+ if (watchdog_active(wdd) || watchdog_hw_running(wdd))
return da9062_wdt_start(wdd);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 247/438] PCI: imx6: Move clock enable after core reset assertion
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (245 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 246/438] fs/dax: check zero or empty entry before converting xarray entry Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 248/438] phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context Greg Kroah-Hartman
` (202 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Leonardo Costa, Franz Schnyder,
Richard Zhu, Manivannan Sadhasivam, Bjorn Helgaas
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Zhu <hongxing.zhu@nxp.com>
commit c9dc7d730319ad64b51570c5387f1fee7b07b510 upstream.
Commit 610fa91d9863 ("PCI: imx6: Assert PERST# before enabling regulators")
inadvertently moved clock enablement before core reset assertion, breaking
PCI device initialization on i.MX6Q Apalis platforms with
ASM1061/ASM1062 SATA controllers connected:
imx6q-pcie 1ffc000.pcie: host bridge /soc/pcie@1ffc000 ranges:
imx6q-pcie 1ffc000.pcie: IO 0x0001f80000..0x0001f8ffff -> 0x0000000000
imx6q-pcie 1ffc000.pcie: MEM 0x0001000000..0x0001efffff -> 0x0001000000
imx6q-pcie 1ffc000.pcie: config reg[1] 0x01f00000 == cpu 0x01f00000
imx6q-pcie 1ffc000.pcie: iATU: unroll F, 4 ob, 4 ib, align 64K, limit 4G
imx6q-pcie 1ffc000.pcie: Link: Only Gen1 is enabled
imx6q-pcie 1ffc000.pcie: Link failed to come up. LTSSM: POLL_CONFIG
imx6q-pcie 1ffc000.pcie: probe with driver imx6q-pcie failed with error -110
NOTE: It is not 100% clear if the issue is specific to the ASM1061/ASM1062
device or on the specific power-up sequence (reset vs cold-power-on).
To fix this regression, restore the original sequence where clocks are
enabled after asserting core reset and configuring the controller type.
Fixes: 610fa91d9863 ("PCI: imx6: Assert PERST# before enabling regulators")
Reported-by: Leonardo Costa <leoreis.costa@gmail.com>
Closes: https://lore.kernel.org/all/bl7i3obu2clzsgeoct2a4mtfhv6typcjdqmgneropf3hpgwve6@n2m5uhlduw57/T/#u
Reported-by: Franz Schnyder <fra.schnyder@gmail.com>
Closes: https://lore.kernel.org/all/t65y5d54axtksbfs7r4olcefqhwm6m4dz3njgnrnf7fcotj74i@o7avoznlafbj/
Signed-off-by: Richard Zhu <hongxing.zhu@nxp.com>
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[bhelgaas: move to pci/for-linus for v7.3]
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Cc: stable@vger.kernel.org # 7.2+
Link: https://patch.msgid.link/20260813095003.356062-1-hongxing.zhu@oss.nxp.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pci/controller/dwc/pci-imx6.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
--- a/drivers/pci/controller/dwc/pci-imx6.c
+++ b/drivers/pci/controller/dwc/pci-imx6.c
@@ -1388,12 +1388,6 @@ static int imx_pcie_host_init(struct dw_
goto err_pwrctrl_destroy;
}
- ret = imx_pcie_clk_enable(imx_pcie);
- if (ret) {
- dev_err(dev, "unable to enable pcie clocks: %d\n", ret);
- goto err_pwrctrl_power_off;
- }
-
if (pp->bridge && imx_check_flag(imx_pcie, IMX_PCIE_FLAG_HAS_LUT)) {
pp->bridge->enable_device = imx_pcie_enable_device;
pp->bridge->disable_device = imx_pcie_disable_device;
@@ -1409,6 +1403,12 @@ static int imx_pcie_host_init(struct dw_
imx_pcie_configure_type(imx_pcie);
+ ret = imx_pcie_clk_enable(imx_pcie);
+ if (ret) {
+ dev_err(dev, "unable to enable pcie clocks: %d\n", ret);
+ goto err_pwrctrl_power_off;
+ }
+
if (imx_pcie->phy) {
ret = phy_init(imx_pcie->phy);
if (ret) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 194/398] ACPI: processor: Update cpuidle driver check in __acpi_processor_start()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (191 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 193/398] watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 195/398] wifi: rtw88: TX QOS Null data the same way as Null data Greg Kroah-Hartman
` (209 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki,
Mario Limonciello (AMD), Borislav Petkov (AMD), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
[ Upstream commit 0089ce1c056aee547115bdc25c223f8f88c08498 ]
Commit 7a8c994cbb2d ("ACPI: processor: idle: Optimize ACPI idle
driver registration") moved the ACPI idle driver registration to
acpi_processor_driver_init() and acpi_processor_power_init() does
not register an idle driver any more.
Accordingly, the cpuidle driver check in __acpi_processor_start() needs
to be updated to avoid calling acpi_processor_power_init() without a
cpuidle driver, in which case the registration of the cpuidle device
in that function would lead to a NULL pointer dereference in
__cpuidle_register_device().
Fixes: 7a8c994cbb2d ("ACPI: processor: idle: Optimize ACPI idle driver registration")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Tested-by: Borislav Petkov (AMD) <bp@alien8.de>
Link: https://patch.msgid.link/20251223100914.2407069-4-lihuisong@huawei.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/processor_driver.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/acpi/processor_driver.c b/drivers/acpi/processor_driver.c
index 06589bf488f74..1b4d2e11a1b1b 100644
--- a/drivers/acpi/processor_driver.c
+++ b/drivers/acpi/processor_driver.c
@@ -166,7 +166,7 @@ static int __acpi_processor_start(struct acpi_device *device)
if (result && !IS_ENABLED(CONFIG_ACPI_CPU_FREQ_PSS))
dev_dbg(&device->dev, "CPPC data invalid or not present\n");
- if (!cpuidle_get_driver() || cpuidle_get_driver() == &acpi_idle_driver)
+ if (cpuidle_get_driver() == &acpi_idle_driver)
acpi_processor_power_init(pr);
acpi_pss_perf_init(pr);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 248/438] phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (246 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 247/438] PCI: imx6: Move clock enable after core reset assertion Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 249/438] posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list Greg Kroah-Hartman
` (201 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pavel Machek, Nobuhiro Iwamatsu,
Claudiu Beznea, Manivannan Sadhasivam, Vinod Koul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
commit 48e97c59a49c9e90270f5e3d221db253b76de5da upstream.
The OTG PHY initialization sequence needs to wait for 20 ms at a specific
step, as described in commit 72c0339c115b ("phy: renesas:
rcar-gen3-usb2: follow the hardware manual procedure").
Commit 55a387ebb921 ("phy: renesas: rcar-gen3-usb2: Lock around hardware
registers and driver data") tried to address various problems in the
rcar-gen3-usb2 driver and converted the mutex protecting HW register
accesses to a spin lock, leaving, however, a long delay in the critical
section protected by the spin lock. This may become a problem,
especially on RT kernels.
To address this, release the spin lock before sleeping for 20 ms as
required by the HW manual and reacquire it afterwards. To avoid other
threads entering the critical section and configuring the HW while the
software is waiting for the OTG initialization to complete, introduce the
otg_initializing variable alongside the otg_init_done wait queue. Any
other thread trying to configure the HW while the OTG PHY initialization
is in progress waits for the wait queue instead of immediately returning
errors to PHY users. The IRQs were also disabled while waiting for the OTG
PHY initialization to complete, as the interrupt handler may also apply HW
settings.
The OTG can only be initialized once. It is initialized by the first PHY
that calls struct phy_ops::rcar_gen3_phy_usb2_init().
To avoid failures when multiple PHYs call struct
phy_ops::rcar_gen3_phy_usb2_init() simultaneously, and the PHY responsible
for initializing the OTG either fails or deinit quiqly and another PHY
takes over the PHY init role), the code waiting for the
channel->otg_init_done wait queue retries up to NUM_OF_PHYS times.
Fixes: 55a387ebb921 ("phy: renesas: rcar-gen3-usb2: Lock around hardware registers and driver data")
Cc: stable@vger.kernel.org
Reported-by: Pavel Machek <pavel@nabladev.com>
Closes: https://lore.kernel.org/all/afhkX2Ys2BG1gnqy@duo.ucw.cz
Reported-by: Nobuhiro Iwamatsu <iwamatsu@nigauri.org>
Closes: https://lore.kernel.org/all/afhkX2Ys2BG1gnqy@duo.ucw.cz
Signed-off-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://lore.kernel.org/all/afhkX2Ys2BG1gnqy@duo.ucw.cz
Link: https://patch.msgid.link/20260716183246.3183877-1-claudiu.beznea+renesas@tuxon.dev
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/phy/renesas/phy-rcar-gen3-usb2.c | 310 ++++++++++++++++++++++++++-----
1 file changed, 265 insertions(+), 45 deletions(-)
--- a/drivers/phy/renesas/phy-rcar-gen3-usb2.c
+++ b/drivers/phy/renesas/phy-rcar-gen3-usb2.c
@@ -27,6 +27,7 @@
#include <linux/reset.h>
#include <linux/string.h>
#include <linux/usb/of.h>
+#include <linux/wait.h>
#include <linux/workqueue.h>
/******* USB2.0 Host registers (original offset is +0x200) *******/
@@ -106,6 +107,13 @@
/* RZ/G2L specific */
#define USB2_LINECTRL1_USB2_IDMON BIT(0)
+/*
+ * The OTG initialization is expected to finish in 20ms. Choose a large enough
+ * timeout to avoid waiters exit prematurely the waiting section under heavy
+ * CPU load.
+ */
+#define USB2_OTG_INIT_TIMEOUT msecs_to_jiffies(120)
+
#define NUM_OF_PHYS 4
enum rcar_gen3_phy_index {
PHY_INDEX_BOTH_HC,
@@ -138,12 +146,20 @@ struct rcar_gen3_chan {
struct rcar_gen3_phy rphys[NUM_OF_PHYS];
struct regulator *vbus;
struct work_struct work;
+ wait_queue_head_t otg_init_done;
spinlock_t lock; /* protects access to hardware and driver data structure. */
enum usb_dr_mode dr_mode;
bool extcon_host;
bool is_otg_channel;
bool uses_otg_pins;
bool otg_internal_reg;
+ /*
+ * The OTG can be initialized only once and needs to release the spinlock
+ * and wait for 20 ms due to hardware constraints. If a thread executes
+ * PHY configuration code while the OTG PHY is waiting for the 20 ms, the
+ * thread will have to wait for the OTG PHY initialization to complete.
+ */
+ bool otg_initializing;
};
struct rcar_gen3_phy_drv_data {
@@ -392,26 +408,58 @@ static ssize_t role_store(struct device
struct rcar_gen3_chan *ch = dev_get_drvdata(dev);
bool is_b_device;
enum phy_mode cur_mode, new_mode;
+ int retries = NUM_OF_PHYS;
+ unsigned long flags;
+ int ret = -EIO;
- guard(spinlock_irqsave)(&ch->lock);
+ spin_lock_irqsave(&ch->lock, flags);
- if (!ch->is_otg_channel || !rcar_gen3_is_any_otg_rphy_initialized(ch))
- return -EIO;
+ if (!ch->is_otg_channel)
+ goto unlock;
+
+ while (retries-- && ch->otg_initializing) {
+ spin_unlock_irqrestore(&ch->lock, flags);
+
+ ret = wait_event_timeout(ch->otg_init_done, !ch->otg_initializing,
+ USB2_OTG_INIT_TIMEOUT);
+ ret = ret ? 0 : -ETIMEDOUT;
+ if (ret && !retries)
+ goto exit;
+
+ spin_lock_irqsave(&ch->lock, flags);
+ }
+
+ /* If another thread started a new initialization just return -EBUSY. */
+ if (ch->otg_initializing) {
+ ret = -EBUSY;
+ goto unlock;
+ } else {
+ ret = 0;
+ }
+
+ if (!rcar_gen3_is_any_otg_rphy_initialized(ch)) {
+ ret = -EIO;
+ goto unlock;
+ }
- if (sysfs_streq(buf, "host"))
+ if (sysfs_streq(buf, "host")) {
new_mode = PHY_MODE_USB_HOST;
- else if (sysfs_streq(buf, "peripheral"))
+ } else if (sysfs_streq(buf, "peripheral")) {
new_mode = PHY_MODE_USB_DEVICE;
- else
- return -EINVAL;
+ } else {
+ ret = -EINVAL;
+ goto unlock;
+ }
/* is_b_device: true is B-Device. false is A-Device. */
is_b_device = rcar_gen3_check_id(ch);
cur_mode = rcar_gen3_get_phy_mode(ch);
/* If current and new mode is the same, this returns the error */
- if (cur_mode == new_mode)
- return -EINVAL;
+ if (cur_mode == new_mode) {
+ ret = -EINVAL;
+ goto unlock;
+ }
if (new_mode == PHY_MODE_USB_HOST) { /* And is_host must be false */
if (!is_b_device) /* A-Peripheral */
@@ -425,7 +473,10 @@ static ssize_t role_store(struct device
rcar_gen3_init_for_peri(ch);
}
- return count;
+unlock:
+ spin_unlock_irqrestore(&ch->lock, flags);
+exit:
+ return ret ?: count;
}
static ssize_t role_show(struct device *dev, struct device_attribute *attr,
@@ -441,14 +492,11 @@ static ssize_t role_show(struct device *
}
static DEVICE_ATTR_RW(role);
-static void rcar_gen3_init_otg(struct rcar_gen3_chan *ch)
+static void rcar_gen3_init_otg_phase0(struct rcar_gen3_chan *ch)
{
void __iomem *usb2_base = ch->base;
u32 val;
- if (!ch->is_otg_channel || rcar_gen3_is_any_otg_rphy_initialized(ch))
- return;
-
/* Should not use functions of read-modify-write a register */
val = readl(usb2_base + USB2_LINECTRL1);
val = (val & ~USB2_LINECTRL1_DP_RPD) | USB2_LINECTRL1_DPRPD_EN |
@@ -471,7 +519,11 @@ static void rcar_gen3_init_otg(struct rc
writel(val | USB2_ADPCTRL_IDPULLUP, usb2_base + USB2_ADPCTRL);
}
}
- mdelay(20);
+}
+
+static void rcar_gen3_init_otg_phase1(struct rcar_gen3_chan *ch)
+{
+ void __iomem *usb2_base = ch->base;
writel(0xffffffff, usb2_base + USB2_OBINTSTA);
writel(ch->phy_data->obint_enable_bits, usb2_base + USB2_OBINTEN);
@@ -502,6 +554,7 @@ static irqreturn_t rcar_gen3_phy_usb2_ir
void __iomem *usb2_base = ch->base;
struct device *dev = ch->dev;
irqreturn_t ret = IRQ_NONE;
+ unsigned long flags;
u32 status;
pm_runtime_get_noresume(dev);
@@ -509,33 +562,102 @@ static irqreturn_t rcar_gen3_phy_usb2_ir
if (pm_runtime_suspended(dev))
goto rpm_put;
- scoped_guard(spinlock, &ch->lock) {
- status = readl(usb2_base + USB2_OBINTSTA);
- if (status & ch->phy_data->obint_enable_bits) {
- dev_vdbg(dev, "%s: %08x\n", __func__, status);
- if (ch->phy_data->vblvl_ctrl)
- writel(USB2_OBINTSTA_CLEAR, usb2_base + USB2_OBINTSTA);
- else
- writel(ch->phy_data->obint_enable_bits, usb2_base + USB2_OBINTSTA);
- rcar_gen3_device_recognition(ch);
- rcar_gen3_configure_vblvl_ctrl(ch);
- ret = IRQ_HANDLED;
- }
+ spin_lock_irqsave(&ch->lock, flags);
+
+ status = readl(usb2_base + USB2_OBINTSTA);
+ if (status & ch->phy_data->obint_enable_bits) {
+ dev_vdbg(dev, "%s: %08x\n", __func__, status);
+ if (ch->phy_data->vblvl_ctrl)
+ writel(USB2_OBINTSTA_CLEAR, usb2_base + USB2_OBINTSTA);
+ else
+ writel(ch->phy_data->obint_enable_bits, usb2_base + USB2_OBINTSTA);
+
+ ret = IRQ_HANDLED;
+
+ /* This should not happen! */
+ if (ch->otg_initializing)
+ goto unlock;
+
+ rcar_gen3_device_recognition(ch);
+ rcar_gen3_configure_vblvl_ctrl(ch);
}
+unlock:
+ spin_unlock_irqrestore(&ch->lock, flags);
rpm_put:
pm_runtime_put_noidle(dev);
return ret;
}
+static void rcar_gen3_phy_usb2_irqs_mask_all(struct rcar_gen3_chan *channel,
+ u32 *masked_irqs_bits)
+{
+ u32 val, bitmask = USB2_INT_ENABLE_UCOM_INTEN;
+ void __iomem *usb2_base = channel->base;
+
+ for (unsigned int i = 0; i < NUM_OF_PHYS; i++)
+ bitmask |= channel->rphys[i].int_enable_bits;
+
+ val = readl(usb2_base + USB2_INT_ENABLE);
+ *masked_irqs_bits = val & bitmask;
+ val &= ~bitmask;
+ writel(val, usb2_base + USB2_INT_ENABLE);
+
+ /*
+ * Don't report channel->phy_data->obint_enable_bits IRQs. These are
+ * unmasked anyway in rcar_gen3_init_otg_phase1().
+ */
+ val = readl(usb2_base + USB2_OBINTEN);
+ val &= ~channel->phy_data->obint_enable_bits;
+ writel(val, usb2_base + USB2_OBINTEN);
+}
+
+static void rcar_gen3_phy_usb2_irqs_unmask(struct rcar_gen3_chan *channel,
+ u32 irqs_bits)
+{
+ u32 val, bitmask = USB2_INT_ENABLE_UCOM_INTEN;
+ void __iomem *usb2_base = channel->base;
+
+ for (unsigned int i = 0; i < NUM_OF_PHYS; i++)
+ bitmask |= channel->rphys[i].int_enable_bits;
+
+ val = readl(usb2_base + USB2_INT_ENABLE);
+ val &= ~bitmask;
+ val |= irqs_bits;
+ writel(val, usb2_base + USB2_INT_ENABLE);
+}
+
static int rcar_gen3_phy_usb2_init(struct phy *p)
{
struct rcar_gen3_phy *rphy = phy_get_drvdata(p);
struct rcar_gen3_chan *channel = rphy->ch;
void __iomem *usb2_base = channel->base;
+ int retries = NUM_OF_PHYS;
+ unsigned long flags;
u32 val;
+ int ret;
+
+ spin_lock_irqsave(&channel->lock, flags);
- guard(spinlock_irqsave)(&channel->lock);
+ while (retries-- && channel->otg_initializing) {
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ ret = wait_event_timeout(channel->otg_init_done, !channel->otg_initializing,
+ USB2_OTG_INIT_TIMEOUT);
+ ret = ret ? 0 : -ETIMEDOUT;
+ if (ret && !retries)
+ return ret;
+
+ spin_lock_irqsave(&channel->lock, flags);
+ }
+
+ /* If another thread started a new initialization just return -EBUSY. */
+ if (channel->otg_initializing) {
+ ret = -EBUSY;
+ goto unlock;
+ } else {
+ ret = 0;
+ }
/* Initialize USB2 part */
val = readl(usb2_base + USB2_INT_ENABLE);
@@ -548,8 +670,23 @@ static int rcar_gen3_phy_usb2_init(struc
}
/* Initialize otg part (only if we initialize a PHY with IRQs). */
- if (rphy->int_enable_bits)
- rcar_gen3_init_otg(channel);
+ if (rphy->int_enable_bits && channel->is_otg_channel &&
+ !rcar_gen3_is_any_otg_rphy_initialized(channel)) {
+ u32 masked_irq_bits = 0;
+
+ rcar_gen3_init_otg_phase0(channel);
+ rcar_gen3_phy_usb2_irqs_mask_all(channel, &masked_irq_bits);
+ channel->otg_initializing = true;
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ fsleep(20000);
+
+ spin_lock_irqsave(&channel->lock, flags);
+ rcar_gen3_phy_usb2_irqs_unmask(channel, masked_irq_bits);
+ rcar_gen3_init_otg_phase1(channel);
+ channel->otg_initializing = false;
+ wake_up_all(&channel->otg_init_done);
+ }
if (channel->phy_data->vblvl_ctrl) {
/* SIDDQ mode release */
@@ -568,7 +705,10 @@ static int rcar_gen3_phy_usb2_init(struc
rphy->initialized = true;
- return 0;
+unlock:
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ return ret;
}
static int rcar_gen3_phy_usb2_exit(struct phy *p)
@@ -576,9 +716,32 @@ static int rcar_gen3_phy_usb2_exit(struc
struct rcar_gen3_phy *rphy = phy_get_drvdata(p);
struct rcar_gen3_chan *channel = rphy->ch;
void __iomem *usb2_base = channel->base;
+ int retries = NUM_OF_PHYS;
+ unsigned long flags;
u32 val;
+ int ret;
+
+ spin_lock_irqsave(&channel->lock, flags);
+
+ while (retries-- && channel->otg_initializing) {
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ ret = wait_event_timeout(channel->otg_init_done, !channel->otg_initializing,
+ USB2_OTG_INIT_TIMEOUT);
+ ret = ret ? 0 : -ETIMEDOUT;
+ if (ret && !retries)
+ return ret;
+
+ spin_lock_irqsave(&channel->lock, flags);
+ }
- guard(spinlock_irqsave)(&channel->lock);
+ /* If another thread started a new initialization just return -EBUSY. */
+ if (channel->otg_initializing) {
+ ret = -EBUSY;
+ goto unlock;
+ } else {
+ ret = 0;
+ }
rphy->initialized = false;
@@ -588,7 +751,9 @@ static int rcar_gen3_phy_usb2_exit(struc
val &= ~USB2_INT_ENABLE_UCOM_INTEN;
writel(val, usb2_base + USB2_INT_ENABLE);
- return 0;
+unlock:
+ spin_unlock_irqrestore(&channel->lock, flags);
+ return ret;
}
static int rcar_gen3_phy_usb2_power_on(struct phy *p)
@@ -596,8 +761,10 @@ static int rcar_gen3_phy_usb2_power_on(s
struct rcar_gen3_phy *rphy = phy_get_drvdata(p);
struct rcar_gen3_chan *channel = rphy->ch;
void __iomem *usb2_base = channel->base;
+ int retries = NUM_OF_PHYS;
+ unsigned long flags;
u32 val;
- int ret = 0;
+ int ret;
if (channel->vbus && !channel->otg_internal_reg) {
ret = regulator_enable(channel->vbus);
@@ -605,7 +772,27 @@ static int rcar_gen3_phy_usb2_power_on(s
return ret;
}
- guard(spinlock_irqsave)(&channel->lock);
+ spin_lock_irqsave(&channel->lock, flags);
+
+ while (retries-- && channel->otg_initializing) {
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ ret = wait_event_timeout(channel->otg_init_done, !channel->otg_initializing,
+ USB2_OTG_INIT_TIMEOUT);
+ ret = ret ? 0 : -ETIMEDOUT;
+ if (ret && !retries)
+ goto disable_regulator;
+
+ spin_lock_irqsave(&channel->lock, flags);
+ }
+
+ /* If another thread started a new initialization just return -EBUSY. */
+ if (channel->otg_initializing) {
+ ret = -EBUSY;
+ goto unlock;
+ } else {
+ ret = 0;
+ }
if (!rcar_gen3_are_all_rphys_power_off(channel))
goto out;
@@ -620,27 +807,59 @@ out:
/* The powered flag should be set for any other phys anyway */
rphy->powered = true;
- return 0;
+unlock:
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+disable_regulator:
+ if (ret && channel->vbus && !channel->otg_internal_reg)
+ regulator_disable(channel->vbus);
+
+ return ret;
}
static int rcar_gen3_phy_usb2_power_off(struct phy *p)
{
struct rcar_gen3_phy *rphy = phy_get_drvdata(p);
struct rcar_gen3_chan *channel = rphy->ch;
- int ret = 0;
+ int retries = NUM_OF_PHYS;
+ unsigned long flags;
+ int ret;
- scoped_guard(spinlock_irqsave, &channel->lock) {
- rphy->powered = false;
+ spin_lock_irqsave(&channel->lock, flags);
- if (rcar_gen3_are_all_rphys_power_off(channel)) {
- u32 val = readl(channel->base + USB2_USBCTR);
+ while (retries-- && channel->otg_initializing) {
+ spin_unlock_irqrestore(&channel->lock, flags);
- val |= USB2_USBCTR_PLL_RST;
- writel(val, channel->base + USB2_USBCTR);
- }
+ ret = wait_event_timeout(channel->otg_init_done, !channel->otg_initializing,
+ USB2_OTG_INIT_TIMEOUT);
+ ret = ret ? 0 : -ETIMEDOUT;
+ if (ret && !retries)
+ return ret;
+
+ spin_lock_irqsave(&channel->lock, flags);
+ }
+
+ /* If another thread started a new initialization just return -EBUSY. */
+ if (channel->otg_initializing) {
+ ret = -EBUSY;
+ goto unlock;
+ } else {
+ ret = 0;
+ }
+
+ rphy->powered = false;
+
+ if (rcar_gen3_are_all_rphys_power_off(channel)) {
+ u32 val = readl(channel->base + USB2_USBCTR);
+
+ val |= USB2_USBCTR_PLL_RST;
+ writel(val, channel->base + USB2_USBCTR);
}
- if (channel->vbus && !channel->otg_internal_reg)
+unlock:
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ if (!ret && channel->vbus && !channel->otg_internal_reg)
ret = regulator_disable(channel->vbus);
return ret;
@@ -1018,6 +1237,7 @@ static int rcar_gen3_phy_usb2_probe(stru
return ret;
spin_lock_init(&channel->lock);
+ init_waitqueue_head(&channel->otg_init_done);
for (i = 0; i < NUM_OF_PHYS; i++) {
channel->rphys[i].phy = devm_phy_create(dev, NULL,
channel->phy_data->phy_usb2_ops);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 195/398] wifi: rtw88: TX QOS Null data the same way as Null data
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (192 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 194/398] ACPI: processor: Update cpuidle driver check in __acpi_processor_start() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 196/398] Input: xpad - add support for Victrix Pro BFG Controller Greg Kroah-Hartman
` (208 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bitterblue Smith, Ping-Ke Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bitterblue Smith <rtl8821cerfe2@gmail.com>
[ Upstream commit 737e980e12983bb7420a2c00b981a1e607079a84 ]
When filling out the TX descriptor, Null data frames are treated like
management frames, but QOS Null data frames are treated like normal
data frames. Somehow this causes a problem for the firmware.
When connected to a network in the 2.4 GHz band, wpa_supplicant (or
NetworkManager?) triggers a scan every five minutes. During these scans
mac80211 transmits many QOS Null frames in quick succession. Because
these frames are marked with IEEE80211_TX_CTL_REQ_TX_STATUS, rtw88
asks the firmware to report the TX ACK status for each of these frames.
Sometimes the firmware can't process the TX status requests quickly
enough, they add up, it only processes some of them, and then marks
every subsequent TX status report with the wrong number.
The symptom is that after a while the warning "failed to get tx report
from firmware" appears every five minutes.
This problem apparently happens only with the older RTL8723D, RTL8821A,
RTL8812A, and probably RTL8703B chips.
Treat QOS Null data frames the same way as Null data frames. This seems
to avoid the problem.
Tested with RTL8821AU, RTL8723DU, RTL8811CU, and RTL8812BU.
Signed-off-by: Bitterblue Smith <rtl8821cerfe2@gmail.com>
Acked-by: Ping-Ke Shih <pkshih@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/2b53fb0d-b1ed-47b6-8caa-2bb9ae2acb80@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw88/tx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/realtek/rtw88/tx.c b/drivers/net/wireless/realtek/rtw88/tx.c
index 611dade1b1eb9..e73c06b268cfa 100644
--- a/drivers/net/wireless/realtek/rtw88/tx.c
+++ b/drivers/net/wireless/realtek/rtw88/tx.c
@@ -426,7 +426,7 @@ void rtw_tx_pkt_info_update(struct rtw_dev *rtwdev,
pkt_info->mac_id = rtwvif->mac_id;
}
- if (ieee80211_is_mgmt(fc) || ieee80211_is_nullfunc(fc))
+ if (ieee80211_is_mgmt(fc) || ieee80211_is_any_nullfunc(fc))
rtw_tx_mgmt_pkt_info_update(rtwdev, pkt_info, sta, skb);
else if (ieee80211_is_data(fc))
rtw_tx_data_pkt_info_update(rtwdev, pkt_info, sta, skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 249/438] posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (247 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 248/438] phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 250/438] rds: ib: use rds_conn_drop() on protocol version mismatch Greg Kroah-Hartman
` (200 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kijo Park, Thomas Gleixner,
Frederic Weisbecker
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Gleixner <tglx@kernel.org>
commit c21eaa72f02fc6e85621cbe09d303d8fb8bd39cd upstream.
Kijo analyzed another race in the POSIX CPU timer code:
Commit bf635681c906 converted cpu_timer::firing from a tristate value to a
boolean. This lost the distinction between "not owned by the firing list"
and "still owned, but delivery was canceled". The resulting race is:
expiry handler timer_settime() timer_delete()
-------------- --------------- --------------
collect timer onto
private firing list
firing = true
observes firing = true
firing = false
return TIMER_RETRY
wait for handler
observes firing = false
finish deletion
unhash and free timer
resume list traversal
read freed elist.next
-> UAF
The firing bit is clearly the wrong indicator since that commit.
Check whether the timer is queued on the expiry list or not instead. If it
is queued clear the firing bit to prevent signal delivery as before and
return TIMER_RETRY so the caller unlocks the timer which allows the expiry
code to make progress and remove it from the list.
Fixes: bf635681c906 ("posix-cpu-timers: Cleanup the firing logic")
Reported-by: Kijo Park <red993688@gmail.com>
Debugged-by: Kijo Park <red993688@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Kijo Park <red993688@gmail.com>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/time/posix-cpu-timers.c | 40 ++++++++++++++++++++++------------------
1 file changed, 22 insertions(+), 18 deletions(-)
--- a/kernel/time/posix-cpu-timers.c
+++ b/kernel/time/posix-cpu-timers.c
@@ -408,6 +408,7 @@ static int posix_cpu_timer_create(struct
new_timer->kclock = &clock_posix_cpu;
timerqueue_init(&new_timer->it.cpu.node);
+ INIT_LIST_HEAD(&new_timer->it.cpu.elist);
new_timer->it.cpu.pid = get_pid(pid);
rcu_read_unlock();
return 0;
@@ -566,6 +567,24 @@ static struct task_struct *timer_lock_si
}
/*
+ * If the timer is queued on the expiry list, then it cannot be dequeued because
+ * the firing list is not protected by sighand->lock. The delivery path is
+ * waiting for the timer lock. So go back, unlock and retry.
+ */
+static bool posix_cpu_timer_on_expiry_list(struct k_itimer *timer)
+{
+ if (list_empty(&timer->it.cpu.elist))
+ return false;
+
+ /*
+ * Prevent signal delivery as there is no point in delivering a signal
+ * which is made obsolete right away.
+ */
+ timer->it.cpu.firing = false;
+ return true;
+}
+
+/*
* Clean up a CPU-clock timer that is about to be destroyed.
* This is called from timer deletion with the timer already locked.
* If we return TIMER_RETRY, it's necessary to release the timer's lock
@@ -580,18 +599,10 @@ static int posix_cpu_timer_del(struct k_
p = timer_lock_sighand(timer, &flags);
if (likely(p)) {
- if (timer->it.cpu.firing) {
- /*
- * Prevent signal delivery. The timer cannot be dequeued
- * because it is on the firing list which is not protected
- * by sighand->lock. The delivery path is waiting for
- * the timer lock. So go back, unlock and retry.
- */
- timer->it.cpu.firing = false;
+ if (posix_cpu_timer_on_expiry_list(timer))
ret = TIMER_RETRY;
- } else {
+ else
disarm_timer(timer, p);
- }
unlock_task_sighand(p, &flags);
}
@@ -731,14 +742,7 @@ static int posix_cpu_timer_set(struct k_
/* Retrieve the current expiry time before disarming the timer */
old_expires = cpu_timer_getexpires(ctmr);
- if (unlikely(timer->it.cpu.firing)) {
- /*
- * Prevent signal delivery. The timer cannot be dequeued
- * because it is on the firing list which is not protected
- * by sighand->lock. The delivery path is waiting for
- * the timer lock. So go back, unlock and retry.
- */
- timer->it.cpu.firing = false;
+ if (posix_cpu_timer_on_expiry_list(timer)) {
ret = TIMER_RETRY;
} else {
cpu_timer_dequeue(ctmr);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 196/398] Input: xpad - add support for Victrix Pro BFG Controller
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (193 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 195/398] wifi: rtw88: TX QOS Null data the same way as Null data Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 197/398] Input: xpad - add support for Azeron devices Greg Kroah-Hartman
` (207 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Erich Sartison, Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Erich Sartison <byt.es@mailbox.org>
commit 971fa7ea8621e123feb9c8d7dc61be1c656bd945 upstream.
The controller doesn't currently work via USB-cable.
Signed-off-by: Erich Sartison <byt.es@mailbox.org>
Link: https://patch.msgid.link/20260903103137.630170-1-byt.es@mailbox.org
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -261,6 +261,7 @@ static const struct xpad_device {
{ 0x0e6f, 0x0213, "Afterglow Gamepad for Xbox 360", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x021f, "Rock Candy Gamepad for Xbox 360", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x0246, "Rock Candy Gamepad for Xbox One 2015", 0, XTYPE_XBOXONE },
+ { 0x0e6f, 0x024c, "PDP Victrix Pro BFG Wired Controller for Xbox", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a0, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a1, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x02a2, "PDP Wired Controller for Xbox One - Crimson Red", 0, XTYPE_XBOXONE },
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 250/438] rds: ib: use rds_conn_drop() on protocol version mismatch
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (248 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 249/438] posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 251/438] signal: Prevent exec() race Greg Kroah-Hartman
` (199 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, TencentOS Corvus AI,
Allison Henderson, Aohan Mei, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aohan Mei <henrymei@tencent.com>
commit f97d8c7bab7843631206a114986c9059da03efeb upstream.
rds_ib_cm_connect_complete() runs from the RDMA-CM event handler with
conn->c_cm_lock held. When the peer negotiates a protocol version
older than RDS_PROTOCOL_COMPAT_VERSION, the handler calls
rds_conn_destroy(), which is only safe in the rmmod path: it
synchronously tears the connection down and flush_work()es the
shutdown work cp_down_w.
That shutdown work (rds_conn_shutdown()) needs cp_cm_lock, which is
the very lock the event handler still holds, so the flush never
completes: the two workers wait on each other and the RDS connection
workqueues stall for good.
All other RDMA-CM failure paths (REJECTED, CONNECT_ERROR,
DISCONNECTED) use rds_conn_drop(), which marks the connection
RDS_CONN_ERROR and schedules the shutdown work asynchronously. Use
it here as well.
Fixes: f147dd9ecabf ("RDS/IB: Disallow connections less than RDS 3.1")
Reported-by: TencentOS Corvus AI <corvus@tencent.com>
Cc: stable@vger.kernel.org
Reviewed-by: Allison Henderson <achender@kernel.org>
Signed-off-by: Aohan Mei <henrymei@tencent.com>
Link: https://patch.msgid.link/20260911073436.3542080-1-ljp1205831794@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/rds/ib_cm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/rds/ib_cm.c
+++ b/net/rds/ib_cm.c
@@ -115,7 +115,7 @@ void rds_ib_cm_connect_complete(struct r
&conn->c_laddr, &conn->c_faddr,
RDS_PROTOCOL_MAJOR(conn->c_version),
RDS_PROTOCOL_MINOR(conn->c_version));
- rds_conn_destroy(conn);
+ rds_conn_drop(conn);
return;
}
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 197/398] Input: xpad - add support for Azeron devices
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (194 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 196/398] Input: xpad - add support for Victrix Pro BFG Controller Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 198/398] Input: xpad - fix PDP Marvel Xbox 360 controller Greg Kroah-Hartman
` (206 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Roberts Kursitis, Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Roberts Kursitis <roberts.kursitis@azeron.eu>
commit cba76c0f47af1a389d718c5bb69e75cbd67bba98 upstream.
Azeron controllers (Cyro, Cyborg, Classic/Compact, Cyro Lefty,
Cyborg II and Keyzen) present a standard Xbox 360 controller
interface, so they work with the existing xpad driver once their
USB IDs are added.
The 0x16d0 vendor ID is a shared block, but this is safe because
xpad only binds interfaces that match the Xbox 360 signature.
Tested with an Azeron Keyzen.
Signed-off-by: Roberts Kursitis <roberts.kursitis@azeron.eu>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260906143040.162418-1-roberts.kursitis@azeron.eu
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -327,6 +327,12 @@ static const struct xpad_device {
{ 0x1689, 0xfd00, "Razer Onza Tournament Edition", 0, XTYPE_XBOX360 },
{ 0x1689, 0xfd01, "Razer Onza Classic Edition", 0, XTYPE_XBOX360 },
{ 0x1689, 0xfe00, "Razer Sabertooth", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1103, "Azeron Cyro", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x113c, "Azeron Cyborg", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1192, "Azeron Classic/Compact", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x1212, "Azeron Cyro Lefty", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x12f7, "Azeron Cyborg II", 0, XTYPE_XBOX360 },
+ { 0x16d0, 0x13ea, "Azeron Keyzen", 0, XTYPE_XBOX360 },
{ 0x17ef, 0x6182, "Lenovo Legion Controller for Windows", 0, XTYPE_XBOX360 },
{ 0x1949, 0x041a, "Amazon Game Controller", 0, XTYPE_XBOX360 },
{ 0x1a86, 0xe310, "Legion Go S", 0, XTYPE_XBOX360 },
@@ -569,6 +575,7 @@ static const struct usb_device_id xpad_t
XPAD_XBOX360_VENDOR(0x15e4), /* Numark Xbox 360 controllers */
XPAD_XBOX360_VENDOR(0x162e), /* Joytech Xbox 360 controllers */
XPAD_XBOX360_VENDOR(0x1689), /* Razer Onza */
+ XPAD_XBOX360_VENDOR(0x16d0), /* Azeron controllers */
XPAD_XBOX360_VENDOR(0x17ef), /* Lenovo */
XPAD_XBOX360_VENDOR(0x1949), /* Amazon controllers */
XPAD_XBOX360_VENDOR(0x1a86), /* Nanjing Qinheng Microelectronics (WCH) */
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 251/438] signal: Prevent exec() race
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (249 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 250/438] rds: ib: use rds_conn_drop() on protocol version mismatch Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 252/438] rust: net: phy: fix off-by-one bit positions in device status accessors Greg Kroah-Hartman
` (198 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hyunwoo Kim, Eric W. Biederman,
Thomas Gleixner, Kijo Park, Oleg Nesterov, Frederic Weisbecker
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Gleixner <tglx@kernel.org>
commit d2710c8d938ae6a825a6463158e6e6f31eac792a upstream.
Hyunwoo debugged the following KASAN UAF splat:
BUG: KASAN: slab-use-after-free in __send_signal_locked+0xb27/0xba0
Write of size 8 at addr ffff888007ed80c8 by task poc/79
...
Call Trace:
__send_signal_locked+0xb27/0xba0
do_send_sig_info+0xa7/0x160
do_send_specific+0x76/0xa0
__x64_sys_tgkill+0x193/0x270
...
Allocated by task 80:
do_timer_create+0x1a4/0x1030
__x64_sys_timer_create+0x145/0x190
...
Freed by task 12:
kmem_cache_free_bulk+0x1f8/0x4a0
kvfree_rcu_bulk+0x14f/0x1c0
kfree_rcu_work+0x128/0x1a0
...
Last potentially related work creation:
kvfree_call_rcu+0x39/0x390
__flush_itimer_signals+0x211/0x320
flush_itimer_signals+0x47/0x90
begin_new_exec+0xa6b/0x28c0
It turned out that this happens with a non-leader exec() as Hyunwoo
explained:
de_thread() calls exchange_tids() before release_task(leader), so the
struct pid held by a SIGEV_THREAD_ID timer created against the leader's tid
now points to the thread which called execve(). pid_task() returns that
thread and lock_task_sighand() on it succeeds.
If the timer signal is blocked, its sigqueue stays queued on the leader's
task::pending. The next expiry of that timer can then run while
release_task() flushes the queue.
posixtimer_send_sigqueue() checks whether the sigqueue is already queued
with a plain list_empty(), which only reads list_head::next.
list_del_init() is not atomic and INIT_LIST_HEAD() stores list_head::next
before list_head::prev, so the check can pass in between. list_add_tail()
queues the entry on the task::pending of the live thread, and the
list_head::prev store from the flush then overwrites the list_head::prev
link that list_add_tail() has just set.
__flush_itimer_signals() does not undo that either. With list_head::prev
pointing at the entry itself, its list_del_init() only stores the same
values again, so the entry is not removed from the list. It is still there
after the last reference is dropped and the timer is freed by RCU, and the
list_add_tail() of a later tgkill() follows that list_head::prev into the
freed timer.
This problem surfaced with the recent commit which moved the sigqueue flush
out of the sighand lock held region.
Hyonwoo proposed to fix this by using list_del_init_careful(), but that
just papers over the problem. After some disucssions and various attempts
to solve it, Eric pointed out that there is no reason to flush
task::pending late in release_task() and it should be done in
exit_signals() already.
As nothing can collect and deliver signals which are queued in a dying
task's pending queue, there is no reason to delay it further.
But it has to be ensured that no signals can be queued into it after that
point. exit_signals() sets PF_EXITING in task::flags, which can be used as
an indicator for this.
Cure it by:
- Preventing signal queueing for task private signals (PIDTYPE_PID) when
the task has PF_EXITING set in __send_signal_locked() and in
posixtimer_send_sigqueue().
- Protecting the unlocked setting of PF_EXITING in exit_signals() for the
task group empty and the group exit case with sighand lock
- Flushing task::pending signals right there.
Optimize that by moving the whole pending list to an on-stack list head
under sighand lock and free the signals without the lock held.
There has been quite some discussion about the lockless flush and the
non-leader exec case on weakly ordered systems. The problem is that a third
party which tries to send a posix timer signal relies on the PID lookup to
find the target task and that lookup might result in the new leader when
the signal was originaly directed to the old leader. In case that the
signal was queued on the old leader then the lockless flush raised a
concern over the following situation:
old_leader new_leader third party
A: flush_list() // list_del_init() stores to sigqueue
LOCK (tasklist)
old_leader->exit_state = EXIT_ZOMBIE;
B: UNLOCK (tasklist)
C: LOCK (tasklist)
if (old_leader->exit_state)
transfer_tids()
D: store PID
posix_timer_send_sigqueue()
// Observes #D so t = new_leader
E: t = get_target()
F: LOCK (sighand)
G: if (list_empty(sigqueue))
list_add(sigqueue)
The concern was that the third party might observe #D but not observe #A
and therefore would proceed to #G while the list_del() stores (#A) in
flush_list() are not visible yet, which could result in list corruption.
That would be possible if looking at it solely from a RELEASE+ACQUIRE
ordering point of view, but B-C is a UNLOCK+LOCK hand-over, which is not
the same as RELEASE+ACQUIRE:
RELEASE+ACQUIRE: RCpc, only the CPUs involved agree on the ordering
UNLOCK+LOCK: RCtso, the hand-over is store-ordering
As B-C is UNLOCK+LOCK, which is RCtso and that does impose store order,
A stores must happen before the D store.
Combine with E-F, which has a data dependency from the LOAD to the LOCK and
thereby constraints later LOADs, those sigqueue loads in G that come after
F must in fact observe the A stores.
Fixes: fb3bbcfe344e ("exit: change the release_task() paths to call flush_sigqueue() lockless")
Reported-by: Hyunwoo Kim <imv4bel@gmail.com>
Debugged-by: Hyunwoo Kim <imv4bel@gmail.com>
Suggested-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Kijo Park <red993688@gmail.com>
Reviewed-by: Oleg Nesterov <oleg@redhat.com>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260911090541.572536604@kernel.org
Closes: https://patch.msgid.link/aok1rdkBgZsynHZB@v4bel
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/exit.c | 11 ++---
kernel/signal.c | 117 +++++++++++++++++++++++++++++++++++++++++---------------
2 files changed, 92 insertions(+), 36 deletions(-)
--- a/kernel/exit.c
+++ b/kernel/exit.c
@@ -303,12 +303,13 @@ repeat:
free_pids(post.pids);
release_thread(p);
/*
- * This task was already removed from the process/thread/pid lists
- * and lock_task_sighand(p) can't succeed. Nobody else can touch
- * ->pending or, if group dead, signal->shared_pending. We can call
- * flush_sigqueue() lockless.
+ * This task was already removed from the process/thread/pid lists and
+ * lock_task_sighand(p) can't succeed. If it's the group leader then
+ * flush tsk->signal->shared_pending. tsk->pending has been flushed
+ * already in exit_signals(). Nothing else can touch
+ * signal->shared_pending anymore, so flush_sigqueue() can be invoked
+ * lockless.
*/
- flush_sigqueue(&p->pending);
if (thread_group_leader(p))
flush_sigqueue(&p->signal->shared_pending);
--- a/kernel/signal.c
+++ b/kernel/signal.c
@@ -475,18 +475,42 @@ static void __sigqueue_free(struct sigqu
kmem_cache_free(sigqueue_cachep, q);
}
-void flush_sigqueue(struct sigpending *queue)
+/*
+ * flush_sigqueue_list() can only be invoked without holding sighand::siglock in
+ * the following cases:
+ *
+ * 1) When flushing task::pending _after_ setting task::flags PF_EXITING
+ *
+ * All functions which try to send a signal to @task will observe PF_EXITING
+ * and drop the signal.
+ *
+ * 2) When flushing task::signal::shared_pending _after_ the last task in a
+ * thread group was unhashed and task::sighand is NULL.
+ *
+ * Nothing can queue a signal anymore because sighand is NULL.
+ */
+static void flush_sigqueue_list(struct list_head *head)
{
- struct sigqueue *q;
+ struct sigqueue *q, *tmp;
- sigemptyset(&queue->signal);
- while (!list_empty(&queue->list)) {
- q = list_entry(queue->list.next, struct sigqueue , list);
+ list_for_each_entry_safe(q, tmp, head, list) {
list_del_init(&q->list);
__sigqueue_free(q);
}
}
+void flush_sigqueue(struct sigpending *queue)
+{
+ sigemptyset(&queue->signal);
+ flush_sigqueue_list(&queue->list);
+}
+
+static void sigqueue_dequeue_pending(struct sigpending *queue, struct list_head *head)
+{
+ sigemptyset(&queue->signal);
+ list_splice_init(&queue->list, head);
+}
+
/*
* Flush all pending signals for this kthread.
*/
@@ -1037,6 +1061,21 @@ static inline bool legacy_queue(struct s
return (sig < SIGRTMIN) && sigismember(&signals->signal, sig);
}
+/*
+ * When PF_EXITING is set the task is on the way out and has t::pending
+ * flushed already. Prevent queueing of PIDTYPE_PID signals as they would
+ * be leaked.
+ */
+static inline bool task_can_queue_signal(struct task_struct *t, enum pid_type type)
+{
+ lockdep_assert_held(&t->sighand->siglock);
+
+ if (!(t->flags & PF_EXITING))
+ return true;
+
+ return type != PIDTYPE_PID;
+}
+
static int __send_signal_locked(int sig, struct kernel_siginfo *info,
struct task_struct *t, enum pid_type type, bool force)
{
@@ -1048,6 +1087,10 @@ static int __send_signal_locked(int sig,
lockdep_assert_held(&t->sighand->siglock);
result = TRACE_SIGNAL_IGNORED;
+
+ if (!task_can_queue_signal(t, type))
+ goto ret;
+
if (!prepare_signal(sig, t, force))
goto ret;
@@ -1991,11 +2034,25 @@ static inline struct task_struct *posixt
struct task_struct *t = pid_task(tmr->it_pid, tmr->it_pid_type);
if (t && tmr->it_pid_type != PIDTYPE_PID &&
- same_thread_group(t, current) && !current->exit_state)
+ same_thread_group(t, current) && !(current->flags & PF_EXITING))
t = current;
return t;
}
+/*
+ * Find the target task for the POSIX timer signal and prevent that a
+ * PIDTYPE_PID signal is queued on a task which has PF_EXITING set.
+ */
+static inline struct task_struct *posixtimer_get_unignore_target(struct k_itimer *tmr)
+{
+ struct task_struct *t = posixtimer_get_target(tmr);
+
+ if (t && task_can_queue_signal(t, tmr->it_pid_type))
+ return t;
+
+ return NULL;
+}
+
void posixtimer_send_sigqueue(struct k_itimer *tmr)
{
struct sigqueue *q = &tmr->sigq;
@@ -2013,6 +2070,9 @@ void posixtimer_send_sigqueue(struct k_i
if (!likely(lock_task_sighand(t, &flags)))
return;
+ if (!task_can_queue_signal(t, tmr->it_pid_type))
+ goto unlock;
+
/*
* Update @tmr::sigqueue_seq for posix timer signals with sighand
* locked to prevent a race against dequeue_signal().
@@ -2104,6 +2164,7 @@ void posixtimer_send_sigqueue(struct k_i
result = TRACE_SIGNAL_DELIVERED;
out:
trace_signal_generate(sig, &q->info, t, tmr->it_pid_type != PIDTYPE_PID, result);
+unlock:
unlock_task_sighand(t, &flags);
}
@@ -2159,7 +2220,7 @@ static void posixtimer_sig_unignore(stru
* has exited by now, drop the reference count.
*/
guard(rcu)();
- target = posixtimer_get_target(tmr);
+ target = posixtimer_get_unignore_target(tmr);
if (target)
posixtimer_queue_sigqueue(&tmr->sigq, target, tmr->it_pid_type);
else
@@ -3143,42 +3204,36 @@ static void retarget_shared_pending(stru
void exit_signals(struct task_struct *tsk)
{
+ LIST_HEAD(sigq_list);
int group_stop = 0;
- sigset_t unblocked;
/*
* @tsk is about to have PF_EXITING set - lock out users which
- * expect stable threadgroup.
+ * expect a stable threadgroup.
*/
cgroup_threadgroup_change_begin(tsk);
- if (thread_group_empty(tsk) || (tsk->signal->flags & SIGNAL_GROUP_EXIT)) {
+ scoped_guard(spinlock_irq, &tsk->sighand->siglock) {
tsk->flags |= PF_EXITING;
- cgroup_threadgroup_change_end(tsk);
- return;
- }
- spin_lock_irq(&tsk->sighand->siglock);
- /*
- * From now this task is not visible for group-wide signals,
- * see wants_signal(), do_signal_stop().
- */
- tsk->flags |= PF_EXITING;
+ sigqueue_dequeue_pending(&tsk->pending, &sigq_list);
- cgroup_threadgroup_change_end(tsk);
+ if (task_sigpending(tsk) && !thread_group_empty(tsk) &&
+ !(tsk->signal->flags & SIGNAL_GROUP_EXIT)) {
+ sigset_t unblocked = tsk->blocked;
+
+ signotset(&unblocked);
+ retarget_shared_pending(tsk, &unblocked);
+
+ if (unlikely(tsk->jobctl & JOBCTL_STOP_PENDING) &&
+ task_participate_group_stop(tsk))
+ group_stop = CLD_STOPPED;
+ }
+ }
- if (!task_sigpending(tsk))
- goto out;
+ cgroup_threadgroup_change_end(tsk);
- unblocked = tsk->blocked;
- signotset(&unblocked);
- retarget_shared_pending(tsk, &unblocked);
-
- if (unlikely(tsk->jobctl & JOBCTL_STOP_PENDING) &&
- task_participate_group_stop(tsk))
- group_stop = CLD_STOPPED;
-out:
- spin_unlock_irq(&tsk->sighand->siglock);
+ flush_sigqueue_list(&sigq_list);
/*
* If group stop has completed, deliver the notification. This
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 198/398] Input: xpad - fix PDP Marvel Xbox 360 controller
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (195 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 197/398] Input: xpad - add support for Azeron devices Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 199/398] ALSA: core: Fix potential UAF after asynchronous card release Greg Kroah-Hartman
` (205 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jeremy Nyberg, Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeremy Nyberg <slickstretch3.0@gmail.com>
commit 7bc369cb3d3f3656eb77285628ee264264d28ad4 upstream.
The PDP Marvel Xbox 360 controller with USB ID 0e6f:0147 is
incorrectly classified as an Xbox One controller.
With the current XTYPE_XBOXONE classification, the controller is
detected but produces no input, while its four player LEDs continue
blinking indefinitely.
Classify USB ID 0e6f:0147 as an Xbox 360 controller instead.
Tested on a PDP Marvel Xbox 360 controller with USB ID 0e6f:0147.
All inputs register correctly and the player LED indicates the
current player.
Fixes: c225370e01b8 ("Input: xpad - sync supported devices with 360Controller")
Cc: stable@vger.kernel.org
Signed-off-by: Jeremy Nyberg <SlickStretch3.0@gmail.com>
Link: https://patch.msgid.link/20260910071627.236014-1-SlickStretch3.0@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/joystick/xpad.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/input/joystick/xpad.c
+++ b/drivers/input/joystick/xpad.c
@@ -249,7 +249,7 @@ static const struct xpad_device {
{ 0x0e6f, 0x0139, "Afterglow Prismatic Wired Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x013a, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x0146, "Rock Candy Wired Controller for Xbox One", 0, XTYPE_XBOXONE },
- { 0x0e6f, 0x0147, "PDP Marvel Xbox One Controller", 0, XTYPE_XBOXONE },
+ { 0x0e6f, 0x0147, "PDP Marvel Xbox 360 Controller", 0, XTYPE_XBOX360 },
{ 0x0e6f, 0x015c, "PDP Xbox One Arcade Stick", MAP_TRIGGERS_TO_BUTTONS, XTYPE_XBOXONE },
{ 0x0e6f, 0x015d, "PDP Mirror's Edge Official Wired Controller for Xbox One", 0, XTYPE_XBOXONE },
{ 0x0e6f, 0x0161, "PDP Xbox One Controller", 0, XTYPE_XBOXONE },
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 252/438] rust: net: phy: fix off-by-one bit positions in device status accessors
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (250 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 251/438] signal: Prevent exec() race Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 253/438] Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware" Greg Kroah-Hartman
` (197 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chunfeng Song, FUJITA Tomonori,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chunfeng Song <springbreeze@stu.pku.edu.cn>
commit 6fb0a9d9071f1ff0cc5cfc0782302d9c90d642cb upstream.
The hand-written bitfield offsets in is_link_up(), is_autoneg_enabled()
and is_autoneg_completed() were correct when the abstraction was
merged: at that time autoneg, link, and autoneg_complete were at bits
13, 14, and 15 of struct phy_device's first bitfield unit. Commit
2796ff1e3dca ("net: phy: add flag is_genphy_driven to struct phy_device")
later inserted is_genphy_driven just before autoneg, shifting the three
fields up by one, so the accessors now read:
is_link_up() reads bit 14 = autoneg
is_autoneg_enabled() reads bit 13 = is_genphy_driven
is_autoneg_completed() reads bit 15 = link
The official ax88796b Rust driver uses all three accessors in its
read_status() implementation, so it inherits the bug.
phy_attach_direct() sets is_genphy_driven only when it falls back to
the generic driver, and ax88796b has a real driver, so
is_genphy_driven stays 0. The broken is_autoneg_enabled() therefore
reads bit 13 as 0, compares it against AUTONEG_ENABLE (1), and always
returns false, so read_status() never reaches the
resolve_aneg_linkmode() call.
The ordinary bindgen accessors take &self. Calling them through
(*phydev).link() would create a shared reference to the complete
bindings::phy_device, which is not appropriate for an object wrapped in
Opaque.
Use the bindgen-generated raw accessors (link_raw(), autoneg_raw(),
and autoneg_complete_raw()) instead. They retain the bit positions and
endianness handling generated from the C layout without creating a Rust
reference to the complete phy_device. Drop the hand-written numbers
together with the TODO comment that marked them as a stopgap.
The raw accessors are only emitted by bindgen 0.71 and later, and were
added at the Rust-for-Linux project's request, so this fix can only be
backported to stable branches whose minimum bindgen version is at least
that, hence the scope on the Cc: stable line below.
Found by a static equivalence audit (C2RustDrv, a C-to-Rust driver
migration tool) that compares hand-written bitfield offsets against
the bindgen layout of struct phy_device. Verified by building the
bindings and checking the generated accessors; no runtime testing was
possible without PHY hardware.
Fixes: 2796ff1e3dca ("net: phy: add flag is_genphy_driven to struct phy_device")
Cc: stable@vger.kernel.org # Only 7.1.y and later (requires bindgen's raw pointer accessors).
Link: https://github.com/rust-lang/rust-bindgen/issues/2674
Signed-off-by: Chunfeng Song <springbreeze@stu.pku.edu.cn>
Reviewed-by: FUJITA Tomonori <fujita.tomonori@gmail.com>
Link: https://patch.msgid.link/20260910055110.167110-1-springbreeze@stu.pku.edu.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
rust/kernel/net/phy.rs | 38 ++++++++++++++++++--------------------
1 file changed, 18 insertions(+), 20 deletions(-)
--- a/rust/kernel/net/phy.rs
+++ b/rust/kernel/net/phy.rs
@@ -123,39 +123,37 @@ impl Device {
/// Gets the current link state.
///
/// It returns true if the link is up.
+ #[inline]
pub fn is_link_up(&self) -> bool {
- const LINK_IS_UP: u64 = 1;
- // TODO: the code to access to the bit field will be replaced with automatically
- // generated code by bindgen when it becomes possible.
- // SAFETY: The struct invariant ensures that we may access
- // this field without additional synchronization.
- let bit_field = unsafe { &(*self.0.get())._bitfield_1 };
- bit_field.get(14, 1) == LINK_IS_UP
+ let phydev = self.0.get().cast_const();
+ // SAFETY: By the type invariant of `Device`, `phydev` points to a valid
+ // `struct phy_device`, and there is no concurrent write to this field.
+ let link = unsafe { bindings::phy_device::link_raw(phydev) };
+ link == 1
}
/// Gets the current auto-negotiation configuration.
///
/// It returns true if auto-negotiation is enabled.
+ #[inline]
pub fn is_autoneg_enabled(&self) -> bool {
- // TODO: the code to access to the bit field will be replaced with automatically
- // generated code by bindgen when it becomes possible.
- // SAFETY: The struct invariant ensures that we may access
- // this field without additional synchronization.
- let bit_field = unsafe { &(*self.0.get())._bitfield_1 };
- bit_field.get(13, 1) == u64::from(bindings::AUTONEG_ENABLE)
+ let phydev = self.0.get().cast_const();
+ // SAFETY: By the type invariant of `Device`, `phydev` points to a valid
+ // `struct phy_device`, and there is no concurrent write to this field.
+ let autoneg = unsafe { bindings::phy_device::autoneg_raw(phydev) };
+ autoneg == bindings::AUTONEG_ENABLE
}
/// Gets the current auto-negotiation state.
///
/// It returns true if auto-negotiation is completed.
+ #[inline]
pub fn is_autoneg_completed(&self) -> bool {
- const AUTONEG_COMPLETED: u64 = 1;
- // TODO: the code to access to the bit field will be replaced with automatically
- // generated code by bindgen when it becomes possible.
- // SAFETY: The struct invariant ensures that we may access
- // this field without additional synchronization.
- let bit_field = unsafe { &(*self.0.get())._bitfield_1 };
- bit_field.get(15, 1) == AUTONEG_COMPLETED
+ let phydev = self.0.get().cast_const();
+ // SAFETY: By the type invariant of `Device`, `phydev` points to a valid
+ // `struct phy_device`, and there is no concurrent write to this field.
+ let completed = unsafe { bindings::phy_device::autoneg_complete_raw(phydev) };
+ completed == 1
}
/// Sets the speed of the PHY.
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 199/398] ALSA: core: Fix potential UAF after asynchronous card release
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (196 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 198/398] Input: xpad - fix PDP Marvel Xbox 360 controller Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 200/398] ALSA: virtio: reset device before deleting virtqueues Greg Kroah-Hartman
` (204 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Farhad Alemi, Takashi Iwai
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
commit fd95e68df6fe66344161a1329cbe5e5805e7b704 upstream.
Usually a sound driver releases the resources assigned to the card via
snd_card_free(), and it synchronizes with the whole release procedure.
However, when the card is released asynchronously via
snd_card_free_when_closed() like USB-audio driver, the situation is
slightly different; although the snd_card_disconnect() call at the
disconnection guarantees that any newer accesses will be gated, the
in-flight tasks might be still accessing to the underlying card->dev
device even after the disconnection, which would cause a
use-after-free in the end, as reported by fuzzers.
For addressing the bug above, this patch takes the refcount of
card->dev at initialization of the card object, and releases at its
destructor. This assures the availability of the card->dev in its
whole lifecycle.
Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Closes: https://lore.kernel.org/CA+0ovChexj4TrZL_2iG_P0WBEbZc5+73GfB3DkciQi=R8pZOnA@mail.gmail.com
Closes: https://lore.kernel.org/CA+0ovCgQUQNN=Z1tJTouiCsDaXR5M-3-SQEGk-cpPXQkM5Xh+w@mail.gmail.com
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20260912162150.455144-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/core/init.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/sound/core/init.c
+++ b/sound/core/init.c
@@ -309,7 +309,7 @@ static int snd_card_init(struct snd_card
kfree(card); /* manually free here, as no destructor called */
return err;
}
- card->dev = parent;
+ card->dev = get_device(parent);
card->number = idx;
WARN_ON(IS_MODULE(CONFIG_SND) && !module);
card->module = module;
@@ -593,6 +593,7 @@ static int snd_card_do_free(struct snd_c
dev_warn(card->dev, "unable to free card info\n");
/* Not fatal error */
}
+ put_device(card->dev);
if (card->release_completion)
complete(card->release_completion);
if (!managed)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 253/438] Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware"
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (251 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 252/438] rust: net: phy: fix off-by-one bit positions in device status accessors Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 254/438] drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini() Greg Kroah-Hartman
` (196 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lyude Paul, Dave Airlie
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lyude Paul <lyude@redhat.com>
commit a5c41fa7f925fda2db394329fa0b26243fa63a81 upstream.
This reverts commit 8302d0afeaec0bc57d951dd085e0cffe997d4d18.
It turns out this looked like the right fix on some systems, but it's not -
as this causes runtime PM to actually fail on many a laptop.
Fixes: 8302d0afeaec ("nouveau/gsp: fix suspend/resume regression on r570 firmware")
Cc: <stable@vger.kernel.org> # v6.19+
Signed-off-by: Lyude Paul <lyude@redhat.com>
Reviewed-by: Dave Airlie <airlied@redhat.com>
Link: https://patch.msgid.link/20260814194542.781955-2-lyude@redhat.com
(cherry picked from commit 94097122bfd701976bc1a62ccd434c13f3f67cde)
Signed-off-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/fbsr.c | 2 +-
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c | 2 +-
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c | 8 ++++----
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h | 2 +-
4 files changed, 7 insertions(+), 7 deletions(-)
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/fbsr.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/fbsr.c
@@ -208,7 +208,7 @@ r535_fbsr_resume(struct nvkm_gsp *gsp)
}
static int
-r535_fbsr_suspend(struct nvkm_gsp *gsp, bool runtime)
+r535_fbsr_suspend(struct nvkm_gsp *gsp)
{
struct nvkm_subdev *subdev = &gsp->subdev;
struct nvkm_device *device = subdev->device;
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c
@@ -1749,7 +1749,7 @@ r535_gsp_fini(struct nvkm_gsp *gsp, enum
sr->sysmemAddrOfSuspendResumeData = gsp->sr.radix3.lvl0.addr;
sr->sizeOfSuspendResumeData = len;
- ret = rm->api->fbsr->suspend(gsp, suspend == NVKM_RUNTIME_SUSPEND);
+ ret = rm->api->fbsr->suspend(gsp);
if (ret) {
nvkm_gsp_mem_dtor(&gsp->sr.meta);
nvkm_gsp_radix3_dtor(gsp, &gsp->sr.radix3);
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c
@@ -62,7 +62,7 @@ r570_fbsr_resume(struct nvkm_gsp *gsp)
}
static int
-r570_fbsr_init(struct nvkm_gsp *gsp, struct sg_table *sgt, u64 size, bool runtime)
+r570_fbsr_init(struct nvkm_gsp *gsp, struct sg_table *sgt, u64 size)
{
NV2080_CTRL_INTERNAL_FBSR_INIT_PARAMS *ctrl;
struct nvkm_gsp_object memlist;
@@ -81,7 +81,7 @@ r570_fbsr_init(struct nvkm_gsp *gsp, str
ctrl->hClient = gsp->internal.client.object.handle;
ctrl->hSysMem = memlist.handle;
ctrl->sysmemAddrOfSuspendResumeData = gsp->sr.meta.addr;
- ctrl->bEnteringGcoffState = runtime ? 1 : 0;
+ ctrl->bEnteringGcoffState = 1;
ret = nvkm_gsp_rm_ctrl_wr(&gsp->internal.device.subdevice, ctrl);
if (ret)
@@ -92,7 +92,7 @@ r570_fbsr_init(struct nvkm_gsp *gsp, str
}
static int
-r570_fbsr_suspend(struct nvkm_gsp *gsp, bool runtime)
+r570_fbsr_suspend(struct nvkm_gsp *gsp)
{
struct nvkm_subdev *subdev = &gsp->subdev;
struct nvkm_device *device = subdev->device;
@@ -133,7 +133,7 @@ r570_fbsr_suspend(struct nvkm_gsp *gsp,
return ret;
/* Initialise FBSR on RM. */
- ret = r570_fbsr_init(gsp, &gsp->sr.fbsr, size, runtime);
+ ret = r570_fbsr_init(gsp, &gsp->sr.fbsr, size);
if (ret) {
nvkm_gsp_sg_free(device, &gsp->sr.fbsr);
return ret;
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h
@@ -79,7 +79,7 @@ struct nvkm_rm_api {
} *device;
const struct nvkm_rm_api_fbsr {
- int (*suspend)(struct nvkm_gsp *, bool runtime);
+ int (*suspend)(struct nvkm_gsp *);
void (*resume)(struct nvkm_gsp *);
} *fbsr;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 200/398] ALSA: virtio: reset device before deleting virtqueues
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (197 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 199/398] ALSA: core: Fix potential UAF after asynchronous card release Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 201/398] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type Greg Kroah-Hartman
` (203 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Takashi Iwai
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <oss.patchbox@gmail.com>
commit 6c05d00af307560e6a9f1631d6270d3df5aa2272 upstream.
virtsnd_remove() and virtsnd_freeze() delete the virtqueues before
resetting the device. del_vqs() frees the vring backing, but does not
provide a generic device quiesce operation. In particular, modern
virtio-pci keeps enabled queues active until the device is reset.
Reset the device before deleting the virtqueues so it can no longer
access the vring memory when that memory is released. This also covers
probe failures after DRIVER_OK, which unwind through virtsnd_remove().
Fixes: de3a9980d8c3 ("ALSA: virtio: add virtio sound driver")
Fixes: 575483e90a32 ("ALSA: virtio: introduce device suspend/resume support")
Cc: stable@vger.kernel.org
Signed-off-by: Yuho Choi <oss.patchbox@gmail.com>
Link: https://patch.msgid.link/20260911031121.1542502-1-oss.patchbox@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/virtio/virtio_card.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/sound/virtio/virtio_card.c
+++ b/sound/virtio/virtio_card.c
@@ -355,8 +355,8 @@ static void virtsnd_remove(struct virtio
if (snd->card)
snd_card_free(snd->card);
- vdev->config->del_vqs(vdev);
virtio_reset_device(vdev);
+ vdev->config->del_vqs(vdev);
for (i = 0; snd->substreams && i < snd->nsubstreams; ++i) {
struct virtio_pcm_substream *vss = &snd->substreams[i];
@@ -384,8 +384,8 @@ static int virtsnd_freeze(struct virtio_
virtsnd_disable_event_vq(snd);
virtsnd_ctl_msg_cancel_all(snd);
- vdev->config->del_vqs(vdev);
virtio_reset_device(vdev);
+ vdev->config->del_vqs(vdev);
for (i = 0; i < snd->nsubstreams; ++i)
cancel_work_sync(&snd->substreams[i].elapsed_period);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 254/438] drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (252 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 253/438] Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware" Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 255/438] drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr Greg Kroah-Hartman
` (195 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lyude Paul, Dave Airlie
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lyude Paul <lyude@redhat.com>
commit bbb9293c9bb792f3f16c842f223b8c97bdbaf227 upstream.
As it turns out, Turing isn't the only architecture that needs this. On
this Dell Precision 7780 with an AD103 GPU, along with pretty much every
other laptop I tested, runtime PM is still somewhat unreliable. At first
glance it seems as if it's fixed, but lowering the autosuspend delay to
500ms and then doing a stress test of suspend/resume cycles on the GPU ends
up causing everything to start timing out.
After quite a lot of digging, I eventually landed back on this magic
timeout in r535_gsp_fini(). As it turns out, increasing the timeout ends up
fixing the runtime PM issues as far as I can tell, even during intense
stress testing.
Unfortunately after spending quite a bit of time trying to dig through
OpenRM to figure out what this magic sleep is actually doing, I've also
come up short with any reasonable explanation. In lieu of that, I'm going
to include the observations I did make while trying to figure this out in
hopes someone eventually does figure this out:
* The magic sleep has to occur after fbsr is initialized. Performing it at
any time before that doesn't appear to work.
* In situations where runtime PM starts getting flaky, some rather
interesting visual effects end up happening on occasion before the GPU
fully falls over. In particular, squares that look like the result of an
incomplete blitting operation to a tiled buffer end up showing up on
applications like vkcube. Interestingly enough, they remain in precisely
the same place between runtime PM cycles until the GPU falls over - even
when restarting vkcube multiple times, and even when vkcube is actively
updating the screen. Even more interestingly, they're not limited to a
specific framebuffer - you can see the squares changing as the cube
rotates around.
We cannot however, say that this is likely to be a incomplete fbsr
operation. The magic sleep happens before fbsr is actually saved (which
happens on the GSP unload), so it's something else.
* During a short bit of testing with a desktop that I have, the magic sleep
seemed to make no difference to whether or not suspend/resume works. It
seems to generally work almost always. So we can assume this is likely
exclusive to runtime PM, not S3.
As well, here's a list of the things I tried before settling on the magic
sleep:
* Hooking up NV2080_CTRL_CMD_INTERNAL_GCX_ENTRY_PREREQUISITE and then
blocking runtime PM until OpenRM signals that GC6/GCOFF is ready appears
to make no difference.
* Hooking up some (maybe not all, unsure about that part) bits of comptag
saving including:
* Fetching static memsys information from GSP
* Adding the size of the comptag storage to the fbsr data
* Adding a GA103+ workaround for disabling raw compression mode during
fbsr (it doesn't seem like it applies for any systems I tried it on
anyhow)
* Setting bPreserveVideoMemoryAllocations=1 in GspSystemInfo
So, until we can figure this out properly - just sleep for longer.
Signed-off-by: Lyude Paul <lyude@redhat.com>
Fixes: 53dac0623853 ("drm/nouveau/gsp: add support for 570.144")
Cc: <stable@vger.kernel.org> # v6.16+
Reviewed-by: Dave Airlie <airlied@redhat.com>
Link: https://patch.msgid.link/20260814194542.781955-5-lyude@redhat.com
(cherry picked from commit 09b47186a4164f3aaa3591313f80794443117342)
Signed-off-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c
@@ -1761,8 +1761,12 @@ r535_gsp_fini(struct nvkm_gsp *gsp, enum
* TODO: Debug the GSP firmware / RPC handling to find out why
* without this Turing (but none of the other architectures)
* ends up resetting all channels after resume.
+ * Additionally, runtime suspend on other architectures quickly
+ * becomes unreliable without this sleep. If you're experiencing
+ * issues with runtime suspend, try bumping this delay up and
+ * sending a patch if it fixes your GPU.
*/
- msleep(50);
+ msleep(200);
}
ret = r535_gsp_rpc_unloading_guest_driver(gsp, suspend);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 201/398] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (198 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 200/398] ALSA: virtio: reset device before deleting virtqueues Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 202/398] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY Greg Kroah-Hartman
` (202 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiangshan Yi, Pierre-Louis Bossart,
Mark Brown
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiangshan Yi <yijiangshan@kylinos.cn>
commit 03a5699a0a04309c597683967aaaf25d1e555ea2 upstream.
stream_config is not initialized before being passed to
sdw_stream_add_slave(). The type field may contain garbage and is
later copied to stream->type by sdw_config_stream().
Zero-initialize stream_config so type defaults to SDW_STREAM_PCM.
While at it, use snd_sdw_params_to_config() helper instead of
open-coding the same logic.
Fixes: 63a511284c9e ("ASoC: rt712-sdca: Add RT712 SDCA driver for Mic topology")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Reviewed-by: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
Link: https://patch.msgid.link/20260914104712.379574-1-yijiangshan@kylinos.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/codecs/rt712-sdca-dmic.c | 14 +++++---------
1 file changed, 5 insertions(+), 9 deletions(-)
--- a/sound/soc/codecs/rt712-sdca-dmic.c
+++ b/sound/soc/codecs/rt712-sdca-dmic.c
@@ -14,6 +14,7 @@
#include <sound/core.h>
#include <sound/pcm.h>
#include <sound/pcm_params.h>
+#include <sound/sdw.h>
#include <sound/tlv.h>
#include "rt712-sdca.h"
#include "rt712-sdca-dmic.h"
@@ -636,10 +637,10 @@ static int rt712_sdca_dmic_hw_params(str
{
struct snd_soc_component *component = dai->component;
struct rt712_sdca_dmic_priv *rt712 = snd_soc_component_get_drvdata(component);
- struct sdw_stream_config stream_config;
+ struct sdw_stream_config stream_config = {0};
struct sdw_port_config port_config;
struct sdw_stream_runtime *sdw_stream;
- int retval, num_channels;
+ int retval;
unsigned int sampling_rate;
dev_dbg(dai->dev, "%s %s", __func__, dai->name);
@@ -651,13 +652,8 @@ static int rt712_sdca_dmic_hw_params(str
if (!rt712->slave)
return -EINVAL;
- stream_config.frame_rate = params_rate(params);
- stream_config.ch_count = params_channels(params);
- stream_config.bps = snd_pcm_format_width(params_format(params));
- stream_config.direction = SDW_DATA_DIR_TX;
-
- num_channels = params_channels(params);
- port_config.ch_mask = GENMASK(num_channels - 1, 0);
+ /* SoundWire specific configuration */
+ snd_sdw_params_to_config(substream, params, &stream_config, &port_config);
port_config.num = 2;
retval = sdw_stream_add_slave(rt712->slave, &stream_config,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 255/438] drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (253 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 254/438] drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 256/438] drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP Greg Kroah-Hartman
` (194 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lyude Paul, Dave Airlie
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lyude Paul <lyude@redhat.com>
commit 12f6eff11ccf9cad3b2dfcdd94184fdb9ffface2 upstream.
Previously, it looked as if we were able to fix suspend/resume on some
desktops by setting Gcoff based on whether or not we were entering runtime
PM. This was a mistake though - the only time suspend/resume would end up
actually working was if Gcoff = 0.
It seems like it's likely the main reason for this is the FBSR GcOff
argument actually controls GSP's behavior with regards to which buffers it
decides to save across suspend/resume. When GcOff = 1, RM reserved regions
are saved unless they are marked as LOST_ON_SUSPEND, and RM channel-context
and kernel-client buffers are also saved -including- when they are
LOST_ON_SUSPEND. This means with GcOff = 1, we end up having GSP save and
restore buffers that actually need to be reinitialized on resume - causing
the failures we're setting.
Thanks to John Hubbard from Nvidia for providing some background on what
these options do in the GSP firmware do!
Signed-off-by: Lyude Paul <lyude@redhat.com>
Fixes: 53dac0623853 ("drm/nouveau/gsp: add support for 570.144")
Cc: <stable@vger.kernel.org> # v6.16+
Reviewed-by: Dave Airlie <airlied@redhat.com>
Link: https://patch.msgid.link/20260814194542.781955-3-lyude@redhat.com
(cherry picked from commit c7abe771e013848970421e5ca29c6b2f05c31965)
Signed-off-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c
@@ -81,7 +81,7 @@ r570_fbsr_init(struct nvkm_gsp *gsp, str
ctrl->hClient = gsp->internal.client.object.handle;
ctrl->hSysMem = memlist.handle;
ctrl->sysmemAddrOfSuspendResumeData = gsp->sr.meta.addr;
- ctrl->bEnteringGcoffState = 1;
+ ctrl->bEnteringGcoffState = 0;
ret = nvkm_gsp_rm_ctrl_wr(&gsp->internal.device.subdevice, ctrl);
if (ret)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 202/398] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (199 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 201/398] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 203/398] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources() Greg Kroah-Hartman
` (201 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Roland Waltersson, Damien Le Moal,
Niklas Cassel
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Cassel <cassel@kernel.org>
commit 82e47533221d4746947b74d2e79a478c36c6433a upstream.
A user reported that commit 105c42566a55 ("ata: ahci: force 32-bit DMA for
JMicron JMB582/JMB585") made the JMicron JMB585 unusable on his board.
The failure is seen as soon as the ahci driver is probed, and booting with
iommu=off does not solve the problem.
Looking at the AHCI specification, PxCLBU and PxFBU are both read only '0'
for HBAs that do not support 64-bit addressing.
For HBAs that do support 64-bit addressing, the registers are read write,
with a reset value that is Implementation Specific.
When using the AHCI_HFLAG_32BIT_ONLY flag, the HBA does support 64-bit
addressing, and a 32-bit DMA mask is set by simply clearing HOST_CAP_64.
Thus, in this case, we need to explicitly clear the registers to 0.
Fixes: 105c42566a55 ("ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585")
Fixes: c7a42156d99b ("ahci: disable 64bit dma on sb600")
Cc: stable@vger.kernel.org
Reported-by: Roland Waltersson <roland.waltersson@netinsight.net>
Closes: https://lore.kernel.org/linux-ide/IA0PR17MB668730A4ECCD65F7A1DC3EDC9EB62@IA0PR17MB6687.namprd17.prod.outlook.com/
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://lore.kernel.org/r/20260904134310.1465051-2-cassel@kernel.org
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libahci.c | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
--- a/drivers/ata/libahci.c
+++ b/drivers/ata/libahci.c
@@ -748,15 +748,28 @@ void ahci_start_fis_rx(struct ata_port *
struct ahci_port_priv *pp = ap->private_data;
u32 tmp;
- /* set FIS registers */
+ /*
+ * On HBAs that only support 32-bit addressing PxCLBU is read only '0'.
+ * When applying the AHCI_HFLAG_32BIT_ONLY quirk, PxCLBU is RW, and the
+ * reset value is Implementation Specific, so we need to clear it to 0.
+ */
if (hpriv->cap & HOST_CAP_64)
writel((pp->cmd_slot_dma >> 16) >> 16,
port_mmio + PORT_LST_ADDR_HI);
+ else if (hpriv->flags & AHCI_HFLAG_32BIT_ONLY)
+ writel(0, port_mmio + PORT_LST_ADDR_HI);
writel(pp->cmd_slot_dma & 0xffffffff, port_mmio + PORT_LST_ADDR);
+ /*
+ * On HBAs that only support 32-bit addressing PxFBU is read only '0'.
+ * When applying the AHCI_HFLAG_32BIT_ONLY quirk, PxFBU is RW, and the
+ * reset value is Implementation Specific, so we need to clear it to 0.
+ */
if (hpriv->cap & HOST_CAP_64)
writel((pp->rx_fis_dma >> 16) >> 16,
port_mmio + PORT_FIS_ADDR_HI);
+ else if (hpriv->flags & AHCI_HFLAG_32BIT_ONLY)
+ writel(0, port_mmio + PORT_FIS_ADDR_HI);
writel(pp->rx_fis_dma & 0xffffffff, port_mmio + PORT_FIS_ADDR);
/* enable FIS reception */
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 256/438] drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (254 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 255/438] drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 257/438] x86/build/64: Prevent native builds from generating EGPR use Greg Kroah-Hartman
` (193 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lyude Paul, Dave Airlie
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lyude Paul <lyude@redhat.com>
commit 24fbd6d4bcf3363ef13ebe0d36dea93f30396c6d upstream.
There's two flags that we've never been setting when asking GSP to suspend
the GPU, which OpenRM does set:
GPU_STATE_FLAGS_PRESERVING
GPU_STATE_FLAGS_PM_TRANSITION
These flags aren't -supposed- to do much in GSP, they're mostly used by
OpenRM itself for state tracking. The only thing they do from GSP's side is
control whether or not a single display related workaround is applied
during suspend.
But as it turns out, that single workaround is actually quite crucial for
getting runtime PM working with nouveau - and without it set we end up
seeing a lot more failures with runtime PM resume. So, let's start setting
it.
Signed-off-by: Lyude Paul <lyude@redhat.com>
Fixes: 53dac0623853 ("drm/nouveau/gsp: add support for 570.144")
Cc: <stable@vger.kernel.org> # v6.16+
Reviewed-by: Dave Airlie <airlied@redhat.com>
Link: https://patch.msgid.link/20260814194542.781955-4-lyude@redhat.com
(cherry picked from commit ca57629b3eb912c77bc4357178a2130ea6c2d6df)
Signed-off-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c | 3 ++-
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/gsp.h | 8 ++++++++
2 files changed, 10 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c
@@ -207,7 +207,8 @@ r570_gsp_set_rmargs(struct nvkm_gsp *gsp
args->srInitArguments.bInPMTransition = 0;
} else {
args->srInitArguments.oldLevel = NV2080_CTRL_GPU_SET_POWER_STATE_GPU_LEVEL_3;
- args->srInitArguments.flags = 0;
+ args->srInitArguments.flags =
+ GPU_STATE_FLAGS_PRESERVING | GPU_STATE_FLAGS_PM_TRANSITION;
args->srInitArguments.bInPMTransition = 1;
}
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/gsp.h
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/gsp.h
@@ -523,6 +523,14 @@ typedef struct
#define NV2080_CTRL_GPU_SET_POWER_STATE_GPU_LEVEL_3 (0x00000003U)
+#define GPU_STATE_FLAGS_PRESERVING BIT(0) // GPU state is preserved
+#define GPU_STATE_FLAGS_VGA_TRANSITION BIT(1) // To be used with GPU_STATE_FLAGS_PRESERVING.
+#define GPU_STATE_FLAGS_PM_TRANSITION BIT(2) // To be used with GPU_STATE_FLAGS_PRESERVING.
+#define GPU_STATE_FLAGS_PM_SUSPEND BIT(3)
+#define GPU_STATE_FLAGS_PM_HIBERNATE BIT(4)
+#define GPU_STATE_FLAGS_GC6_TRANSITION BIT(5) // To be used with GPU_STATE_FLAGS_PRESERVING.
+#define GPU_STATE_FLAGS_FAST_UNLOAD BIT(6) // Used during windows restart, skips stateDestroy steps
+
typedef struct
{
// Magic for verification by secure ucode
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 203/398] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (200 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 202/398] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 204/398] cifs: Fix server use-after-free in cifs_chan_skip_or_disable() Greg Kroah-Hartman
` (200 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wentao Liang, Damien Le Moal,
Niklas Cassel
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 0d1cb83337f13af082afb68b28d3fdfe29cde7fb upstream.
of_find_device_by_node() takes a reference on the port platform device,
which is only used to look up its port regulator and is never released,
neither on success nor on the error paths. Drop the reference with
put_device() once the regulator has been obtained, which covers both the
success and error paths.
Fixes: c7d7ddee7e24 ("ata: libahci: Allow using multiple regulators")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://lore.kernel.org/r/20260915065933.1733061-1-vulab@iscas.ac.cn
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/ata/libahci_platform.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/ata/libahci_platform.c
+++ b/drivers/ata/libahci_platform.c
@@ -623,10 +623,10 @@ struct ahci_host_priv *ahci_platform_get
of_platform_device_create(child, NULL, NULL);
port_dev = of_find_device_by_node(child);
-
if (port_dev) {
rc = ahci_platform_get_regulator(hpriv, port,
&port_dev->dev);
+ put_device(&port_dev->dev);
if (rc == -EPROBE_DEFER)
goto err_out;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 257/438] x86/build/64: Prevent native builds from generating EGPR use
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (255 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 256/438] drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 258/438] x86/microcode/intel: Reject problematic loading on Granite Rapids systems Greg Kroah-Hartman
` (192 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Omar Avelar, Chang S. Bae,
Borislav Petkov (AMD), Nathan Chancellor, Miguel Ojeda
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chang S. Bae <chang.seok.bae@intel.com>
commit 63edf5a009ae366369a1b484cd9ae4ee7c51946c upstream.
Omar reports that CONFIG_X86_NATIVE_CPU=y allows builds to opportunistically
emit instructions using %r16-%r31 (EGPRs) when the build host supports APX
since the commit:
ea1dcca1de12 ("x86/kbuild/64: Add the CONFIG_X86_NATIVE_CPU option to locally optimize the kernel with '-march=native'")
But the kernel is not yet prepared to use new registers internally. For
example, there is no context-switch support for general in-kernel use.
Explicitly disable EGPR use when building with -march=native.
For C, since GCC 14 and Clang 18, both compilers support suppressing EGPR
use with -mno-apx-features=egpr, whose availability can be detected via
cc-option.
For Rust, pass features=-apxf through the generated JSON to avoid
unstable-feature warnings, see
https://github.com/rust-lang/rust/issues/139284
Note Rust only accepts the option to disable APX instructions entirely or not.
Support for this gating also depends on the Rust/LLVM combination. Rust
1.88 introduced the `apxf` feature option, but versions prior to 1.93 may
emit an `apxf` attribute to the backend that only LLVM 23 or later can
interpret. Restrict native Rust builds accordingly.
Fixes: ea1dcca1de12 ("x86/kbuild/64: Add the CONFIG_X86_NATIVE_CPU option to locally optimize the kernel with '-march=native'")
Reported-by: Omar Avelar <omar.avelar@intel.com>
Signed-off-by: Chang S. Bae <chang.seok.bae@intel.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Nathan Chancellor <nathan@kernel.org>
Acked-by: Miguel Ojeda <ojeda@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260916230003.1144622-1-chang.seok.bae@intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/Kconfig.cpu | 11 +++++++++++
arch/x86/Makefile | 5 +++++
scripts/generate_rust_target.rs | 5 +++++
3 files changed, 21 insertions(+)
--- a/arch/x86/Kconfig.cpu
+++ b/arch/x86/Kconfig.cpu
@@ -204,10 +204,21 @@ config CC_HAS_MARCH_NATIVE
# usage warnings that only appear wth '-march=native'.
depends on CC_IS_GCC || CLANG_VERSION >= 190100
+config RUSTC_HAS_APXF
+ # The kernel isn't ready for in-kernel APX instructions. Without
+ # explicit frontend gating of APX, the backend may emit those
+ # instructions in native builds.
+ #
+ # Rust 1.88 added the `apxf` feature option, but versions before 1.93
+ # emit an `apxf` target attribute that only LLVM 23+ can interpret.
+ def_bool (RUSTC_VERSION >= 108800 && RUSTC_LLVM_MAJOR_VERSION >= 23) || \
+ RUSTC_VERSION >= 109300
+
config X86_NATIVE_CPU
bool "Build and optimize for local/native CPU"
depends on X86_64
depends on CC_HAS_MARCH_NATIVE
+ depends on !RUST || RUSTC_HAS_APXF
help
Optimize for the current CPU used to compile the kernel.
Use this option if you intend to build the kernel for your
--- a/arch/x86/Makefile
+++ b/arch/x86/Makefile
@@ -161,6 +161,11 @@ else
ifdef CONFIG_X86_NATIVE_CPU
KBUILD_CFLAGS += -march=native
+ # Prevent the compiler from generating EGPR use. The kernel is
+ # not yet prepared for general in-kernel use.
+ KBUILD_CFLAGS += $(call cc-option,-mno-apx-features=egpr)
+
+ # generate_rust_target.rs handles Rust APX gating.
KBUILD_RUSTFLAGS += -Ctarget-cpu=native
else
KBUILD_CFLAGS += -march=x86-64 -mtune=generic
--- a/scripts/generate_rust_target.rs
+++ b/scripts/generate_rust_target.rs
@@ -224,6 +224,11 @@ fn main() {
features += ",+harden-sls-ijmp";
features += ",+harden-sls-ret";
}
+ if cfg.has("X86_NATIVE_CPU") {
+ // Prevent the backend from generating APX instructions. The kernel is not yet prepared
+ // for general in-kernel EGPR use.
+ features += ",-apxf";
+ }
ts.push("features", features);
ts.push("llvm-target", "x86_64-linux-gnu");
ts.push("supported-sanitizers", ["kcfi", "kernel-address"]);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 204/398] cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (201 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 203/398] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 205/398] exec: Cleanup POSIX timers right after de_thread() Greg Kroah-Hartman
` (199 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Paulo Alcantara
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 717e0a25036b6c92cecace30913b2d874a4c22b8 upstream.
When a secondary channel is no longer supported by the server,
cifs_chan_skip_or_disable() drops the channel reference with
cifs_put_tcp_session() and then continues to use the server pointer by
calling cifs_signal_cifsd_for_reconnect() on it and reading its
primary_server pointer. cifs_put_tcp_session() can drop the last
reference of the channel and tear it down, so both the channel and the
primary server (whose reference is also dropped by
cifs_put_tcp_session()) can be freed before they are signaled for
reconnect.
Signal the channel and the primary server and capture the primary
server pointer before dropping the channel reference with
cifs_put_tcp_session().
Fixes: f591062bdbf4 ("cifs: handle servers that still advertise multichannel after disabling")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2pdu.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
--- a/fs/smb/client/smb2pdu.c
+++ b/fs/smb/client/smb2pdu.c
@@ -190,18 +190,19 @@ cifs_chan_skip_or_disable(struct cifs_se
spin_unlock(&ses->chan_lock);
/*
- * the above reference of server by channel
- * needs to be dropped without holding chan_lock
- * as cifs_put_tcp_session takes a higher lock
- * i.e. cifs_tcp_ses_lock
+ * signal the channel and its primary server to
+ * reconnect before dropping the above reference of
+ * server by channel, which is done without holding
+ * chan_lock as cifs_put_tcp_session takes a higher
+ * lock i.e. cifs_tcp_ses_lock
*/
- cifs_put_tcp_session(server, from_reconnect);
-
cifs_signal_cifsd_for_reconnect(server, false);
/* mark primary server as needing reconnect */
pserver = server->primary_server;
cifs_signal_cifsd_for_reconnect(pserver, false);
+
+ cifs_put_tcp_session(server, from_reconnect);
skip_terminate:
return -EHOSTDOWN;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 258/438] x86/microcode/intel: Reject problematic loading on Granite Rapids systems
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (256 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 257/438] x86/build/64: Prevent native builds from generating EGPR use Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 259/438] tcp: exclude old ACKs from tcp fast path Greg Kroah-Hartman
` (191 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chang S. Bae, Borislav Petkov (AMD),
Dave Hansen
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chang S. Bae <chang.seok.bae@intel.com>
commit e7d3e2f46dd5a69046e6d95a0f189155a5516b93 upstream.
Microcode updates can usually jump revisions. However, there is an erratum on
Granite Rapids systems. If they "jump over" revision 0x1000405, they result in
an #MC. Avoid it.
Signed-off-by: Chang S. Bae <chang.seok.bae@intel.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Dave Hansen <dave.hansen@linux.intel.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260916225939.1144524-1-chang.seok.bae@intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kernel/cpu/microcode/intel.c | 26 ++++++++++++++++++++++++++
1 file changed, 26 insertions(+)
--- a/arch/x86/kernel/cpu/microcode/intel.c
+++ b/arch/x86/kernel/cpu/microcode/intel.c
@@ -345,6 +345,26 @@ static void save_microcode_patch(struct
pr_err("Unable to allocate microcode memory size: %u\n", size);
}
+static bool revision_is_safe(struct cpu_signature *sig, u32 rev)
+{
+ u32 vfm = IFM(x86_family(sig->sig), x86_model(sig->sig));
+
+ /*
+ * Erratum GNR98 can cause #MCs if "jumping over" revision 0x1000405.
+ * Avoid the jumps.
+ */
+ if (vfm == INTEL_GRANITERAPIDS_X &&
+ x86_stepping(sig->sig) == 1 &&
+ sig->pf & 0x95 &&
+ sig->rev < 0x1000405 &&
+ rev > 0x1000405) {
+ pr_err_once("Erratum GNR98: skipping revision 0x%x.\n", rev);
+ return false;
+ }
+
+ return true;
+}
+
/* Scan blob for microcode matching the boot CPUs family, model, stepping */
static __init struct microcode_intel *scan_microcode(void *data, size_t size,
struct ucode_cpu_info *uci,
@@ -366,6 +386,9 @@ static __init struct microcode_intel *sc
if (!intel_find_matching_signature(data, &uci->cpu_sig))
continue;
+ if (!revision_is_safe(&uci->cpu_sig, mc_header->rev))
+ continue;
+
/*
* For saving the early microcode, find the matching revision which
* was loaded on the BSP.
@@ -914,6 +937,9 @@ static enum ucode_state parse_microcode_
if (!intel_find_matching_signature(mc, &uci->cpu_sig))
continue;
+ if (!revision_is_safe(&uci->cpu_sig, mc_header.rev))
+ continue;
+
is_safe = ucode_validate_minrev(&mc_header);
if (force_minrev && !is_safe)
continue;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 205/398] exec: Cleanup POSIX timers right after de_thread()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (202 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 204/398] cifs: Fix server use-after-free in cifs_chan_skip_or_disable() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 206/398] fs/dax: check zero or empty entry before converting xarray entry Greg Kroah-Hartman
` (198 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hyunwoo Kim, Thomas Gleixner,
Kijo Park, Oleg Nesterov, Frederic Weisbecker
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hyunwoo Kim <imv4bel@gmail.com>
commit acb03d3881818581052924a9bbbe92b8741ed448 upstream.
A per-thread CPU timer holds a reference to the PID of the thread it is
attached to and, while it is armed, its node is queued in that thread's
posix_cputimers. The task is looked up by that PID.
When a non-leader thread exec()s, de_thread() changes which task owns
that PID. pid_task(timer->it.cpu.pid, PIDTYPE_PID) then returns NULL,
but the node is still queued on tsk, which is alive. timer_lock_sighand()
takes a failed lookup to mean that the node is already dequeued, so it
has nothing to undo.
begin_new_exec() calls posix_cpu_timers_exit(me) right after
exec_task_namespaces() and that removes the leftover node, so the state
normally stays invisible. But bprm->point_of_no_return is set before
de_thread(), so if unshare_files(), set_mm_exe_file(), exec_mmap() or
exec_task_namespaces() fails, the task dies before it gets there.
exit_itimers() then frees the k_itimer while its node is still queued,
and reaping tsk later erases that freed node from the rbtree.
In short:
the non-leader thread B the parent
timer_create(CLOCK_THREAD_CPUTIME_ID)
timer_settime()
arm_timer() // the node is queued on B
execve()
de_thread(B)
exchange_tids(B, leader) // B's PID now belongs to the leader
release_task(leader)
__exit_signal(leader)
posix_cpu_timers_exit(leader) // cleans leader's queue, not B's
__unhash_process(leader) // that PID has no task anymore
exec_mmap()
mmap_read_lock_killable(old_mm)
kill(B, SIGKILL)
// -EINTR
get_signal()
do_exit()
exit_itimers()
posix_timer_delete()
posix_cpu_timer_del()
posix_timer_unhash_and_free() // freed while still queued
wait4()
release_task(B)
posix_cpu_timers_exit(B)
cleanup_timerqueue()
timerqueue_del() // use-after-free
Move the POSIX timer cleanup right after de_thread() before any of the
later failure conditions brings the task into do_exit().
[ tglx: Move the cleanup right after de_thread() ]
Fixes: 55e8c8eb2c7b ("posix-cpu-timers: Store a reference to a pid not a task")
Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Kijo Park <red993688@gmail.com>
Reviewed-by: Oleg Nesterov <oleg@redhat.com>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/ao7Q8miiuLAPVnWv@v4bel
Link: https://patch.msgid.link/20260911090541.627712075@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/exec.c | 29 +++++++++++++++++++++--------
1 file changed, 21 insertions(+), 8 deletions(-)
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -1094,6 +1094,17 @@ void __set_task_comm(struct task_struct
perf_event_comm(tsk, exec);
}
+static void posixtimer_exec(struct task_struct *me)
+{
+#ifdef CONFIG_POSIX_TIMERS
+ spin_lock_irq(&me->sighand->siglock);
+ posix_cpu_timers_exit(me);
+ spin_unlock_irq(&me->sighand->siglock);
+ exit_itimers(me);
+ flush_itimer_signals();
+#endif
+}
+
/*
* Calling this is the point of no return. None of the failures will be
* seen by userspace since either the process is already taking a fatal
@@ -1127,6 +1138,16 @@ int begin_new_exec(struct linux_binprm *
retval = de_thread(me);
if (retval)
goto out;
+
+ /*
+ * This must be done here to ensure that POSIX CPU timers which were
+ * armed on the current task are dequeued from me::posix_cputimers.
+ * Otherwise in case of a TID switch the deletion of the related POSIX
+ * timer would not remove an enqueued timer because the TID lookup
+ * of the old TID fails.
+ */
+ posixtimer_exec(me);
+
/* see the comment in check_unsafe_exec() */
current->fs->in_exec = 0;
/*
@@ -1181,14 +1202,6 @@ int begin_new_exec(struct linux_binprm *
if (retval)
goto out_unlock;
-#ifdef CONFIG_POSIX_TIMERS
- spin_lock_irq(&me->sighand->siglock);
- posix_cpu_timers_exit(me);
- spin_unlock_irq(&me->sighand->siglock);
- exit_itimers(me);
- flush_itimer_signals();
-#endif
-
/*
* Make the signal table private.
*/
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 259/438] tcp: exclude old ACKs from tcp fast path
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (257 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 258/438] x86/microcode/intel: Reject problematic loading on Granite Rapids systems Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 260/438] swiotlb: use the adjusted address for the highmem page lookup Greg Kroah-Hartman
` (190 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Amit Klein, Tamir Shahar,
Inbal Schussheim, Eric Dumazet, Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
commit f81e6c3fb06327bc49cdd6e559845293ba06a704 upstream.
Exclude old ACKs before SND.UNA from the tcp fast path
as well as ACKs after SND.NXT.
Such ACKs will fall through to the slow path, where tcp_ack()
performs the appropriate validation and challenge ACK handling
according to RFC5961 and Commit 3d501dd326fb1c7 ("tcp: do not
accept ACK of bytes we never sent").
This prevents old ACKs from being accepted
or modifying connection state as part of the fast path before
appropriate ACK validation is applied.
In particular, this prevents payload carried by a segment with
an excessively old ACK from advancing RCV.NXT before the ACK
is rejected.
Fixes: 31770e34e43d ("tcp: Revert "tcp: remove header prediction"")
Reported-by: Amit Klein <amit.klein@mail.huji.ac.il>
Reported-by: Tamir Shahar <tamir.shahar1@mail.huji.ac.il>
Reported-by: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
Suggested-by: Eric Dumazet <edumazet@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260914090408.1435080-2-inbal.lipshtat@mail.huji.ac.il
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/tcp_input.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/net/ipv4/tcp_input.c
+++ b/net/ipv4/tcp_input.c
@@ -6490,6 +6490,7 @@ reset:
* or pure receivers (this means either the sequence number or the ack
* value must stay constant)
* - Unexpected TCP option.
+ * - ACK sequence number is outside [SND.UNA, SND.NXT].
*
* When these conditions are not satisfied it drops into a standard
* receive procedure patterned after RFC793 to handle all cases.
@@ -6539,7 +6540,7 @@ void tcp_rcv_established(struct sock *sk
if ((tcp_flag_word(th) & TCP_HP_BITS) == tp->pred_flags &&
TCP_SKB_CB(skb)->seq == tp->rcv_nxt &&
- !after(TCP_SKB_CB(skb)->ack_seq, tp->snd_nxt)) {
+ between(TCP_SKB_CB(skb)->ack_seq, tp->snd_una, tp->snd_nxt)) {
int tcp_header_len = tp->tcp_header_len;
s32 delta = 0;
int flag = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 206/398] fs/dax: check zero or empty entry before converting xarray entry
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (203 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 205/398] exec: Cleanup POSIX timers right after de_thread() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 207/398] phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context Greg Kroah-Hartman
` (197 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Seunguk Shin, Jan Kara,
Alistair Popple, Kiara Grouwstra, Al Viro, Christian Brauner,
Matthew Wilcox (Oracle), Andrew Morton
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Seunguk Shin <seunguk.shin@arm.com>
commit 8e2b8614039853e68d5338e37821e8bcee9fc05f upstream.
Calling dax_to_folio() with empty entry causes kernel panic below when
booting a VM with DAX enabled storage.
This patch checks empty entry before calling dax_to_folio() on
dax_associate_entry(), dax_disassociate_entry(), and dax_busy_page().
Commit 98c183a4fccf ("fs/dax: don't disassociate zero page entries") added
guards in the associate and disassociate paths, but the guards still come
after dax_to_folio(), and dax_busy_page() still has the same problem.
[ 0.737679] EXT4-fs (pmem0p1): mounted filesystem 79676804-7c8b-491a-b2a6-9bae3c72af70 ro with ordered data mode. Quota mode: disabled.
[ 0.737891] VFS: Mounted root (ext4 filesystem) readonly on device 259:1.
[ 0.739119] devtmpfs: mounted
[ 0.739476] Freeing unused kernel memory: 1920K
[ 0.740156] Run /sbin/init as init process
[ 0.740229] with arguments:
[ 0.740286] /sbin/init
[ 0.740321] with environment:
[ 0.740369] HOME=/
[ 0.740400] TERM=linux
[ 0.743162] Unable to handle kernel paging request at virtual address fffffdffbf000008
[ 0.743285] Mem abort info:
[ 0.743316] ESR = 0x0000000096000006
[ 0.743371] EC = 0x25: DABT (current EL), IL = 32 bits
[ 0.743444] SET = 0, FnV = 0
[ 0.743489] EA = 0, S1PTW = 0
[ 0.743545] FSC = 0x06: level 2 translation fault
[ 0.743610] Data abort info:
[ 0.743656] ISV = 0, ISS = 0x00000006, ISS2 = 0x00000000
[ 0.743720] CM = 0, WnR = 0, TnD = 0, TagAccess = 0
[ 0.743785] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
[ 0.743848] swapper pgtable: 4k pages, 48-bit VAs, pgdp=00000000b9d17000
[ 0.743931] [fffffdffbf000008] pgd=10000000bfa3d403, p4d=10000000bfa3d403, pud=1000000040bfe403, pmd=0000000000000000
[ 0.744070] Internal error: Oops: 0000000096000006 [#1] SMP
[ 0.748888] CPU: 0 UID: 0 PID: 1 Comm: init Not tainted 6.18.4 #1 NONE
[ 0.749421] pstate: 004000c5 (nzcv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 0.749969] pc : dax_disassociate_entry.constprop.0+0x20/0x50
[ 0.750444] lr : dax_insert_entry+0xcc/0x408
[ 0.750802] sp : ffff80008000b9e0
[ 0.751083] x29: ffff80008000b9e0 x28: 0000000000000000 x27: 0000000000000000
[ 0.751682] x26: 0000000001963d01 x25: ffff0000004f7d90 x24: 0000000000000000
[ 0.752264] x23: 0000000000000000 x22: ffff80008000bcc8 x21: 0000000000000011
[ 0.752836] x20: ffff80008000ba90 x19: 0000000001963d01 x18: 0000000000000000
[ 0.753407] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000
[ 0.753970] x14: ffffbf3154b9ae70 x13: 0000000000000000 x12: ffffbf3154b9ae70
[ 0.754548] x11: ffffffffffffffff x10: 0000000000000000 x9 : 0000000000000000
[ 0.755122] x8 : 000000000000000d x7 : 000000000000001f x6 : 0000000000000000
[ 0.755707] x5 : 0000000000000000 x4 : 0000000000000000 x3 : fffffdffc0000000
[ 0.756287] x2 : 0000000000000008 x1 : 0000000040000000 x0 : fffffdffbf000000
[ 0.756871] Call trace:
[ 0.757107] dax_disassociate_entry.constprop.0+0x20/0x50 (P)
[ 0.757592] dax_iomap_pte_fault+0x4fc/0x808
[ 0.757951] dax_iomap_fault+0x28/0x30
[ 0.758258] ext4_dax_huge_fault+0x80/0x2dc
[ 0.758594] ext4_dax_fault+0x10/0x3c
[ 0.758892] __do_fault+0x38/0x12c
[ 0.759175] __handle_mm_fault+0x530/0xcf0
[ 0.759518] handle_mm_fault+0xe4/0x230
[ 0.759833] do_page_fault+0x17c/0x4dc
[ 0.760144] do_translation_fault+0x30/0x38
[ 0.760483] do_mem_abort+0x40/0x8c
[ 0.760771] el0_ia+0x4c/0x170
[ 0.761032] el0t_64_sync_handler+0xd8/0xdc
[ 0.761371] el0t_64_sync+0x168/0x16c
[ 0.761677] Code: f9453021 f2dfbfe3 cb813080 8b001860 (f9400401)
[ 0.762168] ---[ end trace 0000000000000000 ]---
[ 0.762550] note: init[1] exited with irqs disabled
[ 0.762631] Kernel panic - not syncing: Attempted to kill init! exitcode=0x0000000b
Link: https://lore.kernel.org/m2y0enxtzk.fsf@arm.com
Fixes: 38607c62b34b ("fs/dax: properly refcount fs dax pages")
Signed-off-by: Seunguk Shin <seunguk.shin@arm.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Reviewed-by: Alistair Popple <apopple@nvidia.com>
Reported-by: Kiara Grouwstra <cinereal@riseup.net>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/dax.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
--- a/fs/dax.c
+++ b/fs/dax.c
@@ -443,11 +443,12 @@ static void dax_associate_entry(void *en
unsigned long address, bool shared)
{
unsigned long size = dax_entry_size(entry), index;
- struct folio *folio = dax_to_folio(entry);
+ struct folio *folio;
if (dax_is_zero_entry(entry) || dax_is_empty_entry(entry))
return;
+ folio = dax_to_folio(entry);
index = linear_page_index(vma, address & ~(size - 1));
if (shared && (folio->mapping || dax_folio_is_shared(folio))) {
if (folio->mapping)
@@ -468,21 +469,23 @@ static void dax_associate_entry(void *en
static void dax_disassociate_entry(void *entry, struct address_space *mapping,
bool trunc)
{
- struct folio *folio = dax_to_folio(entry);
+ struct folio *folio;
if (dax_is_zero_entry(entry) || dax_is_empty_entry(entry))
return;
+ folio = dax_to_folio(entry);
dax_folio_put(folio);
}
static struct page *dax_busy_page(void *entry)
{
- struct folio *folio = dax_to_folio(entry);
+ struct folio *folio;
if (dax_is_zero_entry(entry) || dax_is_empty_entry(entry))
return NULL;
+ folio = dax_to_folio(entry);
if (folio_ref_count(folio) - folio_mapcount(folio))
return &folio->page;
else
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 260/438] swiotlb: use the adjusted address for the highmem page lookup
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (258 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 259/438] tcp: exclude old ACKs from tcp fast path Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 261/438] soundwire: dmi-quirks: Disable ghost Realtek on Asus GX651AX Greg Kroah-Hartman
` (189 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Michael Kelley,
Marek Szyprowski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
commit b7d7914a9ae3097e63d113007e4fb44d33d515b1 upstream.
swiotlb_bounce() reads the page frame number from the slot's recorded
orig_addr, then advances orig_addr by tlb_offset to reach the address
the caller asked about. The highmem branch mixes the two: the offset
within the page comes from the adjusted address, the page from the value
before it.
Once the adjustment crosses a page boundary the pair no longer describes
one location, and the whole copy lands one page below the intended one
for a positive tlb_offset, one above for a negative one. DMA_FROM_DEVICE
writes the device data over the wrong page and leaves the intended one
stale, DMA_TO_DEVICE feeds the device from a page the mapping may not
cover. Partial syncs through dma_sync_single_range_for_*() are what make
tlb_offset non-zero.
The branch test is picked the same way, so a slot recorded in lowmem can
be adjusted into highmem and the lowmem path then hands a highmem
address to phys_to_virt().
Take both from orig_addr once it is final and keep pfn in the branch
that uses it. PhysHighMem() asks the question straight from the address,
as dma-debug already does.
Fixes: 5f89468e2f06 ("swiotlb: manipulate orig_addr when tlb_addr has offset")
Cc: stable@vger.kernel.org
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Reviewed-by: Michael Kelley <mhklinux@outlook.com>
Link: https://lore.kernel.org/r/20260905084210.148255-1-donggeunyoo.kernel@gmail.com
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/dma/swiotlb.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/kernel/dma/swiotlb.c
+++ b/kernel/dma/swiotlb.c
@@ -867,7 +867,6 @@ static void swiotlb_bounce(struct device
int index = (tlb_addr - mem->start) >> IO_TLB_SHIFT;
phys_addr_t orig_addr = mem->slots[index].orig_addr;
size_t alloc_size = mem->slots[index].alloc_size;
- unsigned long pfn = PFN_DOWN(orig_addr);
unsigned char *vaddr = mem->vaddr + tlb_addr - mem->start;
int tlb_offset;
@@ -900,7 +899,8 @@ static void swiotlb_bounce(struct device
size = alloc_size;
}
- if (PageHighMem(pfn_to_page(pfn))) {
+ if (PhysHighMem(orig_addr)) {
+ unsigned long pfn = PFN_DOWN(orig_addr);
unsigned int offset = orig_addr & ~PAGE_MASK;
struct page *page;
unsigned int sz = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 207/398] phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (204 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 206/398] fs/dax: check zero or empty entry before converting xarray entry Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 208/398] posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list Greg Kroah-Hartman
` (196 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pavel Machek, Nobuhiro Iwamatsu,
Claudiu Beznea, Manivannan Sadhasivam, Vinod Koul
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
commit 48e97c59a49c9e90270f5e3d221db253b76de5da upstream.
The OTG PHY initialization sequence needs to wait for 20 ms at a specific
step, as described in commit 72c0339c115b ("phy: renesas:
rcar-gen3-usb2: follow the hardware manual procedure").
Commit 55a387ebb921 ("phy: renesas: rcar-gen3-usb2: Lock around hardware
registers and driver data") tried to address various problems in the
rcar-gen3-usb2 driver and converted the mutex protecting HW register
accesses to a spin lock, leaving, however, a long delay in the critical
section protected by the spin lock. This may become a problem,
especially on RT kernels.
To address this, release the spin lock before sleeping for 20 ms as
required by the HW manual and reacquire it afterwards. To avoid other
threads entering the critical section and configuring the HW while the
software is waiting for the OTG initialization to complete, introduce the
otg_initializing variable alongside the otg_init_done wait queue. Any
other thread trying to configure the HW while the OTG PHY initialization
is in progress waits for the wait queue instead of immediately returning
errors to PHY users. The IRQs were also disabled while waiting for the OTG
PHY initialization to complete, as the interrupt handler may also apply HW
settings.
The OTG can only be initialized once. It is initialized by the first PHY
that calls struct phy_ops::rcar_gen3_phy_usb2_init().
To avoid failures when multiple PHYs call struct
phy_ops::rcar_gen3_phy_usb2_init() simultaneously, and the PHY responsible
for initializing the OTG either fails or deinit quiqly and another PHY
takes over the PHY init role), the code waiting for the
channel->otg_init_done wait queue retries up to NUM_OF_PHYS times.
Fixes: 55a387ebb921 ("phy: renesas: rcar-gen3-usb2: Lock around hardware registers and driver data")
Cc: stable@vger.kernel.org
Reported-by: Pavel Machek <pavel@nabladev.com>
Closes: https://lore.kernel.org/all/afhkX2Ys2BG1gnqy@duo.ucw.cz
Reported-by: Nobuhiro Iwamatsu <iwamatsu@nigauri.org>
Closes: https://lore.kernel.org/all/afhkX2Ys2BG1gnqy@duo.ucw.cz
Signed-off-by: Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://lore.kernel.org/all/afhkX2Ys2BG1gnqy@duo.ucw.cz
Link: https://patch.msgid.link/20260716183246.3183877-1-claudiu.beznea+renesas@tuxon.dev
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/phy/renesas/phy-rcar-gen3-usb2.c | 310 ++++++++++++++++++++++++++-----
1 file changed, 265 insertions(+), 45 deletions(-)
--- a/drivers/phy/renesas/phy-rcar-gen3-usb2.c
+++ b/drivers/phy/renesas/phy-rcar-gen3-usb2.c
@@ -26,6 +26,7 @@
#include <linux/reset.h>
#include <linux/string.h>
#include <linux/usb/of.h>
+#include <linux/wait.h>
#include <linux/workqueue.h>
/******* USB2.0 Host registers (original offset is +0x200) *******/
@@ -105,6 +106,13 @@
/* RZ/G2L specific */
#define USB2_LINECTRL1_USB2_IDMON BIT(0)
+/*
+ * The OTG initialization is expected to finish in 20ms. Choose a large enough
+ * timeout to avoid waiters exit prematurely the waiting section under heavy
+ * CPU load.
+ */
+#define USB2_OTG_INIT_TIMEOUT msecs_to_jiffies(120)
+
#define NUM_OF_PHYS 4
enum rcar_gen3_phy_index {
PHY_INDEX_BOTH_HC,
@@ -136,12 +144,20 @@ struct rcar_gen3_chan {
struct rcar_gen3_phy rphys[NUM_OF_PHYS];
struct regulator *vbus;
struct work_struct work;
+ wait_queue_head_t otg_init_done;
spinlock_t lock; /* protects access to hardware and driver data structure. */
enum usb_dr_mode dr_mode;
bool extcon_host;
bool is_otg_channel;
bool uses_otg_pins;
bool otg_internal_reg;
+ /*
+ * The OTG can be initialized only once and needs to release the spinlock
+ * and wait for 20 ms due to hardware constraints. If a thread executes
+ * PHY configuration code while the OTG PHY is waiting for the 20 ms, the
+ * thread will have to wait for the OTG PHY initialization to complete.
+ */
+ bool otg_initializing;
};
struct rcar_gen3_phy_drv_data {
@@ -392,26 +408,58 @@ static ssize_t role_store(struct device
struct rcar_gen3_chan *ch = dev_get_drvdata(dev);
bool is_b_device;
enum phy_mode cur_mode, new_mode;
+ int retries = NUM_OF_PHYS;
+ unsigned long flags;
+ int ret = -EIO;
- guard(spinlock_irqsave)(&ch->lock);
+ spin_lock_irqsave(&ch->lock, flags);
- if (!ch->is_otg_channel || !rcar_gen3_is_any_otg_rphy_initialized(ch))
- return -EIO;
+ if (!ch->is_otg_channel)
+ goto unlock;
+
+ while (retries-- && ch->otg_initializing) {
+ spin_unlock_irqrestore(&ch->lock, flags);
+
+ ret = wait_event_timeout(ch->otg_init_done, !ch->otg_initializing,
+ USB2_OTG_INIT_TIMEOUT);
+ ret = ret ? 0 : -ETIMEDOUT;
+ if (ret && !retries)
+ goto exit;
+
+ spin_lock_irqsave(&ch->lock, flags);
+ }
+
+ /* If another thread started a new initialization just return -EBUSY. */
+ if (ch->otg_initializing) {
+ ret = -EBUSY;
+ goto unlock;
+ } else {
+ ret = 0;
+ }
+
+ if (!rcar_gen3_is_any_otg_rphy_initialized(ch)) {
+ ret = -EIO;
+ goto unlock;
+ }
- if (sysfs_streq(buf, "host"))
+ if (sysfs_streq(buf, "host")) {
new_mode = PHY_MODE_USB_HOST;
- else if (sysfs_streq(buf, "peripheral"))
+ } else if (sysfs_streq(buf, "peripheral")) {
new_mode = PHY_MODE_USB_DEVICE;
- else
- return -EINVAL;
+ } else {
+ ret = -EINVAL;
+ goto unlock;
+ }
/* is_b_device: true is B-Device. false is A-Device. */
is_b_device = rcar_gen3_check_id(ch);
cur_mode = rcar_gen3_get_phy_mode(ch);
/* If current and new mode is the same, this returns the error */
- if (cur_mode == new_mode)
- return -EINVAL;
+ if (cur_mode == new_mode) {
+ ret = -EINVAL;
+ goto unlock;
+ }
if (new_mode == PHY_MODE_USB_HOST) { /* And is_host must be false */
if (!is_b_device) /* A-Peripheral */
@@ -425,7 +473,10 @@ static ssize_t role_store(struct device
rcar_gen3_init_for_peri(ch);
}
- return count;
+unlock:
+ spin_unlock_irqrestore(&ch->lock, flags);
+exit:
+ return ret ?: count;
}
static ssize_t role_show(struct device *dev, struct device_attribute *attr,
@@ -441,14 +492,11 @@ static ssize_t role_show(struct device *
}
static DEVICE_ATTR_RW(role);
-static void rcar_gen3_init_otg(struct rcar_gen3_chan *ch)
+static void rcar_gen3_init_otg_phase0(struct rcar_gen3_chan *ch)
{
void __iomem *usb2_base = ch->base;
u32 val;
- if (!ch->is_otg_channel || rcar_gen3_is_any_otg_rphy_initialized(ch))
- return;
-
/* Should not use functions of read-modify-write a register */
val = readl(usb2_base + USB2_LINECTRL1);
val = (val & ~USB2_LINECTRL1_DP_RPD) | USB2_LINECTRL1_DPRPD_EN |
@@ -471,7 +519,11 @@ static void rcar_gen3_init_otg(struct rc
writel(val | USB2_ADPCTRL_IDPULLUP, usb2_base + USB2_ADPCTRL);
}
}
- mdelay(20);
+}
+
+static void rcar_gen3_init_otg_phase1(struct rcar_gen3_chan *ch)
+{
+ void __iomem *usb2_base = ch->base;
writel(0xffffffff, usb2_base + USB2_OBINTSTA);
writel(ch->phy_data->obint_enable_bits, usb2_base + USB2_OBINTEN);
@@ -502,6 +554,7 @@ static irqreturn_t rcar_gen3_phy_usb2_ir
void __iomem *usb2_base = ch->base;
struct device *dev = ch->dev;
irqreturn_t ret = IRQ_NONE;
+ unsigned long flags;
u32 status;
pm_runtime_get_noresume(dev);
@@ -509,33 +562,102 @@ static irqreturn_t rcar_gen3_phy_usb2_ir
if (pm_runtime_suspended(dev))
goto rpm_put;
- scoped_guard(spinlock, &ch->lock) {
- status = readl(usb2_base + USB2_OBINTSTA);
- if (status & ch->phy_data->obint_enable_bits) {
- dev_vdbg(dev, "%s: %08x\n", __func__, status);
- if (ch->phy_data->vblvl_ctrl)
- writel(USB2_OBINTSTA_CLEAR, usb2_base + USB2_OBINTSTA);
- else
- writel(ch->phy_data->obint_enable_bits, usb2_base + USB2_OBINTSTA);
- rcar_gen3_device_recognition(ch);
- rcar_gen3_configure_vblvl_ctrl(ch);
- ret = IRQ_HANDLED;
- }
+ spin_lock_irqsave(&ch->lock, flags);
+
+ status = readl(usb2_base + USB2_OBINTSTA);
+ if (status & ch->phy_data->obint_enable_bits) {
+ dev_vdbg(dev, "%s: %08x\n", __func__, status);
+ if (ch->phy_data->vblvl_ctrl)
+ writel(USB2_OBINTSTA_CLEAR, usb2_base + USB2_OBINTSTA);
+ else
+ writel(ch->phy_data->obint_enable_bits, usb2_base + USB2_OBINTSTA);
+
+ ret = IRQ_HANDLED;
+
+ /* This should not happen! */
+ if (ch->otg_initializing)
+ goto unlock;
+
+ rcar_gen3_device_recognition(ch);
+ rcar_gen3_configure_vblvl_ctrl(ch);
}
+unlock:
+ spin_unlock_irqrestore(&ch->lock, flags);
rpm_put:
pm_runtime_put_noidle(dev);
return ret;
}
+static void rcar_gen3_phy_usb2_irqs_mask_all(struct rcar_gen3_chan *channel,
+ u32 *masked_irqs_bits)
+{
+ u32 val, bitmask = USB2_INT_ENABLE_UCOM_INTEN;
+ void __iomem *usb2_base = channel->base;
+
+ for (unsigned int i = 0; i < NUM_OF_PHYS; i++)
+ bitmask |= channel->rphys[i].int_enable_bits;
+
+ val = readl(usb2_base + USB2_INT_ENABLE);
+ *masked_irqs_bits = val & bitmask;
+ val &= ~bitmask;
+ writel(val, usb2_base + USB2_INT_ENABLE);
+
+ /*
+ * Don't report channel->phy_data->obint_enable_bits IRQs. These are
+ * unmasked anyway in rcar_gen3_init_otg_phase1().
+ */
+ val = readl(usb2_base + USB2_OBINTEN);
+ val &= ~channel->phy_data->obint_enable_bits;
+ writel(val, usb2_base + USB2_OBINTEN);
+}
+
+static void rcar_gen3_phy_usb2_irqs_unmask(struct rcar_gen3_chan *channel,
+ u32 irqs_bits)
+{
+ u32 val, bitmask = USB2_INT_ENABLE_UCOM_INTEN;
+ void __iomem *usb2_base = channel->base;
+
+ for (unsigned int i = 0; i < NUM_OF_PHYS; i++)
+ bitmask |= channel->rphys[i].int_enable_bits;
+
+ val = readl(usb2_base + USB2_INT_ENABLE);
+ val &= ~bitmask;
+ val |= irqs_bits;
+ writel(val, usb2_base + USB2_INT_ENABLE);
+}
+
static int rcar_gen3_phy_usb2_init(struct phy *p)
{
struct rcar_gen3_phy *rphy = phy_get_drvdata(p);
struct rcar_gen3_chan *channel = rphy->ch;
void __iomem *usb2_base = channel->base;
+ int retries = NUM_OF_PHYS;
+ unsigned long flags;
u32 val;
+ int ret;
- guard(spinlock_irqsave)(&channel->lock);
+ spin_lock_irqsave(&channel->lock, flags);
+
+ while (retries-- && channel->otg_initializing) {
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ ret = wait_event_timeout(channel->otg_init_done, !channel->otg_initializing,
+ USB2_OTG_INIT_TIMEOUT);
+ ret = ret ? 0 : -ETIMEDOUT;
+ if (ret && !retries)
+ return ret;
+
+ spin_lock_irqsave(&channel->lock, flags);
+ }
+
+ /* If another thread started a new initialization just return -EBUSY. */
+ if (channel->otg_initializing) {
+ ret = -EBUSY;
+ goto unlock;
+ } else {
+ ret = 0;
+ }
/* Initialize USB2 part */
val = readl(usb2_base + USB2_INT_ENABLE);
@@ -548,8 +670,23 @@ static int rcar_gen3_phy_usb2_init(struc
}
/* Initialize otg part (only if we initialize a PHY with IRQs). */
- if (rphy->int_enable_bits)
- rcar_gen3_init_otg(channel);
+ if (rphy->int_enable_bits && channel->is_otg_channel &&
+ !rcar_gen3_is_any_otg_rphy_initialized(channel)) {
+ u32 masked_irq_bits = 0;
+
+ rcar_gen3_init_otg_phase0(channel);
+ rcar_gen3_phy_usb2_irqs_mask_all(channel, &masked_irq_bits);
+ channel->otg_initializing = true;
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ fsleep(20000);
+
+ spin_lock_irqsave(&channel->lock, flags);
+ rcar_gen3_phy_usb2_irqs_unmask(channel, masked_irq_bits);
+ rcar_gen3_init_otg_phase1(channel);
+ channel->otg_initializing = false;
+ wake_up_all(&channel->otg_init_done);
+ }
if (channel->phy_data->vblvl_ctrl) {
/* SIDDQ mode release */
@@ -568,7 +705,10 @@ static int rcar_gen3_phy_usb2_init(struc
rphy->initialized = true;
- return 0;
+unlock:
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ return ret;
}
static int rcar_gen3_phy_usb2_exit(struct phy *p)
@@ -576,9 +716,32 @@ static int rcar_gen3_phy_usb2_exit(struc
struct rcar_gen3_phy *rphy = phy_get_drvdata(p);
struct rcar_gen3_chan *channel = rphy->ch;
void __iomem *usb2_base = channel->base;
+ int retries = NUM_OF_PHYS;
+ unsigned long flags;
u32 val;
+ int ret;
- guard(spinlock_irqsave)(&channel->lock);
+ spin_lock_irqsave(&channel->lock, flags);
+
+ while (retries-- && channel->otg_initializing) {
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ ret = wait_event_timeout(channel->otg_init_done, !channel->otg_initializing,
+ USB2_OTG_INIT_TIMEOUT);
+ ret = ret ? 0 : -ETIMEDOUT;
+ if (ret && !retries)
+ return ret;
+
+ spin_lock_irqsave(&channel->lock, flags);
+ }
+
+ /* If another thread started a new initialization just return -EBUSY. */
+ if (channel->otg_initializing) {
+ ret = -EBUSY;
+ goto unlock;
+ } else {
+ ret = 0;
+ }
rphy->initialized = false;
@@ -588,7 +751,9 @@ static int rcar_gen3_phy_usb2_exit(struc
val &= ~USB2_INT_ENABLE_UCOM_INTEN;
writel(val, usb2_base + USB2_INT_ENABLE);
- return 0;
+unlock:
+ spin_unlock_irqrestore(&channel->lock, flags);
+ return ret;
}
static int rcar_gen3_phy_usb2_power_on(struct phy *p)
@@ -596,8 +761,10 @@ static int rcar_gen3_phy_usb2_power_on(s
struct rcar_gen3_phy *rphy = phy_get_drvdata(p);
struct rcar_gen3_chan *channel = rphy->ch;
void __iomem *usb2_base = channel->base;
+ int retries = NUM_OF_PHYS;
+ unsigned long flags;
u32 val;
- int ret = 0;
+ int ret;
if (channel->vbus && !channel->otg_internal_reg) {
ret = regulator_enable(channel->vbus);
@@ -605,7 +772,27 @@ static int rcar_gen3_phy_usb2_power_on(s
return ret;
}
- guard(spinlock_irqsave)(&channel->lock);
+ spin_lock_irqsave(&channel->lock, flags);
+
+ while (retries-- && channel->otg_initializing) {
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ ret = wait_event_timeout(channel->otg_init_done, !channel->otg_initializing,
+ USB2_OTG_INIT_TIMEOUT);
+ ret = ret ? 0 : -ETIMEDOUT;
+ if (ret && !retries)
+ goto disable_regulator;
+
+ spin_lock_irqsave(&channel->lock, flags);
+ }
+
+ /* If another thread started a new initialization just return -EBUSY. */
+ if (channel->otg_initializing) {
+ ret = -EBUSY;
+ goto unlock;
+ } else {
+ ret = 0;
+ }
if (!rcar_gen3_are_all_rphys_power_off(channel))
goto out;
@@ -620,27 +807,59 @@ out:
/* The powered flag should be set for any other phys anyway */
rphy->powered = true;
- return 0;
+unlock:
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+disable_regulator:
+ if (ret && channel->vbus && !channel->otg_internal_reg)
+ regulator_disable(channel->vbus);
+
+ return ret;
}
static int rcar_gen3_phy_usb2_power_off(struct phy *p)
{
struct rcar_gen3_phy *rphy = phy_get_drvdata(p);
struct rcar_gen3_chan *channel = rphy->ch;
- int ret = 0;
+ int retries = NUM_OF_PHYS;
+ unsigned long flags;
+ int ret;
- scoped_guard(spinlock_irqsave, &channel->lock) {
- rphy->powered = false;
+ spin_lock_irqsave(&channel->lock, flags);
- if (rcar_gen3_are_all_rphys_power_off(channel)) {
- u32 val = readl(channel->base + USB2_USBCTR);
+ while (retries-- && channel->otg_initializing) {
+ spin_unlock_irqrestore(&channel->lock, flags);
- val |= USB2_USBCTR_PLL_RST;
- writel(val, channel->base + USB2_USBCTR);
- }
+ ret = wait_event_timeout(channel->otg_init_done, !channel->otg_initializing,
+ USB2_OTG_INIT_TIMEOUT);
+ ret = ret ? 0 : -ETIMEDOUT;
+ if (ret && !retries)
+ return ret;
+
+ spin_lock_irqsave(&channel->lock, flags);
+ }
+
+ /* If another thread started a new initialization just return -EBUSY. */
+ if (channel->otg_initializing) {
+ ret = -EBUSY;
+ goto unlock;
+ } else {
+ ret = 0;
+ }
+
+ rphy->powered = false;
+
+ if (rcar_gen3_are_all_rphys_power_off(channel)) {
+ u32 val = readl(channel->base + USB2_USBCTR);
+
+ val |= USB2_USBCTR_PLL_RST;
+ writel(val, channel->base + USB2_USBCTR);
}
- if (channel->vbus && !channel->otg_internal_reg)
+unlock:
+ spin_unlock_irqrestore(&channel->lock, flags);
+
+ if (!ret && channel->vbus && !channel->otg_internal_reg)
ret = regulator_disable(channel->vbus);
return ret;
@@ -1018,6 +1237,7 @@ static int rcar_gen3_phy_usb2_probe(stru
}
spin_lock_init(&channel->lock);
+ init_waitqueue_head(&channel->otg_init_done);
for (i = 0; i < NUM_OF_PHYS; i++) {
channel->rphys[i].phy = devm_phy_create(dev, NULL,
channel->phy_data->phy_usb2_ops);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 261/438] soundwire: dmi-quirks: Disable ghost Realtek on Asus GX651AX
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (259 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 260/438] swiotlb: use the adjusted address for the highmem page lookup Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 262/438] spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes Greg Kroah-Hartman
` (188 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ian Luites, Charles Keepax,
Vinod Koul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Luites <ian@luites.com>
commit 6d49beec658f61801e79019fd73691b17252dee3 upstream.
The Asus ROG Zephyrus Duo GX651AX exposes a Realtek RT722 device in
ACPI which does not exist in the physical hardware. The device remains
unattached while the CS42L43 and both CS35L56 devices attach
successfully.
This confuses the function topology machine driver into creating
duplicate DAI links named SDW3-Playback-SimpleJack, and the sof_sdw
probe fails with error -12. Add a model-specific quirk to remove the
ghost RT722 device.
Fixes: 45cf24da0a10 ("ASoC: Intel: soc-acpi-intel-ptl-match: Remove unnecessary cs42l43 match")
Cc: stable@vger.kernel.org # 7.2.x
Assisted-by: LLM
Signed-off-by: Ian Luites <ian@luites.com>
Reviewed-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Link: https://patch.msgid.link/20260831082534.224716-1-ian@luites.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/soundwire/dmi-quirks.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/soundwire/dmi-quirks.c
+++ b/drivers/soundwire/dmi-quirks.c
@@ -194,6 +194,13 @@ static const struct dmi_system_id adr_re
},
{
.matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "ASUS"),
+ DMI_MATCH(DMI_BOARD_NAME, "GX651AX"),
+ },
+ .driver_data = (void *)ghost_realtek,
+ },
+ {
+ .matches = {
DMI_MATCH(DMI_SYS_VENDOR, "LENOVO"),
DMI_MATCH(DMI_PRODUCT_NAME, "83SF"),
},
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 208/398] posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (205 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 207/398] phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 209/398] rds: ib: use rds_conn_drop() on protocol version mismatch Greg Kroah-Hartman
` (195 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kijo Park, Thomas Gleixner,
Frederic Weisbecker
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Gleixner <tglx@kernel.org>
commit c21eaa72f02fc6e85621cbe09d303d8fb8bd39cd upstream.
Kijo analyzed another race in the POSIX CPU timer code:
Commit bf635681c906 converted cpu_timer::firing from a tristate value to a
boolean. This lost the distinction between "not owned by the firing list"
and "still owned, but delivery was canceled". The resulting race is:
expiry handler timer_settime() timer_delete()
-------------- --------------- --------------
collect timer onto
private firing list
firing = true
observes firing = true
firing = false
return TIMER_RETRY
wait for handler
observes firing = false
finish deletion
unhash and free timer
resume list traversal
read freed elist.next
-> UAF
The firing bit is clearly the wrong indicator since that commit.
Check whether the timer is queued on the expiry list or not instead. If it
is queued clear the firing bit to prevent signal delivery as before and
return TIMER_RETRY so the caller unlocks the timer which allows the expiry
code to make progress and remove it from the list.
Fixes: bf635681c906 ("posix-cpu-timers: Cleanup the firing logic")
Reported-by: Kijo Park <red993688@gmail.com>
Debugged-by: Kijo Park <red993688@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Kijo Park <red993688@gmail.com>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/time/posix-cpu-timers.c | 40 ++++++++++++++++++++++------------------
1 file changed, 22 insertions(+), 18 deletions(-)
--- a/kernel/time/posix-cpu-timers.c
+++ b/kernel/time/posix-cpu-timers.c
@@ -408,6 +408,7 @@ static int posix_cpu_timer_create(struct
new_timer->kclock = &clock_posix_cpu;
timerqueue_init(&new_timer->it.cpu.node);
+ INIT_LIST_HEAD(&new_timer->it.cpu.elist);
new_timer->it.cpu.pid = get_pid(pid);
rcu_read_unlock();
return 0;
@@ -566,6 +567,24 @@ static struct task_struct *timer_lock_si
}
/*
+ * If the timer is queued on the expiry list, then it cannot be dequeued because
+ * the firing list is not protected by sighand->lock. The delivery path is
+ * waiting for the timer lock. So go back, unlock and retry.
+ */
+static bool posix_cpu_timer_on_expiry_list(struct k_itimer *timer)
+{
+ if (list_empty(&timer->it.cpu.elist))
+ return false;
+
+ /*
+ * Prevent signal delivery as there is no point in delivering a signal
+ * which is made obsolete right away.
+ */
+ timer->it.cpu.firing = false;
+ return true;
+}
+
+/*
* Clean up a CPU-clock timer that is about to be destroyed.
* This is called from timer deletion with the timer already locked.
* If we return TIMER_RETRY, it's necessary to release the timer's lock
@@ -580,18 +599,10 @@ static int posix_cpu_timer_del(struct k_
p = timer_lock_sighand(timer, &flags);
if (likely(p)) {
- if (timer->it.cpu.firing) {
- /*
- * Prevent signal delivery. The timer cannot be dequeued
- * because it is on the firing list which is not protected
- * by sighand->lock. The delivery path is waiting for
- * the timer lock. So go back, unlock and retry.
- */
- timer->it.cpu.firing = false;
+ if (posix_cpu_timer_on_expiry_list(timer))
ret = TIMER_RETRY;
- } else {
+ else
disarm_timer(timer, p);
- }
unlock_task_sighand(p, &flags);
}
@@ -731,14 +742,7 @@ static int posix_cpu_timer_set(struct k_
/* Retrieve the current expiry time before disarming the timer */
old_expires = cpu_timer_getexpires(ctmr);
- if (unlikely(timer->it.cpu.firing)) {
- /*
- * Prevent signal delivery. The timer cannot be dequeued
- * because it is on the firing list which is not protected
- * by sighand->lock. The delivery path is waiting for
- * the timer lock. So go back, unlock and retry.
- */
- timer->it.cpu.firing = false;
+ if (posix_cpu_timer_on_expiry_list(timer)) {
ret = TIMER_RETRY;
} else {
cpu_timer_dequeue(ctmr);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 262/438] spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (260 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 261/438] soundwire: dmi-quirks: Disable ghost Realtek on Asus GX651AX Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 263/438] spi: spi-zynqmp-gqspi: stop the controller on shutdown Greg Kroah-Hartman
` (187 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Frieder Schrempf, Han Xu, Mark Brown
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frieder Schrempf <frieder.schrempf@kontron.de>
commit 3d743adf090cd4c9a2120c1e02b0482e88aa0d2d upstream.
fsl_qspi_select_mem() returns early when the chip select has not changed,
which happens before it reaches clk_set_rate(). Since the rate is now
taken from the spi-mem operation rather than from the SPI device, the
controller honours op->max_freq exactly once per chip select and ignores
it for every operation after that.
q->selected is only reset to -1 in fsl_qspi_default_setup(), i.e. at probe
and on resume, so on the common single chip select board the very first
operation latches a rate that all subsequent operations inherit, whatever
frequency they asked for.
This results in operations being issued with the wrong frequency.
Cache the operation frequency the clock was programmed for next to the
selected chip select, and redo the clock setup when either changes.
Fixes: 2438db5253eb ("spi: fsl-qspi: Support per spi-mem operation frequency switches")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: Frieder Schrempf <frieder.schrempf@kontron.de>
Acked-by: Han Xu <han.xu@nxp.com>
Link: https://patch.msgid.link/20260917-fsl-qspi-freq-op-fix-v1-1-5fbe6b02f738@kontron.de
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/spi/spi-fsl-qspi.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/drivers/spi/spi-fsl-qspi.c
+++ b/drivers/spi/spi-fsl-qspi.c
@@ -289,6 +289,7 @@ struct fsl_qspi {
struct pm_qos_request pm_qos_req;
struct device *dev;
int selected;
+ u32 selected_freq;
u32 memmap_phy;
};
@@ -551,7 +552,8 @@ static void fsl_qspi_select_mem(struct f
unsigned long rate = op->max_freq;
int ret;
- if (q->selected == spi_get_chipselect(spi, 0))
+ if (q->selected == spi_get_chipselect(spi, 0) &&
+ q->selected_freq == op->max_freq)
return;
if (needs_4x_clock(q))
@@ -571,6 +573,7 @@ static void fsl_qspi_select_mem(struct f
}
q->selected = spi_get_chipselect(spi, 0);
+ q->selected_freq = op->max_freq;
fsl_qspi_invalidate(q);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 209/398] rds: ib: use rds_conn_drop() on protocol version mismatch
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (206 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 208/398] posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors Greg Kroah-Hartman
` (194 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, TencentOS Corvus AI,
Allison Henderson, Aohan Mei, Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aohan Mei <henrymei@tencent.com>
commit f97d8c7bab7843631206a114986c9059da03efeb upstream.
rds_ib_cm_connect_complete() runs from the RDMA-CM event handler with
conn->c_cm_lock held. When the peer negotiates a protocol version
older than RDS_PROTOCOL_COMPAT_VERSION, the handler calls
rds_conn_destroy(), which is only safe in the rmmod path: it
synchronously tears the connection down and flush_work()es the
shutdown work cp_down_w.
That shutdown work (rds_conn_shutdown()) needs cp_cm_lock, which is
the very lock the event handler still holds, so the flush never
completes: the two workers wait on each other and the RDS connection
workqueues stall for good.
All other RDMA-CM failure paths (REJECTED, CONNECT_ERROR,
DISCONNECTED) use rds_conn_drop(), which marks the connection
RDS_CONN_ERROR and schedules the shutdown work asynchronously. Use
it here as well.
Fixes: f147dd9ecabf ("RDS/IB: Disallow connections less than RDS 3.1")
Reported-by: TencentOS Corvus AI <corvus@tencent.com>
Cc: stable@vger.kernel.org
Reviewed-by: Allison Henderson <achender@kernel.org>
Signed-off-by: Aohan Mei <henrymei@tencent.com>
Link: https://patch.msgid.link/20260911073436.3542080-1-ljp1205831794@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/rds/ib_cm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/rds/ib_cm.c
+++ b/net/rds/ib_cm.c
@@ -115,7 +115,7 @@ void rds_ib_cm_connect_complete(struct r
&conn->c_laddr, &conn->c_faddr,
RDS_PROTOCOL_MAJOR(conn->c_version),
RDS_PROTOCOL_MINOR(conn->c_version));
- rds_conn_destroy(conn);
+ rds_conn_drop(conn);
return;
}
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 263/438] spi: spi-zynqmp-gqspi: stop the controller on shutdown
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (261 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 262/438] spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 264/438] spi: virtio: Use the per-transfer bits per word Greg Kroah-Hartman
` (186 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Itai Handler, Mark Brown
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Itai Handler <itai.handler@gmail.com>
commit e922bad8b2d5028c51a096d083fea41cd0987154 upstream.
The driver has no ->shutdown, and platform_drv_shutdown() has no
fallback of its own. Unlike pci_device_shutdown(), which clears bus
mastering when kexec_in_progress, nothing on the platform bus disarms a
device that can still write to memory. The normal kexec path never
calls ->suspend either, so the quiesce in zynqmp_qspi_suspend() is not
reached.
A controller that is still executing a DMA read may therefore keep
writing to memory across a kexec. QSPIDMA_DST_ADDR still points at
memory owned by the kernel that called kexec, DST_SIZE is non-zero and
the flash is still clocked, so data can keep landing in RAM while the
new kernel is being relocated, and after it has started executing.
That destination is a physical address which means nothing to the new
kernel, so the writes can corrupt whatever now occupies it: kernel text
or data, page tables, or the initrd. Nothing reports an error and the
resulting behaviour is undefined.
This can be observed by reading GQSPI_EN (offset 0x114) and
QSPIDMA_DST_ADDR/SIZE/STS/CTRL (offsets 0x800 to 0x80c) early in the new
kernel, before the driver probes: without this patch GQSPI_EN reads 1
and QSPIDMA_DST_ADDR still points into the previous kernel's memory.
Add a ->shutdown that stops the controller the way zynqmp_qspi_suspend()
already does. spi_controller_suspend() stops the queue, waits for a
message that is already executing and makes any later transfer fail with
-ESHUTDOWN, so nothing can be cut short by the register write that
follows. It may sleep, which is fine here: device_shutdown() runs in
process context. Unlike ->suspend this cannot abort on error, because a
controller left mastering the bus is worse than a truncated transfer, so
a failure to drain is only logged.
GQSPI_EN_OFST is then cleared, as zynqmp_qspi_remove() and
zynqmp_qspi_suspend() already do. Skip that write only when
pm_runtime_get_if_in_use() returns 0, i.e. runtime suspended: the clocks
are gated, so the registers are unreachable and the controller cannot be
mastering the bus. A negative return is not the same thing - it is what
the CONFIG_PM=n stub always returns, and there probe() has enabled pclk
and refclk for good, so the controller is running and must be stopped.
Fixes: dfe11a11d523 ("spi: Add support for Zynq Ultrascale+ MPSoC GQSPI controller")
Cc: stable@vger.kernel.org
Signed-off-by: Itai Handler <itai.handler@gmail.com>
Link: https://patch.msgid.link/20260910174832.873352-1-itai.handler@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/spi/spi-zynqmp-gqspi.c | 34 ++++++++++++++++++++++++++++++++++
1 file changed, 34 insertions(+)
--- a/drivers/spi/spi-zynqmp-gqspi.c
+++ b/drivers/spi/spi-zynqmp-gqspi.c
@@ -1374,11 +1374,45 @@ static void zynqmp_qspi_remove(struct pl
clk_disable_unprepare(xqspi->pclk);
}
+static void zynqmp_qspi_shutdown(struct platform_device *pdev)
+{
+ struct zynqmp_qspi *xqspi = platform_get_drvdata(pdev);
+ int ret;
+
+ /*
+ * Stop the queue and reject any later transfer first, so the write
+ * below cannot cut into a message that is still being executed.
+ * Unlike ->suspend this cannot abort on error: a controller left
+ * mastering the bus is worse than a truncated transfer.
+ */
+ ret = spi_controller_suspend(xqspi->ctlr);
+ if (ret)
+ dev_warn(&pdev->dev, "could not stop the queue: %d\n", ret);
+
+ /*
+ * Only a runtime suspended controller can be left alone: its clocks
+ * are gated, so it cannot be mastering the bus, and its registers
+ * must not be accessed either. Any other answer means it may be
+ * running and has to be stopped. In particular, on a kernel built
+ * without runtime PM this returns -EINVAL, and there the clocks
+ * enabled in probe() are never gated at all.
+ */
+ ret = pm_runtime_get_if_in_use(&pdev->dev);
+ if (!ret)
+ return;
+
+ zynqmp_gqspi_write(xqspi, GQSPI_EN_OFST, 0x0);
+
+ if (ret > 0)
+ pm_runtime_put_noidle(&pdev->dev);
+}
+
MODULE_DEVICE_TABLE(of, zynqmp_qspi_of_match);
static struct platform_driver zynqmp_qspi_driver = {
.probe = zynqmp_qspi_probe,
.remove = zynqmp_qspi_remove,
+ .shutdown = zynqmp_qspi_shutdown,
.driver = {
.name = "zynqmp-qspi",
.of_match_table = zynqmp_qspi_of_match,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (207 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 209/398] rds: ib: use rds_conn_drop() on protocol version mismatch Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-28 4:41 ` springbreeze
2026-09-23 14:04 ` [PATCH 6.18 211/398] Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware" Greg Kroah-Hartman
` (193 subsequent siblings)
402 siblings, 1 reply; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chunfeng Song, FUJITA Tomonori,
Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chunfeng Song <springbreeze@stu.pku.edu.cn>
commit 6fb0a9d9071f1ff0cc5cfc0782302d9c90d642cb upstream.
The hand-written bitfield offsets in is_link_up(), is_autoneg_enabled()
and is_autoneg_completed() were correct when the abstraction was
merged: at that time autoneg, link, and autoneg_complete were at bits
13, 14, and 15 of struct phy_device's first bitfield unit. Commit
2796ff1e3dca ("net: phy: add flag is_genphy_driven to struct phy_device")
later inserted is_genphy_driven just before autoneg, shifting the three
fields up by one, so the accessors now read:
is_link_up() reads bit 14 = autoneg
is_autoneg_enabled() reads bit 13 = is_genphy_driven
is_autoneg_completed() reads bit 15 = link
The official ax88796b Rust driver uses all three accessors in its
read_status() implementation, so it inherits the bug.
phy_attach_direct() sets is_genphy_driven only when it falls back to
the generic driver, and ax88796b has a real driver, so
is_genphy_driven stays 0. The broken is_autoneg_enabled() therefore
reads bit 13 as 0, compares it against AUTONEG_ENABLE (1), and always
returns false, so read_status() never reaches the
resolve_aneg_linkmode() call.
The ordinary bindgen accessors take &self. Calling them through
(*phydev).link() would create a shared reference to the complete
bindings::phy_device, which is not appropriate for an object wrapped in
Opaque.
Use the bindgen-generated raw accessors (link_raw(), autoneg_raw(),
and autoneg_complete_raw()) instead. They retain the bit positions and
endianness handling generated from the C layout without creating a Rust
reference to the complete phy_device. Drop the hand-written numbers
together with the TODO comment that marked them as a stopgap.
The raw accessors are only emitted by bindgen 0.71 and later, and were
added at the Rust-for-Linux project's request, so this fix can only be
backported to stable branches whose minimum bindgen version is at least
that, hence the scope on the Cc: stable line below.
Found by a static equivalence audit (C2RustDrv, a C-to-Rust driver
migration tool) that compares hand-written bitfield offsets against
the bindgen layout of struct phy_device. Verified by building the
bindings and checking the generated accessors; no runtime testing was
possible without PHY hardware.
Fixes: 2796ff1e3dca ("net: phy: add flag is_genphy_driven to struct phy_device")
Cc: stable@vger.kernel.org # Only 7.1.y and later (requires bindgen's raw pointer accessors).
Link: https://github.com/rust-lang/rust-bindgen/issues/2674
Signed-off-by: Chunfeng Song <springbreeze@stu.pku.edu.cn>
Reviewed-by: FUJITA Tomonori <fujita.tomonori@gmail.com>
Link: https://patch.msgid.link/20260910055110.167110-1-springbreeze@stu.pku.edu.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
rust/kernel/net/phy.rs | 38 ++++++++++++++++++--------------------
1 file changed, 18 insertions(+), 20 deletions(-)
diff --git a/rust/kernel/net/phy.rs b/rust/kernel/net/phy.rs
index 956cda573ddb..c4e7b1d6c6f4 100644
--- a/rust/kernel/net/phy.rs
+++ b/rust/kernel/net/phy.rs
@@ -123,39 +123,37 @@ pub fn state(&self) -> DeviceState {
/// Gets the current link state.
///
/// It returns true if the link is up.
+ #[inline]
pub fn is_link_up(&self) -> bool {
- const LINK_IS_UP: u64 = 1;
- // TODO: the code to access to the bit field will be replaced with automatically
- // generated code by bindgen when it becomes possible.
- // SAFETY: The struct invariant ensures that we may access
- // this field without additional synchronization.
- let bit_field = unsafe { &(*self.0.get())._bitfield_1 };
- bit_field.get(14, 1) == LINK_IS_UP
+ let phydev = self.0.get().cast_const();
+ // SAFETY: By the type invariant of `Device`, `phydev` points to a valid
+ // `struct phy_device`, and there is no concurrent write to this field.
+ let link = unsafe { bindings::phy_device::link_raw(phydev) };
+ link == 1
}
/// Gets the current auto-negotiation configuration.
///
/// It returns true if auto-negotiation is enabled.
+ #[inline]
pub fn is_autoneg_enabled(&self) -> bool {
- // TODO: the code to access to the bit field will be replaced with automatically
- // generated code by bindgen when it becomes possible.
- // SAFETY: The struct invariant ensures that we may access
- // this field without additional synchronization.
- let bit_field = unsafe { &(*self.0.get())._bitfield_1 };
- bit_field.get(13, 1) == u64::from(bindings::AUTONEG_ENABLE)
+ let phydev = self.0.get().cast_const();
+ // SAFETY: By the type invariant of `Device`, `phydev` points to a valid
+ // `struct phy_device`, and there is no concurrent write to this field.
+ let autoneg = unsafe { bindings::phy_device::autoneg_raw(phydev) };
+ autoneg == bindings::AUTONEG_ENABLE
}
/// Gets the current auto-negotiation state.
///
/// It returns true if auto-negotiation is completed.
+ #[inline]
pub fn is_autoneg_completed(&self) -> bool {
- const AUTONEG_COMPLETED: u64 = 1;
- // TODO: the code to access to the bit field will be replaced with automatically
- // generated code by bindgen when it becomes possible.
- // SAFETY: The struct invariant ensures that we may access
- // this field without additional synchronization.
- let bit_field = unsafe { &(*self.0.get())._bitfield_1 };
- bit_field.get(15, 1) == AUTONEG_COMPLETED
+ let phydev = self.0.get().cast_const();
+ // SAFETY: By the type invariant of `Device`, `phydev` points to a valid
+ // `struct phy_device`, and there is no concurrent write to this field.
+ let completed = unsafe { bindings::phy_device::autoneg_complete_raw(phydev) };
+ completed == 1
}
/// Sets the speed of the PHY.
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 264/438] spi: virtio: Use the per-transfer bits per word
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (262 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 263/438] spi: spi-zynqmp-gqspi: stop the controller on shutdown Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 265/438] RDMA/ucma: Serialize join and leave on copy_to_user failure Greg Kroah-Hartman
` (185 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hao-Qun Huang, Mark Brown
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hao-Qun Huang <alvinhuang0603@gmail.com>
commit 095858324f063dba830041f067872f0a08765d2f upstream.
virtio_spi_transfer_one() puts spi->bits_per_word into the request
header, so a transfer that sets its own word size reaches the backend
with the device default instead. The SPI core has already copied that
default into xfer->bits_per_word when the transfer leaves it at zero,
the same way it does for xfer->speed_hz, which this function already
uses.
Per-transfer word sizes are ordinary SPI usage. mipi_dbi, for one, sends
a 9-bit command and reads the reply as 8-bit data in the same message.
With a 16-bit device default, a one-byte transfer asking for 8 bits goes
out as a partial 16-bit word, which the backend may reject.
Fixes: f98cabe3f6cf ("SPI: Add virtio SPI driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Hao-Qun Huang <alvinhuang0603@gmail.com>
Link: https://patch.msgid.link/20260913032049.11209.alvinhuang0603@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/spi/spi-virtio.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/spi/spi-virtio.c
+++ b/drivers/spi/spi-virtio.c
@@ -168,7 +168,7 @@ static int virtio_spi_transfer_one(struc
/* Fill struct spi_transfer_head */
th->chip_select_id = spi_get_chipselect(spi, 0);
- th->bits_per_word = spi->bits_per_word;
+ th->bits_per_word = xfer->bits_per_word;
th->cs_change = xfer->cs_change;
th->tx_nbits = xfer->tx_nbits;
th->rx_nbits = xfer->rx_nbits;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 211/398] Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware"
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (208 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 212/398] drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini() Greg Kroah-Hartman
` (192 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lyude Paul, Dave Airlie
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lyude Paul <lyude@redhat.com>
commit a5c41fa7f925fda2db394329fa0b26243fa63a81 upstream.
This reverts commit 8302d0afeaec0bc57d951dd085e0cffe997d4d18.
It turns out this looked like the right fix on some systems, but it's not -
as this causes runtime PM to actually fail on many a laptop.
Fixes: 8302d0afeaec ("nouveau/gsp: fix suspend/resume regression on r570 firmware")
Cc: <stable@vger.kernel.org> # v6.19+
Signed-off-by: Lyude Paul <lyude@redhat.com>
Reviewed-by: Dave Airlie <airlied@redhat.com>
Link: https://patch.msgid.link/20260814194542.781955-2-lyude@redhat.com
(cherry picked from commit 94097122bfd701976bc1a62ccd434c13f3f67cde)
Signed-off-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/fbsr.c | 2 +-
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c | 2 +-
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c | 8 ++++----
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h | 2 +-
4 files changed, 7 insertions(+), 7 deletions(-)
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/fbsr.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/fbsr.c
@@ -208,7 +208,7 @@ r535_fbsr_resume(struct nvkm_gsp *gsp)
}
static int
-r535_fbsr_suspend(struct nvkm_gsp *gsp, bool runtime)
+r535_fbsr_suspend(struct nvkm_gsp *gsp)
{
struct nvkm_subdev *subdev = &gsp->subdev;
struct nvkm_device *device = subdev->device;
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c
@@ -1748,7 +1748,7 @@ r535_gsp_fini(struct nvkm_gsp *gsp, enum
sr->sysmemAddrOfSuspendResumeData = gsp->sr.radix3.lvl0.addr;
sr->sizeOfSuspendResumeData = len;
- ret = rm->api->fbsr->suspend(gsp, suspend == NVKM_RUNTIME_SUSPEND);
+ ret = rm->api->fbsr->suspend(gsp);
if (ret) {
nvkm_gsp_mem_dtor(&gsp->sr.meta);
nvkm_gsp_radix3_dtor(gsp, &gsp->sr.radix3);
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c
@@ -62,7 +62,7 @@ r570_fbsr_resume(struct nvkm_gsp *gsp)
}
static int
-r570_fbsr_init(struct nvkm_gsp *gsp, struct sg_table *sgt, u64 size, bool runtime)
+r570_fbsr_init(struct nvkm_gsp *gsp, struct sg_table *sgt, u64 size)
{
NV2080_CTRL_INTERNAL_FBSR_INIT_PARAMS *ctrl;
struct nvkm_gsp_object memlist;
@@ -81,7 +81,7 @@ r570_fbsr_init(struct nvkm_gsp *gsp, str
ctrl->hClient = gsp->internal.client.object.handle;
ctrl->hSysMem = memlist.handle;
ctrl->sysmemAddrOfSuspendResumeData = gsp->sr.meta.addr;
- ctrl->bEnteringGcoffState = runtime ? 1 : 0;
+ ctrl->bEnteringGcoffState = 1;
ret = nvkm_gsp_rm_ctrl_wr(&gsp->internal.device.subdevice, ctrl);
if (ret)
@@ -92,7 +92,7 @@ r570_fbsr_init(struct nvkm_gsp *gsp, str
}
static int
-r570_fbsr_suspend(struct nvkm_gsp *gsp, bool runtime)
+r570_fbsr_suspend(struct nvkm_gsp *gsp)
{
struct nvkm_subdev *subdev = &gsp->subdev;
struct nvkm_device *device = subdev->device;
@@ -133,7 +133,7 @@ r570_fbsr_suspend(struct nvkm_gsp *gsp,
return ret;
/* Initialise FBSR on RM. */
- ret = r570_fbsr_init(gsp, &gsp->sr.fbsr, size, runtime);
+ ret = r570_fbsr_init(gsp, &gsp->sr.fbsr, size);
if (ret) {
nvkm_gsp_sg_free(device, &gsp->sr.fbsr);
return ret;
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h
@@ -79,7 +79,7 @@ struct nvkm_rm_api {
} *device;
const struct nvkm_rm_api_fbsr {
- int (*suspend)(struct nvkm_gsp *, bool runtime);
+ int (*suspend)(struct nvkm_gsp *);
void (*resume)(struct nvkm_gsp *);
} *fbsr;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 265/438] RDMA/ucma: Serialize join and leave on copy_to_user failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (263 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 264/438] spi: virtio: Use the per-transfer bits per word Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 266/438] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() Greg Kroah-Hartman
` (184 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+a6ffe86390c8a6afc818,
Quanye Yang, Leon Romanovsky
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Quanye Yang <quanyeyang@proton.me>
commit 662ade4de9ff5eceb0820a9f8e9fac70ba6a815b upstream.
rdma_join_multicast() queues RoCE work that later reads the ucma_multicast
through event->param.ud.private_data, then list_add()s the CMA multicast
at the head of id_priv->mc_list. rdma_leave_multicast() matches only by
sockaddr and destroys the first hit.
ucma_process_join() used to drop ctx->mutex after a successful join and
retake it only if copy_to_user() failed. Two concurrent JOIN_MCAST calls
with the same address can therefore insert a second CMA entry before the
first thread's leave. leave then cancels the newer work and the older
worker still dereferences the ucma_multicast that the first thread frees.
Keep ctx->mutex held from rdma_join_multicast() through copy_to_user() and,
on -EFAULT, through rdma_leave_multicast() so leave cannot miss this join.
Do not leave if join itself failed: that path never published this address
on mc_list, and a leave-by-addr would destroy an earlier successful join.
Reported-by: syzbot+a6ffe86390c8a6afc818@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=a6ffe86390c8a6afc818
Fixes: fe454dc31e84 ("RDMA/ucma: Fix use-after-free bug in ucma_create_uevent")
Cc: stable@vger.kernel.org
Signed-off-by: Quanye Yang <quanyeyang@proton.me>
Link: https://patch.msgid.link/20260831-rdma-ucma-mc-uaf-v1-1-b8eeb7046aff@proton.me
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/core/ucma.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
--- a/drivers/infiniband/core/ucma.c
+++ b/drivers/infiniband/core/ucma.c
@@ -1556,9 +1556,10 @@ static ssize_t ucma_process_join(struct
mutex_lock(&ctx->mutex);
ret = rdma_join_multicast(ctx->cm_id, (struct sockaddr *)&mc->addr,
join_state, mc);
- mutex_unlock(&ctx->mutex);
- if (ret)
+ if (ret) {
+ mutex_unlock(&ctx->mutex);
goto err_xa_erase;
+ }
resp.id = mc->id;
if (copy_to_user(u64_to_user_ptr(cmd->response),
@@ -1566,6 +1567,7 @@ static ssize_t ucma_process_join(struct
ret = -EFAULT;
goto err_leave_multicast;
}
+ mutex_unlock(&ctx->mutex);
xa_store(&multicast_table, mc->id, mc, 0);
@@ -1573,7 +1575,6 @@ static ssize_t ucma_process_join(struct
return 0;
err_leave_multicast:
- mutex_lock(&ctx->mutex);
rdma_leave_multicast(ctx->cm_id, (struct sockaddr *) &mc->addr);
mutex_unlock(&ctx->mutex);
ucma_cleanup_mc_events(mc);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 212/398] drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (209 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 211/398] Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware" Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 213/398] drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr Greg Kroah-Hartman
` (191 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lyude Paul, Dave Airlie
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lyude Paul <lyude@redhat.com>
commit bbb9293c9bb792f3f16c842f223b8c97bdbaf227 upstream.
As it turns out, Turing isn't the only architecture that needs this. On
this Dell Precision 7780 with an AD103 GPU, along with pretty much every
other laptop I tested, runtime PM is still somewhat unreliable. At first
glance it seems as if it's fixed, but lowering the autosuspend delay to
500ms and then doing a stress test of suspend/resume cycles on the GPU ends
up causing everything to start timing out.
After quite a lot of digging, I eventually landed back on this magic
timeout in r535_gsp_fini(). As it turns out, increasing the timeout ends up
fixing the runtime PM issues as far as I can tell, even during intense
stress testing.
Unfortunately after spending quite a bit of time trying to dig through
OpenRM to figure out what this magic sleep is actually doing, I've also
come up short with any reasonable explanation. In lieu of that, I'm going
to include the observations I did make while trying to figure this out in
hopes someone eventually does figure this out:
* The magic sleep has to occur after fbsr is initialized. Performing it at
any time before that doesn't appear to work.
* In situations where runtime PM starts getting flaky, some rather
interesting visual effects end up happening on occasion before the GPU
fully falls over. In particular, squares that look like the result of an
incomplete blitting operation to a tiled buffer end up showing up on
applications like vkcube. Interestingly enough, they remain in precisely
the same place between runtime PM cycles until the GPU falls over - even
when restarting vkcube multiple times, and even when vkcube is actively
updating the screen. Even more interestingly, they're not limited to a
specific framebuffer - you can see the squares changing as the cube
rotates around.
We cannot however, say that this is likely to be a incomplete fbsr
operation. The magic sleep happens before fbsr is actually saved (which
happens on the GSP unload), so it's something else.
* During a short bit of testing with a desktop that I have, the magic sleep
seemed to make no difference to whether or not suspend/resume works. It
seems to generally work almost always. So we can assume this is likely
exclusive to runtime PM, not S3.
As well, here's a list of the things I tried before settling on the magic
sleep:
* Hooking up NV2080_CTRL_CMD_INTERNAL_GCX_ENTRY_PREREQUISITE and then
blocking runtime PM until OpenRM signals that GC6/GCOFF is ready appears
to make no difference.
* Hooking up some (maybe not all, unsure about that part) bits of comptag
saving including:
* Fetching static memsys information from GSP
* Adding the size of the comptag storage to the fbsr data
* Adding a GA103+ workaround for disabling raw compression mode during
fbsr (it doesn't seem like it applies for any systems I tried it on
anyhow)
* Setting bPreserveVideoMemoryAllocations=1 in GspSystemInfo
So, until we can figure this out properly - just sleep for longer.
Signed-off-by: Lyude Paul <lyude@redhat.com>
Fixes: 53dac0623853 ("drm/nouveau/gsp: add support for 570.144")
Cc: <stable@vger.kernel.org> # v6.16+
Reviewed-by: Dave Airlie <airlied@redhat.com>
Link: https://patch.msgid.link/20260814194542.781955-5-lyude@redhat.com
(cherry picked from commit 09b47186a4164f3aaa3591313f80794443117342)
Signed-off-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/gsp.c
@@ -1760,8 +1760,12 @@ r535_gsp_fini(struct nvkm_gsp *gsp, enum
* TODO: Debug the GSP firmware / RPC handling to find out why
* without this Turing (but none of the other architectures)
* ends up resetting all channels after resume.
+ * Additionally, runtime suspend on other architectures quickly
+ * becomes unreliable without this sleep. If you're experiencing
+ * issues with runtime suspend, try bumping this delay up and
+ * sending a patch if it fixes your GPU.
*/
- msleep(50);
+ msleep(200);
}
ret = r535_gsp_rpc_unloading_guest_driver(gsp, suspend);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 266/438] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (264 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 265/438] RDMA/ucma: Serialize join and leave on copy_to_user failure Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 267/438] openvswitch: avoid reallocating confirmed conntrack labels Greg Kroah-Hartman
` (183 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+bd317784d628820741b5,
Jeffin Philip, Leon Romanovsky
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeffin Philip <jeffinphilip14@gmail.com>
commit 33fb59da49c4c3f5c2ec9f9d4447a56857a02c02 upstream.
iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail()
making it accessible to global list where another CPU can kref_get()
on nlmsg_request causing a refcount "addition on 0" bug. Fix this
by initializing kref _before_ list_add_tail() so refcount for
nlmsg_request can be incremented/decremented normally. In addition,
also initialize every field before list_add_tail().
Reported-by: syzbot+bd317784d628820741b5@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=bd317784d628820741b5
Fixes: 30dc5e63d6a5 ("RDMA/core: Add support for iWARP Port Mapper user space service")
Cc: stable@vger.kernel.org
Signed-off-by: Jeffin Philip <jeffinphilip14@gmail.com>
Link: https://patch.msgid.link/20260904131437.12917-1-jeffinphilip14@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/core/iwpm_util.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
--- a/drivers/infiniband/core/iwpm_util.c
+++ b/drivers/infiniband/core/iwpm_util.c
@@ -314,10 +314,6 @@ struct iwpm_nlmsg_request *iwpm_get_nlms
if (!nlmsg_request)
return NULL;
- spin_lock_irqsave(&iwpm_nlmsg_req_lock, flags);
- list_add_tail(&nlmsg_request->inprocess_list, &iwpm_nlmsg_req_list);
- spin_unlock_irqrestore(&iwpm_nlmsg_req_lock, flags);
-
kref_init(&nlmsg_request->kref);
kref_get(&nlmsg_request->kref);
nlmsg_request->nlmsg_seq = nlmsg_seq;
@@ -326,6 +322,11 @@ struct iwpm_nlmsg_request *iwpm_get_nlms
nlmsg_request->err_code = 0;
sema_init(&nlmsg_request->sem, 1);
down(&nlmsg_request->sem);
+
+ spin_lock_irqsave(&iwpm_nlmsg_req_lock, flags);
+ list_add_tail(&nlmsg_request->inprocess_list, &iwpm_nlmsg_req_list);
+ spin_unlock_irqrestore(&iwpm_nlmsg_req_lock, flags);
+
return nlmsg_request;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 213/398] drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (210 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 212/398] drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 214/398] drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP Greg Kroah-Hartman
` (190 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lyude Paul, Dave Airlie
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lyude Paul <lyude@redhat.com>
commit 12f6eff11ccf9cad3b2dfcdd94184fdb9ffface2 upstream.
Previously, it looked as if we were able to fix suspend/resume on some
desktops by setting Gcoff based on whether or not we were entering runtime
PM. This was a mistake though - the only time suspend/resume would end up
actually working was if Gcoff = 0.
It seems like it's likely the main reason for this is the FBSR GcOff
argument actually controls GSP's behavior with regards to which buffers it
decides to save across suspend/resume. When GcOff = 1, RM reserved regions
are saved unless they are marked as LOST_ON_SUSPEND, and RM channel-context
and kernel-client buffers are also saved -including- when they are
LOST_ON_SUSPEND. This means with GcOff = 1, we end up having GSP save and
restore buffers that actually need to be reinitialized on resume - causing
the failures we're setting.
Thanks to John Hubbard from Nvidia for providing some background on what
these options do in the GSP firmware do!
Signed-off-by: Lyude Paul <lyude@redhat.com>
Fixes: 53dac0623853 ("drm/nouveau/gsp: add support for 570.144")
Cc: <stable@vger.kernel.org> # v6.16+
Reviewed-by: Dave Airlie <airlied@redhat.com>
Link: https://patch.msgid.link/20260814194542.781955-3-lyude@redhat.com
(cherry picked from commit c7abe771e013848970421e5ca29c6b2f05c31965)
Signed-off-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c
index 2945d5b4e570..af5aa5065c3d 100644
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/fbsr.c
@@ -81,7 +81,7 @@ r570_fbsr_init(struct nvkm_gsp *gsp, struct sg_table *sgt, u64 size)
ctrl->hClient = gsp->internal.client.object.handle;
ctrl->hSysMem = memlist.handle;
ctrl->sysmemAddrOfSuspendResumeData = gsp->sr.meta.addr;
- ctrl->bEnteringGcoffState = 1;
+ ctrl->bEnteringGcoffState = 0;
ret = nvkm_gsp_rm_ctrl_wr(&gsp->internal.device.subdevice, ctrl);
if (ret)
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 267/438] openvswitch: avoid reallocating confirmed conntrack labels
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (265 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 266/438] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 268/438] nfsd: fix handling of NFSEXP_PNFS in the netlink codepath Greg Kroah-Hartman
` (182 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Ilya Maximets,
Aaron Conole, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit 3f118c8217c109fd13ca61caa301d72c483897ef upstream.
ovs_ct_get_conn_labels() adds the labels extension when a conntrack
entry does not have one. Confirmed conntracks can be read locklessly,
so adding an extension may reallocate and free the extension block
while another CPU accesses it.
Only add the extension for unconfirmed conntracks. A confirmed
conntrack without labels now fails the caller's label operation instead
of reallocating its extension storage.
Fixes: c2ac66735870 ("openvswitch: Allow matching on conntrack label")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/372fbb062b40ae6723684f55484be86ff0064f8e.1789218015.git.zhilinz@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/openvswitch/conntrack.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/openvswitch/conntrack.c
+++ b/net/openvswitch/conntrack.c
@@ -366,7 +366,7 @@ static struct nf_conn_labels *ovs_ct_get
struct nf_conn_labels *cl;
cl = nf_ct_labels_find(ct);
- if (!cl) {
+ if (!cl && !nf_ct_is_confirmed(ct)) {
nf_ct_labels_ext_add(ct);
cl = nf_ct_labels_find(ct);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 214/398] drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (211 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 213/398] drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 215/398] x86/build/64: Prevent native builds from generating EGPR use Greg Kroah-Hartman
` (189 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Lyude Paul, Dave Airlie
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lyude Paul <lyude@redhat.com>
commit 24fbd6d4bcf3363ef13ebe0d36dea93f30396c6d upstream.
There's two flags that we've never been setting when asking GSP to suspend
the GPU, which OpenRM does set:
GPU_STATE_FLAGS_PRESERVING
GPU_STATE_FLAGS_PM_TRANSITION
These flags aren't -supposed- to do much in GSP, they're mostly used by
OpenRM itself for state tracking. The only thing they do from GSP's side is
control whether or not a single display related workaround is applied
during suspend.
But as it turns out, that single workaround is actually quite crucial for
getting runtime PM working with nouveau - and without it set we end up
seeing a lot more failures with runtime PM resume. So, let's start setting
it.
Signed-off-by: Lyude Paul <lyude@redhat.com>
Fixes: 53dac0623853 ("drm/nouveau/gsp: add support for 570.144")
Cc: <stable@vger.kernel.org> # v6.16+
Reviewed-by: Dave Airlie <airlied@redhat.com>
Link: https://patch.msgid.link/20260814194542.781955-4-lyude@redhat.com
(cherry picked from commit ca57629b3eb912c77bc4357178a2130ea6c2d6df)
Signed-off-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c | 3 ++-
.../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/gsp.h | 8 ++++++++
2 files changed, 10 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c
index 1488771c63fc..b45781cd0dfd 100644
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c
@@ -207,7 +207,8 @@ r570_gsp_set_rmargs(struct nvkm_gsp *gsp, bool resume)
args->srInitArguments.bInPMTransition = 0;
} else {
args->srInitArguments.oldLevel = NV2080_CTRL_GPU_SET_POWER_STATE_GPU_LEVEL_3;
- args->srInitArguments.flags = 0;
+ args->srInitArguments.flags =
+ GPU_STATE_FLAGS_PRESERVING | GPU_STATE_FLAGS_PM_TRANSITION;
args->srInitArguments.bInPMTransition = 1;
}
diff --git a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/gsp.h b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/gsp.h
index b6075021e74f..c458569af9d7 100644
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/gsp.h
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/gsp.h
@@ -523,6 +523,14 @@ typedef struct
#define NV2080_CTRL_GPU_SET_POWER_STATE_GPU_LEVEL_3 (0x00000003U)
+#define GPU_STATE_FLAGS_PRESERVING BIT(0) // GPU state is preserved
+#define GPU_STATE_FLAGS_VGA_TRANSITION BIT(1) // To be used with GPU_STATE_FLAGS_PRESERVING.
+#define GPU_STATE_FLAGS_PM_TRANSITION BIT(2) // To be used with GPU_STATE_FLAGS_PRESERVING.
+#define GPU_STATE_FLAGS_PM_SUSPEND BIT(3)
+#define GPU_STATE_FLAGS_PM_HIBERNATE BIT(4)
+#define GPU_STATE_FLAGS_GC6_TRANSITION BIT(5) // To be used with GPU_STATE_FLAGS_PRESERVING.
+#define GPU_STATE_FLAGS_FAST_UNLOAD BIT(6) // Used during windows restart, skips stateDestroy steps
+
typedef struct
{
// Magic for verification by secure ucode
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 268/438] nfsd: fix handling of NFSEXP_PNFS in the netlink codepath
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (266 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 267/438] openvswitch: avoid reallocating confirmed conntrack labels Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 269/438] net: xfrm: reject unrepresentable espintcp transport headers Greg Kroah-Hartman
` (181 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Olga Kornievskaia,
Jeff Layton, Chuck Lever
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Layton <jlayton@kernel.org>
commit f76017a7663c4ce5e379f8a8d39f032bdb1fd865 upstream.
The rework of how block layouts were checked moved the check for
NFSEXP_PNFS out of nfsd4_setup_layout_type() and into the callers. That
patch didn't account for the new call in nfsd4_setup_layout_type().
Cc: Christoph Hellwig <hch@lst.de>
Fixes: da9baa5470dc ("exportfs,nfsd: rework checking for layout-based block device access support")
Cc: stable@vger.kernel.org
Reported-by: Olga Kornievskaia <okorniev@redhat.com>
Signed-off-by: Jeff Layton <jlayton@kernel.org>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Link: https://patch.msgid.link/20260414-pnfs-exp-fix-v1-1-9face14c16c2@kernel.org
Signed-off-by: Chuck Lever <cel@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/nfsd/export.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/nfsd/export.c b/fs/nfsd/export.c
index a47c90f40422..1f678583f612 100644
--- a/fs/nfsd/export.c
+++ b/fs/nfsd/export.c
@@ -1006,7 +1006,8 @@ static int nfsd_nl_parse_one_export(struct cache_detail *cd,
goto out_uuid;
err = 0;
- nfsd4_setup_layout_type(&exp);
+ if (exp.ex_flags & NFSEXP_PNFS)
+ nfsd4_setup_layout_type(&exp);
}
expp = svc_export_lookup(&exp);
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 215/398] x86/build/64: Prevent native builds from generating EGPR use
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (212 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 214/398] drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 216/398] x86/microcode/intel: Reject problematic loading on Granite Rapids systems Greg Kroah-Hartman
` (188 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Omar Avelar, Chang S. Bae,
Borislav Petkov (AMD), Nathan Chancellor, Miguel Ojeda
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chang S. Bae <chang.seok.bae@intel.com>
commit 63edf5a009ae366369a1b484cd9ae4ee7c51946c upstream.
Omar reports that CONFIG_X86_NATIVE_CPU=y allows builds to opportunistically
emit instructions using %r16-%r31 (EGPRs) when the build host supports APX
since the commit:
ea1dcca1de12 ("x86/kbuild/64: Add the CONFIG_X86_NATIVE_CPU option to locally optimize the kernel with '-march=native'")
But the kernel is not yet prepared to use new registers internally. For
example, there is no context-switch support for general in-kernel use.
Explicitly disable EGPR use when building with -march=native.
For C, since GCC 14 and Clang 18, both compilers support suppressing EGPR
use with -mno-apx-features=egpr, whose availability can be detected via
cc-option.
For Rust, pass features=-apxf through the generated JSON to avoid
unstable-feature warnings, see
https://github.com/rust-lang/rust/issues/139284
Note Rust only accepts the option to disable APX instructions entirely or not.
Support for this gating also depends on the Rust/LLVM combination. Rust
1.88 introduced the `apxf` feature option, but versions prior to 1.93 may
emit an `apxf` attribute to the backend that only LLVM 23 or later can
interpret. Restrict native Rust builds accordingly.
Fixes: ea1dcca1de12 ("x86/kbuild/64: Add the CONFIG_X86_NATIVE_CPU option to locally optimize the kernel with '-march=native'")
Reported-by: Omar Avelar <omar.avelar@intel.com>
Signed-off-by: Chang S. Bae <chang.seok.bae@intel.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Nathan Chancellor <nathan@kernel.org>
Acked-by: Miguel Ojeda <ojeda@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260916230003.1144622-1-chang.seok.bae@intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/Kconfig.cpu | 11 +++++++++++
arch/x86/Makefile | 5 +++++
scripts/generate_rust_target.rs | 5 +++++
3 files changed, 21 insertions(+)
--- a/arch/x86/Kconfig.cpu
+++ b/arch/x86/Kconfig.cpu
@@ -255,10 +255,21 @@ config CC_HAS_MARCH_NATIVE
# usage warnings that only appear wth '-march=native'.
depends on CC_IS_GCC || CLANG_VERSION >= 190100
+config RUSTC_HAS_APXF
+ # The kernel isn't ready for in-kernel APX instructions. Without
+ # explicit frontend gating of APX, the backend may emit those
+ # instructions in native builds.
+ #
+ # Rust 1.88 added the `apxf` feature option, but versions before 1.93
+ # emit an `apxf` target attribute that only LLVM 23+ can interpret.
+ def_bool (RUSTC_VERSION >= 108800 && RUSTC_LLVM_MAJOR_VERSION >= 23) || \
+ RUSTC_VERSION >= 109300
+
config X86_NATIVE_CPU
bool "Build and optimize for local/native CPU"
depends on X86_64
depends on CC_HAS_MARCH_NATIVE
+ depends on !RUST || RUSTC_HAS_APXF
help
Optimize for the current CPU used to compile the kernel.
Use this option if you intend to build the kernel for your
--- a/arch/x86/Makefile
+++ b/arch/x86/Makefile
@@ -168,6 +168,11 @@ else
ifdef CONFIG_X86_NATIVE_CPU
KBUILD_CFLAGS += -march=native
+ # Prevent the compiler from generating EGPR use. The kernel is
+ # not yet prepared for general in-kernel use.
+ KBUILD_CFLAGS += $(call cc-option,-mno-apx-features=egpr)
+
+ # generate_rust_target.rs handles Rust APX gating.
KBUILD_RUSTFLAGS += -Ctarget-cpu=native
else
KBUILD_CFLAGS += -march=x86-64 -mtune=generic
--- a/scripts/generate_rust_target.rs
+++ b/scripts/generate_rust_target.rs
@@ -224,6 +224,11 @@ fn main() {
features += ",+harden-sls-ijmp";
features += ",+harden-sls-ret";
}
+ if cfg.has("X86_NATIVE_CPU") {
+ // Prevent the backend from generating APX instructions. The kernel is not yet prepared
+ // for general in-kernel EGPR use.
+ features += ",-apxf";
+ }
ts.push("features", features);
ts.push("llvm-target", "x86_64-linux-gnu");
ts.push("supported-sanitizers", ["kcfi", "kernel-address"]);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 269/438] net: xfrm: reject unrepresentable espintcp transport headers
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (267 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 268/438] nfsd: fix handling of NFSEXP_PNFS in the netlink codepath Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 270/438] kselftest/arm64: Fix size of thread_data values for pthread_join() Greg Kroah-Hartman
` (180 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Wyatt Feng, Ren Wei,
Steffen Klassert
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wyatt Feng <wf.kernel.dev@gmail.com>
commit 96f01b53c2d05e003b040892256de54a586e8529 upstream.
ESP-in-TCP can hand xfrm packets whose transport header offset no longer
fits after the stream parser trims the TCP envelope. The plain transport
header reset truncates that offset and triggers the skb warning path.
Use the careful transport-header helper and drop the skb through the
existing XFRM error path when the offset cannot be represented.
Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: Codex:GPT-5.4
Signed-off-by: Wyatt Feng <wf.kernel.dev@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/espintcp.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/net/xfrm/espintcp.c
+++ b/net/xfrm/espintcp.c
@@ -30,7 +30,11 @@ static void handle_esp(struct sk_buff *s
{
struct tcp_skb_cb *tcp_cb = (struct tcp_skb_cb *)skb->cb;
- skb_reset_transport_header(skb);
+ if (!skb_reset_transport_header_careful(skb)) {
+ XFRM_INC_STATS(sock_net(sk), LINUX_MIB_XFRMINERROR);
+ kfree_skb(skb);
+ return;
+ }
/* restore IP CB, we need at least IP6CB->nhoff */
memmove(skb->cb, &tcp_cb->header, sizeof(tcp_cb->header));
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 216/398] x86/microcode/intel: Reject problematic loading on Granite Rapids systems
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (213 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 215/398] x86/build/64: Prevent native builds from generating EGPR use Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 217/398] tcp: exclude old ACKs from tcp fast path Greg Kroah-Hartman
` (187 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chang S. Bae, Borislav Petkov (AMD),
Dave Hansen
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chang S. Bae <chang.seok.bae@intel.com>
commit e7d3e2f46dd5a69046e6d95a0f189155a5516b93 upstream.
Microcode updates can usually jump revisions. However, there is an erratum on
Granite Rapids systems. If they "jump over" revision 0x1000405, they result in
an #MC. Avoid it.
Signed-off-by: Chang S. Bae <chang.seok.bae@intel.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Dave Hansen <dave.hansen@linux.intel.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260916225939.1144524-1-chang.seok.bae@intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kernel/cpu/microcode/intel.c | 26 ++++++++++++++++++++++++++
1 file changed, 26 insertions(+)
--- a/arch/x86/kernel/cpu/microcode/intel.c
+++ b/arch/x86/kernel/cpu/microcode/intel.c
@@ -257,6 +257,26 @@ static void save_microcode_patch(struct
pr_err("Unable to allocate microcode memory size: %u\n", size);
}
+static bool revision_is_safe(struct cpu_signature *sig, u32 rev)
+{
+ u32 vfm = IFM(x86_family(sig->sig), x86_model(sig->sig));
+
+ /*
+ * Erratum GNR98 can cause #MCs if "jumping over" revision 0x1000405.
+ * Avoid the jumps.
+ */
+ if (vfm == INTEL_GRANITERAPIDS_X &&
+ x86_stepping(sig->sig) == 1 &&
+ sig->pf & 0x95 &&
+ sig->rev < 0x1000405 &&
+ rev > 0x1000405) {
+ pr_err_once("Erratum GNR98: skipping revision 0x%x.\n", rev);
+ return false;
+ }
+
+ return true;
+}
+
/* Scan blob for microcode matching the boot CPUs family, model, stepping */
static __init struct microcode_intel *scan_microcode(void *data, size_t size,
struct ucode_cpu_info *uci,
@@ -278,6 +298,9 @@ static __init struct microcode_intel *sc
if (!intel_find_matching_signature(data, &uci->cpu_sig))
continue;
+ if (!revision_is_safe(&uci->cpu_sig, mc_header->rev))
+ continue;
+
/*
* For saving the early microcode, find the matching revision which
* was loaded on the BSP.
@@ -534,6 +557,9 @@ static enum ucode_state parse_microcode_
if (!intel_find_matching_signature(mc, &uci->cpu_sig))
continue;
+ if (!revision_is_safe(&uci->cpu_sig, mc_header.rev))
+ continue;
+
is_safe = ucode_validate_minrev(&mc_header);
if (force_minrev && !is_safe)
continue;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 270/438] kselftest/arm64: Fix size of thread_data values for pthread_join()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (268 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 269/438] net: xfrm: reject unrepresentable espintcp transport headers Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 271/438] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc Greg Kroah-Hartman
` (179 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Thomas Huth, Will Deacon
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Huth <thuth@redhat.com>
commit 3d1ba5cbfb622025690c218d8f20da92a9ecb383 upstream.
pthread_join() stores the thread's return value (a "void *", i.e.
8 bytes on 64 bit computers) into the address that is passed as second
parameter. However, the entries of thread_data are only normal "int"s,
i.e. only 4 bytes. The additional 4 bytes of the return value clobber
whatever is adjacent on the stack, i.e. other members of the thread_data
array (which will be re-written in the next iteration of the for-loop,
so that nobody noticed this problem), or another other local variable
on the stack for the last iteration. Use "intptr_t" to declare the
thread_data array entries with the correct size.
Fixes: 29f080881601c ("kselftest/arm64: check GCR_EL1 after context switch")
Cc: stable@vger.kernel.org
Signed-off-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
+++ b/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
@@ -69,7 +69,7 @@ fail:
int execute_test(pid_t pid)
{
pthread_t thread_id[MAX_THREADS];
- int thread_data[MAX_THREADS];
+ intptr_t thread_data[MAX_THREADS];
for (int i = 0; i < MAX_THREADS; i++)
pthread_create(&thread_id[i], NULL,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 217/398] tcp: exclude old ACKs from tcp fast path
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (214 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 216/398] x86/microcode/intel: Reject problematic loading on Granite Rapids systems Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 218/398] swiotlb: use the adjusted address for the highmem page lookup Greg Kroah-Hartman
` (186 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Amit Klein, Tamir Shahar,
Inbal Schussheim, Eric Dumazet, Paolo Abeni
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
commit f81e6c3fb06327bc49cdd6e559845293ba06a704 upstream.
Exclude old ACKs before SND.UNA from the tcp fast path
as well as ACKs after SND.NXT.
Such ACKs will fall through to the slow path, where tcp_ack()
performs the appropriate validation and challenge ACK handling
according to RFC5961 and Commit 3d501dd326fb1c7 ("tcp: do not
accept ACK of bytes we never sent").
This prevents old ACKs from being accepted
or modifying connection state as part of the fast path before
appropriate ACK validation is applied.
In particular, this prevents payload carried by a segment with
an excessively old ACK from advancing RCV.NXT before the ACK
is rejected.
Fixes: 31770e34e43d ("tcp: Revert "tcp: remove header prediction"")
Reported-by: Amit Klein <amit.klein@mail.huji.ac.il>
Reported-by: Tamir Shahar <tamir.shahar1@mail.huji.ac.il>
Reported-by: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
Suggested-by: Eric Dumazet <edumazet@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Inbal Schussheim <inbal.lipshtat@mail.huji.ac.il>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260914090408.1435080-2-inbal.lipshtat@mail.huji.ac.il
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/tcp_input.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/net/ipv4/tcp_input.c
+++ b/net/ipv4/tcp_input.c
@@ -6283,6 +6283,7 @@ reset:
* or pure receivers (this means either the sequence number or the ack
* value must stay constant)
* - Unexpected TCP option.
+ * - ACK sequence number is outside [SND.UNA, SND.NXT].
*
* When these conditions are not satisfied it drops into a standard
* receive procedure patterned after RFC793 to handle all cases.
@@ -6332,7 +6333,7 @@ void tcp_rcv_established(struct sock *sk
if ((tcp_flag_word(th) & TCP_HP_BITS) == tp->pred_flags &&
TCP_SKB_CB(skb)->seq == tp->rcv_nxt &&
- !after(TCP_SKB_CB(skb)->ack_seq, tp->snd_nxt)) {
+ between(TCP_SKB_CB(skb)->ack_seq, tp->snd_una, tp->snd_nxt)) {
int tcp_header_len = tp->tcp_header_len;
s32 delta = 0;
int flag = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 271/438] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (269 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 270/438] kselftest/arm64: Fix size of thread_data values for pthread_join() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 272/438] arm64: dts: renesas: r8a779f0: Set UFS lane count Greg Kroah-Hartman
` (178 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bradley Morgan, Vladimir Murzin,
Mark Rutland, Will Deacon
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bradley Morgan <include@grrlz.net>
commit 955d86e5f3b95b731991fdb84966c50b16314629 upstream.
swsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub
vectors with an hvc, but never passes the arguments. x0 is not set to
HVC_SET_VECTORS and x1 is not set to the vector address, so the stub
dispatch falls through and returns without writing vbar_el2. EL2 is
left pointing at the trans_pgd copy of the vectors, a page that
swsusp_free() releases right after resume.
Set the arguments up the same way __hyp_set_vectors() does.
Without this fix, Vladimir was able to trigger a hang when resuming from
hibernation with CONFIG_PAGE_POISONING=y and page_poison=on.
Fixes: 788bfdd97434 ("arm64: trans_pgd: hibernate: Add trans_pgd_copy_el2_vectors")
Cc: stable@vger.kernel.org
Signed-off-by: Bradley Morgan <include@grrlz.net>
Reviewed-by: Vladimir Murzin <vladimir.murzin@arm.com>
Tested-by: Vladimir Murzin <vladimir.murzin@arm.com>
Acked-by: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kernel/hibernate-asm.S | 2 ++
1 file changed, 2 insertions(+)
--- a/arch/arm64/kernel/hibernate-asm.S
+++ b/arch/arm64/kernel/hibernate-asm.S
@@ -89,6 +89,8 @@ alternative_insn "dc cvau, x4", "dc civ
isb
cbz x24, 3f /* Do we need to re-initialise EL2? */
+ mov x1, x24
+ mov x0, #HVC_SET_VECTORS
hvc #0
3: ret
SYM_CODE_END(swsusp_arch_suspend_exit)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 218/398] swiotlb: use the adjusted address for the highmem page lookup
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (215 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 217/398] tcp: exclude old ACKs from tcp fast path Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 219/398] spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes Greg Kroah-Hartman
` (185 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Donggeun Yoo, Michael Kelley,
Marek Szyprowski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
commit b7d7914a9ae3097e63d113007e4fb44d33d515b1 upstream.
swiotlb_bounce() reads the page frame number from the slot's recorded
orig_addr, then advances orig_addr by tlb_offset to reach the address
the caller asked about. The highmem branch mixes the two: the offset
within the page comes from the adjusted address, the page from the value
before it.
Once the adjustment crosses a page boundary the pair no longer describes
one location, and the whole copy lands one page below the intended one
for a positive tlb_offset, one above for a negative one. DMA_FROM_DEVICE
writes the device data over the wrong page and leaves the intended one
stale, DMA_TO_DEVICE feeds the device from a page the mapping may not
cover. Partial syncs through dma_sync_single_range_for_*() are what make
tlb_offset non-zero.
The branch test is picked the same way, so a slot recorded in lowmem can
be adjusted into highmem and the lowmem path then hands a highmem
address to phys_to_virt().
Take both from orig_addr once it is final and keep pfn in the branch
that uses it. PhysHighMem() asks the question straight from the address,
as dma-debug already does.
Fixes: 5f89468e2f06 ("swiotlb: manipulate orig_addr when tlb_addr has offset")
Cc: stable@vger.kernel.org
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Reviewed-by: Michael Kelley <mhklinux@outlook.com>
Link: https://lore.kernel.org/r/20260905084210.148255-1-donggeunyoo.kernel@gmail.com
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/dma/swiotlb.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/kernel/dma/swiotlb.c
+++ b/kernel/dma/swiotlb.c
@@ -869,7 +869,6 @@ static void swiotlb_bounce(struct device
int index = (tlb_addr - mem->start) >> IO_TLB_SHIFT;
phys_addr_t orig_addr = mem->slots[index].orig_addr;
size_t alloc_size = mem->slots[index].alloc_size;
- unsigned long pfn = PFN_DOWN(orig_addr);
unsigned char *vaddr = mem->vaddr + tlb_addr - mem->start;
int tlb_offset;
@@ -899,7 +898,8 @@ static void swiotlb_bounce(struct device
size = alloc_size;
}
- if (PageHighMem(pfn_to_page(pfn))) {
+ if (PhysHighMem(orig_addr)) {
+ unsigned long pfn = PFN_DOWN(orig_addr);
unsigned int offset = orig_addr & ~PAGE_MASK;
struct page *page;
unsigned int sz = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 272/438] arm64: dts: renesas: r8a779f0: Set UFS lane count
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (270 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 271/438] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 273/438] arm64: dts: socfpga: change access permission from 755 to 644 Greg Kroah-Hartman
` (177 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Koichiro Den, Geert Uytterhoeven
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Koichiro Den <den@valinux.co.jp>
commit 8dc2615d5702059b2b71fca6f93c0d7d10ae54cb upstream.
Since commit e72323f3b09f ("scsi: ufs: core: Configure only active lanes
during link"), the following error is observed on R-Car S4:
ufshcd-renesas e6860000.ufs: Tx lane mismatch [config,reported] [2,1]
ufshcd-renesas e6860000.ufs: link startup failed -67
ufshcd-renesas e6860000.ufs: error -ENOLINK: Initialization failed with error -67
ufshcd-renesas e6860000.ufs: probe with driver ufshcd-renesas failed with error -67
R-Car S4 has one UFS lane per direction, as described in section 152.1
of its hardware manual. Without lanes-per-direction, the UFS platform
driver defaults to two lanes.
Previously, the core used PA_CONNECTEDRXDATALANES and
PA_CONNECTEDTXDATALANES to configure the link without checking them
against lanes-per-direction, so the missing property did not prevent
initialization.
Explicitly set lanes-per-direction to 1, now that the validation is in
place.
Fixes: 5235d551779d ("arm64: dts: renesas: r8a779f0: Add UFS node")
Cc: stable@vger.kernel.org # 7.2+
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Tested-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260911073058.253000-1-den@valinux.co.jp
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/boot/dts/renesas/r8a779f0.dtsi | 1 +
1 file changed, 1 insertion(+)
--- a/arch/arm64/boot/dts/renesas/r8a779f0.dtsi
+++ b/arch/arm64/boot/dts/renesas/r8a779f0.dtsi
@@ -901,6 +901,7 @@
clocks = <&cpg CPG_MOD 1514>, <&ufs30_clk>;
clock-names = "fck", "ref_clk";
freq-table-hz = <200000000 200000000>, <38400000 38400000>;
+ lanes-per-direction = <1>;
power-domains = <&sysc R8A779F0_PD_ALWAYS_ON>;
resets = <&cpg 1514>;
status = "disabled";
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 219/398] spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (216 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 218/398] swiotlb: use the adjusted address for the highmem page lookup Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 220/398] spi: spi-zynqmp-gqspi: stop the controller on shutdown Greg Kroah-Hartman
` (184 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Frieder Schrempf, Han Xu, Mark Brown
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frieder Schrempf <frieder.schrempf@kontron.de>
commit 3d743adf090cd4c9a2120c1e02b0482e88aa0d2d upstream.
fsl_qspi_select_mem() returns early when the chip select has not changed,
which happens before it reaches clk_set_rate(). Since the rate is now
taken from the spi-mem operation rather than from the SPI device, the
controller honours op->max_freq exactly once per chip select and ignores
it for every operation after that.
q->selected is only reset to -1 in fsl_qspi_default_setup(), i.e. at probe
and on resume, so on the common single chip select board the very first
operation latches a rate that all subsequent operations inherit, whatever
frequency they asked for.
This results in operations being issued with the wrong frequency.
Cache the operation frequency the clock was programmed for next to the
selected chip select, and redo the clock setup when either changes.
Fixes: 2438db5253eb ("spi: fsl-qspi: Support per spi-mem operation frequency switches")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: Frieder Schrempf <frieder.schrempf@kontron.de>
Acked-by: Han Xu <han.xu@nxp.com>
Link: https://patch.msgid.link/20260917-fsl-qspi-freq-op-fix-v1-1-5fbe6b02f738@kontron.de
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/spi/spi-fsl-qspi.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/drivers/spi/spi-fsl-qspi.c
+++ b/drivers/spi/spi-fsl-qspi.c
@@ -271,6 +271,7 @@ struct fsl_qspi {
struct pm_qos_request pm_qos_req;
struct device *dev;
int selected;
+ u32 selected_freq;
u32 memmap_phy;
};
@@ -528,7 +529,8 @@ static void fsl_qspi_select_mem(struct f
unsigned long rate = op->max_freq;
int ret;
- if (q->selected == spi_get_chipselect(spi, 0))
+ if (q->selected == spi_get_chipselect(spi, 0) &&
+ q->selected_freq == op->max_freq)
return;
if (needs_4x_clock(q))
@@ -545,6 +547,7 @@ static void fsl_qspi_select_mem(struct f
return;
q->selected = spi_get_chipselect(spi, 0);
+ q->selected_freq = op->max_freq;
fsl_qspi_invalidate(q);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 273/438] arm64: dts: socfpga: change access permission from 755 to 644
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (271 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 272/438] arm64: dts: renesas: r8a779f0: Set UFS lane count Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 274/438] arm64: percpu: Fix this_cpu_write() casting Greg Kroah-Hartman
` (176 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Dinh Nguyen
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dinh Nguyen <dinguyen@kernel.org>
commit 5f8cb07d7a8573753c5d31dc76b51cab8e5e9460 upstream.
These files have an incorrect access permission of 755 instead of 644.
Change them to the correct access permission of 644.
Fixes: 4bc04eb90b7c ("arm64: dts: socfpga: stratix10: Add emmc support")
Cc: <stable@vger.kernel.org> # v7.1+
Signed-off-by: Dinh Nguyen <dinguyen@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/boot/dts/altera/socfpga_stratix10_socdk.dtsi | 0
arch/arm64/boot/dts/altera/socfpga_stratix10_socdk_emmc.dts | 0
2 files changed, 0 insertions(+), 0 deletions(-)
mode change 100755 => 100644 arch/arm64/boot/dts/altera/socfpga_stratix10_socdk.dtsi
mode change 100755 => 100644 arch/arm64/boot/dts/altera/socfpga_stratix10_socdk_emmc.dts
diff --git a/arch/arm64/boot/dts/altera/socfpga_stratix10_socdk.dtsi b/arch/arm64/boot/dts/altera/socfpga_stratix10_socdk.dtsi
old mode 100755
new mode 100644
diff --git a/arch/arm64/boot/dts/altera/socfpga_stratix10_socdk_emmc.dts b/arch/arm64/boot/dts/altera/socfpga_stratix10_socdk_emmc.dts
old mode 100755
new mode 100644
--
2.55.0
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 220/398] spi: spi-zynqmp-gqspi: stop the controller on shutdown
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (217 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 219/398] spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 221/398] spi: virtio: Use the per-transfer bits per word Greg Kroah-Hartman
` (183 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Itai Handler, Mark Brown
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Itai Handler <itai.handler@gmail.com>
commit e922bad8b2d5028c51a096d083fea41cd0987154 upstream.
The driver has no ->shutdown, and platform_drv_shutdown() has no
fallback of its own. Unlike pci_device_shutdown(), which clears bus
mastering when kexec_in_progress, nothing on the platform bus disarms a
device that can still write to memory. The normal kexec path never
calls ->suspend either, so the quiesce in zynqmp_qspi_suspend() is not
reached.
A controller that is still executing a DMA read may therefore keep
writing to memory across a kexec. QSPIDMA_DST_ADDR still points at
memory owned by the kernel that called kexec, DST_SIZE is non-zero and
the flash is still clocked, so data can keep landing in RAM while the
new kernel is being relocated, and after it has started executing.
That destination is a physical address which means nothing to the new
kernel, so the writes can corrupt whatever now occupies it: kernel text
or data, page tables, or the initrd. Nothing reports an error and the
resulting behaviour is undefined.
This can be observed by reading GQSPI_EN (offset 0x114) and
QSPIDMA_DST_ADDR/SIZE/STS/CTRL (offsets 0x800 to 0x80c) early in the new
kernel, before the driver probes: without this patch GQSPI_EN reads 1
and QSPIDMA_DST_ADDR still points into the previous kernel's memory.
Add a ->shutdown that stops the controller the way zynqmp_qspi_suspend()
already does. spi_controller_suspend() stops the queue, waits for a
message that is already executing and makes any later transfer fail with
-ESHUTDOWN, so nothing can be cut short by the register write that
follows. It may sleep, which is fine here: device_shutdown() runs in
process context. Unlike ->suspend this cannot abort on error, because a
controller left mastering the bus is worse than a truncated transfer, so
a failure to drain is only logged.
GQSPI_EN_OFST is then cleared, as zynqmp_qspi_remove() and
zynqmp_qspi_suspend() already do. Skip that write only when
pm_runtime_get_if_in_use() returns 0, i.e. runtime suspended: the clocks
are gated, so the registers are unreachable and the controller cannot be
mastering the bus. A negative return is not the same thing - it is what
the CONFIG_PM=n stub always returns, and there probe() has enabled pclk
and refclk for good, so the controller is running and must be stopped.
Fixes: dfe11a11d523 ("spi: Add support for Zynq Ultrascale+ MPSoC GQSPI controller")
Cc: stable@vger.kernel.org
Signed-off-by: Itai Handler <itai.handler@gmail.com>
Link: https://patch.msgid.link/20260910174832.873352-1-itai.handler@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/spi/spi-zynqmp-gqspi.c | 34 ++++++++++++++++++++++++++++++++++
1 file changed, 34 insertions(+)
--- a/drivers/spi/spi-zynqmp-gqspi.c
+++ b/drivers/spi/spi-zynqmp-gqspi.c
@@ -1374,11 +1374,45 @@ static void zynqmp_qspi_remove(struct pl
clk_disable_unprepare(xqspi->pclk);
}
+static void zynqmp_qspi_shutdown(struct platform_device *pdev)
+{
+ struct zynqmp_qspi *xqspi = platform_get_drvdata(pdev);
+ int ret;
+
+ /*
+ * Stop the queue and reject any later transfer first, so the write
+ * below cannot cut into a message that is still being executed.
+ * Unlike ->suspend this cannot abort on error: a controller left
+ * mastering the bus is worse than a truncated transfer.
+ */
+ ret = spi_controller_suspend(xqspi->ctlr);
+ if (ret)
+ dev_warn(&pdev->dev, "could not stop the queue: %d\n", ret);
+
+ /*
+ * Only a runtime suspended controller can be left alone: its clocks
+ * are gated, so it cannot be mastering the bus, and its registers
+ * must not be accessed either. Any other answer means it may be
+ * running and has to be stopped. In particular, on a kernel built
+ * without runtime PM this returns -EINVAL, and there the clocks
+ * enabled in probe() are never gated at all.
+ */
+ ret = pm_runtime_get_if_in_use(&pdev->dev);
+ if (!ret)
+ return;
+
+ zynqmp_gqspi_write(xqspi, GQSPI_EN_OFST, 0x0);
+
+ if (ret > 0)
+ pm_runtime_put_noidle(&pdev->dev);
+}
+
MODULE_DEVICE_TABLE(of, zynqmp_qspi_of_match);
static struct platform_driver zynqmp_qspi_driver = {
.probe = zynqmp_qspi_probe,
.remove = zynqmp_qspi_remove,
+ .shutdown = zynqmp_qspi_shutdown,
.driver = {
.name = "zynqmp-qspi",
.of_match_table = zynqmp_qspi_of_match,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 274/438] arm64: percpu: Fix this_cpu_write() casting
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (272 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 273/438] arm64: dts: socfpga: change access permission from 755 to 644 Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 275/438] arm64: percpu: Fix this_cpu_and() mask generation Greg Kroah-Hartman
` (175 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Laight, Mark Rutland,
Jinjie Ruan, Muhammad Usama Anjum, Christopher Lameter (Ampere),
Ada Couprie Diaz, Ard Biesheuvel, Catalin Marinas, James Morse,
Marc Zyngier, Peter Zijlstra, Vladimir Murzin, Will Deacon,
Yang Shi, Lorenzo Stoakes (ARM)
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Rutland <mark.rutland@arm.com>
commit 885bff055a0f251a51a0d4fd4f0a7b525582a3de upstream.
The arm64 implementation of this_cpu_write() casts 'val' to unsigned
long. This is necessary to handle cases where 'val' is a pointer type,
and to avoid spurious compiler warnings for the (unreachable!) cases
where the pointer type would be cast to a smaller integer type.
Unfortunately, the cast is applied to 'val' rather than '(val)', which
won't always generate the expected value when 'val' is an expression.
For example, for this_cpu_write(pcp, zero - 1), where 'pcp' is a u64 and
'zero' is a u32:
* 'zero' ===> (u32) 0x00000000
* 'zero - 1' ===> (u32) 0xffffffff
* '(unsigned long)zero - 1' ===> (u64) 0xffffffffffffffff
* '(unsigned long)(zero - 1)' ===> (u64) 0x00000000ffffffff
Fix this by adding brackets around 'val'.
Fixes: 959bf2fd03b5 ("arm64: percpu: Rewrite per-cpu ops to allow use of LSE atomics")
Reported-by: David Laight <david.laight.linux@gmail.com>
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Reviewed-by: David Laight <david.laight.linux@gmail.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Tested-by: Muhammad Usama Anjum <usama.anjum@arm.com>
Acked-by: Christopher Lameter (Ampere) <cl@gentwo.org>
Cc: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Vladimir Murzin <vladimir.murzin@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/percpu.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/arch/arm64/include/asm/percpu.h
+++ b/arch/arm64/include/asm/percpu.h
@@ -179,13 +179,13 @@ PERCPU_RET_OP(add, add, ldadd)
_pcp_protect_return(__percpu_read_64, pcp)
#define this_cpu_write_1(pcp, val) \
- _pcp_protect(__percpu_write_8, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_8, pcp, (unsigned long)(val))
#define this_cpu_write_2(pcp, val) \
- _pcp_protect(__percpu_write_16, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_16, pcp, (unsigned long)(val))
#define this_cpu_write_4(pcp, val) \
- _pcp_protect(__percpu_write_32, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_32, pcp, (unsigned long)(val))
#define this_cpu_write_8(pcp, val) \
- _pcp_protect(__percpu_write_64, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_64, pcp, (unsigned long)(val))
#define this_cpu_add_1(pcp, val) \
_pcp_protect(__percpu_add_case_8, pcp, val)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 221/398] spi: virtio: Use the per-transfer bits per word
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (218 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 220/398] spi: spi-zynqmp-gqspi: stop the controller on shutdown Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 222/398] RDMA/ucma: Serialize join and leave on copy_to_user failure Greg Kroah-Hartman
` (182 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hao-Qun Huang, Mark Brown
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hao-Qun Huang <alvinhuang0603@gmail.com>
commit 095858324f063dba830041f067872f0a08765d2f upstream.
virtio_spi_transfer_one() puts spi->bits_per_word into the request
header, so a transfer that sets its own word size reaches the backend
with the device default instead. The SPI core has already copied that
default into xfer->bits_per_word when the transfer leaves it at zero,
the same way it does for xfer->speed_hz, which this function already
uses.
Per-transfer word sizes are ordinary SPI usage. mipi_dbi, for one, sends
a 9-bit command and reads the reply as 8-bit data in the same message.
With a 16-bit device default, a one-byte transfer asking for 8 bits goes
out as a partial 16-bit word, which the backend may reject.
Fixes: f98cabe3f6cf ("SPI: Add virtio SPI driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Hao-Qun Huang <alvinhuang0603@gmail.com>
Link: https://patch.msgid.link/20260913032049.11209.alvinhuang0603@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/spi/spi-virtio.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/spi/spi-virtio.c
+++ b/drivers/spi/spi-virtio.c
@@ -169,7 +169,7 @@ static int virtio_spi_transfer_one(struc
/* Fill struct spi_transfer_head */
th->chip_select_id = spi_get_chipselect(spi, 0);
- th->bits_per_word = spi->bits_per_word;
+ th->bits_per_word = xfer->bits_per_word;
th->cs_change = xfer->cs_change;
th->tx_nbits = xfer->tx_nbits;
th->rx_nbits = xfer->rx_nbits;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 275/438] arm64: percpu: Fix this_cpu_and() mask generation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (273 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 274/438] arm64: percpu: Fix this_cpu_write() casting Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 276/438] arm64: percpu: Fix LSE operations on {8,16}-bit types Greg Kroah-Hartman
` (174 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Rutland, Jinjie Ruan,
Muhammad Usama Anjum, Christopher Lameter (Ampere),
Ada Couprie Diaz, Ard Biesheuvel, Catalin Marinas, James Morse,
Marc Zyngier, Peter Zijlstra, Vladimir Murzin, Will Deacon,
Yang Shi
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Rutland <mark.rutland@arm.com>
commit 44274c657256b4911de82f8104e9e22f054cf742 upstream.
The arm64 implementation of this_cpu_and(pcp, val) is built in terms of
ANDNOT operations, which requires the 'val' argument to be bitwise
negated. The bitwise negation is not implemented correctly, with two
bugs described below.
(1) The bitwise negation is performed as '~val' rather than '~(val)'.
This won't always generate the expected value when 'val' is an
expression.
For example, for this_cpu_and(pcp, 1 - 1):
* 'val' is '1 - 1' ===> (int) 0x00000000
* '~val' is '~1 - 1' ===> (int) 0xfffffffd
* '~(val)' is '~(1 - 1)' ===> (int) 0xffffffff
... and thus bit[1] of 'pcp' would be preserved unexpectedly by the
ANDNOT operation.
(2) The bitwise negation is performed on 'val' before it has been cast
to (at least) the width of 'pcp'. This won't always generate the
expected value for the upper bits.
For example, for this_cpu_and(pcp, zero), where 'pcp' is a u64 and
'zero' is a u32:
* 'zero' ===> (u32) 0x00000000
* '~(zero)' ===> (u32) 0xffffffff
* '(u64)~(zero)' ===> (u64) 0x00000000ffffffff
* '~((u64)(zero))' ===> (u64) 0xffffffffffffffff
... and thus bits[63:32] of 'pcp' would be preserved unexpectedly by
the ANDNOT operation.
Fix these issues by adding brackets around 'val', and by casting 'val'
to an appropriately-sized type before bitwise negation.
Fixes: 959bf2fd03b5 ("arm64: percpu: Rewrite per-cpu ops to allow use of LSE atomics")
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Tested-by: Muhammad Usama Anjum <usama.anjum@arm.com>
Acked-by: Christopher Lameter (Ampere) <cl@gentwo.org>
Cc: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Vladimir Murzin <vladimir.murzin@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/percpu.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/arch/arm64/include/asm/percpu.h
+++ b/arch/arm64/include/asm/percpu.h
@@ -206,13 +206,13 @@ PERCPU_RET_OP(add, add, ldadd)
_pcp_protect_return(__percpu_add_return_case_64, pcp, val)
#define this_cpu_and_1(pcp, val) \
- _pcp_protect(__percpu_andnot_case_8, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_8, pcp, ~(u8)(val))
#define this_cpu_and_2(pcp, val) \
- _pcp_protect(__percpu_andnot_case_16, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_16, pcp, ~(u16)(val))
#define this_cpu_and_4(pcp, val) \
- _pcp_protect(__percpu_andnot_case_32, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_32, pcp, ~(u32)(val))
#define this_cpu_and_8(pcp, val) \
- _pcp_protect(__percpu_andnot_case_64, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_64, pcp, ~(u64)(val))
#define this_cpu_or_1(pcp, val) \
_pcp_protect(__percpu_or_case_8, pcp, val)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 222/398] RDMA/ucma: Serialize join and leave on copy_to_user failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (219 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 221/398] spi: virtio: Use the per-transfer bits per word Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 223/398] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() Greg Kroah-Hartman
` (181 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+a6ffe86390c8a6afc818,
Quanye Yang, Leon Romanovsky
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Quanye Yang <quanyeyang@proton.me>
commit 662ade4de9ff5eceb0820a9f8e9fac70ba6a815b upstream.
rdma_join_multicast() queues RoCE work that later reads the ucma_multicast
through event->param.ud.private_data, then list_add()s the CMA multicast
at the head of id_priv->mc_list. rdma_leave_multicast() matches only by
sockaddr and destroys the first hit.
ucma_process_join() used to drop ctx->mutex after a successful join and
retake it only if copy_to_user() failed. Two concurrent JOIN_MCAST calls
with the same address can therefore insert a second CMA entry before the
first thread's leave. leave then cancels the newer work and the older
worker still dereferences the ucma_multicast that the first thread frees.
Keep ctx->mutex held from rdma_join_multicast() through copy_to_user() and,
on -EFAULT, through rdma_leave_multicast() so leave cannot miss this join.
Do not leave if join itself failed: that path never published this address
on mc_list, and a leave-by-addr would destroy an earlier successful join.
Reported-by: syzbot+a6ffe86390c8a6afc818@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=a6ffe86390c8a6afc818
Fixes: fe454dc31e84 ("RDMA/ucma: Fix use-after-free bug in ucma_create_uevent")
Cc: stable@vger.kernel.org
Signed-off-by: Quanye Yang <quanyeyang@proton.me>
Link: https://patch.msgid.link/20260831-rdma-ucma-mc-uaf-v1-1-b8eeb7046aff@proton.me
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/core/ucma.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
--- a/drivers/infiniband/core/ucma.c
+++ b/drivers/infiniband/core/ucma.c
@@ -1556,9 +1556,10 @@ static ssize_t ucma_process_join(struct
mutex_lock(&ctx->mutex);
ret = rdma_join_multicast(ctx->cm_id, (struct sockaddr *)&mc->addr,
join_state, mc);
- mutex_unlock(&ctx->mutex);
- if (ret)
+ if (ret) {
+ mutex_unlock(&ctx->mutex);
goto err_xa_erase;
+ }
resp.id = mc->id;
if (copy_to_user(u64_to_user_ptr(cmd->response),
@@ -1566,6 +1567,7 @@ static ssize_t ucma_process_join(struct
ret = -EFAULT;
goto err_leave_multicast;
}
+ mutex_unlock(&ctx->mutex);
xa_store(&multicast_table, mc->id, mc, 0);
@@ -1573,7 +1575,6 @@ static ssize_t ucma_process_join(struct
return 0;
err_leave_multicast:
- mutex_lock(&ctx->mutex);
rdma_leave_multicast(ctx->cm_id, (struct sockaddr *) &mc->addr);
mutex_unlock(&ctx->mutex);
ucma_cleanup_mc_events(mc);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 276/438] arm64: percpu: Fix LSE operations on {8,16}-bit types
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (274 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 275/438] arm64: percpu: Fix this_cpu_and() mask generation Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 277/438] Bluetooth: btusb: fix NXP IW610 composite device handling Greg Kroah-Hartman
` (173 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Rutland, Jinjie Ruan,
Ada Couprie Diaz, Ard Biesheuvel, Catalin Marinas, James Morse,
Marc Zyngier, Peter Zijlstra, Vladimir Murzin, Will Deacon,
Yang Shi
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Rutland <mark.rutland@arm.com>
commit 8cf2093f5372952a9ebc805c418d45df7112cd14 upstream.
The assembly for __percpu_##name##_case_##sz() and
__percpu_##name##_return_case_##sz() doesn't use the 'sfx' macro
argument to form the LSE instruction. Without 'sfx', a W register
argument will imply a 32-bit memory location, and consequently
{8,16}-bit ops will erroneously read and write 32 bits of memory when
the LSE instruction is used.
Fix this by appending 'sfx' to 'op_lse' to LSE instruction. It is not
necessary (and not valid) to append 'sfx' to 'op_llsc', as 'op_llsc' is
a register-register operation which does not access memory (and does not
take a size suffix).
Fixes: 959bf2fd03b5 ("arm64: percpu: Rewrite per-cpu ops to allow use of LSE atomics")
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Cc: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Vladimir Murzin <vladimir.murzin@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Reviewed-by: Vladimir Murzin <vladimir.murzin@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/percpu.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/arch/arm64/include/asm/percpu.h
+++ b/arch/arm64/include/asm/percpu.h
@@ -77,7 +77,7 @@ __percpu_##name##_case_##sz(void *ptr, u
" stxr" #sfx "\t%w[loop], %" #w "[tmp], %[ptr]\n" \
" cbnz %w[loop], 1b", \
/* LSE atomics */ \
- #op_lse "\t%" #w "[val], %" #w "[tmp], %[ptr]\n" \
+ #op_lse #sfx "\t%" #w "[val], %" #w "[tmp], %[ptr]\n" \
__nops(3)) \
: [loop] "=&r" (loop), [tmp] "=&r" (tmp), \
[ptr] "+Q"(*(u##sz *)ptr) \
@@ -98,7 +98,7 @@ __percpu_##name##_return_case_##sz(void
" stxr" #sfx "\t%w[loop], %" #w "[ret], %[ptr]\n" \
" cbnz %w[loop], 1b", \
/* LSE atomics */ \
- #op_lse "\t%" #w "[val], %" #w "[ret], %[ptr]\n" \
+ #op_lse #sfx "\t%" #w "[val], %" #w "[ret], %[ptr]\n" \
#op_llsc "\t%" #w "[ret], %" #w "[ret], %" #w "[val]\n" \
__nops(2)) \
: [loop] "=&r" (loop), [ret] "=&r" (ret), \
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 223/398] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (220 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 222/398] RDMA/ucma: Serialize join and leave on copy_to_user failure Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 224/398] openvswitch: avoid reallocating confirmed conntrack labels Greg Kroah-Hartman
` (180 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+bd317784d628820741b5,
Jeffin Philip, Leon Romanovsky
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeffin Philip <jeffinphilip14@gmail.com>
commit 33fb59da49c4c3f5c2ec9f9d4447a56857a02c02 upstream.
iwpm_get_nlmsg_request() initializes refcount _after_ list_add_tail()
making it accessible to global list where another CPU can kref_get()
on nlmsg_request causing a refcount "addition on 0" bug. Fix this
by initializing kref _before_ list_add_tail() so refcount for
nlmsg_request can be incremented/decremented normally. In addition,
also initialize every field before list_add_tail().
Reported-by: syzbot+bd317784d628820741b5@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=bd317784d628820741b5
Fixes: 30dc5e63d6a5 ("RDMA/core: Add support for iWARP Port Mapper user space service")
Cc: stable@vger.kernel.org
Signed-off-by: Jeffin Philip <jeffinphilip14@gmail.com>
Link: https://patch.msgid.link/20260904131437.12917-1-jeffinphilip14@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/core/iwpm_util.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
--- a/drivers/infiniband/core/iwpm_util.c
+++ b/drivers/infiniband/core/iwpm_util.c
@@ -314,10 +314,6 @@ struct iwpm_nlmsg_request *iwpm_get_nlms
if (!nlmsg_request)
return NULL;
- spin_lock_irqsave(&iwpm_nlmsg_req_lock, flags);
- list_add_tail(&nlmsg_request->inprocess_list, &iwpm_nlmsg_req_list);
- spin_unlock_irqrestore(&iwpm_nlmsg_req_lock, flags);
-
kref_init(&nlmsg_request->kref);
kref_get(&nlmsg_request->kref);
nlmsg_request->nlmsg_seq = nlmsg_seq;
@@ -326,6 +322,11 @@ struct iwpm_nlmsg_request *iwpm_get_nlms
nlmsg_request->err_code = 0;
sema_init(&nlmsg_request->sem, 1);
down(&nlmsg_request->sem);
+
+ spin_lock_irqsave(&iwpm_nlmsg_req_lock, flags);
+ list_add_tail(&nlmsg_request->inprocess_list, &iwpm_nlmsg_req_list);
+ spin_unlock_irqrestore(&iwpm_nlmsg_req_lock, flags);
+
return nlmsg_request;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 277/438] Bluetooth: btusb: fix NXP IW610 composite device handling
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (275 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 276/438] arm64: percpu: Fix LSE operations on {8,16}-bit types Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 278/438] Bluetooth: eir: validate service data length before reading UUID Greg Kroah-Hartman
` (172 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nicolas Thibert,
Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Thibert <nithibert@gmail.com>
commit 2b50adefed9808a56d84d1de803cad882cc787fa upstream.
The NXP IW610 module exposes itself as a composite USB device
(0471:0215) with three interfaces: two real Bluetooth HCI interfaces
(class 0xe0) and one vendor-specific WiFi interface (class 0xff) used
by mwifiex-nxp.
The composite device's whole USB descriptor reports class 0xe0/01/01
(Bluetooth), so btusb_table's generic USB_DEVICE_INFO(0xe0, 0x01, 0x01)
entry matches every interface, not just the two real HCI ones -- btusb
ends up binding the WiFi interface too, and mwifiex-nxp never gets it.
Fix:
1. In btusb_table (the table the USB core actually matches against),
explicitly ignore the WiFi interface via BTUSB_IGNORE, ahead of the
generic entry.
2. In quirks_table, scope the existing BTUSB_MARVELL entry to the BT
interface class instead of matching the whole device by VID/PID
(harmless either way since quirks_table isn't consulted for initial
binding, but keep it correct).
Not upstream anywhere: checked NXP's own i.MX kernel fork
(nxp-imx/linux-imx), no IW610 references in btusb.c on any branch --
their reference designs wire this chip differently (WiFi over SDIO
per their release notes), so they never hit this.
Signed-off-by: Nicolas Thibert <nithibert@gmail.com>
Cc: stable@vger.kernel.org
Assisted-by: LLM (Claude Sonnet 5, Anthropic)
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/bluetooth/btusb.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -71,6 +71,15 @@ static struct usb_driver btusb_driver;
#define BTUSB_BROKEN_EXT_SCAN BIT(29)
static const struct usb_device_id btusb_table[] = {
+ /*
+ * NXP IW610 (0471:0215): the composite device reports Bluetooth
+ * class at the whole-device level, so the generic entry below
+ * would also match this WiFi vendor interface. Ignore it here
+ * first so mwifiex-nxp can bind it instead.
+ */
+ { USB_DEVICE_AND_INTERFACE_INFO(0x0471, 0x0215, 0xff, 0xff, 0xff),
+ .driver_info = BTUSB_IGNORE },
+
/* Generic Bluetooth USB device */
{ USB_DEVICE_INFO(0xe0, 0x01, 0x01) },
@@ -475,6 +484,14 @@ static const struct usb_device_id quirks
{ USB_DEVICE(0x1286, 0x2046), .driver_info = BTUSB_MARVELL },
{ USB_DEVICE(0x1286, 0x204e), .driver_info = BTUSB_MARVELL },
+ /*
+ * NXP IW610 BT interfaces (Marvell-lineage silicon, same quirk as
+ * the 0x1286 entries above). Scoped to the BT interface class,
+ * not just VID/PID -- see the btusb_table entry above.
+ */
+ { USB_DEVICE_AND_INTERFACE_INFO(0x0471, 0x0215, 0xe0, 0x01, 0x01),
+ .driver_info = BTUSB_MARVELL },
+
/* Intel Bluetooth devices */
{ USB_DEVICE(0x8087, 0x0025), .driver_info = BTUSB_INTEL_COMBINED },
{ USB_DEVICE(0x8087, 0x0026), .driver_info = BTUSB_INTEL_COMBINED },
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 224/398] openvswitch: avoid reallocating confirmed conntrack labels
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (221 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 223/398] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 225/398] net: xfrm: reject unrepresentable espintcp transport headers Greg Kroah-Hartman
` (179 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Ilya Maximets,
Aaron Conole, Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit 3f118c8217c109fd13ca61caa301d72c483897ef upstream.
ovs_ct_get_conn_labels() adds the labels extension when a conntrack
entry does not have one. Confirmed conntracks can be read locklessly,
so adding an extension may reallocate and free the extension block
while another CPU accesses it.
Only add the extension for unconfirmed conntracks. A confirmed
conntrack without labels now fails the caller's label operation instead
of reallocating its extension storage.
Fixes: c2ac66735870 ("openvswitch: Allow matching on conntrack label")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Aaron Conole <aconole@redhat.com>
Link: https://patch.msgid.link/372fbb062b40ae6723684f55484be86ff0064f8e.1789218015.git.zhilinz@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/openvswitch/conntrack.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/openvswitch/conntrack.c
+++ b/net/openvswitch/conntrack.c
@@ -366,7 +366,7 @@ static struct nf_conn_labels *ovs_ct_get
struct nf_conn_labels *cl;
cl = nf_ct_labels_find(ct);
- if (!cl) {
+ if (!cl && !nf_ct_is_confirmed(ct)) {
nf_ct_labels_ext_add(ct);
cl = nf_ct_labels_find(ct);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 278/438] Bluetooth: eir: validate service data length before reading UUID
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (276 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 277/438] Bluetooth: btusb: fix NXP IW610 composite device handling Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 279/438] Bluetooth: hci_codec: validate vendor codec count length Greg Kroah-Hartman
` (171 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Aamir Ahmed, Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aamir Ahmed <elb12345@hotmail.co.uk>
commit e8241766794cf551d787fa3a77c0d54bbea6f6aa upstream.
eir_get_service_data() reads a 16-bit UUID from the service data using
get_unaligned_le16() without first checking that the data is long enough
to hold a UUID16 (2 bytes). If a malformed EIR entry has a service data
field with only 1 byte of payload (field_len=2), eir_get_data() returns
dlen=1. The subsequent get_unaligned_le16() then reads 1 byte past the
field boundary.
Additionally, if the corrupted UUID happens to match, the length
calculation "dlen - 2" underflows to SIZE_MAX since dlen is size_t.
Current callers either pass NULL for the length parameter or bounds-check
the returned length, but future callers may not.
Add a check that dlen >= sizeof(u16) and skip fields that are too short
to contain a valid UUID16.
Fixes: 8f9ae5b3ae80 ("Bluetooth: eir: Add helpers for managing service data")
Cc: stable@vger.kernel.org
Signed-off-by: Aamir Ahmed <elb12345@hotmail.co.uk>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/eir.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
--- a/net/bluetooth/eir.c
+++ b/net/bluetooth/eir.c
@@ -373,7 +373,15 @@ void *eir_get_service_data(u8 *eir, size
size_t dlen;
while ((eir = eir_get_data(eir, eir_len, EIR_SERVICE_DATA, &dlen))) {
- u16 value = get_unaligned_le16(eir);
+ u16 value;
+
+ if (dlen < sizeof(value)) {
+ eir += dlen;
+ eir_len = eir_end - eir;
+ continue;
+ }
+
+ value = get_unaligned_le16(eir);
if (uuid == value) {
if (len)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 225/398] net: xfrm: reject unrepresentable espintcp transport headers
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (222 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 224/398] openvswitch: avoid reallocating confirmed conntrack labels Greg Kroah-Hartman
@ 2026-09-23 14:04 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 226/398] HID: logitech-hidpp: fix race condition when accessing stale stack pointer Greg Kroah-Hartman
` (178 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:04 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Wyatt Feng, Ren Wei,
Steffen Klassert
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wyatt Feng <wf.kernel.dev@gmail.com>
commit 96f01b53c2d05e003b040892256de54a586e8529 upstream.
ESP-in-TCP can hand xfrm packets whose transport header offset no longer
fits after the stream parser trims the TCP envelope. The plain transport
header reset truncates that offset and triggers the skb warning path.
Use the careful transport-header helper and drop the skb through the
existing XFRM error path when the offset cannot be represented.
Fixes: e27cca96cd68 ("xfrm: add espintcp (RFC 8229)")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: Codex:GPT-5.4
Signed-off-by: Wyatt Feng <wf.kernel.dev@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/espintcp.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/net/xfrm/espintcp.c
+++ b/net/xfrm/espintcp.c
@@ -33,7 +33,11 @@ static void handle_esp(struct sk_buff *s
{
struct tcp_skb_cb *tcp_cb = (struct tcp_skb_cb *)skb->cb;
- skb_reset_transport_header(skb);
+ if (!skb_reset_transport_header_careful(skb)) {
+ XFRM_INC_STATS(sock_net(sk), LINUX_MIB_XFRMINERROR);
+ kfree_skb(skb);
+ return;
+ }
/* restore IP CB, we need at least IP6CB->nhoff */
memmove(skb->cb, &tcp_cb->header, sizeof(tcp_cb->header));
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 279/438] Bluetooth: hci_codec: validate vendor codec count length
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (277 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 7.2 278/438] Bluetooth: eir: validate service data length before reading UUID Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 280/438] Bluetooth: hci_sync: Serialize local codec list cleanup Greg Kroah-Hartman
` (170 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz,
Laxman Acharya Padhya, Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
commit d0795cfd6f655f4de84868a4f4bb41a03f037b3d upstream.
The Read Local Supported Codecs parsers consume the variable-sized
standard codec array before parsing the vendor codec count. Although the
initial reply-size check includes a vendor count byte in the fixed layout,
it does not guarantee that the byte remains after the standard codec array.
If a controller reply ends immediately after that array, calculating the
vendor codec array size reads vnd_codecs->num beyond the skb data. Use
skb_pull_data() to validate and consume each codec header before using its
count in both command variants.
Fixes: 8961987f3f5f ("Bluetooth: Enumerate local supported codec and cache details")
Fixes: 9ae664028a9e ("Bluetooth: Add support for Read Local Supported Codecs V2")
Cc: stable@vger.kernel.org
Suggested-by: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_codec.c | 36 ++++++++++++++++++------------------
1 file changed, 18 insertions(+), 18 deletions(-)
--- a/net/bluetooth/hci_codec.c
+++ b/net/bluetooth/hci_codec.c
@@ -145,11 +145,12 @@ void hci_read_supported_codecs(struct hc
skb_pull(skb, sizeof(rp->status));
- std_codecs = (void *)skb->data;
+ std_codecs = skb_pull_data(skb, sizeof(*std_codecs));
+ if (!std_codecs)
+ goto error;
/* validate codecs length before accessing */
- if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num))
+ if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num))
goto error;
/* enumerate codec capabilities of standard codecs */
@@ -161,15 +162,14 @@ void hci_read_supported_codecs(struct hc
LOCAL_CODEC_ACL_MASK | LOCAL_CODEC_SCO_MASK, &caps);
}
- skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num));
+ skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num));
- vnd_codecs = (void *)skb->data;
+ vnd_codecs = skb_pull_data(skb, sizeof(*vnd_codecs));
+ if (!vnd_codecs)
+ goto error;
/* validate vendor codecs length before accessing */
- if (skb->len <
- flex_array_size(vnd_codecs, codec, vnd_codecs->num)
- + sizeof(vnd_codecs->num))
+ if (skb->len < flex_array_size(vnd_codecs, codec, vnd_codecs->num))
goto error;
/* enumerate vendor codec capabilities */
@@ -214,11 +214,12 @@ void hci_read_supported_codecs_v2(struct
skb_pull(skb, sizeof(rp->status));
- std_codecs = (void *)skb->data;
+ std_codecs = skb_pull_data(skb, sizeof(*std_codecs));
+ if (!std_codecs)
+ goto error;
/* check for payload data length before accessing */
- if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num))
+ if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num))
goto error;
memset(&caps, 0, sizeof(caps));
@@ -229,15 +230,14 @@ void hci_read_supported_codecs_v2(struct
&caps);
}
- skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num));
+ skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num));
- vnd_codecs = (void *)skb->data;
+ vnd_codecs = skb_pull_data(skb, sizeof(*vnd_codecs));
+ if (!vnd_codecs)
+ goto error;
/* check for payload data length before accessing */
- if (skb->len <
- flex_array_size(vnd_codecs, codec, vnd_codecs->num)
- + sizeof(vnd_codecs->num))
+ if (skb->len < flex_array_size(vnd_codecs, codec, vnd_codecs->num))
goto error;
for (i = 0; i < vnd_codecs->num; i++) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 226/398] HID: logitech-hidpp: fix race condition when accessing stale stack pointer
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (223 preceding siblings ...)
2026-09-23 14:04 ` [PATCH 6.18 225/398] net: xfrm: reject unrepresentable espintcp transport headers Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 227/398] kselftest/arm64: Fix size of thread_data values for pthread_join() Greg Kroah-Hartman
` (177 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Benoît Sevens, Jiri Kosina,
Lee Jones
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Benoît Sevens <bsevens@google.com>
commit e2aaf2d3ad92ac4a8afa6b69ad4c38e7747d3d6e upstream.
The driver uses hidpp->send_receive_buf to point to a stack-allocated
buffer in the synchronous command path (__do_hidpp_send_message_sync).
However, this pointer is not cleared when the function returns.
If an event is processed (e.g. by a different thread) while the
send_mutex is held by a new command, but before that command has
updated send_receive_buf, the handler (hidpp_raw_hidpp_event) will
observe that the mutex is locked and dereference the stale pointer.
This results in an out-of-bounds access on a different thread's kernel
stack (or a NULL pointer dereference on the very first command).
Fix this by:
1. Clearing hidpp->send_receive_buf to NULL before releasing the mutex
in the synchronous command path.
2. Moving the assignment of the local 'question' and 'answer' pointers
inside the mutex_is_locked() block in the handler, and adding
a NULL check before dereferencing.
Signed-off-by: Benoît Sevens <bsevens@google.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Cc: Lee Jones <lee@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hid/hid-logitech-hidpp.c | 24 +++++++++++++++++-------
1 file changed, 17 insertions(+), 7 deletions(-)
--- a/drivers/hid/hid-logitech-hidpp.c
+++ b/drivers/hid/hid-logitech-hidpp.c
@@ -305,21 +305,22 @@ static int __do_hidpp_send_message_sync(
if (ret) {
dbg_hid("__hidpp_send_report returned err: %d\n", ret);
memset(response, 0, sizeof(struct hidpp_report));
- return ret;
+ goto out;
}
if (!wait_event_timeout(hidpp->wait, hidpp->answer_available,
5*HZ)) {
dbg_hid("%s:timeout waiting for response\n", __func__);
memset(response, 0, sizeof(struct hidpp_report));
- return -ETIMEDOUT;
+ ret = -ETIMEDOUT;
+ goto out;
}
if (response->report_id == REPORT_ID_HIDPP_SHORT &&
response->rap.sub_id == HIDPP_ERROR) {
ret = response->rap.params[1];
dbg_hid("%s:got hidpp error %02X\n", __func__, ret);
- return ret;
+ goto out;
}
if ((response->report_id == REPORT_ID_HIDPP_LONG ||
@@ -327,10 +328,14 @@ static int __do_hidpp_send_message_sync(
response->fap.feature_index == HIDPP20_ERROR) {
ret = response->fap.params[1];
dbg_hid("%s:got hidpp 2.0 error %02X\n", __func__, ret);
- return ret;
+ goto out;
}
- return 0;
+ ret = 0;
+
+out:
+ hidpp->send_receive_buf = NULL;
+ return ret;
}
/*
@@ -3838,8 +3843,7 @@ static int hidpp_input_configured(struct
static int hidpp_raw_hidpp_event(struct hidpp_device *hidpp, u8 *data,
int size)
{
- struct hidpp_report *question = hidpp->send_receive_buf;
- struct hidpp_report *answer = hidpp->send_receive_buf;
+ struct hidpp_report *question, *answer;
struct hidpp_report *report = (struct hidpp_report *)data;
int ret;
int last_online;
@@ -3849,6 +3853,12 @@ static int hidpp_raw_hidpp_event(struct
* previously sent command.
*/
if (unlikely(mutex_is_locked(&hidpp->send_mutex))) {
+ question = hidpp->send_receive_buf;
+ answer = hidpp->send_receive_buf;
+
+ if (!question)
+ return 0;
+
/*
* Check for a correct hidpp20 answer or the corresponding
* error
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 280/438] Bluetooth: hci_sync: Serialize local codec list cleanup
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (278 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 279/438] Bluetooth: hci_codec: validate vendor codec count length Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 281/438] Bluetooth: keep dst_type with dst when reusing an LE connection Greg Kroah-Hartman
` (169 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chengfeng Ye, Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengfeng Ye <nicoyip.dev@gmail.com>
commit 9a10987a2f160a44a638c9a35994ca6e3089696e upstream.
hci_dev_close_sync() clears hdev->local_codecs after releasing hdev->lock.
Codec list additions and both traversals in sco_sock_getsockopt() use that
lock, but the close path does not. A close and BT_CODEC query can therefore
interleave as follows:
hci_dev_close_sync() sco_sock_getsockopt()
hci_dev_lock()
fetch codec entry
hci_codec_list_clear()
kfree(entry)
read entry->id
The reader then accesses an entry which the close path has freed. KASAN
reported:
BUG: KASAN: slab-use-after-free in sco_sock_getsockopt+0xfa0/0xfe0
Read of size 1 at addr ffff8881001c3450
Call Trace:
sco_sock_getsockopt+0xfa0/0xfe0
do_sock_getsockopt+0x537/0x7b0
__sys_getsockopt+0xf2/0x170
Allocated by task 92:
hci_codec_list_add.isra.0+0x2c/0x440
hci_read_codec_capabilities+0x224/0x590
hci_read_supported_codecs+0x2c2/0x640
Freed by task 92:
kfree+0x131/0x3c0
hci_codec_list_clear+0xd8/0x160
hci_dev_close_sync+0x92a/0xfa0
Take hdev->lock around the clear operation at its existing point in the
close path. This makes the clear wait for active readers and prevents a new
traversal until the list is empty without changing teardown ordering.
Fixes: b938790e7054 ("Bluetooth: hci_codec: Fix leaking content of local_codecs")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_sync.c | 2 ++
1 file changed, 2 insertions(+)
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -5587,7 +5587,9 @@ int hci_dev_close_sync(struct hci_dev *h
memset(hdev->eir, 0, sizeof(hdev->eir));
memset(hdev->dev_class, 0, sizeof(hdev->dev_class));
bacpy(&hdev->random_addr, BDADDR_ANY);
+ hci_dev_lock(hdev);
hci_codec_list_clear(&hdev->local_codecs);
+ hci_dev_unlock(hdev);
hci_dev_put(hdev);
return err;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 227/398] kselftest/arm64: Fix size of thread_data values for pthread_join()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (224 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 226/398] HID: logitech-hidpp: fix race condition when accessing stale stack pointer Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 228/398] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc Greg Kroah-Hartman
` (176 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Thomas Huth, Will Deacon
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Huth <thuth@redhat.com>
commit 3d1ba5cbfb622025690c218d8f20da92a9ecb383 upstream.
pthread_join() stores the thread's return value (a "void *", i.e.
8 bytes on 64 bit computers) into the address that is passed as second
parameter. However, the entries of thread_data are only normal "int"s,
i.e. only 4 bytes. The additional 4 bytes of the return value clobber
whatever is adjacent on the stack, i.e. other members of the thread_data
array (which will be re-written in the next iteration of the for-loop,
so that nobody noticed this problem), or another other local variable
on the stack for the last iteration. Use "intptr_t" to declare the
thread_data array entries with the correct size.
Fixes: 29f080881601c ("kselftest/arm64: check GCR_EL1 after context switch")
Cc: stable@vger.kernel.org
Signed-off-by: Thomas Huth <thuth@redhat.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
+++ b/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
@@ -69,7 +69,7 @@ fail:
int execute_test(pid_t pid)
{
pthread_t thread_id[MAX_THREADS];
- int thread_data[MAX_THREADS];
+ intptr_t thread_data[MAX_THREADS];
for (int i = 0; i < MAX_THREADS; i++)
pthread_create(&thread_id[i], NULL,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 281/438] Bluetooth: keep dst_type with dst when reusing an LE connection
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (279 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 280/438] Bluetooth: hci_sync: Serialize local codec list cleanup Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 282/438] btrfs: take commit root semaphore when iterating in mark_block_group_to_copy() Greg Kroah-Hartman
` (168 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Radek Podgorny,
Luiz Augusto von Dentz
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Radek Podgorny <radek@podgorny.cz>
commit 555cd2bd860e7c4bdc3f4e4405b05515b0d9bc87 upstream.
hci_connect_le() swaps the caller's identity address for the peer's
cached RPA when one is known, and stamps the matching
ADDR_LE_DEV_RANDOM on the local dst_type. On the conn-reuse path only
the address is copied into the connection:
if (conn) {
bacpy(&conn->dst, dst);
so conn->dst ends up holding an RPA while conn->dst_type still names the
identity it was resolved from, and hci_le_create_conn_sync() puts that
pair on air unchanged. An RPA declared as a public address is not
something any peer can answer.
Measured on a CYW43438 against a peer advertising an RPA the host holds
the IRK for, connecting to the identity address over a raw L2CAP socket.
The first attempt creates the connection, the second takes the reuse
path:
LE Create Connection 3C:78:95:78:37:C3 type public
LE Create Connection 5B:75:A2:26:D6:18 type public
LE Connection Complete: Unknown Connection Identifier (0x02)
The second address is the peer's RPA. btmon annotates it with an OUI
lookup rather than "(Resolvable)" precisely because the command declares
it public; the same bit pattern annotates as resolvable once the type is
right.
The mistyped pair is also why nothing downstream repairs it.
hci_bdaddr_is_rpa() tests the type before the address, so an RPA carrying
a public type is not recognised as one, and hci_find_irk_by_addr() then
searches for an identity address that does not match it either.
Copy the type along with the address.
The assignment used to be unconditional just below this block and covered
both paths; it moved into hci_conn_add_unset(), which the reuse path does
not go through.
Cc: stable@vger.kernel.org
Fixes: 14b06c3a88f7 ("Bluetooth: HCI: Always use the identity address when initializing a connection")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Radek Podgorny <radek@podgorny.cz>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_conn.c | 8 ++++++++
1 file changed, 8 insertions(+)
--- a/net/bluetooth/hci_conn.c
+++ b/net/bluetooth/hci_conn.c
@@ -1518,7 +1518,15 @@ struct hci_conn *hci_connect_le(struct h
}
if (conn) {
+ /* dst may just have been swapped for the peer's RPA above, and
+ * dst_type describes dst -- it has to travel with it. Leaving
+ * the identity type behind makes the pair describe a peer that
+ * does not exist, and nothing downstream repairs it:
+ * hci_bdaddr_is_rpa() tests the type before the address, so
+ * the RPA is never treated as one.
+ */
bacpy(&conn->dst, dst);
+ conn->dst_type = dst_type;
} else {
conn = hci_conn_add_unset(hdev, LE_LINK, dst, dst_type, role);
if (IS_ERR(conn))
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 228/398] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (225 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 227/398] kselftest/arm64: Fix size of thread_data values for pthread_join() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 229/398] arm64: dts: renesas: r8a779f0: Set UFS lane count Greg Kroah-Hartman
` (175 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bradley Morgan, Vladimir Murzin,
Mark Rutland, Will Deacon
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bradley Morgan <include@grrlz.net>
commit 955d86e5f3b95b731991fdb84966c50b16314629 upstream.
swsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub
vectors with an hvc, but never passes the arguments. x0 is not set to
HVC_SET_VECTORS and x1 is not set to the vector address, so the stub
dispatch falls through and returns without writing vbar_el2. EL2 is
left pointing at the trans_pgd copy of the vectors, a page that
swsusp_free() releases right after resume.
Set the arguments up the same way __hyp_set_vectors() does.
Without this fix, Vladimir was able to trigger a hang when resuming from
hibernation with CONFIG_PAGE_POISONING=y and page_poison=on.
Fixes: 788bfdd97434 ("arm64: trans_pgd: hibernate: Add trans_pgd_copy_el2_vectors")
Cc: stable@vger.kernel.org
Signed-off-by: Bradley Morgan <include@grrlz.net>
Reviewed-by: Vladimir Murzin <vladimir.murzin@arm.com>
Tested-by: Vladimir Murzin <vladimir.murzin@arm.com>
Acked-by: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kernel/hibernate-asm.S | 2 ++
1 file changed, 2 insertions(+)
--- a/arch/arm64/kernel/hibernate-asm.S
+++ b/arch/arm64/kernel/hibernate-asm.S
@@ -89,6 +89,8 @@ alternative_insn "dc cvau, x4", "dc civ
isb
cbz x24, 3f /* Do we need to re-initialise EL2? */
+ mov x1, x24
+ mov x0, #HVC_SET_VECTORS
hvc #0
3: ret
SYM_CODE_END(swsusp_arch_suspend_exit)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 282/438] btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (280 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 281/438] Bluetooth: keep dst_type with dst when reusing an LE connection Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 283/438] btrfs: fix creation of compressed inline extents that dont save space Greg Kroah-Hartman
` (167 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johannes Thumshirn, Hongling Zeng,
David Sterba
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongling Zeng <zenghongling@kylinos.cn>
commit 0594e3423f4ba3137c734371169491f9a98e9af4 upstream.
mark_block_group_to_copy() iterates over the commit root with
skip_locking=true. A concurrent transaction commit can swap and free
the commit root during iteration, causing use-after-free when
accessing extent buffers.
Fix it by using path->need_commit_sem to protect the commit root search.
Fixes: 78ce9fc269af ("btrfs: zoned: mark block groups to copy for device-replace")
CC: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.5
Reviewed-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/dev-replace.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/btrfs/dev-replace.c
+++ b/fs/btrfs/dev-replace.c
@@ -493,6 +493,7 @@ static int mark_block_group_to_copy(stru
path->reada = READA_FORWARD;
path->search_commit_root = true;
path->skip_locking = true;
+ path->need_commit_sem = true;
key.objectid = src_dev->devid;
key.type = BTRFS_DEV_EXTENT_KEY;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 229/398] arm64: dts: renesas: r8a779f0: Set UFS lane count
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (226 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 228/398] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 230/398] arm64: percpu: Fix this_cpu_write() casting Greg Kroah-Hartman
` (174 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Koichiro Den, Geert Uytterhoeven
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Koichiro Den <den@valinux.co.jp>
commit 8dc2615d5702059b2b71fca6f93c0d7d10ae54cb upstream.
Since commit e72323f3b09f ("scsi: ufs: core: Configure only active lanes
during link"), the following error is observed on R-Car S4:
ufshcd-renesas e6860000.ufs: Tx lane mismatch [config,reported] [2,1]
ufshcd-renesas e6860000.ufs: link startup failed -67
ufshcd-renesas e6860000.ufs: error -ENOLINK: Initialization failed with error -67
ufshcd-renesas e6860000.ufs: probe with driver ufshcd-renesas failed with error -67
R-Car S4 has one UFS lane per direction, as described in section 152.1
of its hardware manual. Without lanes-per-direction, the UFS platform
driver defaults to two lanes.
Previously, the core used PA_CONNECTEDRXDATALANES and
PA_CONNECTEDTXDATALANES to configure the link without checking them
against lanes-per-direction, so the missing property did not prevent
initialization.
Explicitly set lanes-per-direction to 1, now that the validation is in
place.
Fixes: 5235d551779d ("arm64: dts: renesas: r8a779f0: Add UFS node")
Cc: stable@vger.kernel.org # 7.2+
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Tested-by: Geert Uytterhoeven <geert+renesas@glider.be>
Link: https://patch.msgid.link/20260911073058.253000-1-den@valinux.co.jp
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/boot/dts/renesas/r8a779f0.dtsi | 1 +
1 file changed, 1 insertion(+)
--- a/arch/arm64/boot/dts/renesas/r8a779f0.dtsi
+++ b/arch/arm64/boot/dts/renesas/r8a779f0.dtsi
@@ -891,6 +891,7 @@
clocks = <&cpg CPG_MOD 1514>, <&ufs30_clk>;
clock-names = "fck", "ref_clk";
freq-table-hz = <200000000 200000000>, <38400000 38400000>;
+ lanes-per-direction = <1>;
power-domains = <&sysc R8A779F0_PD_ALWAYS_ON>;
resets = <&cpg 1514>;
status = "disabled";
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 283/438] btrfs: fix creation of compressed inline extents that dont save space
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (281 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 282/438] btrfs: take commit root semaphore when iterating in mark_block_group_to_copy() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 284/438] btrfs: derive f_fsid with dev_t only when temp_fsid is active Greg Kroah-Hartman
` (166 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hanabishi, Qu Wenruo, Filipe Manana,
David Sterba
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
commit cc337324cc6be1ce0ae7e5a068dcb7e99ae1b59c upstream.
If the compressed data of an inline extent is larger than or equals to the
size of the uncompressed data, we are still allowing the creation of the
compressed inline extent, which does not result in any benefits, quite the
contrary as we waste metadata space and have to decompress when reading.
This is a recent regression introduced in commit 3eaf5f082c4c ("btrfs:
extract inlined creation into a dedicated delalloc helper").
It happens because we are passing the block size to btrfs_compress_bio(),
so we don't get -E2BIG from the compression code anymore, but we can not
pass i_size either, because if i_size is smaller than sector size, we
end up never creating lzo compressed inline extent for such small i_size
values. So refuse the compressed result at run_delalloc_inline() if
its size is not smaller than the uncompressed size (i_size).
Reported-by: Hanabishi <i.r.e.c.c.a.k.u.n+kernel.org@gmail.com>
Link: https://lore.kernel.org/linux-btrfs/c97652a5-ac6b-4de6-aa23-3cdebc01d00b@gmail.com/
Fixes: 3eaf5f082c4c ("btrfs: extract inlined creation into a dedicated delalloc helper")
CC: stable@vger.kernel.org # 7.1+
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/inode.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
--- a/fs/btrfs/inode.c
+++ b/fs/btrfs/inode.c
@@ -2338,12 +2338,27 @@ static int run_delalloc_inline(struct bt
} else if (inode->prop_compress) {
compress_type = inode->prop_compress;
}
+ /*
+ * We need to pass blocksize and not i_size, otherwise we can't
+ * create compressed inline extents for data smaller than sector
+ * size with lzo.
+ */
cb = btrfs_compress_bio(inode, 0, blocksize, compress_type, compress_level, 0);
if (IS_ERR(cb)) {
cb = NULL;
/* Just fall back to non-compressed case. */
} else {
compressed_size = cb->bbio.bio.bi_iter.bi_size;
+ /*
+ * If we did not save space, it's pointless and wasteful
+ * to have an inline compressed extent, so fallback to
+ * an uncompressed inline extent.
+ */
+ if (compressed_size >= i_size) {
+ cleanup_compressed_bio(cb);
+ cb = NULL;
+ compressed_size = 0;
+ }
}
}
if (!can_cow_file_range_inline(inode, 0, i_size, compressed_size)) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 230/398] arm64: percpu: Fix this_cpu_write() casting
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (227 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 229/398] arm64: dts: renesas: r8a779f0: Set UFS lane count Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 231/398] arm64: percpu: Fix this_cpu_and() mask generation Greg Kroah-Hartman
` (173 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Laight, Mark Rutland,
Jinjie Ruan, Muhammad Usama Anjum, Christopher Lameter (Ampere),
Ada Couprie Diaz, Ard Biesheuvel, Catalin Marinas, James Morse,
Marc Zyngier, Peter Zijlstra, Vladimir Murzin, Will Deacon,
Yang Shi, Lorenzo Stoakes (ARM)
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Rutland <mark.rutland@arm.com>
commit 885bff055a0f251a51a0d4fd4f0a7b525582a3de upstream.
The arm64 implementation of this_cpu_write() casts 'val' to unsigned
long. This is necessary to handle cases where 'val' is a pointer type,
and to avoid spurious compiler warnings for the (unreachable!) cases
where the pointer type would be cast to a smaller integer type.
Unfortunately, the cast is applied to 'val' rather than '(val)', which
won't always generate the expected value when 'val' is an expression.
For example, for this_cpu_write(pcp, zero - 1), where 'pcp' is a u64 and
'zero' is a u32:
* 'zero' ===> (u32) 0x00000000
* 'zero - 1' ===> (u32) 0xffffffff
* '(unsigned long)zero - 1' ===> (u64) 0xffffffffffffffff
* '(unsigned long)(zero - 1)' ===> (u64) 0x00000000ffffffff
Fix this by adding brackets around 'val'.
Fixes: 959bf2fd03b5 ("arm64: percpu: Rewrite per-cpu ops to allow use of LSE atomics")
Reported-by: David Laight <david.laight.linux@gmail.com>
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Reviewed-by: David Laight <david.laight.linux@gmail.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Tested-by: Muhammad Usama Anjum <usama.anjum@arm.com>
Acked-by: Christopher Lameter (Ampere) <cl@gentwo.org>
Cc: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Vladimir Murzin <vladimir.murzin@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/percpu.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/arch/arm64/include/asm/percpu.h
+++ b/arch/arm64/include/asm/percpu.h
@@ -179,13 +179,13 @@ PERCPU_RET_OP(add, add, ldadd)
_pcp_protect_return(__percpu_read_64, pcp)
#define this_cpu_write_1(pcp, val) \
- _pcp_protect(__percpu_write_8, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_8, pcp, (unsigned long)(val))
#define this_cpu_write_2(pcp, val) \
- _pcp_protect(__percpu_write_16, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_16, pcp, (unsigned long)(val))
#define this_cpu_write_4(pcp, val) \
- _pcp_protect(__percpu_write_32, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_32, pcp, (unsigned long)(val))
#define this_cpu_write_8(pcp, val) \
- _pcp_protect(__percpu_write_64, pcp, (unsigned long)val)
+ _pcp_protect(__percpu_write_64, pcp, (unsigned long)(val))
#define this_cpu_add_1(pcp, val) \
_pcp_protect(__percpu_add_case_8, pcp, val)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 284/438] btrfs: derive f_fsid with dev_t only when temp_fsid is active
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (282 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 283/438] btrfs: fix creation of compressed inline extents that dont save space Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 285/438] btrfs: clear free space tree creation state on rebuild failure Greg Kroah-Hartman
` (165 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Dave Hansen, Anand Jain,
David Sterba
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Anand Jain <asj@kernel.org>
commit 72de4807ba84da485dda1a91572d66da9149e95a upstream.
Commit c2a74ed0494c ("btrfs: derive f_fsid from on-disk fsid and dev_t")
mixed dev_t into f_fsid for all single-device setups to avoid f_fsid
collisions with cloned filesystems.
However, doing this unconditionally breaks backward compatibility.
statfs(2) f_fsid changes after a kernel upgrade, and also can shift
across reboots or dev re-attaches as dev_t values change.
Fix this by only mixing dev_t when temp_fsid is active. This means for
non-temp_fsid setups or the original mount, we use the old method of
deriving fsid based on the UUID.
So in the case of a cloned Btrfs filesystem, we won't be able to
maintain the same fsid across mount recycle if the mount order changes.
Reported-by: Dave Hansen <dave.hansen@intel.com>
Link: https://lore.kernel.org/linux-btrfs/be0c08f5-2f31-40f5-8a3b-f2f58b3e00ff@intel.com
Fixes: c2a74ed0494c ("btrfs: derive f_fsid from on-disk fsid and dev_t")
CC: stable@vger.kernel.org # 7.2
Signed-off-by: Anand Jain <asj@kernel.org>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/super.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/fs/btrfs/super.c
+++ b/fs/btrfs/super.c
@@ -1845,8 +1845,12 @@ static int btrfs_statfs(struct dentry *d
f_fsid.val[0] ^= btrfs_root_id(BTRFS_I(d_inode(dentry))->root) >> 32;
f_fsid.val[1] ^= btrfs_root_id(BTRFS_I(d_inode(dentry))->root);
- /* Hash dev_t to avoid f_fsid collision with cloned filesystems. */
- if (fs_info->fs_devices->total_devices == 1) {
+ /*
+ * Hash dev_t to avoid f_fsid collisions with cloned filesystems.
+ * Only do this when a clone is present so the original filesystem
+ * (mounted first) maintains backward-compatible f_fsid behavior.
+ */
+ if (fs_info->fs_devices->temp_fsid) {
__kernel_fsid_t dev_fsid =
u64_to_fsid(huge_encode_dev(fs_info->fs_devices->latest_dev->bdev->bd_dev));
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 231/398] arm64: percpu: Fix this_cpu_and() mask generation
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (228 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 230/398] arm64: percpu: Fix this_cpu_write() casting Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 232/398] arm64: percpu: Fix LSE operations on {8,16}-bit types Greg Kroah-Hartman
` (172 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Rutland, Jinjie Ruan,
Muhammad Usama Anjum, Christopher Lameter (Ampere),
Ada Couprie Diaz, Ard Biesheuvel, Catalin Marinas, James Morse,
Marc Zyngier, Peter Zijlstra, Vladimir Murzin, Will Deacon,
Yang Shi
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Rutland <mark.rutland@arm.com>
commit 44274c657256b4911de82f8104e9e22f054cf742 upstream.
The arm64 implementation of this_cpu_and(pcp, val) is built in terms of
ANDNOT operations, which requires the 'val' argument to be bitwise
negated. The bitwise negation is not implemented correctly, with two
bugs described below.
(1) The bitwise negation is performed as '~val' rather than '~(val)'.
This won't always generate the expected value when 'val' is an
expression.
For example, for this_cpu_and(pcp, 1 - 1):
* 'val' is '1 - 1' ===> (int) 0x00000000
* '~val' is '~1 - 1' ===> (int) 0xfffffffd
* '~(val)' is '~(1 - 1)' ===> (int) 0xffffffff
... and thus bit[1] of 'pcp' would be preserved unexpectedly by the
ANDNOT operation.
(2) The bitwise negation is performed on 'val' before it has been cast
to (at least) the width of 'pcp'. This won't always generate the
expected value for the upper bits.
For example, for this_cpu_and(pcp, zero), where 'pcp' is a u64 and
'zero' is a u32:
* 'zero' ===> (u32) 0x00000000
* '~(zero)' ===> (u32) 0xffffffff
* '(u64)~(zero)' ===> (u64) 0x00000000ffffffff
* '~((u64)(zero))' ===> (u64) 0xffffffffffffffff
... and thus bits[63:32] of 'pcp' would be preserved unexpectedly by
the ANDNOT operation.
Fix these issues by adding brackets around 'val', and by casting 'val'
to an appropriately-sized type before bitwise negation.
Fixes: 959bf2fd03b5 ("arm64: percpu: Rewrite per-cpu ops to allow use of LSE atomics")
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Tested-by: Muhammad Usama Anjum <usama.anjum@arm.com>
Acked-by: Christopher Lameter (Ampere) <cl@gentwo.org>
Cc: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Vladimir Murzin <vladimir.murzin@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/percpu.h | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/arch/arm64/include/asm/percpu.h
+++ b/arch/arm64/include/asm/percpu.h
@@ -206,13 +206,13 @@ PERCPU_RET_OP(add, add, ldadd)
_pcp_protect_return(__percpu_add_return_case_64, pcp, val)
#define this_cpu_and_1(pcp, val) \
- _pcp_protect(__percpu_andnot_case_8, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_8, pcp, ~(u8)(val))
#define this_cpu_and_2(pcp, val) \
- _pcp_protect(__percpu_andnot_case_16, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_16, pcp, ~(u16)(val))
#define this_cpu_and_4(pcp, val) \
- _pcp_protect(__percpu_andnot_case_32, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_32, pcp, ~(u32)(val))
#define this_cpu_and_8(pcp, val) \
- _pcp_protect(__percpu_andnot_case_64, pcp, ~val)
+ _pcp_protect(__percpu_andnot_case_64, pcp, ~(u64)(val))
#define this_cpu_or_1(pcp, val) \
_pcp_protect(__percpu_or_case_8, pcp, val)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 285/438] btrfs: clear free space tree creation state on rebuild failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (283 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 284/438] btrfs: derive f_fsid with dev_t only when temp_fsid is active Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 286/438] gpiolib: Put fwnode reference on failure Greg Kroah-Hartman
` (164 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Boris Burkov, Qu Wenruo,
Guanghui Yang, David Sterba
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanghui Yang <3497809730@qq.com>
commit 3565893cc72cdf6b795cf6a33e7ff9605322334d upstream.
btrfs_rebuild_free_space_tree() sets BTRFS_FS_CREATING_FREE_SPACE_TREE
before rebuilding the free space tree. Several error paths return
without clearing this flag.
The transaction restart failure path can leave the flag set on a live
filesystem, causing delayed reference processing to be skipped. Clear it
on all free space tree rebuild failure paths. Keep
BTRFS_FS_FREE_SPACE_TREE_UNTRUSTED set, since a failed rebuild leaves
the free space tree untrusted. Callers must fall back to extent-tree
caching.
Fixes: 882af9f13e83 ("btrfs: handle free space tree rebuild in multiple transactions")
CC: stable@vger.kernel.org # 6.14+
Assisted-by: LLM
Reviewed-by: Boris Burkov <boris@bur.io>
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Guanghui Yang <3497809730@qq.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/free-space-tree.c | 14 ++++++++++----
1 file changed, 10 insertions(+), 4 deletions(-)
--- a/fs/btrfs/free-space-tree.c
+++ b/fs/btrfs/free-space-tree.c
@@ -1353,7 +1353,7 @@ int btrfs_rebuild_free_space_tree(struct
if (unlikely(ret)) {
btrfs_abort_transaction(trans, ret);
btrfs_end_transaction(trans);
- return ret;
+ goto out_clear;
}
node = rb_first_cached(&fs_info->block_group_cache_tree);
@@ -1371,14 +1371,16 @@ int btrfs_rebuild_free_space_tree(struct
if (unlikely(ret)) {
btrfs_abort_transaction(trans, ret);
btrfs_end_transaction(trans);
- return ret;
+ goto out_clear;
}
next:
if (btrfs_should_end_transaction(trans)) {
btrfs_end_transaction(trans);
trans = btrfs_start_transaction(free_space_root, 1);
- if (IS_ERR(trans))
- return PTR_ERR(trans);
+ if (IS_ERR(trans)) {
+ ret = PTR_ERR(trans);
+ goto out_clear;
+ }
}
node = rb_next(node);
}
@@ -1390,6 +1392,10 @@ next:
ret = btrfs_commit_transaction(trans);
clear_bit(BTRFS_FS_FREE_SPACE_TREE_UNTRUSTED, &fs_info->flags);
return ret;
+
+out_clear:
+ clear_bit(BTRFS_FS_CREATING_FREE_SPACE_TREE, &fs_info->flags);
+ return ret;
}
static int __add_block_group_free_space(struct btrfs_trans_handle *trans,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 232/398] arm64: percpu: Fix LSE operations on {8,16}-bit types
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (229 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 231/398] arm64: percpu: Fix this_cpu_and() mask generation Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 233/398] Bluetooth: btusb: fix NXP IW610 composite device handling Greg Kroah-Hartman
` (171 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Rutland, Jinjie Ruan,
Ada Couprie Diaz, Ard Biesheuvel, Catalin Marinas, James Morse,
Marc Zyngier, Peter Zijlstra, Vladimir Murzin, Will Deacon,
Yang Shi
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Rutland <mark.rutland@arm.com>
commit 8cf2093f5372952a9ebc805c418d45df7112cd14 upstream.
The assembly for __percpu_##name##_case_##sz() and
__percpu_##name##_return_case_##sz() doesn't use the 'sfx' macro
argument to form the LSE instruction. Without 'sfx', a W register
argument will imply a 32-bit memory location, and consequently
{8,16}-bit ops will erroneously read and write 32 bits of memory when
the LSE instruction is used.
Fix this by appending 'sfx' to 'op_lse' to LSE instruction. It is not
necessary (and not valid) to append 'sfx' to 'op_llsc', as 'op_llsc' is
a register-register operation which does not access memory (and does not
take a size suffix).
Fixes: 959bf2fd03b5 ("arm64: percpu: Rewrite per-cpu ops to allow use of LSE atomics")
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Cc: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Cc: Ard Biesheuvel <ardb@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: James Morse <james.morse@arm.com>
Cc: Marc Zyngier <maz@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Vladimir Murzin <vladimir.murzin@arm.com>
Cc: Will Deacon <will@kernel.org>
Cc: Yang Shi <yang@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Reviewed-by: Vladimir Murzin <vladimir.murzin@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/percpu.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/arch/arm64/include/asm/percpu.h
+++ b/arch/arm64/include/asm/percpu.h
@@ -77,7 +77,7 @@ __percpu_##name##_case_##sz(void *ptr, u
" stxr" #sfx "\t%w[loop], %" #w "[tmp], %[ptr]\n" \
" cbnz %w[loop], 1b", \
/* LSE atomics */ \
- #op_lse "\t%" #w "[val], %" #w "[tmp], %[ptr]\n" \
+ #op_lse #sfx "\t%" #w "[val], %" #w "[tmp], %[ptr]\n" \
__nops(3)) \
: [loop] "=&r" (loop), [tmp] "=&r" (tmp), \
[ptr] "+Q"(*(u##sz *)ptr) \
@@ -98,7 +98,7 @@ __percpu_##name##_return_case_##sz(void
" stxr" #sfx "\t%w[loop], %" #w "[ret], %[ptr]\n" \
" cbnz %w[loop], 1b", \
/* LSE atomics */ \
- #op_lse "\t%" #w "[val], %" #w "[ret], %[ptr]\n" \
+ #op_lse #sfx "\t%" #w "[val], %" #w "[ret], %[ptr]\n" \
#op_llsc "\t%" #w "[ret], %" #w "[ret], %" #w "[val]\n" \
__nops(2)) \
: [loop] "=&r" (loop), [ret] "=&r" (ret), \
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 286/438] gpiolib: Put fwnode reference on failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (284 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 285/438] btrfs: clear free space tree creation state on rebuild failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 287/438] gpiolib: of: dont mark hog nodes OF_POPULATED before a chip is found Greg Kroah-Hartman
` (163 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Michail Tatas, Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michail Tatas <michail.tatas@gmail.com>
commit 16b10f64c63f78220c3b4035f1ed6cd3bdcb0b02 upstream.
We get a reference to the fwnode handle which we pass to
gpio_shared_make_ref. In case it fails we do not put the reference.
Fix by putting the reference in the failure case
Fixes: 49416483a953 ("gpio: shared: allow sharing a reset-gpios pin between reset-gpio and gpiolib")
Cc: stable@vger.kernel.org
Signed-off-by: Michail Tatas <michail.tatas@gmail.com>
Link: https://patch.msgid.link/an4Asr4tx3D2QvLD@michalis-linux
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpiolib-shared.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
--- a/drivers/gpio/gpiolib-shared.c
+++ b/drivers/gpio/gpiolib-shared.c
@@ -261,10 +261,13 @@ static int gpio_shared_of_traverse(struc
con_id[con_id_len - suffix_len] = '\0';
}
- ref = gpio_shared_make_ref(fwnode_handle_get(of_fwnode_handle(curr)),
- con_id, args.args[1]);
- if (!ref)
+ struct fwnode_handle *curr_fwnode =
+ fwnode_handle_get(of_fwnode_handle(curr));
+ ref = gpio_shared_make_ref(curr_fwnode, con_id, args.args[1]);
+ if (!ref) {
+ fwnode_handle_put(curr_fwnode);
return -ENOMEM;
+ }
if (!list_empty(&entry->refs))
pr_debug("GPIO %u at %s is shared by multiple firmware nodes\n",
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 233/398] Bluetooth: btusb: fix NXP IW610 composite device handling
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (230 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 232/398] arm64: percpu: Fix LSE operations on {8,16}-bit types Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 234/398] Bluetooth: eir: validate service data length before reading UUID Greg Kroah-Hartman
` (170 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nicolas Thibert,
Luiz Augusto von Dentz
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Thibert <nithibert@gmail.com>
commit 2b50adefed9808a56d84d1de803cad882cc787fa upstream.
The NXP IW610 module exposes itself as a composite USB device
(0471:0215) with three interfaces: two real Bluetooth HCI interfaces
(class 0xe0) and one vendor-specific WiFi interface (class 0xff) used
by mwifiex-nxp.
The composite device's whole USB descriptor reports class 0xe0/01/01
(Bluetooth), so btusb_table's generic USB_DEVICE_INFO(0xe0, 0x01, 0x01)
entry matches every interface, not just the two real HCI ones -- btusb
ends up binding the WiFi interface too, and mwifiex-nxp never gets it.
Fix:
1. In btusb_table (the table the USB core actually matches against),
explicitly ignore the WiFi interface via BTUSB_IGNORE, ahead of the
generic entry.
2. In quirks_table, scope the existing BTUSB_MARVELL entry to the BT
interface class instead of matching the whole device by VID/PID
(harmless either way since quirks_table isn't consulted for initial
binding, but keep it correct).
Not upstream anywhere: checked NXP's own i.MX kernel fork
(nxp-imx/linux-imx), no IW610 references in btusb.c on any branch --
their reference designs wire this chip differently (WiFi over SDIO
per their release notes), so they never hit this.
Signed-off-by: Nicolas Thibert <nithibert@gmail.com>
Cc: stable@vger.kernel.org
Assisted-by: LLM (Claude Sonnet 5, Anthropic)
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/bluetooth/btusb.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -70,6 +70,15 @@ static struct usb_driver btusb_driver;
#define BTUSB_BROKEN_EXT_SCAN BIT(29)
static const struct usb_device_id btusb_table[] = {
+ /*
+ * NXP IW610 (0471:0215): the composite device reports Bluetooth
+ * class at the whole-device level, so the generic entry below
+ * would also match this WiFi vendor interface. Ignore it here
+ * first so mwifiex-nxp can bind it instead.
+ */
+ { USB_DEVICE_AND_INTERFACE_INFO(0x0471, 0x0215, 0xff, 0xff, 0xff),
+ .driver_info = BTUSB_IGNORE },
+
/* Generic Bluetooth USB device */
{ USB_DEVICE_INFO(0xe0, 0x01, 0x01) },
@@ -474,6 +483,14 @@ static const struct usb_device_id quirks
{ USB_DEVICE(0x1286, 0x2046), .driver_info = BTUSB_MARVELL },
{ USB_DEVICE(0x1286, 0x204e), .driver_info = BTUSB_MARVELL },
+ /*
+ * NXP IW610 BT interfaces (Marvell-lineage silicon, same quirk as
+ * the 0x1286 entries above). Scoped to the BT interface class,
+ * not just VID/PID -- see the btusb_table entry above.
+ */
+ { USB_DEVICE_AND_INTERFACE_INFO(0x0471, 0x0215, 0xe0, 0x01, 0x01),
+ .driver_info = BTUSB_MARVELL },
+
/* Intel Bluetooth devices */
{ USB_DEVICE(0x8087, 0x0025), .driver_info = BTUSB_INTEL_COMBINED },
{ USB_DEVICE(0x8087, 0x0026), .driver_info = BTUSB_INTEL_COMBINED },
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 287/438] gpiolib: of: dont mark hog nodes OF_POPULATED before a chip is found
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (285 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 286/438] gpiolib: Put fwnode reference on failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 288/438] dmaengine: sun6i: fix non-atomic read of DMA position registers Greg Kroah-Hartman
` (162 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abdurrahman Hussain, Daniel Drake,
Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abdurrahman Hussain <abdurrahman@nexthop.ai>
commit 1f1d0812f6a8ab8e6f709c599f137c99646512cc upstream.
When a gpio-hog node is attached by a device-tree overlay before its
parent GPIO chip has been registered, of_gpio_notify() sets
OF_POPULATED on the node via of_node_test_and_set_flag() and only then
discovers that there is no gpio_device for the parent, returning
NOTIFY_DONE without clearing the flag.
Since gpiochip_hog_lines() skips any hog child whose of_node carries
OF_POPULATED, the leaked flag makes the hog silently ignored when the
chip is registered later. Applying an overlay containing both a GPIO
controller node and its hog children - and populating devices only
after the overlay apply completes - hits this on every boot; the hog
is only applied if the chip driver is unbound (which clears the flag
in the remove path) and rebound.
Look up the parent gpio_device before claiming the node so that a hog
attached ahead of its chip stays unclaimed and is picked up normally
by gpiochip_hog_lines() at registration time.
Signed-off-by: Abdurrahman Hussain <abdurrahman@nexthop.ai>
Fixes: a23226b7c1f6 ("gpiolib: handle gpio-hogs only once")
Cc: stable@vger.kernel.org
Reviewed-by: Daniel Drake <dan@reactivated.net>
Link: https://patch.msgid.link/20260815-gpiolib-of-hog-flag-leak-v1-1-6126aac5f6f3@nexthop.ai
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpio/gpiolib-of.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/gpio/gpiolib-of.c b/drivers/gpio/gpiolib-of.c
index 940b566946ce..f36e4b171fa7 100644
--- a/drivers/gpio/gpiolib-of.c
+++ b/drivers/gpio/gpiolib-of.c
@@ -788,13 +788,13 @@ static int of_gpio_notify(struct notifier_block *nb, unsigned long action,
if (!of_property_read_bool(rd->dn, "gpio-hog"))
return NOTIFY_DONE; /* not for us */
- if (of_node_test_and_set_flag(rd->dn, OF_POPULATED))
- return NOTIFY_DONE;
-
gdev = of_find_gpio_device_by_node(rd->dn->parent);
if (!gdev)
return NOTIFY_DONE; /* not for us */
+ if (of_node_test_and_set_flag(rd->dn, OF_POPULATED))
+ return NOTIFY_DONE;
+
ret = gpiochip_add_hog(gpio_device_get_chip(gdev), of_fwnode_handle(rd->dn));
if (ret < 0) {
pr_err("%s: failed to add hogs for %pOF\n", __func__,
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 234/398] Bluetooth: eir: validate service data length before reading UUID
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (231 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 233/398] Bluetooth: btusb: fix NXP IW610 composite device handling Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 235/398] Bluetooth: hci_codec: validate vendor codec count length Greg Kroah-Hartman
` (169 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Aamir Ahmed, Luiz Augusto von Dentz
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aamir Ahmed <elb12345@hotmail.co.uk>
commit e8241766794cf551d787fa3a77c0d54bbea6f6aa upstream.
eir_get_service_data() reads a 16-bit UUID from the service data using
get_unaligned_le16() without first checking that the data is long enough
to hold a UUID16 (2 bytes). If a malformed EIR entry has a service data
field with only 1 byte of payload (field_len=2), eir_get_data() returns
dlen=1. The subsequent get_unaligned_le16() then reads 1 byte past the
field boundary.
Additionally, if the corrupted UUID happens to match, the length
calculation "dlen - 2" underflows to SIZE_MAX since dlen is size_t.
Current callers either pass NULL for the length parameter or bounds-check
the returned length, but future callers may not.
Add a check that dlen >= sizeof(u16) and skip fields that are too short
to contain a valid UUID16.
Fixes: 8f9ae5b3ae80 ("Bluetooth: eir: Add helpers for managing service data")
Cc: stable@vger.kernel.org
Signed-off-by: Aamir Ahmed <elb12345@hotmail.co.uk>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/eir.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
--- a/net/bluetooth/eir.c
+++ b/net/bluetooth/eir.c
@@ -373,7 +373,15 @@ void *eir_get_service_data(u8 *eir, size
size_t dlen;
while ((eir = eir_get_data(eir, eir_len, EIR_SERVICE_DATA, &dlen))) {
- u16 value = get_unaligned_le16(eir);
+ u16 value;
+
+ if (dlen < sizeof(value)) {
+ eir += dlen;
+ eir_len = eir_end - eir;
+ continue;
+ }
+
+ value = get_unaligned_le16(eir);
if (uuid == value) {
if (len)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 288/438] dmaengine: sun6i: fix non-atomic read of DMA position registers
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (286 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 287/438] gpiolib: of: dont mark hog nodes OF_POPULATED before a chip is found Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 289/438] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status Greg Kroah-Hartman
` (161 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Lugnberg, Frank Li,
Vinod Koul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Lugnberg <christian.lugnberg@soundtrack.io>
commit c90b6973daa37f4c283342dff881ae001dea4fe6 upstream.
sun6i_get_chan_size() reads DMA_CHAN_LLI_ADDR and DMA_CHAN_CUR_CNT in two
separate readl() calls with no synchronisation between them:
pos = readl(pchan->base + DMA_CHAN_LLI_ADDR);
bytes = readl(pchan->base + DMA_CHAN_CUR_CNT);
DMA_CHAN_LLI_ADDR holds the physical address of the *next* descriptor the
engine will load once the current one completes. DMA_CHAN_CUR_CNT holds the
remaining byte count for the *current* descriptor. If the DMA engine
advances to the next LLI entry between the two reads, pos becomes stale: it
still points to what was the next descriptor at the time of the first read,
but that descriptor is now the current one and CUR_CNT reflects its initial
(full) byte count. The subsequent virtual-chain walk starts one entry too
early and accumulates an extra full period's worth of bytes into the
residue estimate.
Fix this by re-reading DMA_CHAN_LLI_ADDR after DMA_CHAN_CUR_CNT and
retrying if the value changed. This double-read pattern guarantees that
both registers were sampled during the same descriptor interval. The cost
is at most one extra readl() pair per call in the racy case, which occurs
only at descriptor boundaries (~every 2 ms) and is negligible.
Fixes: a90e173f3faf ("dmaengine: sun6i: Add cyclic capability")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Christian Lugnberg <christian.lugnberg@soundtrack.io>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260817135723.12807-2-christian.lugnberg@soundtrack.io
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma/sun6i-dma.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/drivers/dma/sun6i-dma.c
+++ b/drivers/dma/sun6i-dma.c
@@ -354,8 +354,10 @@ static size_t sun6i_get_chan_size(struct
size_t bytes;
dma_addr_t pos;
- pos = readl(pchan->base + DMA_CHAN_LLI_ADDR);
- bytes = readl(pchan->base + DMA_CHAN_CUR_CNT);
+ do {
+ pos = readl(pchan->base + DMA_CHAN_LLI_ADDR);
+ bytes = readl(pchan->base + DMA_CHAN_CUR_CNT);
+ } while (pos != readl(pchan->base + DMA_CHAN_LLI_ADDR));
if (pos == LLI_LAST_ITEM)
return bytes;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 235/398] Bluetooth: hci_codec: validate vendor codec count length
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (232 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 234/398] Bluetooth: eir: validate service data length before reading UUID Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 236/398] Bluetooth: hci_sync: Serialize local codec list cleanup Greg Kroah-Hartman
` (168 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luiz Augusto von Dentz,
Laxman Acharya Padhya, Luiz Augusto von Dentz
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
commit d0795cfd6f655f4de84868a4f4bb41a03f037b3d upstream.
The Read Local Supported Codecs parsers consume the variable-sized
standard codec array before parsing the vendor codec count. Although the
initial reply-size check includes a vendor count byte in the fixed layout,
it does not guarantee that the byte remains after the standard codec array.
If a controller reply ends immediately after that array, calculating the
vendor codec array size reads vnd_codecs->num beyond the skb data. Use
skb_pull_data() to validate and consume each codec header before using its
count in both command variants.
Fixes: 8961987f3f5f ("Bluetooth: Enumerate local supported codec and cache details")
Fixes: 9ae664028a9e ("Bluetooth: Add support for Read Local Supported Codecs V2")
Cc: stable@vger.kernel.org
Suggested-by: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_codec.c | 36 ++++++++++++++++++------------------
1 file changed, 18 insertions(+), 18 deletions(-)
--- a/net/bluetooth/hci_codec.c
+++ b/net/bluetooth/hci_codec.c
@@ -145,11 +145,12 @@ void hci_read_supported_codecs(struct hc
skb_pull(skb, sizeof(rp->status));
- std_codecs = (void *)skb->data;
+ std_codecs = skb_pull_data(skb, sizeof(*std_codecs));
+ if (!std_codecs)
+ goto error;
/* validate codecs length before accessing */
- if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num))
+ if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num))
goto error;
/* enumerate codec capabilities of standard codecs */
@@ -161,15 +162,14 @@ void hci_read_supported_codecs(struct hc
LOCAL_CODEC_ACL_MASK | LOCAL_CODEC_SCO_MASK, &caps);
}
- skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num));
+ skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num));
- vnd_codecs = (void *)skb->data;
+ vnd_codecs = skb_pull_data(skb, sizeof(*vnd_codecs));
+ if (!vnd_codecs)
+ goto error;
/* validate vendor codecs length before accessing */
- if (skb->len <
- flex_array_size(vnd_codecs, codec, vnd_codecs->num)
- + sizeof(vnd_codecs->num))
+ if (skb->len < flex_array_size(vnd_codecs, codec, vnd_codecs->num))
goto error;
/* enumerate vendor codec capabilities */
@@ -214,11 +214,12 @@ void hci_read_supported_codecs_v2(struct
skb_pull(skb, sizeof(rp->status));
- std_codecs = (void *)skb->data;
+ std_codecs = skb_pull_data(skb, sizeof(*std_codecs));
+ if (!std_codecs)
+ goto error;
/* check for payload data length before accessing */
- if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num))
+ if (skb->len < flex_array_size(std_codecs, codec, std_codecs->num))
goto error;
memset(&caps, 0, sizeof(caps));
@@ -229,15 +230,14 @@ void hci_read_supported_codecs_v2(struct
&caps);
}
- skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num)
- + sizeof(std_codecs->num));
+ skb_pull(skb, flex_array_size(std_codecs, codec, std_codecs->num));
- vnd_codecs = (void *)skb->data;
+ vnd_codecs = skb_pull_data(skb, sizeof(*vnd_codecs));
+ if (!vnd_codecs)
+ goto error;
/* check for payload data length before accessing */
- if (skb->len <
- flex_array_size(vnd_codecs, codec, vnd_codecs->num)
- + sizeof(vnd_codecs->num))
+ if (skb->len < flex_array_size(vnd_codecs, codec, vnd_codecs->num))
goto error;
for (i = 0; i < vnd_codecs->num; i++) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 289/438] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (287 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 288/438] dmaengine: sun6i: fix non-atomic read of DMA position registers Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 290/438] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn() Greg Kroah-Hartman
` (160 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Lugnberg, Frank Li,
Vinod Koul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Lugnberg <christian.lugnberg@soundtrack.io>
commit 9096bdc8d930147f7c39a493a859acbd3a8485d8 upstream.
sun6i_dma_tx_status() calls vchan_find_desc() to look up the virtual
descriptor for a given cookie, before checking whether the pointer
vd is NULL:
vd = vchan_find_desc(&vchan->vc, cookie);
txd = to_sun6i_desc(&vd->tx); /* vd may be NULL here */
if (vd) {
for (lli = txd->v_lli; ...)
vchan_find_desc() returns NULL when the descriptor has already been
completed or is in-flight on a physical channel and no longer present
in the virtual channel's descriptor list. When vd is NULL,
to_sun6i_desc() is called unconditionally on &vd->tx before the NULL
check, which is undefined behaviour. Move the call inside the if (vd)
guard to ensure it is only reached with a valid pointer.
vd = vchan_find_desc(&vchan->vc, cookie);
if (vd) {
struct sun6i_desc *txd = to_sun6i_desc(&vd->tx);
for (lli = txd->v_lli; ...)
Fixes: 555859308723 ("dmaengine: sun6i: Add driver for the Allwinner A31 DMA controller")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Christian Lugnberg <christian.lugnberg@soundtrack.io>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260817135723.12807-3-christian.lugnberg@soundtrack.io
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma/sun6i-dma.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
--- a/drivers/dma/sun6i-dma.c
+++ b/drivers/dma/sun6i-dma.c
@@ -981,7 +981,6 @@ static enum dma_status sun6i_dma_tx_stat
struct sun6i_pchan *pchan = vchan->phy;
struct sun6i_dma_lli *lli;
struct virt_dma_desc *vd;
- struct sun6i_desc *txd;
enum dma_status ret;
unsigned long flags;
size_t bytes = 0;
@@ -993,9 +992,9 @@ static enum dma_status sun6i_dma_tx_stat
spin_lock_irqsave(&vchan->vc.lock, flags);
vd = vchan_find_desc(&vchan->vc, cookie);
- txd = to_sun6i_desc(&vd->tx);
if (vd) {
+ struct sun6i_desc *txd = to_sun6i_desc(&vd->tx);
for (lli = txd->v_lli; lli != NULL; lli = lli->v_lli_next)
bytes += lli->len;
} else if (!pchan || !pchan->desc) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 236/398] Bluetooth: hci_sync: Serialize local codec list cleanup
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (233 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 235/398] Bluetooth: hci_codec: validate vendor codec count length Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 237/398] btrfs: take commit root semaphore when iterating in mark_block_group_to_copy() Greg Kroah-Hartman
` (167 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chengfeng Ye, Luiz Augusto von Dentz
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengfeng Ye <nicoyip.dev@gmail.com>
commit 9a10987a2f160a44a638c9a35994ca6e3089696e upstream.
hci_dev_close_sync() clears hdev->local_codecs after releasing hdev->lock.
Codec list additions and both traversals in sco_sock_getsockopt() use that
lock, but the close path does not. A close and BT_CODEC query can therefore
interleave as follows:
hci_dev_close_sync() sco_sock_getsockopt()
hci_dev_lock()
fetch codec entry
hci_codec_list_clear()
kfree(entry)
read entry->id
The reader then accesses an entry which the close path has freed. KASAN
reported:
BUG: KASAN: slab-use-after-free in sco_sock_getsockopt+0xfa0/0xfe0
Read of size 1 at addr ffff8881001c3450
Call Trace:
sco_sock_getsockopt+0xfa0/0xfe0
do_sock_getsockopt+0x537/0x7b0
__sys_getsockopt+0xf2/0x170
Allocated by task 92:
hci_codec_list_add.isra.0+0x2c/0x440
hci_read_codec_capabilities+0x224/0x590
hci_read_supported_codecs+0x2c2/0x640
Freed by task 92:
kfree+0x131/0x3c0
hci_codec_list_clear+0xd8/0x160
hci_dev_close_sync+0x92a/0xfa0
Take hdev->lock around the clear operation at its existing point in the
close path. This makes the clear wait for active readers and prevents a new
traversal until the list is empty without changing teardown ordering.
Fixes: b938790e7054 ("Bluetooth: hci_codec: Fix leaking content of local_codecs")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/bluetooth/hci_sync.c | 2 ++
1 file changed, 2 insertions(+)
--- a/net/bluetooth/hci_sync.c
+++ b/net/bluetooth/hci_sync.c
@@ -5508,7 +5508,9 @@ int hci_dev_close_sync(struct hci_dev *h
memset(hdev->eir, 0, sizeof(hdev->eir));
memset(hdev->dev_class, 0, sizeof(hdev->dev_class));
bacpy(&hdev->random_addr, BDADDR_ANY);
+ hci_dev_lock(hdev);
hci_codec_list_clear(&hdev->local_codecs);
+ hci_dev_unlock(hdev);
hci_dev_put(hdev);
return err;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 290/438] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (288 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 289/438] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 291/438] dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3 Greg Kroah-Hartman
` (159 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pavel Zhigulin, Alexander Chesnokov,
Frank Li, Vinod Koul
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
commit 0294b6dd515256c03ea2dbf508ddd3826d788579 upstream.
If devm_kcalloc() for rx_chn->flows fails in a channel request function,
the error path calls k3_udma_glue_release_rx_chn(), which dereferences
the NULL rx_chn->flows pointer in k3_udma_glue_release_rx_flow().
Skip the flow release loop in k3_udma_glue_release_rx_chn() when
rx_chn->flows is not allocated.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: d70241913413 ("dmaengine: ti: k3-udma: Add glue layer for non DMAengine users")
Cc: stable@vger.kernel.org
Reported-by: Pavel Zhigulin <Pavel.Zhigulin@kaspersky.com>
Signed-off-by: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260812053426.3521589-1-Alexander.Chesnokov@kaspersky.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma/ti/k3-udma-glue.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/drivers/dma/ti/k3-udma-glue.c
+++ b/drivers/dma/ti/k3-udma-glue.c
@@ -1243,8 +1243,9 @@ void k3_udma_glue_release_rx_chn(struct
rx_chn->psil_paired = false;
}
- for (i = 0; i < rx_chn->flow_num; i++)
- k3_udma_glue_release_rx_flow(rx_chn, i);
+ if (rx_chn->flows)
+ for (i = 0; i < rx_chn->flow_num; i++)
+ k3_udma_glue_release_rx_flow(rx_chn, i);
if (xudma_rflow_is_gp(rx_chn->common.udmax, rx_chn->flow_id_base))
xudma_free_gp_rflow_range(rx_chn->common.udmax,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 237/398] btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (234 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 236/398] Bluetooth: hci_sync: Serialize local codec list cleanup Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 238/398] btrfs: clear free space tree creation state on rebuild failure Greg Kroah-Hartman
` (166 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johannes Thumshirn, Hongling Zeng,
David Sterba
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongling Zeng <zenghongling@kylinos.cn>
commit 0594e3423f4ba3137c734371169491f9a98e9af4 upstream.
mark_block_group_to_copy() iterates over the commit root with
skip_locking=true. A concurrent transaction commit can swap and free
the commit root during iteration, causing use-after-free when
accessing extent buffers.
Fix it by using path->need_commit_sem to protect the commit root search.
Fixes: 78ce9fc269af ("btrfs: zoned: mark block groups to copy for device-replace")
CC: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.5
Reviewed-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Reviewed-by: David Sterba <dsterba@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/dev-replace.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/btrfs/dev-replace.c
+++ b/fs/btrfs/dev-replace.c
@@ -491,6 +491,7 @@ static int mark_block_group_to_copy(stru
path->reada = READA_FORWARD;
path->search_commit_root = true;
path->skip_locking = true;
+ path->need_commit_sem = true;
key.objectid = src_dev->devid;
key.type = BTRFS_DEV_EXTENT_KEY;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 291/438] dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (289 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 290/438] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 292/438] dma-buf: Fix silent overflow for phys vec to sgt Greg Kroah-Hartman
` (158 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian König,
Jonghyuk Kim(MalHyuk), Philipp Stanner
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian König <christian.koenig@amd.com>
commit 3ed11c671ff7ec58c8fd96410233c677df23f407 upstream.
The patch "dma-buf: dma-fence: Fix potential NULL pointer dereference"
changed the check to test for the ops pointer instead of the signaled
bit to avoid a potential NULL dereference when the ops pointer has been
cleared.
The problem is now that the ops pointer is cleared only when neither the
release nor the wait callback is implemented and this isn't true for a lot
of dma_fence implementations yet. So those implementations lost the RCU
protection after signaling of the returned string resulting in potential
use after free.
Add the signaling check additional to the ops pointer check so that we
have both the protection against NULL dereference as well as the RCU
protection after signaling for the returned string.
v2: improve comments to note RCU protection and explain why we check
both signaling state and ops pointer
v3: some comment improvements suggested by Philip
Signed-off-by: Christian König <christian.koenig@amd.com>
Fixes: 035219a760ed ("dma-buf: dma-fence: Fix potential NULL pointer dereference")
CC: stable@vger.kernel.org # 7.2+
Reported-by: Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
Tested-by: Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
Reviewed-by: Philipp Stanner <phasta@kernel.org>
Link: https://lore.kernel.org/r/20260914182740.1587-1-christian.koenig@amd.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma-buf/dma-fence.c | 14 ++++++++++++--
include/linux/dma-fence.h | 6 ++++++
2 files changed, 18 insertions(+), 2 deletions(-)
--- a/drivers/dma-buf/dma-fence.c
+++ b/drivers/dma-buf/dma-fence.c
@@ -1168,7 +1168,12 @@ const char __rcu *dma_fence_driver_name(
/* RCU protection is required for safe access to returned string */
ops = rcu_dereference(fence->ops);
- if (ops)
+
+ /*
+ * Make load ordering irrelevant by checking both signaled state and ops
+ * pointer and ops pointer is only set to NULL on newer implementations.
+ */
+ if (!dma_fence_test_signaled_flag(fence) && ops)
return (const char __rcu *)ops->get_driver_name(fence);
else
return (const char __rcu *)"detached-driver";
@@ -1201,7 +1206,12 @@ const char __rcu *dma_fence_timeline_nam
/* RCU protection is required for safe access to returned string */
ops = rcu_dereference(fence->ops);
- if (ops)
+
+ /*
+ * Make load ordering irrelevant by checking both signaled state and ops
+ * pointer and ops pointer is only set to NULL on newer implementations.
+ */
+ if (!dma_fence_test_signaled_flag(fence) && ops)
return (const char __rcu *)ops->get_timeline_name(fence);
else
return (const char __rcu *)"signaled-timeline";
--- a/include/linux/dma-fence.h
+++ b/include/linux/dma-fence.h
@@ -141,6 +141,9 @@ struct dma_fence_ops {
* compute the name at runtime, without having it to store permanently
* for each fence, or build a cache of some sort.
*
+ * The returned string is RCU protected and can be freed after the fence
+ * signaled and a RCU grace period passed.
+ *
* This callback is mandatory.
*/
const char * (*get_driver_name)(struct dma_fence *fence);
@@ -153,6 +156,9 @@ struct dma_fence_ops {
* having it to store permanently for each fence, or build a cache of
* some sort.
*
+ * The returned string is RCU protected and can be freed after the fence
+ * signaled and a RCU grace period passed.
+ *
* This callback is mandatory.
*/
const char * (*get_timeline_name)(struct dma_fence *fence);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 238/398] btrfs: clear free space tree creation state on rebuild failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (235 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 237/398] btrfs: take commit root semaphore when iterating in mark_block_group_to_copy() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 239/398] dmaengine: sun6i: fix non-atomic read of DMA position registers Greg Kroah-Hartman
` (165 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Boris Burkov, Qu Wenruo,
Guanghui Yang, David Sterba
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanghui Yang <3497809730@qq.com>
commit 3565893cc72cdf6b795cf6a33e7ff9605322334d upstream.
btrfs_rebuild_free_space_tree() sets BTRFS_FS_CREATING_FREE_SPACE_TREE
before rebuilding the free space tree. Several error paths return
without clearing this flag.
The transaction restart failure path can leave the flag set on a live
filesystem, causing delayed reference processing to be skipped. Clear it
on all free space tree rebuild failure paths. Keep
BTRFS_FS_FREE_SPACE_TREE_UNTRUSTED set, since a failed rebuild leaves
the free space tree untrusted. Callers must fall back to extent-tree
caching.
Fixes: 882af9f13e83 ("btrfs: handle free space tree rebuild in multiple transactions")
CC: stable@vger.kernel.org # 6.14+
Assisted-by: LLM
Reviewed-by: Boris Burkov <boris@bur.io>
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Guanghui Yang <3497809730@qq.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/btrfs/free-space-tree.c | 14 ++++++++++----
1 file changed, 10 insertions(+), 4 deletions(-)
--- a/fs/btrfs/free-space-tree.c
+++ b/fs/btrfs/free-space-tree.c
@@ -1346,7 +1346,7 @@ int btrfs_rebuild_free_space_tree(struct
if (unlikely(ret)) {
btrfs_abort_transaction(trans, ret);
btrfs_end_transaction(trans);
- return ret;
+ goto out_clear;
}
node = rb_first_cached(&fs_info->block_group_cache_tree);
@@ -1364,14 +1364,16 @@ int btrfs_rebuild_free_space_tree(struct
if (unlikely(ret)) {
btrfs_abort_transaction(trans, ret);
btrfs_end_transaction(trans);
- return ret;
+ goto out_clear;
}
next:
if (btrfs_should_end_transaction(trans)) {
btrfs_end_transaction(trans);
trans = btrfs_start_transaction(free_space_root, 1);
- if (IS_ERR(trans))
- return PTR_ERR(trans);
+ if (IS_ERR(trans)) {
+ ret = PTR_ERR(trans);
+ goto out_clear;
+ }
}
node = rb_next(node);
}
@@ -1383,6 +1385,10 @@ next:
ret = btrfs_commit_transaction(trans);
clear_bit(BTRFS_FS_FREE_SPACE_TREE_UNTRUSTED, &fs_info->flags);
return ret;
+
+out_clear:
+ clear_bit(BTRFS_FS_CREATING_FREE_SPACE_TREE, &fs_info->flags);
+ return ret;
}
static int __add_block_group_free_space(struct btrfs_trans_handle *trans,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 292/438] dma-buf: Fix silent overflow for phys vec to sgt
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (290 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 291/438] dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3 Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 293/438] dma-buf: Split sgl by largest page-aligned chunk Greg Kroah-Hartman
` (157 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, iommu, Pranjal Shrivastava,
Kevin Tian, Leon Romanovsky, David Hu, Christian König
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Hu <xuehaohu@google.com>
commit b344ca94e8cc85796f16ea25e2e5a8e0303fe813 upstream.
In case MMIO size is bigger than 4G and peer2peer DMA goes
through host bridge, we trigger a code path that assigns the
total linked IOVA (which is greater than 4G) to mapped_len.
Previously, `mapped_len` was declared as 32-bit `unsigned int`.
When accumulating `size_t` lengths, this leads to a silent wrap-around.
This truncation causes truncated lengths to be passed to functions
like `fill_sg_entry()`.
Fix this by changing `mapped_len` to `size_t` (64-bit). While
at it, fix similar potential overflow issues in `calc_sg_nents`
by using `check_add_overflow()` for `nents` and using
`unsigned int` for the loop iterator in `fill_sg_entry` to match.
Fixes: 3aa31a8bb11e ("dma-buf: provide phys_vec to scatter-gather mapping routine")
Cc: stable@vger.kernel.org
Cc: iommu@lists.linux.dev
Reviewed-by: Pranjal Shrivastava <praan@google.com>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Reviewed-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: David Hu <xuehaohu@google.com>
Signed-off-by: Christian König <christian.koenig@amd.com>
Link: https://lore.kernel.org/r/20260901170849.4052816-2-dhu@x6u.co
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma-buf/dma-buf-mapping.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
--- a/drivers/dma-buf/dma-buf-mapping.c
+++ b/drivers/dma-buf/dma-buf-mapping.c
@@ -5,12 +5,13 @@
*/
#include <linux/dma-buf-mapping.h>
#include <linux/dma-resv.h>
+#include <linux/overflow.h>
static struct scatterlist *fill_sg_entry(struct scatterlist *sgl, size_t length,
dma_addr_t addr)
{
unsigned int len, nents;
- int i;
+ unsigned int i;
nents = DIV_ROUND_UP(length, UINT_MAX);
for (i = 0; i < nents; i++) {
@@ -40,8 +41,12 @@ static unsigned int calc_sg_nents(struct
size_t i;
if (!state || !dma_use_iova(state)) {
- for (i = 0; i < nr_ranges; i++)
- nents += DIV_ROUND_UP(phys_vec[i].len, UINT_MAX);
+ for (i = 0; i < nr_ranges; i++) {
+ unsigned int added = DIV_ROUND_UP(phys_vec[i].len, UINT_MAX);
+
+ if (check_add_overflow(nents, added, &nents))
+ return 0;
+ }
} else {
/*
* In IOVA case, there is only one SG entry which spans
@@ -95,9 +100,10 @@ struct sg_table *dma_buf_phys_vec_to_sgt
size_t nr_ranges, size_t size,
enum dma_data_direction dir)
{
- unsigned int nents, mapped_len = 0;
struct dma_buf_dma *dma;
struct scatterlist *sgl;
+ size_t mapped_len = 0;
+ unsigned int nents;
dma_addr_t addr;
size_t i;
int ret;
@@ -133,6 +139,8 @@ struct sg_table *dma_buf_phys_vec_to_sgt
}
nents = calc_sg_nents(dma->state, phys_vec, nr_ranges, size);
+
+ /* sg_alloc_table will cleanly fail and return -EINVAL if nents == 0 */
ret = sg_alloc_table(&dma->sgt, nents, GFP_KERNEL | __GFP_ZERO);
if (ret)
goto err_free_state;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 239/398] dmaengine: sun6i: fix non-atomic read of DMA position registers
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (236 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 238/398] btrfs: clear free space tree creation state on rebuild failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 240/398] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status Greg Kroah-Hartman
` (164 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Lugnberg, Frank Li,
Vinod Koul
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Lugnberg <christian.lugnberg@soundtrack.io>
commit c90b6973daa37f4c283342dff881ae001dea4fe6 upstream.
sun6i_get_chan_size() reads DMA_CHAN_LLI_ADDR and DMA_CHAN_CUR_CNT in two
separate readl() calls with no synchronisation between them:
pos = readl(pchan->base + DMA_CHAN_LLI_ADDR);
bytes = readl(pchan->base + DMA_CHAN_CUR_CNT);
DMA_CHAN_LLI_ADDR holds the physical address of the *next* descriptor the
engine will load once the current one completes. DMA_CHAN_CUR_CNT holds the
remaining byte count for the *current* descriptor. If the DMA engine
advances to the next LLI entry between the two reads, pos becomes stale: it
still points to what was the next descriptor at the time of the first read,
but that descriptor is now the current one and CUR_CNT reflects its initial
(full) byte count. The subsequent virtual-chain walk starts one entry too
early and accumulates an extra full period's worth of bytes into the
residue estimate.
Fix this by re-reading DMA_CHAN_LLI_ADDR after DMA_CHAN_CUR_CNT and
retrying if the value changed. This double-read pattern guarantees that
both registers were sampled during the same descriptor interval. The cost
is at most one extra readl() pair per call in the racy case, which occurs
only at descriptor boundaries (~every 2 ms) and is negligible.
Fixes: a90e173f3faf ("dmaengine: sun6i: Add cyclic capability")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Christian Lugnberg <christian.lugnberg@soundtrack.io>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260817135723.12807-2-christian.lugnberg@soundtrack.io
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma/sun6i-dma.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/drivers/dma/sun6i-dma.c
+++ b/drivers/dma/sun6i-dma.c
@@ -354,8 +354,10 @@ static size_t sun6i_get_chan_size(struct
size_t bytes;
dma_addr_t pos;
- pos = readl(pchan->base + DMA_CHAN_LLI_ADDR);
- bytes = readl(pchan->base + DMA_CHAN_CUR_CNT);
+ do {
+ pos = readl(pchan->base + DMA_CHAN_LLI_ADDR);
+ bytes = readl(pchan->base + DMA_CHAN_CUR_CNT);
+ } while (pos != readl(pchan->base + DMA_CHAN_LLI_ADDR));
if (pos == LLI_LAST_ITEM)
return bytes;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 293/438] dma-buf: Split sgl by largest page-aligned chunk
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (291 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 292/438] dma-buf: Fix silent overflow for phys vec to sgt Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 294/438] ipv6: xfrm: use full sockets in local error paths Greg Kroah-Hartman
` (156 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Leon Romanovsky,
David Hu, Christian König
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Hu <xuehaohu@google.com>
commit 06dd5e1ae8ce4e129791087c8c66594950f0ba03 upstream.
Currently, `fill_sg_entry()` splits the scatterlist using `UINT_MAX`.
This creates a non-page-aligned DMA length (`0xFFFFFFFF`) for the
first entry, resulting in non-page-aligned DMA addresses for all
subsequent entries.
While the underlying IOMMU mapping may be contiguous, hardware
DMA engines often require explicit address alignment (e.g., page,
cacheline, or storage sector boundaries). Passing unaligned
addresses and lengths can cause explicit failures in DMA descriptor
creation or silent data corruption if lower unaligned bits are
truncated.
In addition, a non-page-aligned sgl length will trigger an edge case
in `ib_umem_find_best_pgsz()`. In case of a discontinuity in later
buffers, we will have a `va` with lowest bit set to 1. That will lead
to `ib_umem_find_best_pgsz()` always return 0, and break the promise
to find best page size for the mapping on the NIC side.
Fix this by splitting the scatterlist by the largest possible page
aligned chunk within `UINT_MAX` (`ALIGN_DOWN(UINT_MAX, PAGE_SIZE)`).
This ensures all scatterlist DMA addresses and lengths remain page
aligned, while minimizing the total number of sgl entries.
Page-aligned entries allow the system to cleanly chunk payloads into
PCIe MaxPayloadSize (MPS) (e.g., 128 bytes, 256 bytes, 512 bytes).
As a result, this may help reduce TLP fragmentation in P2P transfers
and alleviate potential congestion within a logical PCIe switch
partition, especially when Relaxed Ordering is not possible due to
hardware constraints.
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260609165431.778061F00893@smtp.kernel.org/
Fixes: 3aa31a8bb11e ("dma-buf: provide phys_vec to scatter-gather mapping routine")
Cc: stable@vger.kernel.org
Reviewed-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: David Hu <xuehaohu@google.com>
Signed-off-by: Christian König <christian.koenig@amd.com>
Link: https://lore.kernel.org/r/20260901170849.4052816-3-dhu@x6u.co
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma-buf/dma-buf-mapping.c | 19 +++++++++++--------
1 file changed, 11 insertions(+), 8 deletions(-)
diff --git a/drivers/dma-buf/dma-buf-mapping.c b/drivers/dma-buf/dma-buf-mapping.c
index 80f6ab2f4809..833be519e1e6 100644
--- a/drivers/dma-buf/dma-buf-mapping.c
+++ b/drivers/dma-buf/dma-buf-mapping.c
@@ -6,16 +6,17 @@
#include <linux/dma-buf-mapping.h>
#include <linux/dma-resv.h>
#include <linux/overflow.h>
+#include <linux/align.h>
+
+#define MAX_SG_ENT_SZ ALIGN_DOWN(UINT_MAX, PAGE_SIZE)
static struct scatterlist *fill_sg_entry(struct scatterlist *sgl, size_t length,
dma_addr_t addr)
{
- unsigned int len, nents;
- unsigned int i;
+ size_t len;
- nents = DIV_ROUND_UP(length, UINT_MAX);
- for (i = 0; i < nents; i++) {
- len = min_t(size_t, length, UINT_MAX);
+ while (length) {
+ len = min(length, MAX_SG_ENT_SZ);
length -= len;
/*
* DMABUF abuses scatterlist to create a scatterlist
@@ -25,8 +26,10 @@ static struct scatterlist *fill_sg_entry(struct scatterlist *sgl, size_t length,
* does not require the CPU list for mapping or unmapping.
*/
sg_set_page(sgl, NULL, 0, 0);
- sg_dma_address(sgl) = addr + (dma_addr_t)i * UINT_MAX;
+ sg_dma_address(sgl) = addr;
sg_dma_len(sgl) = len;
+ addr += len;
+ /* Unconditionally advance. On last segment, this becomes NULL */
sgl = sg_next(sgl);
}
@@ -42,7 +45,7 @@ static unsigned int calc_sg_nents(struct dma_iova_state *state,
if (!state || !dma_use_iova(state)) {
for (i = 0; i < nr_ranges; i++) {
- unsigned int added = DIV_ROUND_UP(phys_vec[i].len, UINT_MAX);
+ unsigned int added = DIV_ROUND_UP(phys_vec[i].len, MAX_SG_ENT_SZ);
if (check_add_overflow(nents, added, &nents))
return 0;
@@ -53,7 +56,7 @@ static unsigned int calc_sg_nents(struct dma_iova_state *state,
* for whole IOVA address space, but we need to make sure
* that it fits sg->length, maybe we need more.
*/
- nents = DIV_ROUND_UP(size, UINT_MAX);
+ nents = DIV_ROUND_UP(size, MAX_SG_ENT_SZ);
}
return nents;
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 240/398] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (237 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 239/398] dmaengine: sun6i: fix non-atomic read of DMA position registers Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 241/398] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn() Greg Kroah-Hartman
` (163 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Lugnberg, Frank Li,
Vinod Koul
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Lugnberg <christian.lugnberg@soundtrack.io>
commit 9096bdc8d930147f7c39a493a859acbd3a8485d8 upstream.
sun6i_dma_tx_status() calls vchan_find_desc() to look up the virtual
descriptor for a given cookie, before checking whether the pointer
vd is NULL:
vd = vchan_find_desc(&vchan->vc, cookie);
txd = to_sun6i_desc(&vd->tx); /* vd may be NULL here */
if (vd) {
for (lli = txd->v_lli; ...)
vchan_find_desc() returns NULL when the descriptor has already been
completed or is in-flight on a physical channel and no longer present
in the virtual channel's descriptor list. When vd is NULL,
to_sun6i_desc() is called unconditionally on &vd->tx before the NULL
check, which is undefined behaviour. Move the call inside the if (vd)
guard to ensure it is only reached with a valid pointer.
vd = vchan_find_desc(&vchan->vc, cookie);
if (vd) {
struct sun6i_desc *txd = to_sun6i_desc(&vd->tx);
for (lli = txd->v_lli; ...)
Fixes: 555859308723 ("dmaengine: sun6i: Add driver for the Allwinner A31 DMA controller")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Christian Lugnberg <christian.lugnberg@soundtrack.io>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260817135723.12807-3-christian.lugnberg@soundtrack.io
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma/sun6i-dma.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
--- a/drivers/dma/sun6i-dma.c
+++ b/drivers/dma/sun6i-dma.c
@@ -971,7 +971,6 @@ static enum dma_status sun6i_dma_tx_stat
struct sun6i_pchan *pchan = vchan->phy;
struct sun6i_dma_lli *lli;
struct virt_dma_desc *vd;
- struct sun6i_desc *txd;
enum dma_status ret;
unsigned long flags;
size_t bytes = 0;
@@ -983,9 +982,9 @@ static enum dma_status sun6i_dma_tx_stat
spin_lock_irqsave(&vchan->vc.lock, flags);
vd = vchan_find_desc(&vchan->vc, cookie);
- txd = to_sun6i_desc(&vd->tx);
if (vd) {
+ struct sun6i_desc *txd = to_sun6i_desc(&vd->tx);
for (lli = txd->v_lli; lli != NULL; lli = lli->v_lli_next)
bytes += lli->len;
} else if (!pchan || !pchan->desc) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 294/438] ipv6: xfrm: use full sockets in local error paths
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (292 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 293/438] dma-buf: Split sgl by largest page-aligned chunk Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 295/438] net: ip_tunnel: initialize `options_len` before referencing options Greg Kroah-Hartman
` (155 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Steffen Klassert
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit 6973a21ee73c5567f883813c8ef414774b45892f upstream.
xfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it
always pointed at a full IPv6 socket.
That is not guaranteed. TCP SYN-ACK skbs can be owned by a
TCP_NEW_SYN_RECV request_sock while the output path itself is driven by the
full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower
MTU, the local PMTU/error handling path can reach these callbacks with that
mini-socket still attached to the skb.
The callbacks then miscast the request socket as a full inet/IPv6 socket and
can read beyond the request_sock allocation when they access inet_sock or
ipv6_pinfo state.
Resolve the owner with skb_to_full_sk() in both callbacks and bail out when
no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error
logic, which already reasons about full sockets with skb_to_full_sk().
Fixes: dd767856a36e ("xfrm6: Don't call icmpv6_send on local error")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/xfrm6_output.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/net/ipv6/xfrm6_output.c
+++ b/net/ipv6/xfrm6_output.c
@@ -19,7 +19,10 @@
void xfrm6_local_rxpmtu(struct sk_buff *skb, u32 mtu)
{
struct flowi6 fl6;
- struct sock *sk = skb->sk;
+ struct sock *sk = skb_to_full_sk(skb);
+
+ if (!sk)
+ return;
fl6.flowi6_oif = sk->sk_bound_dev_if;
fl6.daddr = ipv6_hdr(skb)->daddr;
@@ -31,7 +34,10 @@ void xfrm6_local_error(struct sk_buff *s
{
struct flowi6 fl6;
const struct ipv6hdr *hdr;
- struct sock *sk = skb->sk;
+ struct sock *sk = skb_to_full_sk(skb);
+
+ if (!sk)
+ return;
hdr = skb->encapsulation ? inner_ipv6_hdr(skb) : ipv6_hdr(skb);
fl6.fl6_dport = inet_sk(sk)->inet_dport;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 241/398] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (238 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 240/398] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 242/398] ipv6: xfrm: use full sockets in local error paths Greg Kroah-Hartman
` (162 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pavel Zhigulin, Alexander Chesnokov,
Frank Li, Vinod Koul
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
commit 0294b6dd515256c03ea2dbf508ddd3826d788579 upstream.
If devm_kcalloc() for rx_chn->flows fails in a channel request function,
the error path calls k3_udma_glue_release_rx_chn(), which dereferences
the NULL rx_chn->flows pointer in k3_udma_glue_release_rx_flow().
Skip the flow release loop in k3_udma_glue_release_rx_chn() when
rx_chn->flows is not allocated.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: d70241913413 ("dmaengine: ti: k3-udma: Add glue layer for non DMAengine users")
Cc: stable@vger.kernel.org
Reported-by: Pavel Zhigulin <Pavel.Zhigulin@kaspersky.com>
Signed-off-by: Alexander Chesnokov <Alexander.Chesnokov@kaspersky.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260812053426.3521589-1-Alexander.Chesnokov@kaspersky.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma/ti/k3-udma-glue.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/drivers/dma/ti/k3-udma-glue.c
+++ b/drivers/dma/ti/k3-udma-glue.c
@@ -1243,8 +1243,9 @@ void k3_udma_glue_release_rx_chn(struct
rx_chn->psil_paired = false;
}
- for (i = 0; i < rx_chn->flow_num; i++)
- k3_udma_glue_release_rx_flow(rx_chn, i);
+ if (rx_chn->flows)
+ for (i = 0; i < rx_chn->flow_num; i++)
+ k3_udma_glue_release_rx_flow(rx_chn, i);
if (xudma_rflow_is_gp(rx_chn->common.udmax, rx_chn->flow_id_base))
xudma_free_gp_rflow_range(rx_chn->common.udmax,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 295/438] net: ip_tunnel: initialize `options_len` before referencing options
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (293 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 294/438] ipv6: xfrm: use full sockets in local error paths Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 296/438] net: lan743x: fix RX checksum use-after-free Greg Kroah-Hartman
` (154 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gris Ge, Hangbin Liu,
Gustavo A. R. Silva, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gris Ge <cnfourt@gmail.com>
commit 455ebeadf714f51e1dbbd6a022c74c9215b1cd76 upstream.
The following command triggers a kernel panic:
ip link add d0 type dummy; ip link set d0 up
ip route add 10.30.0.0/16 \
encap ip id 300 geneve_opts 4660:66:11223344 dev d0
memcpy: detected buffer overflow: 4 byte write of buffer size 0
kernel BUG at lib/string_helpers.c:1044!
...
ip_tun_parse_opts.part.0.cold+0x10/0x10
ip_tun_build_state+0x116/0x2a0
On kernels built with GCC 15+ and `CONFIG_FORTIFY_SOURCE`, the fortified
`memcpy()` got 0 sized destination with request of 4 bytes length:
static int ip_tun_parse_opts_geneve(...)
{
...
attr = tb[LWTUNNEL_IP_OPT_GENEVE_DATA];
data_len = nla_len(attr); /* == 4 */
struct geneve_opt *opt = ip_tunnel_info_opts(info) + opts_len;
memcpy(opt->opt_data, nla_data(attr), data_len);
/* ^^^^^^^^^^^^^ 0 since options_len is assigned afterwards */
Fixed by initializing the counter before the options are referenced.
Matching what `tunnel_key_opts_set()` already does.
Fixes: bb5e62f2d547 ("net: Add options as a flexible array to struct ip_tunnel_info")
Cc: stable@vger.kernel.org
Signed-off-by: Gris Ge <cnfourt@gmail.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Reviewed-by: Gustavo A. R. Silva <gustavoars@kernel.org>
Link: https://patch.msgid.link/20260913090851.468216-1-cnfourt@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/ip_tunnel_core.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
--- a/net/ipv4/ip_tunnel_core.c
+++ b/net/ipv4/ip_tunnel_core.c
@@ -680,8 +680,14 @@ static int ip_tun_get_optlen(struct nlat
}
static int ip_tun_set_opts(struct nlattr *attr, struct ip_tunnel_info *info,
- struct netlink_ext_ack *extack)
+ int opts_len, struct netlink_ext_ack *extack)
{
+ /* `options_len` is the __counted_by() annotation of the `options`
+ * flexible array, it must be initialized before parsing writes
+ * into it.
+ */
+ info->options_len = opts_len;
+
return ip_tun_parse_opts(attr, info, extack);
}
@@ -712,7 +718,8 @@ static int ip_tun_build_state(struct net
tun_info = lwt_tun_info(new_state);
- err = ip_tun_set_opts(tb[LWTUNNEL_IP_OPTS], tun_info, extack);
+ err = ip_tun_set_opts(tb[LWTUNNEL_IP_OPTS], tun_info, opt_len,
+ extack);
if (err < 0) {
lwtstate_free(new_state);
return err;
@@ -753,7 +760,6 @@ static int ip_tun_build_state(struct net
}
tun_info->mode = IP_TUNNEL_INFO_TX;
- tun_info->options_len = opt_len;
*ts = new_state;
@@ -1006,7 +1012,8 @@ static int ip6_tun_build_state(struct ne
tun_info = lwt_tun_info(new_state);
- err = ip_tun_set_opts(tb[LWTUNNEL_IP6_OPTS], tun_info, extack);
+ err = ip_tun_set_opts(tb[LWTUNNEL_IP6_OPTS], tun_info, opt_len,
+ extack);
if (err < 0) {
lwtstate_free(new_state);
return err;
@@ -1040,7 +1047,6 @@ static int ip6_tun_build_state(struct ne
}
tun_info->mode = IP_TUNNEL_INFO_TX | IP_TUNNEL_INFO_IPV6;
- tun_info->options_len = opt_len;
*ts = new_state;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 242/398] ipv6: xfrm: use full sockets in local error paths
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (239 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 241/398] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 243/398] net: ip_tunnel: initialize `options_len` before referencing options Greg Kroah-Hartman
` (161 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Steffen Klassert
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit 6973a21ee73c5567f883813c8ef414774b45892f upstream.
xfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it
always pointed at a full IPv6 socket.
That is not guaranteed. TCP SYN-ACK skbs can be owned by a
TCP_NEW_SYN_RECV request_sock while the output path itself is driven by the
full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower
MTU, the local PMTU/error handling path can reach these callbacks with that
mini-socket still attached to the skb.
The callbacks then miscast the request socket as a full inet/IPv6 socket and
can read beyond the request_sock allocation when they access inet_sock or
ipv6_pinfo state.
Resolve the owner with skb_to_full_sk() in both callbacks and bail out when
no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error
logic, which already reasons about full sockets with skb_to_full_sk().
Fixes: dd767856a36e ("xfrm6: Don't call icmpv6_send on local error")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv6/xfrm6_output.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/net/ipv6/xfrm6_output.c
+++ b/net/ipv6/xfrm6_output.c
@@ -19,7 +19,10 @@
void xfrm6_local_rxpmtu(struct sk_buff *skb, u32 mtu)
{
struct flowi6 fl6;
- struct sock *sk = skb->sk;
+ struct sock *sk = skb_to_full_sk(skb);
+
+ if (!sk)
+ return;
fl6.flowi6_oif = sk->sk_bound_dev_if;
fl6.daddr = ipv6_hdr(skb)->daddr;
@@ -31,7 +34,10 @@ void xfrm6_local_error(struct sk_buff *s
{
struct flowi6 fl6;
const struct ipv6hdr *hdr;
- struct sock *sk = skb->sk;
+ struct sock *sk = skb_to_full_sk(skb);
+
+ if (!sk)
+ return;
hdr = skb->encapsulation ? inner_ipv6_hdr(skb) : ipv6_hdr(skb);
fl6.fl6_dport = inet_sk(sk)->inet_dport;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 296/438] net: lan743x: fix RX checksum use-after-free
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (294 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 295/438] net: ip_tunnel: initialize `options_len` before referencing options Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 297/438] net: phy: mediatek: do not report link and per-speed LED rules together Greg Kroah-Hartman
` (153 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Chenguang Zhao,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
commit a9ce4053dc945c5372dedba5017ee675b30dc0c5 upstream.
lan743x_rx_process_buffer() adds each non-first receive buffer to the
head skb's frag_list. On the last descriptor, lan743x_rx_trim_skb()
linearizes the head and frees the fragment skb metadata.
The checksum-success path then writes ip_summed through the local skb
pointer, which still points to the final fragment. This causes a
use-after-free write when a packet spans more than one receive buffer.
Set ip_summed on the surviving head skb instead. Multi-buffer receive
can occur after a live MTU increase because existing ring entries keep
their old buffer size until they are replenished.
A KUnit test invoking lan743x_rx_process_buffer() with a two-buffer
packet produced a one-byte KASAN use-after-free write before this change.
The same test passed after the change. The driver object also builds
with W=1. This was not tested on physical LAN743x hardware.
Fixes: cd6910501cfd ("net: lan743x: Add support for Rx IP & TCP checksum offload")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Link: https://patch.msgid.link/20260913-b4-send-lan743x-uaf-v1-1-73d563d08ba9@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/microchip/lan743x_main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/ethernet/microchip/lan743x_main.c
+++ b/drivers/net/ethernet/microchip/lan743x_main.c
@@ -2594,7 +2594,7 @@ process_extension:
rx->adapter->netdev);
if (rx->adapter->netdev->features & NETIF_F_RXCSUM) {
if (!is_ice && !is_tce && !is_icsm)
- skb->ip_summed = CHECKSUM_UNNECESSARY;
+ rx->skb_head->ip_summed = CHECKSUM_UNNECESSARY;
}
netdev_dbg(netdev, "sending %d byte frame to OS",
rx->skb_head->len);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 243/398] net: ip_tunnel: initialize `options_len` before referencing options
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (240 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 242/398] ipv6: xfrm: use full sockets in local error paths Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 244/398] net: lan743x: fix RX checksum use-after-free Greg Kroah-Hartman
` (160 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gris Ge, Hangbin Liu,
Gustavo A. R. Silva, Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gris Ge <cnfourt@gmail.com>
commit 455ebeadf714f51e1dbbd6a022c74c9215b1cd76 upstream.
The following command triggers a kernel panic:
ip link add d0 type dummy; ip link set d0 up
ip route add 10.30.0.0/16 \
encap ip id 300 geneve_opts 4660:66:11223344 dev d0
memcpy: detected buffer overflow: 4 byte write of buffer size 0
kernel BUG at lib/string_helpers.c:1044!
...
ip_tun_parse_opts.part.0.cold+0x10/0x10
ip_tun_build_state+0x116/0x2a0
On kernels built with GCC 15+ and `CONFIG_FORTIFY_SOURCE`, the fortified
`memcpy()` got 0 sized destination with request of 4 bytes length:
static int ip_tun_parse_opts_geneve(...)
{
...
attr = tb[LWTUNNEL_IP_OPT_GENEVE_DATA];
data_len = nla_len(attr); /* == 4 */
struct geneve_opt *opt = ip_tunnel_info_opts(info) + opts_len;
memcpy(opt->opt_data, nla_data(attr), data_len);
/* ^^^^^^^^^^^^^ 0 since options_len is assigned afterwards */
Fixed by initializing the counter before the options are referenced.
Matching what `tunnel_key_opts_set()` already does.
Fixes: bb5e62f2d547 ("net: Add options as a flexible array to struct ip_tunnel_info")
Cc: stable@vger.kernel.org
Signed-off-by: Gris Ge <cnfourt@gmail.com>
Reviewed-by: Hangbin Liu <liuhangbin@kylinos.cn>
Reviewed-by: Gustavo A. R. Silva <gustavoars@kernel.org>
Link: https://patch.msgid.link/20260913090851.468216-1-cnfourt@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/ip_tunnel_core.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
diff --git a/net/ipv4/ip_tunnel_core.c b/net/ipv4/ip_tunnel_core.c
index 5168d546ea2f..bab42b9e277f 100644
--- a/net/ipv4/ip_tunnel_core.c
+++ b/net/ipv4/ip_tunnel_core.c
@@ -680,8 +680,14 @@ static int ip_tun_get_optlen(struct nlattr *attr,
}
static int ip_tun_set_opts(struct nlattr *attr, struct ip_tunnel_info *info,
- struct netlink_ext_ack *extack)
+ int opts_len, struct netlink_ext_ack *extack)
{
+ /* `options_len` is the __counted_by() annotation of the `options`
+ * flexible array, it must be initialized before parsing writes
+ * into it.
+ */
+ info->options_len = opts_len;
+
return ip_tun_parse_opts(attr, info, extack);
}
@@ -712,7 +718,8 @@ static int ip_tun_build_state(struct net *net, struct nlattr *attr,
tun_info = lwt_tun_info(new_state);
- err = ip_tun_set_opts(tb[LWTUNNEL_IP_OPTS], tun_info, extack);
+ err = ip_tun_set_opts(tb[LWTUNNEL_IP_OPTS], tun_info, opt_len,
+ extack);
if (err < 0) {
lwtstate_free(new_state);
return err;
@@ -753,7 +760,6 @@ static int ip_tun_build_state(struct net *net, struct nlattr *attr,
}
tun_info->mode = IP_TUNNEL_INFO_TX;
- tun_info->options_len = opt_len;
*ts = new_state;
@@ -1006,7 +1012,8 @@ static int ip6_tun_build_state(struct net *net, struct nlattr *attr,
tun_info = lwt_tun_info(new_state);
- err = ip_tun_set_opts(tb[LWTUNNEL_IP6_OPTS], tun_info, extack);
+ err = ip_tun_set_opts(tb[LWTUNNEL_IP6_OPTS], tun_info, opt_len,
+ extack);
if (err < 0) {
lwtstate_free(new_state);
return err;
@@ -1040,7 +1047,6 @@ static int ip6_tun_build_state(struct net *net, struct nlattr *attr,
}
tun_info->mode = IP_TUNNEL_INFO_TX | IP_TUNNEL_INFO_IPV6;
- tun_info->options_len = opt_len;
*ts = new_state;
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 297/438] net: phy: mediatek: do not report link and per-speed LED rules together
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (295 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 296/438] net: lan743x: fix RX checksum use-after-free Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 298/438] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() Greg Kroah-Hartman
` (152 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ahmed Naseef, Andrew Lunn,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ahmed Naseef <naseefkm@gmail.com>
commit bde5212360bd44506edec073ebbd6d0c72f75820 upstream.
mtk_phy_led_hw_ctrl_get() reports TRIGGER_NETDEV_LINK whenever any of the
speed bits in on_set is on, and in addition reports every individual
TRIGGER_NETDEV_LINK_* bit that is set. The netdev trigger refuses that
combination: netdev_led_attr_store() rejects TRIGGER_NETDEV_LINK together
with any per-speed rule, and it validates the whole resulting mode rather
than just the bit being written. Once the hardware has any link bit
programmed, every write to the trigger attributes of that LED therefore
fails with -EINVAL and the LED can no longer be configured.
The rules are also fed back into the hardware: the trigger stores what is
read back, and a later write of device_name programs it again, expanding
TRIGGER_NETDEV_LINK to every speed in on_set. An LED configured for a
single speed is thereby silently widened to "on at any link speed".
Both are easy to see on the EcoNet EN7528, whose four PHYs share one LED
block. The first LED programs the block correctly, the second reads those
rules back and rewrites them widened, and the remaining two then read the
widened value, so an LED configured for "link_10 link_100" ends up lit on a
1000 Mbps link.
on_set holds every speed the LED can indicate and is exactly what
mtk_phy_led_hw_ctrl_set() programs for TRIGGER_NETDEV_LINK, so report the
speed independent rule only when all of them are on, and the individual
speeds otherwise. The mapping is then the inverse of the one used when
programming the LED and round trips without changing the register.
Fixes: c66937b0f8db ("net: phy: mediatek-ge-soc: support PHY LEDs")
Cc: stable@vger.kernel.org
Signed-off-by: Ahmed Naseef <naseefkm@gmail.com>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/20260912134306.3544329-1-naseefkm@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/phy/mediatek/mtk-phy-lib.c | 33 ++++++++++++++++++++-------------
1 file changed, 20 insertions(+), 13 deletions(-)
--- a/drivers/net/phy/mediatek/mtk-phy-lib.c
+++ b/drivers/net/phy/mediatek/mtk-phy-lib.c
@@ -156,20 +156,27 @@ int mtk_phy_led_hw_ctrl_get(struct phy_d
if (!rules)
return 0;
- if (on & on_set)
+ /* TRIGGER_NETDEV_LINK must not be reported together with any of the
+ * per-speed rules, the netdev trigger rejects that combination.
+ * on_set holds every speed this LED can indicate and is what
+ * mtk_phy_led_hw_ctrl_set() programs for TRIGGER_NETDEV_LINK, so
+ * report the speed independent rule only when they are all on.
+ */
+ if ((on & on_set) == on_set) {
*rules |= BIT(TRIGGER_NETDEV_LINK);
-
- if (on & MTK_PHY_LED_ON_LINK10)
- *rules |= BIT(TRIGGER_NETDEV_LINK_10);
-
- if (on & MTK_PHY_LED_ON_LINK100)
- *rules |= BIT(TRIGGER_NETDEV_LINK_100);
-
- if (on & MTK_PHY_LED_ON_LINK1000)
- *rules |= BIT(TRIGGER_NETDEV_LINK_1000);
-
- if (on & MTK_PHY_LED_ON_LINK2500)
- *rules |= BIT(TRIGGER_NETDEV_LINK_2500);
+ } else {
+ if (on & MTK_PHY_LED_ON_LINK10)
+ *rules |= BIT(TRIGGER_NETDEV_LINK_10);
+
+ if (on & MTK_PHY_LED_ON_LINK100)
+ *rules |= BIT(TRIGGER_NETDEV_LINK_100);
+
+ if (on & MTK_PHY_LED_ON_LINK1000)
+ *rules |= BIT(TRIGGER_NETDEV_LINK_1000);
+
+ if (on & MTK_PHY_LED_ON_LINK2500)
+ *rules |= BIT(TRIGGER_NETDEV_LINK_2500);
+ }
if (on & MTK_PHY_LED_ON_FDX)
*rules |= BIT(TRIGGER_NETDEV_FULL_DUPLEX);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 244/398] net: lan743x: fix RX checksum use-after-free
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (241 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 243/398] net: ip_tunnel: initialize `options_len` before referencing options Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 245/398] net: phy: mediatek: do not report link and per-speed LED rules together Greg Kroah-Hartman
` (159 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Chenguang Zhao,
Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
commit a9ce4053dc945c5372dedba5017ee675b30dc0c5 upstream.
lan743x_rx_process_buffer() adds each non-first receive buffer to the
head skb's frag_list. On the last descriptor, lan743x_rx_trim_skb()
linearizes the head and frees the fragment skb metadata.
The checksum-success path then writes ip_summed through the local skb
pointer, which still points to the final fragment. This causes a
use-after-free write when a packet spans more than one receive buffer.
Set ip_summed on the surviving head skb instead. Multi-buffer receive
can occur after a live MTU increase because existing ring entries keep
their old buffer size until they are replenished.
A KUnit test invoking lan743x_rx_process_buffer() with a two-buffer
packet produced a one-byte KASAN use-after-free write before this change.
The same test passed after the change. The driver object also builds
with W=1. This was not tested on physical LAN743x hardware.
Fixes: cd6910501cfd ("net: lan743x: Add support for Rx IP & TCP checksum offload")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Link: https://patch.msgid.link/20260913-b4-send-lan743x-uaf-v1-1-73d563d08ba9@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/microchip/lan743x_main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/ethernet/microchip/lan743x_main.c
+++ b/drivers/net/ethernet/microchip/lan743x_main.c
@@ -2588,7 +2588,7 @@ process_extension:
rx->adapter->netdev);
if (rx->adapter->netdev->features & NETIF_F_RXCSUM) {
if (!is_ice && !is_tce && !is_icsm)
- skb->ip_summed = CHECKSUM_UNNECESSARY;
+ rx->skb_head->ip_summed = CHECKSUM_UNNECESSARY;
}
netdev_dbg(netdev, "sending %d byte frame to OS",
rx->skb_head->len);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 298/438] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (296 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 297/438] net: phy: mediatek: do not report link and per-speed LED rules together Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 299/438] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain Greg Kroah-Hartman
` (151 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guanglei Zhu, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanglei Zhu <zhugl3@xiaopeng.com>
commit c7ead9704249d57d4693a04697e3bbd285138fa9 upstream.
The netif index carried in the DPMAIF PIT header is five bits wide,
but ccmni_inst[] only has room for NIC_DEV_MAX (21) entries.
t7xx_ccmni_recv_skb() indexes the array without a bounds check, so
indexes 21 to 31 read past it. The out-of-bounds value lands in the
callback table that follows the array, which is never NULL, so the
existing !ccmni check does not catch it and the driver dereferences
whatever sits there as a struct t7xx_ccmni.
Drop the skb when the index is out of range.
Fixes: 05d19bf500f8 ("net: wwan: t7xx: Add WWAN network interface")
Cc: stable@vger.kernel.org
Signed-off-by: Guanglei Zhu <zhugl3@xiaopeng.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Verified in a QEMU guest with a fault injector setting the netif
index to 25: the unpatched driver reads a value past ccmni_inst[],
which lands in the callback table, and dereferences it far enough to
queue the skb. With this check the packet is dropped. Well-formed
traffic on index 0 is unaffected.
Changes in v2: none.
Link: https://patch.msgid.link/20260911021734.1396599-3-zhugl3@xiaopeng.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
drivers/net/wwan/t7xx/t7xx_netdev.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/net/wwan/t7xx/t7xx_netdev.c
+++ b/drivers/net/wwan/t7xx/t7xx_netdev.c
@@ -420,6 +420,10 @@ static void t7xx_ccmni_recv_skb(struct t
skb_cb = T7XX_SKB_CB(skb);
netif_id = skb_cb->netif_idx;
+ if (netif_id >= NIC_DEV_MAX) {
+ dev_kfree_skb(skb);
+ return;
+ }
ccmni = READ_ONCE(ccmni_ctlb->ccmni_inst[netif_id]);
if (!ccmni) {
dev_kfree_skb(skb);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 245/398] net: phy: mediatek: do not report link and per-speed LED rules together
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (242 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 244/398] net: lan743x: fix RX checksum use-after-free Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 246/398] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() Greg Kroah-Hartman
` (158 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ahmed Naseef, Andrew Lunn,
Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ahmed Naseef <naseefkm@gmail.com>
commit bde5212360bd44506edec073ebbd6d0c72f75820 upstream.
mtk_phy_led_hw_ctrl_get() reports TRIGGER_NETDEV_LINK whenever any of the
speed bits in on_set is on, and in addition reports every individual
TRIGGER_NETDEV_LINK_* bit that is set. The netdev trigger refuses that
combination: netdev_led_attr_store() rejects TRIGGER_NETDEV_LINK together
with any per-speed rule, and it validates the whole resulting mode rather
than just the bit being written. Once the hardware has any link bit
programmed, every write to the trigger attributes of that LED therefore
fails with -EINVAL and the LED can no longer be configured.
The rules are also fed back into the hardware: the trigger stores what is
read back, and a later write of device_name programs it again, expanding
TRIGGER_NETDEV_LINK to every speed in on_set. An LED configured for a
single speed is thereby silently widened to "on at any link speed".
Both are easy to see on the EcoNet EN7528, whose four PHYs share one LED
block. The first LED programs the block correctly, the second reads those
rules back and rewrites them widened, and the remaining two then read the
widened value, so an LED configured for "link_10 link_100" ends up lit on a
1000 Mbps link.
on_set holds every speed the LED can indicate and is exactly what
mtk_phy_led_hw_ctrl_set() programs for TRIGGER_NETDEV_LINK, so report the
speed independent rule only when all of them are on, and the individual
speeds otherwise. The mapping is then the inverse of the one used when
programming the LED and round trips without changing the register.
Fixes: c66937b0f8db ("net: phy: mediatek-ge-soc: support PHY LEDs")
Cc: stable@vger.kernel.org
Signed-off-by: Ahmed Naseef <naseefkm@gmail.com>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Link: https://patch.msgid.link/20260912134306.3544329-1-naseefkm@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/phy/mediatek/mtk-phy-lib.c | 33 ++++++++++++++++++++-------------
1 file changed, 20 insertions(+), 13 deletions(-)
--- a/drivers/net/phy/mediatek/mtk-phy-lib.c
+++ b/drivers/net/phy/mediatek/mtk-phy-lib.c
@@ -156,20 +156,27 @@ int mtk_phy_led_hw_ctrl_get(struct phy_d
if (!rules)
return 0;
- if (on & on_set)
+ /* TRIGGER_NETDEV_LINK must not be reported together with any of the
+ * per-speed rules, the netdev trigger rejects that combination.
+ * on_set holds every speed this LED can indicate and is what
+ * mtk_phy_led_hw_ctrl_set() programs for TRIGGER_NETDEV_LINK, so
+ * report the speed independent rule only when they are all on.
+ */
+ if ((on & on_set) == on_set) {
*rules |= BIT(TRIGGER_NETDEV_LINK);
-
- if (on & MTK_PHY_LED_ON_LINK10)
- *rules |= BIT(TRIGGER_NETDEV_LINK_10);
-
- if (on & MTK_PHY_LED_ON_LINK100)
- *rules |= BIT(TRIGGER_NETDEV_LINK_100);
-
- if (on & MTK_PHY_LED_ON_LINK1000)
- *rules |= BIT(TRIGGER_NETDEV_LINK_1000);
-
- if (on & MTK_PHY_LED_ON_LINK2500)
- *rules |= BIT(TRIGGER_NETDEV_LINK_2500);
+ } else {
+ if (on & MTK_PHY_LED_ON_LINK10)
+ *rules |= BIT(TRIGGER_NETDEV_LINK_10);
+
+ if (on & MTK_PHY_LED_ON_LINK100)
+ *rules |= BIT(TRIGGER_NETDEV_LINK_100);
+
+ if (on & MTK_PHY_LED_ON_LINK1000)
+ *rules |= BIT(TRIGGER_NETDEV_LINK_1000);
+
+ if (on & MTK_PHY_LED_ON_LINK2500)
+ *rules |= BIT(TRIGGER_NETDEV_LINK_2500);
+ }
if (on & MTK_PHY_LED_ON_FDX)
*rules |= BIT(TRIGGER_NETDEV_FULL_DUPLEX);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 299/438] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (297 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 298/438] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 300/438] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value Greg Kroah-Hartman
` (150 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Loic Poulain, Guanglei Zhu,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanglei Zhu <zhugl3@xiaopeng.com>
commit 5d063822ac5184939c1ed377a339a01d8ae814e8 upstream.
The NDP traversal in mhi_mbim_rx() only stops when wNextNdpIndex is
zero. Nothing requires the offsets to advance, so a modem that
points an NDP at itself, or at an earlier NDP, keeps the loop
spinning forever on one CPU.
Break out when the next NDP offset is not larger than the current
one.
Fixes: aa730a9905b7 ("net: wwan: Add MHI MBIM network driver")
Cc: stable@vger.kernel.org
Suggested-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Signed-off-by: Guanglei Zhu <zhugl3@xiaopeng.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Verified in a QEMU guest with a fault injector feeding the driver's
receive callback an NTB whose single NDP points at itself: the
unpatched driver spins in mhi_mbim_rx() with one CPU pinned at 100%
and the thread never returns. With this check the loop terminates
within one iteration.
Changes in v2: move the non-increasing check to the wNextNdpIndex
retrieval site, as suggested by Loic Poulain, instead of tracking
the previous offset in a separate variable.
Link: https://patch.msgid.link/20260911021734.1396599-1-zhugl3@xiaopeng.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
drivers/net/wwan/mhi_wwan_mbim.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
--- a/drivers/net/wwan/mhi_wwan_mbim.c
+++ b/drivers/net/wwan/mhi_wwan_mbim.c
@@ -349,9 +349,13 @@ static void mhi_mbim_rx(struct mhi_mbim_
unlock:
rcu_read_unlock();
next_ndp:
- /* Other NDP to process? */
- ndpoffset = (int)le16_to_cpu(ndp16.wNextNdpIndex);
- if (!ndpoffset)
+ /* Other NDP to process? The offsets must advance, or a
+ * self-referencing NDP keeps the loop spinning forever.
+ */
+ n = (int)le16_to_cpu(ndp16.wNextNdpIndex);
+ if (n > ndpoffset)
+ ndpoffset = n;
+ else
break;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 246/398] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (243 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 245/398] net: phy: mediatek: do not report link and per-speed LED rules together Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 247/398] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain Greg Kroah-Hartman
` (157 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guanglei Zhu, Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanglei Zhu <zhugl3@xiaopeng.com>
commit c7ead9704249d57d4693a04697e3bbd285138fa9 upstream.
The netif index carried in the DPMAIF PIT header is five bits wide,
but ccmni_inst[] only has room for NIC_DEV_MAX (21) entries.
t7xx_ccmni_recv_skb() indexes the array without a bounds check, so
indexes 21 to 31 read past it. The out-of-bounds value lands in the
callback table that follows the array, which is never NULL, so the
existing !ccmni check does not catch it and the driver dereferences
whatever sits there as a struct t7xx_ccmni.
Drop the skb when the index is out of range.
Fixes: 05d19bf500f8 ("net: wwan: t7xx: Add WWAN network interface")
Cc: stable@vger.kernel.org
Signed-off-by: Guanglei Zhu <zhugl3@xiaopeng.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Verified in a QEMU guest with a fault injector setting the netif
index to 25: the unpatched driver reads a value past ccmni_inst[],
which lands in the callback table, and dereferences it far enough to
queue the skb. With this check the packet is dropped. Well-formed
traffic on index 0 is unaffected.
Changes in v2: none.
Link: https://patch.msgid.link/20260911021734.1396599-3-zhugl3@xiaopeng.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
drivers/net/wwan/t7xx/t7xx_netdev.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/net/wwan/t7xx/t7xx_netdev.c
+++ b/drivers/net/wwan/t7xx/t7xx_netdev.c
@@ -420,6 +420,10 @@ static void t7xx_ccmni_recv_skb(struct t
skb_cb = T7XX_SKB_CB(skb);
netif_id = skb_cb->netif_idx;
+ if (netif_id >= NIC_DEV_MAX) {
+ dev_kfree_skb(skb);
+ return;
+ }
ccmni = READ_ONCE(ccmni_ctlb->ccmni_inst[netif_id]);
if (!ccmni) {
dev_kfree_skb(skb);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 300/438] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (298 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 299/438] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 301/438] net/sched: act_api: release tail references on DELACTION failure Greg Kroah-Hartman
` (149 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Loic Poulain, Guanglei Zhu,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanglei Zhu <zhugl3@xiaopeng.com>
commit 31550d585589fde1ae95bf7f7a8188b2d2fdf1c7 upstream.
mhi_mbim_rx() ignores the return value of skb_copy_bits() when it
copies each datagram out of the NTB. The datagram offset and length
come from the DPE, which is only checked to lie within the NTB
itself, so a modem can point a datagram outside the received skb.
The copy then fails and the freshly allocated skbn is passed to
netif_rx() with its uninitialized contents still in place, leaking
kernel heap memory into the network stack.
Free the skb and account an error when the copy fails.
Fixes: aa730a9905b7 ("net: wwan: Add MHI MBIM network driver")
Cc: stable@vger.kernel.org
Suggested-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Signed-off-by: Guanglei Zhu <zhugl3@xiaopeng.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Verified in a QEMU guest with a fault injector pointing a DPE
outside the received NTB: the copy fails, and the unpatched driver
hands the uninitialized skbn to the network stack (observed as
"unknown protocol" on bytes that were never written). With this
check the failed datagram is dropped and counted as an rx error.
Changes in v2: factor the free-and-count sequence out into
mhi_mbim_rx_drop(), shared with the unknown-protocol path, as
suggested by Loic Poulain.
Link: https://patch.msgid.link/20260911021734.1396599-2-zhugl3@xiaopeng.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
drivers/net/wwan/mhi_wwan_mbim.c | 18 +++++++++++++-----
1 file changed, 13 insertions(+), 5 deletions(-)
--- a/drivers/net/wwan/mhi_wwan_mbim.c
+++ b/drivers/net/wwan/mhi_wwan_mbim.c
@@ -251,6 +251,14 @@ static int mbim_rx_verify_ndp16(struct s
return ret;
}
+static void mhi_mbim_rx_drop(struct mhi_mbim_link *link, struct sk_buff *skb)
+{
+ dev_kfree_skb_any(skb);
+ u64_stats_update_begin(&link->rx_syncp);
+ u64_stats_inc(&link->rx_errors);
+ u64_stats_update_end(&link->rx_syncp);
+}
+
static void mhi_mbim_rx(struct mhi_mbim_context *mbim, struct sk_buff *skb)
{
int ndpoffset;
@@ -320,7 +328,10 @@ static void mhi_mbim_rx(struct mhi_mbim_
continue;
skb_put(skbn, dgram_len);
- skb_copy_bits(skb, dgram_offset, skbn->data, dgram_len);
+ if (skb_copy_bits(skb, dgram_offset, skbn->data, dgram_len)) {
+ mhi_mbim_rx_drop(link, skbn);
+ continue;
+ }
switch (skbn->data[0] & 0xf0) {
case 0x40:
@@ -332,10 +343,7 @@ static void mhi_mbim_rx(struct mhi_mbim_
default:
net_err_ratelimited("%s: unknown protocol\n",
link->ndev->name);
- dev_kfree_skb_any(skbn);
- u64_stats_update_begin(&link->rx_syncp);
- u64_stats_inc(&link->rx_errors);
- u64_stats_update_end(&link->rx_syncp);
+ mhi_mbim_rx_drop(link, skbn);
continue;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 247/398] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (244 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 246/398] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 248/398] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value Greg Kroah-Hartman
` (156 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Loic Poulain, Guanglei Zhu,
Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanglei Zhu <zhugl3@xiaopeng.com>
commit 5d063822ac5184939c1ed377a339a01d8ae814e8 upstream.
The NDP traversal in mhi_mbim_rx() only stops when wNextNdpIndex is
zero. Nothing requires the offsets to advance, so a modem that
points an NDP at itself, or at an earlier NDP, keeps the loop
spinning forever on one CPU.
Break out when the next NDP offset is not larger than the current
one.
Fixes: aa730a9905b7 ("net: wwan: Add MHI MBIM network driver")
Cc: stable@vger.kernel.org
Suggested-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Signed-off-by: Guanglei Zhu <zhugl3@xiaopeng.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Verified in a QEMU guest with a fault injector feeding the driver's
receive callback an NTB whose single NDP points at itself: the
unpatched driver spins in mhi_mbim_rx() with one CPU pinned at 100%
and the thread never returns. With this check the loop terminates
within one iteration.
Changes in v2: move the non-increasing check to the wNextNdpIndex
retrieval site, as suggested by Loic Poulain, instead of tracking
the previous offset in a separate variable.
Link: https://patch.msgid.link/20260911021734.1396599-1-zhugl3@xiaopeng.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
drivers/net/wwan/mhi_wwan_mbim.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
--- a/drivers/net/wwan/mhi_wwan_mbim.c
+++ b/drivers/net/wwan/mhi_wwan_mbim.c
@@ -350,9 +350,13 @@ static void mhi_mbim_rx(struct mhi_mbim_
unlock:
rcu_read_unlock();
next_ndp:
- /* Other NDP to process? */
- ndpoffset = (int)le16_to_cpu(ndp16.wNextNdpIndex);
- if (!ndpoffset)
+ /* Other NDP to process? The offsets must advance, or a
+ * self-referencing NDP keeps the loop spinning forever.
+ */
+ n = (int)le16_to_cpu(ndp16.wNextNdpIndex);
+ if (n > ndpoffset)
+ ndpoffset = n;
+ else
break;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 301/438] net/sched: act_api: release tail references on DELACTION failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (299 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 300/438] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 302/438] net/sched: hhf: cap hh_flows_limit at change time Greg Kroah-Hartman
` (148 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xuanqiang Luo, Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
commit 6e05e46fa821a5c1b281355f1f622ac76cb6080a upstream.
A batched RTM_DELACTION request takes a temporary reference on each
action before attempting any deletion. tcf_action_delete() clears
each processed slot and drops its temporary reference before attempting
the deletion. If deletion fails, tca_action_gd() calls
tcf_action_put_many() to release the remaining references, but its
tcf_act_for_each_action() iterator stops at the first NULL slot.
When a batch stops at an action bound to a filter, this leaks a
reference on each subsequent action. A later delete of an unbound
action can then return success without removing it from the IDR.
Walk the full array in tcf_action_put_many() and skip NULL slots to
release the references held on the unprocessed actions.
Fixes: a0e947c9ccff ("net/sched: act_api: avoid non-contiguous action array")
Cc: stable@vger.kernel.org
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260910093413.34509-2-xuanqiang.luo@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/act_api.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -1218,11 +1218,16 @@ static int tcf_action_put(struct tc_acti
static void tcf_action_put_many(struct tc_action *actions[])
{
- struct tc_action *a;
int i;
- tcf_act_for_each_action(i, a, actions) {
- const struct tc_action_ops *ops = a->ops;
+ /* Deletion may have cleared entries before failing. */
+ for (i = 0; i < TCA_ACT_MAX_PRIO; i++) {
+ struct tc_action *a = actions[i];
+ const struct tc_action_ops *ops;
+
+ if (!a)
+ continue;
+ ops = a->ops;
if (tcf_action_put(a))
module_put(ops->owner);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 248/398] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (245 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 247/398] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 249/398] net/sched: act_api: release tail references on DELACTION failure Greg Kroah-Hartman
` (155 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Loic Poulain, Guanglei Zhu,
Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanglei Zhu <zhugl3@xiaopeng.com>
commit 31550d585589fde1ae95bf7f7a8188b2d2fdf1c7 upstream.
mhi_mbim_rx() ignores the return value of skb_copy_bits() when it
copies each datagram out of the NTB. The datagram offset and length
come from the DPE, which is only checked to lie within the NTB
itself, so a modem can point a datagram outside the received skb.
The copy then fails and the freshly allocated skbn is passed to
netif_rx() with its uninitialized contents still in place, leaking
kernel heap memory into the network stack.
Free the skb and account an error when the copy fails.
Fixes: aa730a9905b7 ("net: wwan: Add MHI MBIM network driver")
Cc: stable@vger.kernel.org
Suggested-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Signed-off-by: Guanglei Zhu <zhugl3@xiaopeng.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Verified in a QEMU guest with a fault injector pointing a DPE
outside the received NTB: the copy fails, and the unpatched driver
hands the uninitialized skbn to the network stack (observed as
"unknown protocol" on bytes that were never written). With this
check the failed datagram is dropped and counted as an rx error.
Changes in v2: factor the free-and-count sequence out into
mhi_mbim_rx_drop(), shared with the unknown-protocol path, as
suggested by Loic Poulain.
Link: https://patch.msgid.link/20260911021734.1396599-2-zhugl3@xiaopeng.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
drivers/net/wwan/mhi_wwan_mbim.c | 18 +++++++++++++-----
1 file changed, 13 insertions(+), 5 deletions(-)
--- a/drivers/net/wwan/mhi_wwan_mbim.c
+++ b/drivers/net/wwan/mhi_wwan_mbim.c
@@ -252,6 +252,14 @@ static int mbim_rx_verify_ndp16(struct s
return ret;
}
+static void mhi_mbim_rx_drop(struct mhi_mbim_link *link, struct sk_buff *skb)
+{
+ dev_kfree_skb_any(skb);
+ u64_stats_update_begin(&link->rx_syncp);
+ u64_stats_inc(&link->rx_errors);
+ u64_stats_update_end(&link->rx_syncp);
+}
+
static void mhi_mbim_rx(struct mhi_mbim_context *mbim, struct sk_buff *skb)
{
int ndpoffset;
@@ -321,7 +329,10 @@ static void mhi_mbim_rx(struct mhi_mbim_
continue;
skb_put(skbn, dgram_len);
- skb_copy_bits(skb, dgram_offset, skbn->data, dgram_len);
+ if (skb_copy_bits(skb, dgram_offset, skbn->data, dgram_len)) {
+ mhi_mbim_rx_drop(link, skbn);
+ continue;
+ }
switch (skbn->data[0] & 0xf0) {
case 0x40:
@@ -333,10 +344,7 @@ static void mhi_mbim_rx(struct mhi_mbim_
default:
net_err_ratelimited("%s: unknown protocol\n",
link->ndev->name);
- dev_kfree_skb_any(skbn);
- u64_stats_update_begin(&link->rx_syncp);
- u64_stats_inc(&link->rx_errors);
- u64_stats_update_end(&link->rx_syncp);
+ mhi_mbim_rx_drop(link, skbn);
continue;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 302/438] net/sched: hhf: cap hh_flows_limit at change time
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (300 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 301/438] net/sched: act_api: release tail references on DELACTION failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 303/438] net/packet: clear RX owner on VNET header error Greg Kroah-Hartman
` (147 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko (gemini), Victor Nogueira,
hybris, Jamal Hadi Salim, Simon Horman, Paolo Abeni
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
commit 2cef2588c995722a901368def30befeef9ae55c6 upstream.
hhf_change() stores TCA_HHF_HH_FLOWS_LIMIT with no upper bound. A huge
hh_flows_limit lets each new heavy-hitter flow pass the
hh_flows_current_cnt check in alloc_new_hh() and forces a fixed-size
kzalloc(GFP_ATOMIC) per flow under spoofed traffic, for unbounded memory
growth.
Bound the attribute with NLA_POLICY_MAX() at 2*HH_FLOWS_CNT (the
hhf_init() default) and report the rejected value via extack. The
deprecated nested parse is kept: legacy tc does not set NLA_F_NESTED on
TCA_OPTIONS. Configs relying on hh_limit above the default were relying
on unbounded, unsafe behaviour and are not supported going forward.
hhf_init() also ran hhf_change() before setting the default
hh_flows_limit, so a user-supplied hh_limit at add time was clobbered
back to 2048. Set the default before hhf_change() so the configured
value sticks.
This is a follow-up to commit eb56a495f59b ("net/sched: hhf: clamp
quantum in change and init paths"), which bounded the quantum of the
same qdisc; the hh_flows_limit bound is the remaining unbounded knob of
that series' scope.
Conditions to recreate the bug: CAP_NET_ADMIN in a user namespace;
tc qdisc change dev X root hhf hh_limit 4294967295 succeeds and the
value is echoed by tc qdisc show, unbounding heavy-hitter flow
allocations; also tc qdisc add dev X root hhf hh_limit 500 stores 2048
instead of 500.
Fixes: 10239edf86f1 ("net-qdisc-hhf: Heavy-Hitter Filter (HHF) qdisc")
Cc: stable@vger.kernel.org
Reported-by: Sashiko (gemini) <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260822195509.112717-1-jhs@mojatatu.com
Reviewed-by: Victor Nogueira <victor@mojatatu.com>
Tested-by: hybris <hybris@mojatatu.ai>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/QDISC-B855.v1.20260911153152@mojatatu.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/sch_hhf.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
--- a/net/sched/sch_hhf.c
+++ b/net/sched/sch_hhf.c
@@ -527,7 +527,7 @@ static void hhf_destroy(struct Qdisc *sc
static const struct nla_policy hhf_policy[TCA_HHF_MAX + 1] = {
[TCA_HHF_BACKLOG_LIMIT] = { .type = NLA_U32 },
[TCA_HHF_QUANTUM] = { .type = NLA_U32 },
- [TCA_HHF_HH_FLOWS_LIMIT] = { .type = NLA_U32 },
+ [TCA_HHF_HH_FLOWS_LIMIT] = NLA_POLICY_MAX(NLA_U32, 2 * HH_FLOWS_CNT),
[TCA_HHF_RESET_TIMEOUT] = { .type = NLA_U32 },
[TCA_HHF_ADMIT_BYTES] = { .type = NLA_U32 },
[TCA_HHF_EVICT_TIMEOUT] = { .type = NLA_U32 },
@@ -546,7 +546,7 @@ static int hhf_change(struct Qdisc *sch,
u32 new_hhf_non_hh_weight = q->hhf_non_hh_weight;
err = nla_parse_nested_deprecated(tb, TCA_HHF_MAX, opt, hhf_policy,
- NULL);
+ extack);
if (err < 0)
return err;
@@ -624,6 +624,9 @@ static int hhf_init(struct Qdisc *sch, s
q->hhf_evict_timeout = HZ; /* 1 sec */
q->hhf_non_hh_weight = 2;
+ /* Cap max active HHs at twice len of hh_flows table. */
+ q->hh_flows_limit = 2 * HH_FLOWS_CNT;
+
if (opt) {
int err = hhf_change(sch, opt, extack);
@@ -639,8 +642,6 @@ static int hhf_init(struct Qdisc *sch, s
for (i = 0; i < HH_FLOWS_CNT; i++)
INIT_LIST_HEAD(&q->hh_flows[i]);
- /* Cap max active HHs at twice len of hh_flows table. */
- q->hh_flows_limit = 2 * HH_FLOWS_CNT;
q->hh_flows_overlimit = 0;
q->hh_flows_total_cnt = 0;
q->hh_flows_current_cnt = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 249/398] net/sched: act_api: release tail references on DELACTION failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (246 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 248/398] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 250/398] net/sched: hhf: cap hh_flows_limit at change time Greg Kroah-Hartman
` (154 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xuanqiang Luo, Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
commit 6e05e46fa821a5c1b281355f1f622ac76cb6080a upstream.
A batched RTM_DELACTION request takes a temporary reference on each
action before attempting any deletion. tcf_action_delete() clears
each processed slot and drops its temporary reference before attempting
the deletion. If deletion fails, tca_action_gd() calls
tcf_action_put_many() to release the remaining references, but its
tcf_act_for_each_action() iterator stops at the first NULL slot.
When a batch stops at an action bound to a filter, this leaks a
reference on each subsequent action. A later delete of an unbound
action can then return success without removing it from the IDR.
Walk the full array in tcf_action_put_many() and skip NULL slots to
release the references held on the unprocessed actions.
Fixes: a0e947c9ccff ("net/sched: act_api: avoid non-contiguous action array")
Cc: stable@vger.kernel.org
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260910093413.34509-2-xuanqiang.luo@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/act_api.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -1218,11 +1218,16 @@ static int tcf_action_put(struct tc_acti
static void tcf_action_put_many(struct tc_action *actions[])
{
- struct tc_action *a;
int i;
- tcf_act_for_each_action(i, a, actions) {
- const struct tc_action_ops *ops = a->ops;
+ /* Deletion may have cleared entries before failing. */
+ for (i = 0; i < TCA_ACT_MAX_PRIO; i++) {
+ struct tc_action *a = actions[i];
+ const struct tc_action_ops *ops;
+
+ if (!a)
+ continue;
+ ops = a->ops;
if (tcf_action_put(a))
module_put(ops->owner);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 303/438] net/packet: clear RX owner on VNET header error
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (301 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 302/438] net/sched: hhf: cap hh_flows_limit at change time Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 304/438] net/packet: avoid truncating TPACKET_V3 private size Greg Kroah-Hartman
` (146 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Willem de Bruijn,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
commit 33ff111d7ba3beb86e28938d6382bb5beabd865a upstream.
Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race
condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2
ring slot before converting the virtio-net header. If the conversion
fails, the drop path leaves the slot claimed.
With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves
the only slot unavailable, so the ring also drops the next valid packet.
Clear the ownership bit on this error path. TPACKET_V3 already clears
its block state here.
Fixes: 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race condition")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260913-b4-send-packet-vnet-v1-1-5545ffb528ae@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/packet/af_packet.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -2384,7 +2384,9 @@ static int tpacket_rcv(struct sk_buff *s
virtio_net_hdr_from_skb(skb, h.raw + macoff -
sizeof(struct virtio_net_hdr),
vio_le(), true, 0)) {
- if (po->tp_version == TPACKET_V3)
+ if (po->tp_version <= TPACKET_V2)
+ __clear_bit(slot_id, po->rx_ring.rx_owner_map);
+ else
prb_clear_blk_fill_status(&po->rx_ring);
goto drop_n_account;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 250/398] net/sched: hhf: cap hh_flows_limit at change time
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (247 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 249/398] net/sched: act_api: release tail references on DELACTION failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 251/398] net/packet: clear RX owner on VNET header error Greg Kroah-Hartman
` (153 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko (gemini), Victor Nogueira,
hybris, Jamal Hadi Salim, Simon Horman, Paolo Abeni
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jamal Hadi Salim <jhs@mojatatu.com>
commit 2cef2588c995722a901368def30befeef9ae55c6 upstream.
hhf_change() stores TCA_HHF_HH_FLOWS_LIMIT with no upper bound. A huge
hh_flows_limit lets each new heavy-hitter flow pass the
hh_flows_current_cnt check in alloc_new_hh() and forces a fixed-size
kzalloc(GFP_ATOMIC) per flow under spoofed traffic, for unbounded memory
growth.
Bound the attribute with NLA_POLICY_MAX() at 2*HH_FLOWS_CNT (the
hhf_init() default) and report the rejected value via extack. The
deprecated nested parse is kept: legacy tc does not set NLA_F_NESTED on
TCA_OPTIONS. Configs relying on hh_limit above the default were relying
on unbounded, unsafe behaviour and are not supported going forward.
hhf_init() also ran hhf_change() before setting the default
hh_flows_limit, so a user-supplied hh_limit at add time was clobbered
back to 2048. Set the default before hhf_change() so the configured
value sticks.
This is a follow-up to commit eb56a495f59b ("net/sched: hhf: clamp
quantum in change and init paths"), which bounded the quantum of the
same qdisc; the hh_flows_limit bound is the remaining unbounded knob of
that series' scope.
Conditions to recreate the bug: CAP_NET_ADMIN in a user namespace;
tc qdisc change dev X root hhf hh_limit 4294967295 succeeds and the
value is echoed by tc qdisc show, unbounding heavy-hitter flow
allocations; also tc qdisc add dev X root hhf hh_limit 500 stores 2048
instead of 500.
Fixes: 10239edf86f1 ("net-qdisc-hhf: Heavy-Hitter Filter (HHF) qdisc")
Cc: stable@vger.kernel.org
Reported-by: Sashiko (gemini) <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260822195509.112717-1-jhs@mojatatu.com
Reviewed-by: Victor Nogueira <victor@mojatatu.com>
Tested-by: hybris <hybris@mojatatu.ai>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/QDISC-B855.v1.20260911153152@mojatatu.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/sched/sch_hhf.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
--- a/net/sched/sch_hhf.c
+++ b/net/sched/sch_hhf.c
@@ -526,7 +526,7 @@ static void hhf_destroy(struct Qdisc *sc
static const struct nla_policy hhf_policy[TCA_HHF_MAX + 1] = {
[TCA_HHF_BACKLOG_LIMIT] = { .type = NLA_U32 },
[TCA_HHF_QUANTUM] = { .type = NLA_U32 },
- [TCA_HHF_HH_FLOWS_LIMIT] = { .type = NLA_U32 },
+ [TCA_HHF_HH_FLOWS_LIMIT] = NLA_POLICY_MAX(NLA_U32, 2 * HH_FLOWS_CNT),
[TCA_HHF_RESET_TIMEOUT] = { .type = NLA_U32 },
[TCA_HHF_ADMIT_BYTES] = { .type = NLA_U32 },
[TCA_HHF_EVICT_TIMEOUT] = { .type = NLA_U32 },
@@ -545,7 +545,7 @@ static int hhf_change(struct Qdisc *sch,
u32 new_hhf_non_hh_weight = q->hhf_non_hh_weight;
err = nla_parse_nested_deprecated(tb, TCA_HHF_MAX, opt, hhf_policy,
- NULL);
+ extack);
if (err < 0)
return err;
@@ -623,6 +623,9 @@ static int hhf_init(struct Qdisc *sch, s
q->hhf_evict_timeout = HZ; /* 1 sec */
q->hhf_non_hh_weight = 2;
+ /* Cap max active HHs at twice len of hh_flows table. */
+ q->hh_flows_limit = 2 * HH_FLOWS_CNT;
+
if (opt) {
int err = hhf_change(sch, opt, extack);
@@ -639,8 +642,6 @@ static int hhf_init(struct Qdisc *sch, s
for (i = 0; i < HH_FLOWS_CNT; i++)
INIT_LIST_HEAD(&q->hh_flows[i]);
- /* Cap max active HHs at twice len of hh_flows table. */
- q->hh_flows_limit = 2 * HH_FLOWS_CNT;
q->hh_flows_overlimit = 0;
q->hh_flows_total_cnt = 0;
q->hh_flows_current_cnt = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 304/438] net/packet: avoid truncating TPACKET_V3 private size
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (302 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 303/438] net/packet: clear RX owner on VNET header error Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 305/438] scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() Greg Kroah-Hartman
` (145 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Willem de Bruijn,
Jakub Kicinski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
commit 37213e61120297920ae4c937fcb326a360da5084 upstream.
tpacket_req3.tp_sizeof_priv is an unsigned int, and packet_set_ring()
validates the full value against the block size. init_prb_bdqc() then
stores it in the unsigned short blk_sizeof_priv field.
Commit 2b6867c2ce76 ("net/packet: fix overflow in check for priv area
size") fixed the validation arithmetic, but an accepted value above
USHRT_MAX still narrows when it is stored.
For a 131072-byte block, tp_sizeof_priv=65536 is valid. The narrowing
makes offset_to_first_pkt 48 instead of 65584, so packet records can be
placed in the private area that userspace asked the kernel to preserve.
blk_sizeof_priv is internal state, so widen it to hold the validated
UAPI value.
Fixes: f6fb8f100b80 ("af-packet: TPACKET_V3 flexible buffer implementation.")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260913-b4-send-packet-private-v1-1-925eab2cd388@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/packet/internal.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/packet/internal.h
+++ b/net/packet/internal.h
@@ -21,7 +21,7 @@ struct tpacket_kbdq_core {
unsigned int hdrlen;
unsigned char reset_pending_on_curr_blk;
unsigned short kactive_blk_num;
- unsigned short blk_sizeof_priv;
+ unsigned int blk_sizeof_priv;
unsigned short version;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 251/398] net/packet: clear RX owner on VNET header error
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (248 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 250/398] net/sched: hhf: cap hh_flows_limit at change time Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 252/398] net/packet: avoid truncating TPACKET_V3 private size Greg Kroah-Hartman
` (152 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Willem de Bruijn,
Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
commit 33ff111d7ba3beb86e28938d6382bb5beabd865a upstream.
Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race
condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2
ring slot before converting the virtio-net header. If the conversion
fails, the drop path leaves the slot claimed.
With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves
the only slot unavailable, so the ring also drops the next valid packet.
Clear the ownership bit on this error path. TPACKET_V3 already clears
its block state here.
Fixes: 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race condition")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260913-b4-send-packet-vnet-v1-1-5545ffb528ae@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/packet/af_packet.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/net/packet/af_packet.c
+++ b/net/packet/af_packet.c
@@ -2383,7 +2383,9 @@ static int tpacket_rcv(struct sk_buff *s
virtio_net_hdr_from_skb(skb, h.raw + macoff -
sizeof(struct virtio_net_hdr),
vio_le(), true, 0)) {
- if (po->tp_version == TPACKET_V3)
+ if (po->tp_version <= TPACKET_V2)
+ __clear_bit(slot_id, po->rx_ring.rx_owner_map);
+ else
prb_clear_blk_fill_status(&po->rx_ring);
goto drop_n_account;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 305/438] scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (303 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 304/438] net/packet: avoid truncating TPACKET_V3 private size Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 306/438] xfrm: serialize state GC with device state flush Greg Kroah-Hartman
` (144 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko AI Review,
Pimen Flavian Dei (Drivesec S.r.l.),
Alberto Carboneri (Drivesec S.r.l.), Damien Le Moal,
Martin K. Petersen (Oracle)
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alberto Carboneri <acarboneri@drivesec.com>
commit 3d676e458fe0c566f5a62753dc696b6a862fc412 upstream.
scsi_cdl_enable() uses length fields returned by MODE SENSE to locate
the ATA feature mode page in a 64-byte stack buffer. A target can report
a total length shorter than its mode header and block descriptors. The
unsigned subtraction used for the MODE SELECT length can wrap, and the
separately computed buf_data can point beyond buf.
During automatic scan, enable is false, so the read-modify-write of
buf_data[4] can clear the low two bits of a target-selected
out-of-bounds stack byte. scsi_mode_select() can then copy up to 64
bytes from outside the buffer into the outgoing MODE SELECT payload,
disclosing stack contents to the target.
This is reachable while scanning a USB storage device that identifies as
an ATA device and advertises CDL support. No filesystem mount or
userspace access to the block device is required.
On upstream commit cee9395acd80 ("Linux 7.3-rc1"), a build-specific,
one-vCPU QEMU/Raw Gadget proof using QEMU-only multi-UDC allocator
sampling executed a fixed proof command inside the guest and created a
UID-0-owned marker during automatic enumeration, with KASLR and NX
enabled.
The issue was independently found during security research at Drivesec
S.r.l.
Cap the available length to the buffer size. Validate and consume the
mode header and block descriptor lengths before using the page, and
require the five bytes needed to access the CDL field.
Fixes: 1b22cfb14142 ("scsi: core: Allow enabling and disabling command duration limits")
Reported-by: Sashiko AI Review <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/linux-scsi/20260717192313.93D791F000E9@smtp.kernel.org/
Link: https://lore.kernel.org/linux-scsi/20260717222931.AC4EE1F000E9@smtp.kernel.org/
Link: https://lore.kernel.org/linux-scsi/df13ec87ac9b28e3b0a2d9eb26477e276ff0278a.camel@HansenPartnership.com/
Cc: stable@vger.kernel.org
Assisted-by: LLM
Co-developed-by: Pimen Flavian Dei (Drivesec S.r.l.) <fdei@drivesec.com>
Signed-off-by: Pimen Flavian Dei (Drivesec S.r.l.) <fdei@drivesec.com>
Signed-off-by: Alberto Carboneri (Drivesec S.r.l.) <acarboneri@drivesec.com>
Link: https://lore.kernel.org/linux-scsi/20260717192313.93D791F000E9@smtp.kernel.org/
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://patch.msgid.link/20260904135410.360314-1-acarboneri@drivesec.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/scsi.c | 24 +++++++++++++++++++-----
1 file changed, 19 insertions(+), 5 deletions(-)
--- a/drivers/scsi/scsi.c
+++ b/drivers/scsi/scsi.c
@@ -727,6 +727,7 @@ int scsi_cdl_enable(struct scsi_device *
struct scsi_mode_data data;
struct scsi_sense_hdr sshdr;
char *buf_data;
+ size_t avail, offset;
int len;
ret = scsi_mode_sense(sdev, 0x08, 0x0a, 0xf2, buf, sizeof(buf),
@@ -735,11 +736,24 @@ int scsi_cdl_enable(struct scsi_device *
return -EINVAL;
/* Enable or disable CDL using the ATA feature page */
- len = min_t(size_t, sizeof(buf),
- data.length - data.header_length -
- data.block_descriptor_length);
- buf_data = buf + data.header_length +
- data.block_descriptor_length;
+ avail = min_t(size_t, data.length, sizeof(buf));
+ if (data.header_length > avail)
+ return -EINVAL;
+
+ offset = data.header_length;
+ avail -= data.header_length;
+
+ if (data.block_descriptor_length > avail)
+ return -EINVAL;
+
+ offset += data.block_descriptor_length;
+ avail -= data.block_descriptor_length;
+
+ if (avail < 5)
+ return -EINVAL;
+
+ buf_data = buf + offset;
+ len = avail;
/*
* If we want to enable CDL and CDL is already enabled on the
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 252/398] net/packet: avoid truncating TPACKET_V3 private size
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (249 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 251/398] net/packet: clear RX owner on VNET header error Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 253/398] scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() Greg Kroah-Hartman
` (151 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Amirkan, Willem de Bruijn,
Jakub Kicinski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Amirkan <markdamirkan@gmail.com>
commit 37213e61120297920ae4c937fcb326a360da5084 upstream.
tpacket_req3.tp_sizeof_priv is an unsigned int, and packet_set_ring()
validates the full value against the block size. init_prb_bdqc() then
stores it in the unsigned short blk_sizeof_priv field.
Commit 2b6867c2ce76 ("net/packet: fix overflow in check for priv area
size") fixed the validation arithmetic, but an accepted value above
USHRT_MAX still narrows when it is stored.
For a 131072-byte block, tp_sizeof_priv=65536 is valid. The narrowing
makes offset_to_first_pkt 48 instead of 65584, so packet records can be
placed in the private area that userspace asked the kernel to preserve.
blk_sizeof_priv is internal state, so widen it to hold the validated
UAPI value.
Fixes: f6fb8f100b80 ("af-packet: TPACKET_V3 flexible buffer implementation.")
Cc: stable@vger.kernel.org
Signed-off-by: Mark Amirkan <markdamirkan@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260913-b4-send-packet-private-v1-1-925eab2cd388@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/packet/internal.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/packet/internal.h
+++ b/net/packet/internal.h
@@ -21,7 +21,7 @@ struct tpacket_kbdq_core {
unsigned int hdrlen;
unsigned char reset_pending_on_curr_blk;
unsigned short kactive_blk_num;
- unsigned short blk_sizeof_priv;
+ unsigned int blk_sizeof_priv;
unsigned short version;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 306/438] xfrm: serialize state GC with device state flush
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (304 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 305/438] scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 307/438] xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Greg Kroah-Hartman
` (143 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chengfeng Ye, Steffen Klassert
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengfeng Ye <nicoyip.dev@gmail.com>
commit 89fefad9f971bc637fb22373078144f2563c4be9 upstream.
The deferred-device pass in xfrm_dev_state_flush() finds states under
xfrm_state_dev_gc_lock, but drops the lock before calling
xfrm_dev_state_free() because the driver callback may sleep. The device
GC list does not hold an xfrm_state reference, so the state GC worker can
destroy the same state concurrently.
The race can proceed as follows:
CPU 0 CPU 1
find x on the device GC list
drop xfrm_state_dev_gc_lock
read x->xso.dev
xfrm_state_gc_destroy(x)
xfrm_dev_state_free(x)
xfrm_state_free(x)
continue xfrm_dev_state_free(x)
Both paths can invoke the driver callback and drop the device reference.
CPU 0 can also access the xfrm_state after CPU 1 has freed it.
KASAN reported:
BUG: KASAN: slab-use-after-free in xfrm_dev_state_free+0x24c/0x2a0
Read of size 8 at addr ffff88810bbaa960 by task poc/102
Call Trace:
xfrm_dev_state_free+0x24c/0x2a0
xfrm_dev_state_flush+0x353/0x400
xfrm_dev_event+0x26d/0x3a0
notifier_call_chain+0xc0/0x280
__dev_notify_flags+0x169/0x250
netif_change_flags+0xe7/0x160
dev_change_flags+0x96/0x220
devinet_ioctl+0x7f4/0x1880
Allocated by task 87:
xfrm_state_alloc+0x1e/0x5c0
xfrm_add_sa+0xe7f/0x5820
xfrm_user_rcv_msg+0x4f3/0x940
Freed by task 57:
kmem_cache_free+0xcb/0x3d0
xfrm_state_gc_task+0x4a8/0x650
process_one_work+0x63a/0x1070
Serialize xfrm_state destruction against the deferred-device pass with a
mutex. Keep xfrm_state_dev_gc_lock limited to list operations and retain
the existing callback and device-reference release ordering.
Fixes: 07b87f9eea0c ("xfrm: Fix unregister netdevice hang on hardware offload.")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/xfrm_state.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/net/xfrm/xfrm_state.c
+++ b/net/xfrm/xfrm_state.c
@@ -226,6 +226,7 @@ static struct xfrm_state_afinfo __rcu *x
static DEFINE_SPINLOCK(xfrm_state_gc_lock);
static DEFINE_SPINLOCK(xfrm_state_dev_gc_lock);
+static DEFINE_MUTEX(xfrm_state_gc_mutex);
int __xfrm_state_delete(struct xfrm_state *x);
@@ -632,8 +633,10 @@ static void xfrm_state_gc_task(struct wo
synchronize_rcu();
+ mutex_lock(&xfrm_state_gc_mutex);
hlist_for_each_entry_safe(x, tmp, &gc_list, gclist)
xfrm_state_gc_destroy(x);
+ mutex_unlock(&xfrm_state_gc_mutex);
}
static enum hrtimer_restart xfrm_timer_handler(struct hrtimer *me)
@@ -1000,6 +1003,7 @@ restart:
out:
spin_unlock_bh(&net->xfrm.xfrm_state_lock);
+ mutex_lock(&xfrm_state_gc_mutex);
spin_lock_bh(&xfrm_state_dev_gc_lock);
restart_gc:
hlist_for_each_entry_safe(x, tmp, &xfrm_state_dev_gc_list, dev_gclist) {
@@ -1014,6 +1018,7 @@ restart_gc:
}
spin_unlock_bh(&xfrm_state_dev_gc_lock);
+ mutex_unlock(&xfrm_state_gc_mutex);
xfrm_flush_gc();
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 253/398] scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (250 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 252/398] net/packet: avoid truncating TPACKET_V3 private size Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 254/398] xfrm: serialize state GC with device state flush Greg Kroah-Hartman
` (150 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko AI Review,
Pimen Flavian Dei (Drivesec S.r.l.),
Alberto Carboneri (Drivesec S.r.l.), Damien Le Moal,
Martin K. Petersen (Oracle)
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alberto Carboneri <acarboneri@drivesec.com>
commit 3d676e458fe0c566f5a62753dc696b6a862fc412 upstream.
scsi_cdl_enable() uses length fields returned by MODE SENSE to locate
the ATA feature mode page in a 64-byte stack buffer. A target can report
a total length shorter than its mode header and block descriptors. The
unsigned subtraction used for the MODE SELECT length can wrap, and the
separately computed buf_data can point beyond buf.
During automatic scan, enable is false, so the read-modify-write of
buf_data[4] can clear the low two bits of a target-selected
out-of-bounds stack byte. scsi_mode_select() can then copy up to 64
bytes from outside the buffer into the outgoing MODE SELECT payload,
disclosing stack contents to the target.
This is reachable while scanning a USB storage device that identifies as
an ATA device and advertises CDL support. No filesystem mount or
userspace access to the block device is required.
On upstream commit cee9395acd80 ("Linux 7.3-rc1"), a build-specific,
one-vCPU QEMU/Raw Gadget proof using QEMU-only multi-UDC allocator
sampling executed a fixed proof command inside the guest and created a
UID-0-owned marker during automatic enumeration, with KASLR and NX
enabled.
The issue was independently found during security research at Drivesec
S.r.l.
Cap the available length to the buffer size. Validate and consume the
mode header and block descriptor lengths before using the page, and
require the five bytes needed to access the CDL field.
Fixes: 1b22cfb14142 ("scsi: core: Allow enabling and disabling command duration limits")
Reported-by: Sashiko AI Review <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/linux-scsi/20260717192313.93D791F000E9@smtp.kernel.org/
Link: https://lore.kernel.org/linux-scsi/20260717222931.AC4EE1F000E9@smtp.kernel.org/
Link: https://lore.kernel.org/linux-scsi/df13ec87ac9b28e3b0a2d9eb26477e276ff0278a.camel@HansenPartnership.com/
Cc: stable@vger.kernel.org
Assisted-by: LLM
Co-developed-by: Pimen Flavian Dei (Drivesec S.r.l.) <fdei@drivesec.com>
Signed-off-by: Pimen Flavian Dei (Drivesec S.r.l.) <fdei@drivesec.com>
Signed-off-by: Alberto Carboneri (Drivesec S.r.l.) <acarboneri@drivesec.com>
Link: https://lore.kernel.org/linux-scsi/20260717192313.93D791F000E9@smtp.kernel.org/
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://patch.msgid.link/20260904135410.360314-1-acarboneri@drivesec.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/scsi.c | 24 +++++++++++++++++++-----
1 file changed, 19 insertions(+), 5 deletions(-)
--- a/drivers/scsi/scsi.c
+++ b/drivers/scsi/scsi.c
@@ -722,6 +722,7 @@ int scsi_cdl_enable(struct scsi_device *
struct scsi_mode_data data;
struct scsi_sense_hdr sshdr;
char *buf_data;
+ size_t avail, offset;
int len;
ret = scsi_mode_sense(sdev, 0x08, 0x0a, 0xf2, buf, sizeof(buf),
@@ -730,11 +731,24 @@ int scsi_cdl_enable(struct scsi_device *
return -EINVAL;
/* Enable or disable CDL using the ATA feature page */
- len = min_t(size_t, sizeof(buf),
- data.length - data.header_length -
- data.block_descriptor_length);
- buf_data = buf + data.header_length +
- data.block_descriptor_length;
+ avail = min_t(size_t, data.length, sizeof(buf));
+ if (data.header_length > avail)
+ return -EINVAL;
+
+ offset = data.header_length;
+ avail -= data.header_length;
+
+ if (data.block_descriptor_length > avail)
+ return -EINVAL;
+
+ offset += data.block_descriptor_length;
+ avail -= data.block_descriptor_length;
+
+ if (avail < 5)
+ return -EINVAL;
+
+ buf_data = buf + offset;
+ len = avail;
/*
* If we want to enable CDL and CDL is already enabled on the
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 307/438] xfrm: use hlist_del_init_rcu for state_cache and state_cache_input
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (305 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 306/438] xfrm: serialize state GC with device state flush Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 308/438] xfrm: save input state data before secpath resets Greg Kroah-Hartman
` (142 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Siwei Zhang, Steffen Klassert
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Siwei Zhang <fourdizhang@tencent.com>
commit 2afb8dc1f4390f164db8352f8e685e126e9db566 upstream.
Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in
__xfrm_state_delete") converted bydst/bysrc/byseq/byspi from
hlist_del_rcu() to hlist_del_init_rcu() so that a second
__xfrm_state_delete() on the same object becomes a no-op rather than a
write through LIST_POISON pprev. It missed state_cache and
state_cache_input, which kept hlist_del_rcu():
- hlist_del_rcu() leaves pprev = LIST_POISON2 (non-NULL), so
hlist_unhashed() returns false.
- hlist_del_init_rcu() leaves pprev = NULL, so hlist_unhashed()
returns true.
A second __xfrm_state_delete() therefore enters __hlist_del() on the
already-deleted state_cache/state_cache_input nodes and does
WRITE_ONCE(*pprev, next) through LIST_POISON2 — a write use-after-free
once the slab is reused. The corruption can in turn cause a subsequent
hlist_for_each_entry_rcu traversal to follow a dangling next pointer,
producing the read use-after-free reported in xfrm_input_state_lookup().
Switch state_cache and state_cache_input to hlist_del_init_rcu() to
match the other four lists, closing the write use-after-free and, with
it, the read use-after-free it spawns.
Assisted-by: CodeBuddy:GLM-5.2
Fixes: 0045e3d80613 ("xfrm: Cache used outbound xfrm states at the policy.")
Fixes: 81a331a0e72d ("xfrm: Add an inbound percpu state cache.")
Cc: stable@vger.kernel.org
Signed-off-by: Siwei Zhang <fourdizhang@tencent.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/xfrm_state.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/net/xfrm/xfrm_state.c
+++ b/net/xfrm/xfrm_state.c
@@ -826,9 +826,9 @@ int __xfrm_state_delete(struct xfrm_stat
if (!hlist_unhashed(&x->byseq))
hlist_del_init_rcu(&x->byseq);
if (!hlist_unhashed(&x->state_cache))
- hlist_del_rcu(&x->state_cache);
+ hlist_del_init_rcu(&x->state_cache);
if (!hlist_unhashed(&x->state_cache_input))
- hlist_del_rcu(&x->state_cache_input);
+ hlist_del_init_rcu(&x->state_cache_input);
if (!hlist_unhashed(&x->byspi))
hlist_del_init_rcu(&x->byspi);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 254/398] xfrm: serialize state GC with device state flush
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (251 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 253/398] scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 255/398] xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Greg Kroah-Hartman
` (149 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chengfeng Ye, Steffen Klassert
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengfeng Ye <nicoyip.dev@gmail.com>
commit 89fefad9f971bc637fb22373078144f2563c4be9 upstream.
The deferred-device pass in xfrm_dev_state_flush() finds states under
xfrm_state_dev_gc_lock, but drops the lock before calling
xfrm_dev_state_free() because the driver callback may sleep. The device
GC list does not hold an xfrm_state reference, so the state GC worker can
destroy the same state concurrently.
The race can proceed as follows:
CPU 0 CPU 1
find x on the device GC list
drop xfrm_state_dev_gc_lock
read x->xso.dev
xfrm_state_gc_destroy(x)
xfrm_dev_state_free(x)
xfrm_state_free(x)
continue xfrm_dev_state_free(x)
Both paths can invoke the driver callback and drop the device reference.
CPU 0 can also access the xfrm_state after CPU 1 has freed it.
KASAN reported:
BUG: KASAN: slab-use-after-free in xfrm_dev_state_free+0x24c/0x2a0
Read of size 8 at addr ffff88810bbaa960 by task poc/102
Call Trace:
xfrm_dev_state_free+0x24c/0x2a0
xfrm_dev_state_flush+0x353/0x400
xfrm_dev_event+0x26d/0x3a0
notifier_call_chain+0xc0/0x280
__dev_notify_flags+0x169/0x250
netif_change_flags+0xe7/0x160
dev_change_flags+0x96/0x220
devinet_ioctl+0x7f4/0x1880
Allocated by task 87:
xfrm_state_alloc+0x1e/0x5c0
xfrm_add_sa+0xe7f/0x5820
xfrm_user_rcv_msg+0x4f3/0x940
Freed by task 57:
kmem_cache_free+0xcb/0x3d0
xfrm_state_gc_task+0x4a8/0x650
process_one_work+0x63a/0x1070
Serialize xfrm_state destruction against the deferred-device pass with a
mutex. Keep xfrm_state_dev_gc_lock limited to list operations and retain
the existing callback and device-reference release ordering.
Fixes: 07b87f9eea0c ("xfrm: Fix unregister netdevice hang on hardware offload.")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/xfrm_state.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/net/xfrm/xfrm_state.c
+++ b/net/xfrm/xfrm_state.c
@@ -226,6 +226,7 @@ static struct xfrm_state_afinfo __rcu *x
static DEFINE_SPINLOCK(xfrm_state_gc_lock);
static DEFINE_SPINLOCK(xfrm_state_dev_gc_lock);
+static DEFINE_MUTEX(xfrm_state_gc_mutex);
int __xfrm_state_delete(struct xfrm_state *x);
@@ -632,8 +633,10 @@ static void xfrm_state_gc_task(struct wo
synchronize_rcu();
+ mutex_lock(&xfrm_state_gc_mutex);
hlist_for_each_entry_safe(x, tmp, &gc_list, gclist)
xfrm_state_gc_destroy(x);
+ mutex_unlock(&xfrm_state_gc_mutex);
}
static enum hrtimer_restart xfrm_timer_handler(struct hrtimer *me)
@@ -1000,6 +1003,7 @@ restart:
out:
spin_unlock_bh(&net->xfrm.xfrm_state_lock);
+ mutex_lock(&xfrm_state_gc_mutex);
spin_lock_bh(&xfrm_state_dev_gc_lock);
restart_gc:
hlist_for_each_entry_safe(x, tmp, &xfrm_state_dev_gc_list, dev_gclist) {
@@ -1014,6 +1018,7 @@ restart_gc:
}
spin_unlock_bh(&xfrm_state_dev_gc_lock);
+ mutex_unlock(&xfrm_state_gc_mutex);
xfrm_flush_gc();
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 308/438] xfrm: save input state data before secpath resets
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (306 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 307/438] xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 309/438] soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node Greg Kroah-Hartman
` (141 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Steffen Klassert
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
commit 3cf5cdecd99c9c186a5ea518d93bbf3045b6e3aa upstream.
xfrm_input() stores the current xfrm_state in the skb secpath while it
continues receive-side processing. Some input paths can reset that secpath
before xfrm_input() has finished dereferencing the state.
Receive callback users such as VTI and XFRM interfaces can reset the
secpath. The VTI receive path does so before checking whether the packet
crosses network namespaces, while the XFRM interface path does so only for
cross-network-namespace packets. The XFRM_MAX_DEPTH error path can also
reset the secpath before the final drop callback reports the current
state's protocol.
If secpath_reset() drops the last state reference while the state is
concurrently deleted, xfrm_input() can still dereference the freed state
when selecting transport_finish() or reporting the drop callback protocol.
Save the state protocol on the stack while the state is still valid,
and use the already saved address family for transport_finish(). A larval
XFRM_STATE_ACQ state has no type, so retain nexthdr as its protocol. This
preserves the existing drop-path fallback while avoiding the post-reset
state dereferences without adding an extra state reference to every
received packet.
Fixes: df3893c176e9 ("vti: Update the ipv4 side to use it's own receive hook.")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/xfrm_input.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
--- a/net/xfrm/xfrm_input.c
+++ b/net/xfrm/xfrm_input.c
@@ -474,6 +474,7 @@ int xfrm_input(struct sk_buff *skb, int
struct xfrm_state *x = NULL;
xfrm_address_t *daddr;
u32 mark = skb->mark;
+ u8 xfrm_proto = nexthdr;
unsigned int family = AF_UNSPEC;
int decaps = 0;
int async = 0;
@@ -485,6 +486,7 @@ int xfrm_input(struct sk_buff *skb, int
if (encap_type < 0 || (xo && (xo->flags & XFRM_GRO || encap_type == 0 ||
encap_type == UDP_ENCAP_ESPINUDP))) {
x = xfrm_input_state(skb);
+ xfrm_proto = x->type ? x->type->proto : nexthdr;
if (unlikely(x->km.state != XFRM_STATE_VALID)) {
if (x->km.state == XFRM_STATE_ACQ)
@@ -592,11 +594,13 @@ int xfrm_input(struct sk_buff *skb, int
x = xfrm_input_state_lookup(net, mark, daddr, spi, nexthdr, family);
if (x == NULL) {
+ xfrm_proto = nexthdr;
secpath_reset(skb);
XFRM_INC_STATS(net, LINUX_MIB_XFRMINNOSTATES);
xfrm_audit_state_notfound(skb, family, spi, seq);
goto drop;
}
+ xfrm_proto = x->type ? x->type->proto : nexthdr;
if (unlikely(x->dir && x->dir != XFRM_SA_DIR_IN)) {
secpath_reset(skb);
@@ -604,6 +608,7 @@ int xfrm_input(struct sk_buff *skb, int
xfrm_audit_state_notfound(skb, family, spi, seq);
xfrm_state_put(x);
x = NULL;
+ xfrm_proto = nexthdr;
goto drop;
}
@@ -728,7 +733,7 @@ resume_decapped:
} while (!err);
rcu_read_lock();
- err = xfrm_rcv_cb(skb, family, x->type->proto, 0);
+ err = xfrm_rcv_cb(skb, family, xfrm_proto, 0);
if (err) {
rcu_read_unlock();
goto drop;
@@ -753,7 +758,7 @@ resume_decapped:
xfrm_gro = xo->flags & XFRM_GRO;
err = -EAFNOSUPPORT;
- afinfo = xfrm_state_afinfo_get_rcu(x->props.family);
+ afinfo = xfrm_state_afinfo_get_rcu(family);
if (likely(afinfo))
err = afinfo->transport_finish(skb, xfrm_gro || async);
if (xfrm_gro) {
@@ -776,7 +781,7 @@ drop_unlock:
drop:
if (async)
dev_put(dev);
- xfrm_rcv_cb(skb, family, x && x->type ? x->type->proto : nexthdr, -1);
+ xfrm_rcv_cb(skb, family, xfrm_proto, -1);
kfree_skb(skb);
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 255/398] xfrm: use hlist_del_init_rcu for state_cache and state_cache_input
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (252 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 254/398] xfrm: serialize state GC with device state flush Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 256/398] soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node Greg Kroah-Hartman
` (148 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Siwei Zhang, Steffen Klassert
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Siwei Zhang <fourdizhang@tencent.com>
commit 2afb8dc1f4390f164db8352f8e685e126e9db566 upstream.
Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in
__xfrm_state_delete") converted bydst/bysrc/byseq/byspi from
hlist_del_rcu() to hlist_del_init_rcu() so that a second
__xfrm_state_delete() on the same object becomes a no-op rather than a
write through LIST_POISON pprev. It missed state_cache and
state_cache_input, which kept hlist_del_rcu():
- hlist_del_rcu() leaves pprev = LIST_POISON2 (non-NULL), so
hlist_unhashed() returns false.
- hlist_del_init_rcu() leaves pprev = NULL, so hlist_unhashed()
returns true.
A second __xfrm_state_delete() therefore enters __hlist_del() on the
already-deleted state_cache/state_cache_input nodes and does
WRITE_ONCE(*pprev, next) through LIST_POISON2 — a write use-after-free
once the slab is reused. The corruption can in turn cause a subsequent
hlist_for_each_entry_rcu traversal to follow a dangling next pointer,
producing the read use-after-free reported in xfrm_input_state_lookup().
Switch state_cache and state_cache_input to hlist_del_init_rcu() to
match the other four lists, closing the write use-after-free and, with
it, the read use-after-free it spawns.
Assisted-by: CodeBuddy:GLM-5.2
Fixes: 0045e3d80613 ("xfrm: Cache used outbound xfrm states at the policy.")
Fixes: 81a331a0e72d ("xfrm: Add an inbound percpu state cache.")
Cc: stable@vger.kernel.org
Signed-off-by: Siwei Zhang <fourdizhang@tencent.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/xfrm_state.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/net/xfrm/xfrm_state.c
+++ b/net/xfrm/xfrm_state.c
@@ -826,9 +826,9 @@ int __xfrm_state_delete(struct xfrm_stat
if (!hlist_unhashed(&x->byseq))
hlist_del_init_rcu(&x->byseq);
if (!hlist_unhashed(&x->state_cache))
- hlist_del_rcu(&x->state_cache);
+ hlist_del_init_rcu(&x->state_cache);
if (!hlist_unhashed(&x->state_cache_input))
- hlist_del_rcu(&x->state_cache_input);
+ hlist_del_init_rcu(&x->state_cache_input);
if (!hlist_unhashed(&x->byspi))
hlist_del_init_rcu(&x->byspi);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 309/438] soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (307 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 308/438] xfrm: save input state data before secpath resets Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 310/438] mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ Greg Kroah-Hartman
` (140 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Alexey Klimov,
Krzysztof Kozlowski, Arnd Bergmann
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexey Klimov <alexey.klimov@linaro.org>
commit 4dd1999783d7d12434006289338373e49492dc96 upstream.
The setup_cpuhp_and_cpuidle() parses the device tree node for the
interrupt generation block via of_parse_phandle() and decrements its
reference count using of_node_put() immediately after fetching the resource
address. However, later the intr_gen_node pointer is passed into
of_syscon_register_regmap().
Fix this by declaring intr_gen_node with __free() and removing
of_node_put().
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260513-exynos850-cpuhotplug-v4-0-54fec5f65362@linaro.org?part=3
Fixes: 78b72897a5c8 ("soc: samsung: exynos-pmu: Enable CPU Idle for gs101")
Cc: stable@vger.kernel.org
Signed-off-by: Alexey Klimov <alexey.klimov@linaro.org>
Link: https://patch.msgid.link/20260828-exynos-pmu-cpuhp-idle-fixes-v2-1-06bce6107bd6@linaro.org
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Link: https://lore.kernel.org/r/20260917081641.72291-2-krzk@kernel.org
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/soc/samsung/exynos-pmu.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
--- a/drivers/soc/samsung/exynos-pmu.c
+++ b/drivers/soc/samsung/exynos-pmu.c
@@ -409,13 +409,12 @@ static struct notifier_block exynos_cpup
static int setup_cpuhp_and_cpuidle(struct device *dev)
{
- struct device_node *intr_gen_node;
+ struct device_node *intr_gen_node __free(device_node) =
+ of_parse_phandle(dev->of_node, "google,pmu-intr-gen-syscon", 0);
struct resource intrgen_res;
void __iomem *virt_addr;
int ret, cpu;
- intr_gen_node = of_parse_phandle(dev->of_node,
- "google,pmu-intr-gen-syscon", 0);
if (!intr_gen_node) {
/*
* To maintain support for older DTs that didn't specify syscon
@@ -431,8 +430,6 @@ static int setup_cpuhp_and_cpuidle(struc
* syscon provided regmap.
*/
ret = of_address_to_resource(intr_gen_node, 0, &intrgen_res);
- of_node_put(intr_gen_node);
-
virt_addr = devm_ioremap(dev, intrgen_res.start,
resource_size(&intrgen_res));
if (!virt_addr)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 256/398] soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (253 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 255/398] xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 257/398] memcg: avoid charging the root memcg from obj_cgroup_charge_pages() Greg Kroah-Hartman
` (147 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Alexey Klimov,
Krzysztof Kozlowski, Arnd Bergmann
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexey Klimov <alexey.klimov@linaro.org>
commit 4dd1999783d7d12434006289338373e49492dc96 upstream.
The setup_cpuhp_and_cpuidle() parses the device tree node for the
interrupt generation block via of_parse_phandle() and decrements its
reference count using of_node_put() immediately after fetching the resource
address. However, later the intr_gen_node pointer is passed into
of_syscon_register_regmap().
Fix this by declaring intr_gen_node with __free() and removing
of_node_put().
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260513-exynos850-cpuhotplug-v4-0-54fec5f65362@linaro.org?part=3
Fixes: 78b72897a5c8 ("soc: samsung: exynos-pmu: Enable CPU Idle for gs101")
Cc: stable@vger.kernel.org
Signed-off-by: Alexey Klimov <alexey.klimov@linaro.org>
Link: https://patch.msgid.link/20260828-exynos-pmu-cpuhp-idle-fixes-v2-1-06bce6107bd6@linaro.org
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Link: https://lore.kernel.org/r/20260917081641.72291-2-krzk@kernel.org
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/soc/samsung/exynos-pmu.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
--- a/drivers/soc/samsung/exynos-pmu.c
+++ b/drivers/soc/samsung/exynos-pmu.c
@@ -540,13 +540,12 @@ static struct notifier_block exynos_cpup
static int setup_cpuhp_and_cpuidle(struct device *dev)
{
- struct device_node *intr_gen_node;
+ struct device_node *intr_gen_node __free(device_node) =
+ of_parse_phandle(dev->of_node, "google,pmu-intr-gen-syscon", 0);
struct resource intrgen_res;
void __iomem *virt_addr;
int ret, cpu;
- intr_gen_node = of_parse_phandle(dev->of_node,
- "google,pmu-intr-gen-syscon", 0);
if (!intr_gen_node) {
/*
* To maintain support for older DTs that didn't specify syscon
@@ -562,8 +561,6 @@ static int setup_cpuhp_and_cpuidle(struc
* syscon provided regmap.
*/
ret = of_address_to_resource(intr_gen_node, 0, &intrgen_res);
- of_node_put(intr_gen_node);
-
virt_addr = devm_ioremap(dev, intrgen_res.start,
resource_size(&intrgen_res));
if (!virt_addr)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 310/438] mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (308 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 309/438] soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 311/438] memcg: avoid charging the root memcg from obj_cgroup_charge_pages() Greg Kroah-Hartman
` (139 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Théo Lebrun, Jiaxun Yang,
Thomas Bogendoerfer
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Théo Lebrun <theo.lebrun@bootlin.com>
commit bbc448c541ed90d52f9ec22f17394304e3bf170e upstream.
On I6500 CPU cores, lld and scd give no ordering guarantees (same as all
other instructions). To respect the assumption that arch_cmpxchg() is
fully ordered, we must inject sync instructions above and below our
lld/scd loops using the already in place WEAK_REORDERING_BEYOND_LLSC
infrastructure.
Otherwise, bad things can happen:
[ 34.054496] CPU 3 Unable to handle kernel paging request at virtual address 0000000000000000, epc == a80000080838e01c, ra == a80000080838dfc4
[ 34.054559] Oops[#1]:
[ 34.069561] CPU: 3 UID: 0 PID: 170 Comm: pipe_race Not tainted 7.2.0-rc6-01553-gb73c35220968-dirty #103 VOLUNTARY
[ 34.079932] Hardware name: Mobile EyeQ5 MP5 Evaluation board
[ 34.085592] $ 0 : 0000000000000000 0000000000000001 0000000000000000 0000000000000000
[ 34.093616] $ 4 : a800000808ee2618 000000000b7a879d 0000000000001000 0000000000000000
[ 34.101638] $ 8 : 0000000000e3f2c9 0000000000000000 a800000808a2a9f8 0000000000000000
[ 34.109660] $12 : a8000008139ffcd8 ffffffff84080018 a80000080837fae0 7878787878787878
[ 34.117682] $16 : a800000807e82940 0000000000001000 0000000000000000 0000000000000000
[ 34.125704] $20 : a800000802920e00 a8000008139ffdf8 a800000802649400 0000000000e3f2c9
[ 34.133726] $24 : 0000000000000006 00000001200406e0
[ 34.141783] $28 : a8000008139fc000 a8000008139ffd10 0000000000e3f2c8 a80000080838dfc4
[ 34.149837] epc : a80000080838e01c anon_pipe_read+0xd4/0x428
[ 34.155697] ra : a80000080838dfc4 anon_pipe_read+0x7c/0x428
[ 34.161549] Status: 140000e3 KX SX UX KERNEL EXL IE
[ 34.166551] Cause : 40800408 (ExcCode 02)
[ 34.170574] BadVA : 0000000000000000
[ 34.174161] PrId : 0001b028 (MIPS I6500)
[ 34.178183] Process pipe_race (pid: 170, threadinfo=000000005ca35720, task=00000000e1013890, tls=000000014ebbb780)
[ 34.188568] Stack : a800000802649400 0000000000000000 0000000000000000 a8000008139ffdd0
[ 34.196623] 0000000000000fba a800000808ee0000 0000000000000001 a8000008130c3e80
[ 34.204676] a8000008080d1280 a8000008139ffd58 a8000008139ffd58 1dbd2b22ea1dd500
[ 34.212729] a800000802649400 a800000808ee0000 ffffffffffffffea 0000000000000001
[ 34.220783] 0000000000001000 0000000000000000 00000001200ae518 ffffffffffffffff
[ 34.228836] 000000fffbe0e530 a80000080837edf4 000000fffbe0e530 0000000000000000
[ 34.236890] 0000000000000000 0000000000000000 000000014ebb55a0 0000000000001000
[ 34.244943] 0000000000000001 a800000802649400 0000000000000000 0000000000000000
[ 34.252996] 0000000000000000 0000400400000000 0000000000000000 1dbd2b22ea1dd500
[ 34.261049] 00000000140000e3 a800000802649400 a800000802649400 a800000808ee0000
[ 34.269103] ...
[ 34.271568] Call Trace:
[ 34.274026] [<a80000080838e01c>] anon_pipe_read+0xd4/0x428
[ 34.279533] [<a80000080837edf4>] vfs_read+0x25c/0x318
[ 34.284607] [<a80000080837faac>] ksys_read+0x104/0x138
[ 34.289763] [<a80000080802b9cc>] syscall_common+0x44/0x68
[ 34.295187]
[ 34.296689] Code: f84000cf 02209825 de020010 <dc420000> d8400004 02002825 0040f809 02802025 f84000c3
[ 34.306504]
[ 34.308099] ---[ end trace 0000000000000000 ]---
My initial reproducer was the xdp-tools test suite. A standalone
reproducer would be an lld/scd loop that, when the read is reordered by
the CPU, triggers a fault. We can achieve this from userspace by
stressing an anonymous pipe, which uses a mutex. Program used:
// SPDX-License-Identifier: GPL-2.0
// pipe_race.c - reproducer for MIPS LL/SC reordering vs fs/pipe.c
//
// Two userspace processes on an anonymous pipe:
// parent = writer: tight write() loop
// child = reader: tight read() loop
#define _GNU_SOURCE
#include <assert.h>
#include <errno.h>
#include <sched.h>
#include <signal.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/types.h>
#include <sys/wait.h>
#include <time.h>
#include <unistd.h>
int main(void)
{
long wrsize = 70; // bytes per write()
long rdsize = 4096; // bytes per read()
int pfd[2];
char *buf;
pid_t pid;
int ret;
ret = pipe(pfd);
assert(!ret);
pid = fork();
assert(pid >= 0);
if (pid == 0) { /* reader */
close(pfd[1]);
buf = malloc(rdsize);
assert(buf);
for (;;) {
ssize_t n = read(pfd[0], buf, rdsize);
if (n < 0 && errno == EINTR)
continue;
if (n <= 0)
_exit(n < 0 ? 1 : 0);
}
}
close(pfd[0]); /* writer */
buf = malloc(wrsize);
assert(buf);
memset(buf, 'x', wrsize);
for (;;) {
ssize_t n = write(pfd[1], buf, wrsize);
if (n < 0 && errno == EINTR)
continue;
if (n != wrsize)
break;
}
kill(pid, SIGKILL);
wait(NULL);
return 0;
}
Fixes: fbe0fae601b7 ("MIPS: mobileye: Add EyeQ6H support")
Cc: stable@vger.kernel.org
Signed-off-by: Théo Lebrun <theo.lebrun@bootlin.com>
Reviewed-by: Jiaxun Yang <jiaxun.yang@flygoat.com>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/mips/Kconfig | 1 +
1 file changed, 1 insertion(+)
--- a/arch/mips/Kconfig
+++ b/arch/mips/Kconfig
@@ -659,6 +659,7 @@ config EYEQ
select USB_UHCI_BIG_ENDIAN_MMIO if CPU_BIG_ENDIAN
select USE_OF
select HOTPLUG_PARALLEL if HOTPLUG_CPU
+ select WEAK_REORDERING_BEYOND_LLSC
help
Select this to build a kernel supporting EyeQ SoC from Mobileye.
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 257/398] memcg: avoid charging the root memcg from obj_cgroup_charge_pages()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (254 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 256/398] soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 258/398] memstick: ms_block: destroy io_queue workqueue on removal Greg Kroah-Hartman
` (146 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shakeel Butt, Farhad Alemi,
Muchun Song, Johannes Weiner, Michal Hocko, Roman Gushchin,
Andrew Morton
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shakeel Butt <shakeel.butt@linux.dev>
commit 6e673d0879ef78c395cfe0d3ba316690a60055d8 upstream.
obj_cgroup_charge_pages() resolves the objcg to its memcg and calls
try_charge_memcg(), which does not short circuit the root memcg. That
memcg can be the root memcg: obj_cgroup_is_root() reflects the memcg the
objcg was created for and is never updated, while memcg_reparent_objcgs()
does redirect objcg->memcg to the parent on rmdir. An objcg of a dying
child of root therefore passes every obj_cgroup_is_root() filter but
resolves to the root memcg.
Folios keep the objcg they were charged with, so this is easy to reach
through zswap: allocate anon memory in a cgroup, move the task out, remove
the cgroup, then write to the root cgroup's memory.reclaim. The reclaimed
folios are charged through the reparented objcg and end up in
refill_stock() with the root memcg:
WARNING: mm/memcontrol.c:2198 at refill_stock+0x644/0x940
refill_stock+0x644/0x940
try_charge_memcg+0x12d6/0x1570
__obj_cgroup_charge+0x35/0xf0
obj_cgroup_charge+0x1de/0x210
obj_cgroup_charge_zswap+0x83/0x270
zswap_store+0x1620/0x2000
swap_writeout+0x94c/0x14c0
shrink_folio_list+0x3388/0x52b0
[...]
try_to_free_mem_cgroup_pages+0x30d/0x830
user_proactive_reclaim+0x504/0x840
memory_reclaim+0x1f/0x30
Beyond the warning, the charge is asymmetric: obj_cgroup_uncharge_pages()
skips refill_stock() for the root memcg, so the root's page counter grows
and is never uncharged. It is not user visible, since memory.current is
not exposed on the root, but it is a leak.
Use try_charge(), which returns early for the root memcg, restoring the
symmetry with obj_cgroup_uncharge_pages().
The above sequence was scripted into a standalone reproducer (zswap on,
swap on a virtio disk, 512MB of anon memory faulted in inside a child of
the root cgroup, the task then migrated to the root cgroup, the child
removed, followed by "echo 600M swappiness=max > memory.reclaim" on the
root) and run in a CONFIG_DEBUG_VM=y VM. It reproduces the splat on the
first zswap store of a reparented folio, with the same call chain as the
report. With this patch applied the splat is gone while the zswap store
count over the run is unchanged, so the same path is still exercised.
cgroup selftests test_zswap, test_kmem and test_memcontrol show no new
failures.
Link: https://lore.kernel.org/20260829023251.474083-1-shakeel.butt@linux.dev
Fixes: 20d6c1725228 ("memcg: avoid refill_stock for root memcg")
Signed-off-by: Shakeel Butt <shakeel.butt@linux.dev>
Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Closes: https://lore.kernel.org/all/CA+0ovCgWzUMK+nNbbtH7eV65Ca=fDN4Ozu7iASgryjvv8Tk8zQ@mail.gmail.com/
Reviewed-by: Muchun Song <muchun.song@linux.dev>
Reviewed-by: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/memcontrol.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/memcontrol.c
+++ b/mm/memcontrol.c
@@ -2812,7 +2812,7 @@ static int obj_cgroup_charge_pages(struc
memcg = get_mem_cgroup_from_objcg(objcg);
- ret = try_charge_memcg(memcg, gfp, nr_pages);
+ ret = try_charge(memcg, gfp, nr_pages);
if (ret)
goto out;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 311/438] memcg: avoid charging the root memcg from obj_cgroup_charge_pages()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (309 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 310/438] mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 312/438] memstick: ms_block: destroy io_queue workqueue on removal Greg Kroah-Hartman
` (138 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shakeel Butt, Farhad Alemi,
Muchun Song, Johannes Weiner, Michal Hocko, Roman Gushchin,
Andrew Morton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shakeel Butt <shakeel.butt@linux.dev>
commit 6e673d0879ef78c395cfe0d3ba316690a60055d8 upstream.
obj_cgroup_charge_pages() resolves the objcg to its memcg and calls
try_charge_memcg(), which does not short circuit the root memcg. That
memcg can be the root memcg: obj_cgroup_is_root() reflects the memcg the
objcg was created for and is never updated, while memcg_reparent_objcgs()
does redirect objcg->memcg to the parent on rmdir. An objcg of a dying
child of root therefore passes every obj_cgroup_is_root() filter but
resolves to the root memcg.
Folios keep the objcg they were charged with, so this is easy to reach
through zswap: allocate anon memory in a cgroup, move the task out, remove
the cgroup, then write to the root cgroup's memory.reclaim. The reclaimed
folios are charged through the reparented objcg and end up in
refill_stock() with the root memcg:
WARNING: mm/memcontrol.c:2198 at refill_stock+0x644/0x940
refill_stock+0x644/0x940
try_charge_memcg+0x12d6/0x1570
__obj_cgroup_charge+0x35/0xf0
obj_cgroup_charge+0x1de/0x210
obj_cgroup_charge_zswap+0x83/0x270
zswap_store+0x1620/0x2000
swap_writeout+0x94c/0x14c0
shrink_folio_list+0x3388/0x52b0
[...]
try_to_free_mem_cgroup_pages+0x30d/0x830
user_proactive_reclaim+0x504/0x840
memory_reclaim+0x1f/0x30
Beyond the warning, the charge is asymmetric: obj_cgroup_uncharge_pages()
skips refill_stock() for the root memcg, so the root's page counter grows
and is never uncharged. It is not user visible, since memory.current is
not exposed on the root, but it is a leak.
Use try_charge(), which returns early for the root memcg, restoring the
symmetry with obj_cgroup_uncharge_pages().
The above sequence was scripted into a standalone reproducer (zswap on,
swap on a virtio disk, 512MB of anon memory faulted in inside a child of
the root cgroup, the task then migrated to the root cgroup, the child
removed, followed by "echo 600M swappiness=max > memory.reclaim" on the
root) and run in a CONFIG_DEBUG_VM=y VM. It reproduces the splat on the
first zswap store of a reparented folio, with the same call chain as the
report. With this patch applied the splat is gone while the zswap store
count over the run is unchanged, so the same path is still exercised.
cgroup selftests test_zswap, test_kmem and test_memcontrol show no new
failures.
Link: https://lore.kernel.org/20260829023251.474083-1-shakeel.butt@linux.dev
Fixes: 20d6c1725228 ("memcg: avoid refill_stock for root memcg")
Signed-off-by: Shakeel Butt <shakeel.butt@linux.dev>
Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Closes: https://lore.kernel.org/all/CA+0ovCgWzUMK+nNbbtH7eV65Ca=fDN4Ozu7iASgryjvv8Tk8zQ@mail.gmail.com/
Reviewed-by: Muchun Song <muchun.song@linux.dev>
Reviewed-by: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/memcontrol.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/memcontrol.c
+++ b/mm/memcontrol.c
@@ -3107,7 +3107,7 @@ static int obj_cgroup_charge_pages(struc
memcg = get_mem_cgroup_from_objcg(objcg);
- ret = try_charge_memcg(memcg, gfp, nr_pages);
+ ret = try_charge(memcg, gfp, nr_pages);
if (ret)
goto out;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 258/398] memstick: ms_block: destroy io_queue workqueue on removal
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (255 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 257/398] memcg: avoid charging the root memcg from obj_cgroup_charge_pages() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 259/398] mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count Greg Kroah-Hartman
` (145 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yifei Gao, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yifei Gao <gyf161023@gmail.com>
commit 90af7fde083e1b22c349c3a8b1626728e44e474c upstream.
msb_init_disk() creates the per-card ordered workqueue msb->io_queue with
alloc_ordered_workqueue(). It is torn down with destroy_workqueue() only
on the init error path; msb_remove() never destroys it. msb_stop() merely
flushes the queue, and neither msb_data_clear() nor put_disk() free it. As
a result every card insert/remove cycle leaks the workqueue and its
kworker, exhausting kernel memory over repeated cycles.
Destroy the workqueue in msb_remove() after the disk has been removed and
the queue drained.
Fixes: 0ab30494bc4f ("memstick: add support for legacy memorysticks")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Yifei Gao <gyf161023@gmail.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/memstick/core/ms_block.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/memstick/core/ms_block.c
+++ b/drivers/memstick/core/ms_block.c
@@ -2205,6 +2205,8 @@ static void msb_remove(struct memstick_d
msb_data_clear(msb);
mutex_unlock(&msb_disk_lock);
+ destroy_workqueue(msb->io_queue);
+
put_disk(msb->disk);
memstick_set_drvdata(card, NULL);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 312/438] memstick: ms_block: destroy io_queue workqueue on removal
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (310 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 311/438] memcg: avoid charging the root memcg from obj_cgroup_charge_pages() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 313/438] mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count Greg Kroah-Hartman
` (137 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yifei Gao, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yifei Gao <gyf161023@gmail.com>
commit 90af7fde083e1b22c349c3a8b1626728e44e474c upstream.
msb_init_disk() creates the per-card ordered workqueue msb->io_queue with
alloc_ordered_workqueue(). It is torn down with destroy_workqueue() only
on the init error path; msb_remove() never destroys it. msb_stop() merely
flushes the queue, and neither msb_data_clear() nor put_disk() free it. As
a result every card insert/remove cycle leaks the workqueue and its
kworker, exhausting kernel memory over repeated cycles.
Destroy the workqueue in msb_remove() after the disk has been removed and
the queue drained.
Fixes: 0ab30494bc4f ("memstick: add support for legacy memorysticks")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Yifei Gao <gyf161023@gmail.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/memstick/core/ms_block.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/memstick/core/ms_block.c
+++ b/drivers/memstick/core/ms_block.c
@@ -2204,6 +2204,8 @@ static void msb_remove(struct memstick_d
msb_data_clear(msb);
mutex_unlock(&msb_disk_lock);
+ destroy_workqueue(msb->io_queue);
+
put_disk(msb->disk);
memstick_set_drvdata(card, NULL);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 259/398] mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (256 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 258/398] memstick: ms_block: destroy io_queue workqueue on removal Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 260/398] mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio() Greg Kroah-Hartman
` (144 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nhat Pham, Sashiko, Andrew Morton,
Kairui Song, Baoquan He, Barry Song, Chris Li, Gregory Price,
Johannes Weiner, Joshua Hahn, Kemeng Shi, Shakeel Butt,
Youngjun Park
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nhat Pham <nphamcs@gmail.com>
commit 12e9ac7bc5b254048f886bf421e3a15491106c1f upstream.
SWAP_USAGE_OFFLIST_BIT is embedded in the si->inuse_pages usage counter,
and is meant to sit above any value that counter can reach. However, it
is defined from BITS_PER_TYPE(atomic_t), so it is bit 30. On a system
with 4 KiB pages the flag collides with the usage count once that count
reaches 4 TiB.
swap_usage_in_pages() masks bit 30 out, so whenever the real count has
that bit set, every caller of it reads 4 TiB low:
* /proc/swaps understates Used by 4 TiB.
* A raw count of exactly 2^30 masks to zero, so try_to_unuse() takes its
"if (!swap_usage_in_pages(si)) goto success;" early exit and swapoff
tears the device down while pages are still swapped out. Nothing in
the rest of swapoff aborts the teardown, so those pages are lost.
Independently of swapoff, the collision also corrupts the counter and the
plist. On a device in normal use, a free that leaves bit 30 set in the
count makes swap_usage_sub() see the flag where there is only count, and
call add_to_avail_list(). It clears the bit with
fetch_and(~SWAP_USAGE_OFFLIST_BIT), leaving the stored count 4 TiB below
the real one, and calls plist_add() on a device that is already listed,
tripping the WARN_ON(!plist_node_empty(node)) in plist_add() and linking
the node a second time.
Change the definition of SWAP_USAGE_OFFLIST_BIT to be based on
atomic_long_t instead. Note that the usage counter field itself is of
this same type, so it is still a valid bit.
Link: https://lore.kernel.org/20260828191433.3304458-1-nphamcs@gmail.com
Fixes: b228386cf237 ("mm, swap: clean up plist removal and adding")
Signed-off-by: Nhat Pham <nphamcs@gmail.com>
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260825153238.2695446-1-nphamcs%40gmail.com
Suggested-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Acked-by: Kairui Song <kasong@tencent.com>
Cc: Baoquan He <baoquan.he@linux.dev>
Cc: Barry Song <baohua@kernel.org>
Cc: Chris Li <chrisl@kernel.org>
Cc: Gregory Price <gourry@gourry.net>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Joshua Hahn <joshua.hahnjy@gmail.com>
Cc: Kemeng Shi <shikemeng@huaweicloud.com>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: Youngjun Park <youngjun.park@lge.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/swapfile.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/swapfile.c
+++ b/mm/swapfile.c
@@ -162,7 +162,7 @@ static inline unsigned char swap_count(u
* This bit will be set if the device is not on the plist and not
* usable, will be cleared if the device is on the plist.
*/
-#define SWAP_USAGE_OFFLIST_BIT (1UL << (BITS_PER_TYPE(atomic_t) - 2))
+#define SWAP_USAGE_OFFLIST_BIT (1UL << (BITS_PER_TYPE(atomic_long_t) - 2))
#define SWAP_USAGE_COUNTER_MASK (~SWAP_USAGE_OFFLIST_BIT)
static long swap_usage_in_pages(struct swap_info_struct *si)
{
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 313/438] mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (311 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 312/438] memstick: ms_block: destroy io_queue workqueue on removal Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 314/438] mm/huge_memory: bypass THP tuneables for huge pfnmap mappings Greg Kroah-Hartman
` (136 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nhat Pham, Sashiko, Andrew Morton,
Kairui Song, Baoquan He, Barry Song, Chris Li, Gregory Price,
Johannes Weiner, Joshua Hahn, Kemeng Shi, Shakeel Butt,
Youngjun Park
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nhat Pham <nphamcs@gmail.com>
commit 12e9ac7bc5b254048f886bf421e3a15491106c1f upstream.
SWAP_USAGE_OFFLIST_BIT is embedded in the si->inuse_pages usage counter,
and is meant to sit above any value that counter can reach. However, it
is defined from BITS_PER_TYPE(atomic_t), so it is bit 30. On a system
with 4 KiB pages the flag collides with the usage count once that count
reaches 4 TiB.
swap_usage_in_pages() masks bit 30 out, so whenever the real count has
that bit set, every caller of it reads 4 TiB low:
* /proc/swaps understates Used by 4 TiB.
* A raw count of exactly 2^30 masks to zero, so try_to_unuse() takes its
"if (!swap_usage_in_pages(si)) goto success;" early exit and swapoff
tears the device down while pages are still swapped out. Nothing in
the rest of swapoff aborts the teardown, so those pages are lost.
Independently of swapoff, the collision also corrupts the counter and the
plist. On a device in normal use, a free that leaves bit 30 set in the
count makes swap_usage_sub() see the flag where there is only count, and
call add_to_avail_list(). It clears the bit with
fetch_and(~SWAP_USAGE_OFFLIST_BIT), leaving the stored count 4 TiB below
the real one, and calls plist_add() on a device that is already listed,
tripping the WARN_ON(!plist_node_empty(node)) in plist_add() and linking
the node a second time.
Change the definition of SWAP_USAGE_OFFLIST_BIT to be based on
atomic_long_t instead. Note that the usage counter field itself is of
this same type, so it is still a valid bit.
Link: https://lore.kernel.org/20260828191433.3304458-1-nphamcs@gmail.com
Fixes: b228386cf237 ("mm, swap: clean up plist removal and adding")
Signed-off-by: Nhat Pham <nphamcs@gmail.com>
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260825153238.2695446-1-nphamcs%40gmail.com
Suggested-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Acked-by: Kairui Song <kasong@tencent.com>
Cc: Baoquan He <baoquan.he@linux.dev>
Cc: Barry Song <baohua@kernel.org>
Cc: Chris Li <chrisl@kernel.org>
Cc: Gregory Price <gourry@gourry.net>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Joshua Hahn <joshua.hahnjy@gmail.com>
Cc: Kemeng Shi <shikemeng@huaweicloud.com>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: Youngjun Park <youngjun.park@lge.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/swapfile.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/swapfile.c
+++ b/mm/swapfile.c
@@ -156,7 +156,7 @@ static struct swap_info_struct *swap_ent
* This bit will be set if the device is not on the plist and not
* usable, will be cleared if the device is on the plist.
*/
-#define SWAP_USAGE_OFFLIST_BIT (1UL << (BITS_PER_TYPE(atomic_t) - 2))
+#define SWAP_USAGE_OFFLIST_BIT (1UL << (BITS_PER_TYPE(atomic_long_t) - 2))
#define SWAP_USAGE_COUNTER_MASK (~SWAP_USAGE_OFFLIST_BIT)
static long swap_usage_in_pages(struct swap_info_struct *si)
{
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 260/398] mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (257 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 259/398] mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 262/398] mm: filemap: retain mapped dropbehind folios Greg Kroah-Hartman
` (143 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shakeel Butt,
syzbot+cd2073ee6d958a8d0fcd, Hugh Dickins, Jann Horn,
Liam R. Howlett, Lorenzo Stoakes, Matthew Wilcox (Oracle),
Pedro Falcato, Vlastimil Babka, Andrew Morton
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shakeel Butt <shakeel.butt@linux.dev>
commit e14a3454806468b086fe2e4ca2e1bff95b528531 upstream.
NR_MLOCK is updated from interrupt context. __free_pages_prepare() clears
a stray PG_mlocked and adjusts NR_MLOCK, and a folio can reach it with the
flag still set from a bio completion handler:
__free_pages_ok+0x6af/0x7a0
<IRQ>
__bio_release_pages+0xde/0x260
__iomap_dio_bio_end_io+0x16e/0x1a0
blk_update_request+0x14b/0x3d0
blk_mq_end_request+0x18/0x30
blk_done_softirq+0x49/0x60
The folio gets there like this. A MAP_SHARED file mapping is mlocked, so
its page cache folios carry PG_mlocked, and an O_DIRECT write sourced from
that mapping GUP-pins those same folios. munlock() then runs
mlock_vma_pages_range(), which clears VM_LOCKED before walking the page
tables to munlock each folio. A concurrent hole punch reaches the folio
through the rmap (i_mmap_rwsem, not mmap_lock) and can land inside that
window: __folio_remove_rmap() -> munlock_vma_folio() sees VM_LOCKED
already clear, so it neither queues the folio on the mlock batch nor takes
a reference, and the pte it clears makes the pending mlock_pte_range()
walk skip the folio at its !pte_present() check. filemap_remove_folio()
then drops the page cache reference, leaving the bio's pin as the last
one, released from the completion handler above.
So __zone_stat_mod_folio() here needs interrupts disabled, not merely
preemption, and __munlock_folio() has a path where they are not: when the
folio has already been taken off the LRU by somebody else the function
jumps straight to the counter update without taking the lruvec lock. The
read-modify-write of the per-CPU NR_MLOCK diff can then be interrupted by
the softirq above, and one of the two decrements is lost, leaving Mlocked
in /proc/meminfo permanently overstated.
Use zone_stat_mod_folio(). mod_zone_state()'s this_cpu_try_cmpxchg() is
atomic against a same-CPU interrupt and retries, and on the path where the
lruvec lock is held its cost is negligible next to the lock itself.
The UNEVICTABLE_PG* events are deliberately left on the __ accessors: they
occupy different vm_event_states slots from the UNEVICTABLE_PGCLEARED that
__free_pages_prepare() bumps, and nothing updates those two from interrupt
context.
Link: https://lore.kernel.org/20260901180109.3797944-1-shakeel.butt@linux.dev
Fixes: 2fbb0c10d1e8 ("mm/munlock: mlock_page() munlock_page() batch by pagevec")
Signed-off-by: Shakeel Butt <shakeel.butt@linux.dev>
Reported-by: syzbot+cd2073ee6d958a8d0fcd@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/linux-mm/6a931c5a.08e933ee.dbf97.0093.GAE@google.com/
Acked-by: Hugh Dickins <hughd@google.com>
Cc: Jann Horn <jannh@google.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
Cc: Pedro Falcato <pfalcato@suse.de>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/mlock.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/mlock.c
+++ b/mm/mlock.c
@@ -141,7 +141,7 @@ static struct lruvec *__munlock_folio(st
munlock:
if (folio_test_clear_mlocked(folio)) {
- __zone_stat_mod_folio(folio, NR_MLOCK, -nr_pages);
+ zone_stat_mod_folio(folio, NR_MLOCK, -nr_pages);
if (isolated || !folio_test_unevictable(folio))
__count_vm_events(UNEVICTABLE_PGMUNLOCKED, nr_pages);
else
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 314/438] mm/huge_memory: bypass THP tuneables for huge pfnmap mappings
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (312 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 313/438] mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 315/438] mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio() Greg Kroah-Hartman
` (135 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM), Zi Yan,
Cedric Le Goater, Saravanan D, Lance Yang, SJ Park, Baolin Wang,
Barry Song, David Hildenbrand, Dev Jain, Jason Gunthorpe,
Liam R. Howlett, Peter Xu, Ryan Roberts, Andrew Morton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Stoakes (ARM) <ljs@kernel.org>
commit e384abeb559d10d6505aec053ede9368d81d4c71 upstream.
The sysfs THP tuneables at /sys/kernel/mm/transparent_huge_pages/ rather
confusingly only control the behaviour of THP in some instances.
They are not applicable to MADV_COLLAPSE operations, nor to DAX mappings.
Long-term, THP is predicated upon compaction being able to obtain large
folios to populate THP ranges.
However, vm_normal_folio() returns NULL for PFN map mappings, thus their
reference count is maintained by the driver, not core mm.
As a consequence, the folios are not subject to reclaim nor compaction, so
are not truly part of the THP mechanism at all.
However, since commit 5dd40721f147 ("mm: allow THP orders for PFNMAPs")
introduced the ability to establish huge PFN maps, they have been subject
to THP tuneables.
This is incorrect - if a huge PFN map is available (defined by
vma->vm_ops->huge_fault being non-NULL for a VMA_PFNMAP_BIT VMA), then it
should be mapped huge upon fault-in.
Correct this by explicitly checking for this while ensuring that smaps
continues to accurately report THPeligible statistics.
While here, abstract the entire file-backed THP check in
vma_can_map_huge_file(), with sensible separation of logic into helper
functions.
Note that drm_gem_shmem_mmap() and panthor_gem_mmap() establish huge PFN
maps of shmem folios, however they are marked unevictable in
drm_gem_get_pages(), and in any case would fail the reference check in
__remove_mapping() even if they weren't.
Failing to map huge PFN maps has resulted in significant real-world
performance degradation, see links for details.
[ziy@nvidia.com: rename some functions]
Link: https://lore.kernel.org/DL1HIHWYJ7TB.1CY76SJS0V03L@nvidia.com
Link: https://lore.kernel.org/20260827-hugepfn-allowable-orders-v1-1-94819c8807c8@kernel.org
Fixes: 5dd40721f147 ("mm: allow THP orders for PFNMAPs")
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Signed-off-by: Zi Yan <ziy@nvidia.com>
Reported-by: Cedric Le Goater <clg@redhat.com>
Closes: https://lore.kernel.org/linux-mm/20260805055544.1568534-1-clg@redhat.com/
Reported-by: Saravanan D <saravanand@crusoe.ai>
Closes: https://lore.kernel.org/linux-mm/20260821070520.25759-1-saravanand@crusoe.ai/
Reviewed-by: Zi Yan <ziy@nvidia.com>
Tested-by: Saravanan D <saravanand@crusoe.ai>
Tested-by: Lance Yang <lance.yang@linux.dev>
Reviewed-by: SJ Park <sj@kernel.org>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Barry Song <baohua@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Jason Gunthorpe <jgg@ziepe.ca>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Peter Xu <peterx@redhat.com>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/huge_memory.c | 86 ++++++++++++++++++++++++++++++++++++++++---------------
1 file changed, 64 insertions(+), 22 deletions(-)
--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -92,7 +92,7 @@ unsigned long huge_anon_orders_madvise _
unsigned long huge_anon_orders_inherit __read_mostly;
static bool anon_orders_configured __initdata;
-static inline bool file_thp_enabled(struct vm_area_struct *vma)
+static inline bool file_thp_enabled(const struct vm_area_struct *vma)
{
struct inode *inode;
@@ -118,6 +118,67 @@ static bool vma_is_special_huge(const st
return vma_test_any(vma, VMA_PFNMAP_BIT, VMA_MIXEDMAP_BIT);
}
+static bool vma_file_bypass_thp_tuneables(const struct vm_area_struct *vma,
+ enum tva_type type)
+{
+ const bool has_huge_fault = vma->vm_ops->huge_fault;
+
+ /* MADV_COLLAPSE ignores tuneables. */
+ if (type == TVA_FORCED_COLLAPSE)
+ return true;
+ /* Huge PFN mappings are uncompactable so the policy doesn't apply. */
+ if (vma_test(vma, VMA_PFNMAP_BIT) && has_huge_fault)
+ return true;
+ return false;
+}
+
+static bool vma_file_allow_thp_tuneables(vm_flags_t vm_flags)
+{
+ /* THP=always? */
+ if (hugepage_global_always())
+ return true;
+ /* THP=madvise and marked MADV_HUGEPAGE? */
+ if (hugepage_global_enabled() && (vm_flags & VM_HUGEPAGE))
+ return true;
+ return false;
+}
+
+static bool vma_file_check_thp_tuneables(const struct vm_area_struct *vma,
+ vm_flags_t vm_flags, enum tva_type type)
+{
+ return vma_file_bypass_thp_tuneables(vma, type) ||
+ vma_file_allow_thp_tuneables(vm_flags);
+}
+
+static bool vma_can_map_huge_file(const struct vm_area_struct *vma,
+ vm_flags_t vm_flags, enum tva_type type)
+{
+ const bool has_huge_fault = vma->vm_ops->huge_fault;
+
+ /*
+ * Enforce THP collapse requirements as necessary. Anonymous vmas
+ * were already handled in thp_vma_allowable_orders().
+ */
+ if (!vma_file_check_thp_tuneables(vma, vm_flags, type))
+ return false;
+
+ switch (type) {
+ case TVA_PAGEFAULT:
+ /*
+ * Trust that ->huge_fault() handlers know what they are doing
+ * in fault path.
+ */
+ return has_huge_fault;
+ case TVA_SMAPS:
+ if (has_huge_fault)
+ return true;
+ fallthrough;
+ default:
+ /* Only regular file is valid in collapse path. */
+ return file_thp_enabled(vma);
+ }
+}
+
unsigned long __thp_vma_allowable_orders(struct vm_area_struct *vma,
vm_flags_t vm_flags,
enum tva_type type,
@@ -190,27 +251,8 @@ unsigned long __thp_vma_allowable_orders
vma, vma->vm_pgoff, 0,
forced_collapse);
- if (!vma_is_anonymous(vma)) {
- /*
- * Enforce THP collapse requirements as necessary. Anonymous vmas
- * were already handled in thp_vma_allowable_orders().
- */
- if (!forced_collapse &&
- (!hugepage_global_enabled() || (!(vm_flags & VM_HUGEPAGE) &&
- !hugepage_global_always())))
- return 0;
-
- /*
- * Trust that ->huge_fault() handlers know what they are doing
- * in fault path.
- */
- if (((in_pf || smaps)) && vma->vm_ops->huge_fault)
- return orders;
- /* Only regular file is valid in collapse path */
- if (((!in_pf || smaps)) && file_thp_enabled(vma))
- return orders;
- return 0;
- }
+ if (!vma_is_anonymous(vma))
+ return vma_can_map_huge_file(vma, vm_flags, type) ? orders : 0;
if (vma_is_temporary_stack(vma))
return 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 261/398] mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP
2026-09-23 14:03 ` [PATCH 7.2 209/438] net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
0 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM), sashiko-bot,
Kunwu Chan, Vlastimil Babka (SUSE), Jann Horn, Liam R. Howlett,
Pedro Falcato, Andrew Morton
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Stoakes (ARM) <ljs@kernel.org>
commit 397432cab17bccb600fd6c16ed593f1149042268 upstream.
When a VMA is mremap()'d with MREMAP_DONTUNMAP set, that results in the
VMA being copied, but the source VMA not being unmapped.
If the VMA is mlock()'d this is a legal operation, though the source VMA
has its VMA_LOCKED_BIT cleared.
However this is done in dontunmap_complete(), after mm->locked_vm was
incremented via vrm_stat_account(), resulting in double-counting.
Worse, this is not even corrected when source VMA is unmapped, due to the
VMA_LOCKED_BIT flag having been cleared.
This all works fine in the usual mremap() case (without MREMAP_DONTUNMAP),
as the source VMA is unmapped with VMA_LOCKED_BIT intact, at which time
mm->locked_vm is decremented accordingly.
Resolve the issue by invoking vrm_stat_account() only after
dontunmap_complete() has run.
Note that MREMAP_DONTUNMAP requires old_len == new_len, so no need to
account for a delta in size in this case.
The bug was introduced by commit b714ccb02a76 ("mm/mremap: complete
refactor of move_vma()") which incorrectly reordered the accounting and
the clearing of the VMA_LOCKED_BIT flag.
Link: https://lore.kernel.org/20260828-mremap-fix-locked-vm-v1-1-c80be7505d1e@kernel.org
Fixes: b714ccb02a76 ("mm/mremap: complete refactor of move_vma()")
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260825-fix-mremap-dontunmap-pgoff-v1-1-39a40b2c98b3@kernel.org
Reported-by: Kunwu Chan <kunwu.chan@gmail.com>
Closes: https://lore.kernel.org/all/20260828094823.594279-1-kunwu.chan@linux.dev/
Acked-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Tested-by: Kunwu Chan <kunwu.chan@gmail.com>
Reviewed-by: Kunwu Chan <kunwu.chan@gmail.com>
Cc: Jann Horn <jannh@google.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Pedro Falcato <pfalcato@suse.de>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/mremap.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
--- a/mm/mremap.c
+++ b/mm/mremap.c
@@ -1270,12 +1270,11 @@ static void dontunmap_complete(struct vm
if (vma_is_anonymous(vma) && !vma->vm_file)
vma->vm_pgoff = pgoff_unfaulted;
}
-
- /* Because we won't unmap we don't need to touch locked_vm. */
}
static unsigned long move_vma(struct vma_remap_struct *vrm)
{
+ const bool is_dontunmap = vrm->flags & MREMAP_DONTUNMAP;
struct mm_struct *mm = current->mm;
struct vm_area_struct *new_vma;
unsigned long hiwater_vm;
@@ -1316,10 +1315,10 @@ static unsigned long move_vma(struct vma
*/
hiwater_vm = mm->hiwater_vm;
- vrm_stat_account(vrm, vrm->new_len);
- if (unlikely(!err && (vrm->flags & MREMAP_DONTUNMAP)))
+ if (unlikely(is_dontunmap && !err))
dontunmap_complete(vrm, new_vma);
- else
+ vrm_stat_account(vrm, vrm->new_len);
+ if (!is_dontunmap || err)
unmap_source_vma(vrm);
mm->hiwater_vm = hiwater_vm;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 315/438] mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (313 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 314/438] mm/huge_memory: bypass THP tuneables for huge pfnmap mappings Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 316/438] mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP Greg Kroah-Hartman
` (134 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shakeel Butt,
syzbot+cd2073ee6d958a8d0fcd, Hugh Dickins, Jann Horn,
Liam R. Howlett, Lorenzo Stoakes, Matthew Wilcox (Oracle),
Pedro Falcato, Vlastimil Babka, Andrew Morton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shakeel Butt <shakeel.butt@linux.dev>
commit e14a3454806468b086fe2e4ca2e1bff95b528531 upstream.
NR_MLOCK is updated from interrupt context. __free_pages_prepare() clears
a stray PG_mlocked and adjusts NR_MLOCK, and a folio can reach it with the
flag still set from a bio completion handler:
__free_pages_ok+0x6af/0x7a0
<IRQ>
__bio_release_pages+0xde/0x260
__iomap_dio_bio_end_io+0x16e/0x1a0
blk_update_request+0x14b/0x3d0
blk_mq_end_request+0x18/0x30
blk_done_softirq+0x49/0x60
The folio gets there like this. A MAP_SHARED file mapping is mlocked, so
its page cache folios carry PG_mlocked, and an O_DIRECT write sourced from
that mapping GUP-pins those same folios. munlock() then runs
mlock_vma_pages_range(), which clears VM_LOCKED before walking the page
tables to munlock each folio. A concurrent hole punch reaches the folio
through the rmap (i_mmap_rwsem, not mmap_lock) and can land inside that
window: __folio_remove_rmap() -> munlock_vma_folio() sees VM_LOCKED
already clear, so it neither queues the folio on the mlock batch nor takes
a reference, and the pte it clears makes the pending mlock_pte_range()
walk skip the folio at its !pte_present() check. filemap_remove_folio()
then drops the page cache reference, leaving the bio's pin as the last
one, released from the completion handler above.
So __zone_stat_mod_folio() here needs interrupts disabled, not merely
preemption, and __munlock_folio() has a path where they are not: when the
folio has already been taken off the LRU by somebody else the function
jumps straight to the counter update without taking the lruvec lock. The
read-modify-write of the per-CPU NR_MLOCK diff can then be interrupted by
the softirq above, and one of the two decrements is lost, leaving Mlocked
in /proc/meminfo permanently overstated.
Use zone_stat_mod_folio(). mod_zone_state()'s this_cpu_try_cmpxchg() is
atomic against a same-CPU interrupt and retries, and on the path where the
lruvec lock is held its cost is negligible next to the lock itself.
The UNEVICTABLE_PG* events are deliberately left on the __ accessors: they
occupy different vm_event_states slots from the UNEVICTABLE_PGCLEARED that
__free_pages_prepare() bumps, and nothing updates those two from interrupt
context.
Link: https://lore.kernel.org/20260901180109.3797944-1-shakeel.butt@linux.dev
Fixes: 2fbb0c10d1e8 ("mm/munlock: mlock_page() munlock_page() batch by pagevec")
Signed-off-by: Shakeel Butt <shakeel.butt@linux.dev>
Reported-by: syzbot+cd2073ee6d958a8d0fcd@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/linux-mm/6a931c5a.08e933ee.dbf97.0093.GAE@google.com/
Acked-by: Hugh Dickins <hughd@google.com>
Cc: Jann Horn <jannh@google.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Matthew Wilcox (Oracle) <willy@infradead.org>
Cc: Pedro Falcato <pfalcato@suse.de>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/mlock.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/mlock.c
+++ b/mm/mlock.c
@@ -141,7 +141,7 @@ static struct lruvec *__munlock_folio(st
munlock:
if (folio_test_clear_mlocked(folio)) {
- __zone_stat_mod_folio(folio, NR_MLOCK, -nr_pages);
+ zone_stat_mod_folio(folio, NR_MLOCK, -nr_pages);
if (isolated || !folio_test_unevictable(folio))
__count_vm_events(UNEVICTABLE_PGMUNLOCKED, nr_pages);
else
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 262/398] mm: filemap: retain mapped dropbehind folios
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (258 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 260/398] mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 263/398] KEYS: encrypted: fix integer overflow of datablob_len Greg Kroah-Hartman
` (142 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wenjie Qi, Matthew Wilcox (Oracle),
Tal Zussman, Barry Song, Jan Kara, Jens Axboe, Trond Myklebust,
Andrew Morton
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wenjie Qi <qiwenjie@xiaomi.com>
commit 848d2ce2fce15fbdc083fbf9691bfa72911033c4 upstream.
Fault-around can map ready dropbehind folios without going through the
normal page-cache lookup that clears dropbehind. A mapping represents a
competing cached user, so retain the folio instead of forcibly unmapping
it when writeback completes.
For a mapped folio, folio_unmap_invalidate() can call
unmap_mapping_folio(), which takes i_mmap_rwsem and may sleep. Retaining
mapped folios avoids this path when folio_end_dropbehind() runs in
non-preemptible task context.
Tal was able to trigger a sleeping-in-atomic warning due to this [1].
Unmapped dropbehind folios continue through the existing invalidation path.
Link: https://lore.kernel.org/4aba05e1a2c3b61cb337d373eb9b7a8db4ddd822.1788024049.git.qiwenjie@xiaomi.com
Link: https://lore.kernel.org/076bb01b-6fcf-4691-be8c-0e8507c9fe64@columbia.edu [1]
Fixes: fb7d3bc41493 ("mm/filemap: drop streaming/uncached pages when writeback completes")
Signed-off-by: Wenjie Qi <qiwenjie@xiaomi.com>
Reviewed-by: Matthew Wilcox (Oracle) <willy@infradead.org>
Reviewed-by: Tal Zussman <tz2294@columbia.edu>
Tested-by: Tal Zussman <tz2294@columbia.edu>
Cc: Barry Song <baohua@kernel.org>
Cc: Jan Kara <jack@suse.cz>
Cc: Jens Axboe <axboe@kernel.dk>
Cc: Trond Myklebust <trond.myklebust@hammerspace.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/filemap.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/filemap.c
+++ b/mm/filemap.c
@@ -1624,7 +1624,7 @@ static void filemap_end_dropbehind(struc
return;
if (!folio_test_clear_dropbehind(folio))
return;
- if (mapping)
+ if (mapping && !folio_mapped(folio))
folio_unmap_invalidate(mapping, folio, 0);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 316/438] mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (314 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 315/438] mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 317/438] mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem Greg Kroah-Hartman
` (133 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM), sashiko-bot,
Kunwu Chan, Vlastimil Babka (SUSE), Jann Horn, Liam R. Howlett,
Pedro Falcato, Andrew Morton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Stoakes (ARM) <ljs@kernel.org>
commit 397432cab17bccb600fd6c16ed593f1149042268 upstream.
When a VMA is mremap()'d with MREMAP_DONTUNMAP set, that results in the
VMA being copied, but the source VMA not being unmapped.
If the VMA is mlock()'d this is a legal operation, though the source VMA
has its VMA_LOCKED_BIT cleared.
However this is done in dontunmap_complete(), after mm->locked_vm was
incremented via vrm_stat_account(), resulting in double-counting.
Worse, this is not even corrected when source VMA is unmapped, due to the
VMA_LOCKED_BIT flag having been cleared.
This all works fine in the usual mremap() case (without MREMAP_DONTUNMAP),
as the source VMA is unmapped with VMA_LOCKED_BIT intact, at which time
mm->locked_vm is decremented accordingly.
Resolve the issue by invoking vrm_stat_account() only after
dontunmap_complete() has run.
Note that MREMAP_DONTUNMAP requires old_len == new_len, so no need to
account for a delta in size in this case.
The bug was introduced by commit b714ccb02a76 ("mm/mremap: complete
refactor of move_vma()") which incorrectly reordered the accounting and
the clearing of the VMA_LOCKED_BIT flag.
Link: https://lore.kernel.org/20260828-mremap-fix-locked-vm-v1-1-c80be7505d1e@kernel.org
Fixes: b714ccb02a76 ("mm/mremap: complete refactor of move_vma()")
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260825-fix-mremap-dontunmap-pgoff-v1-1-39a40b2c98b3@kernel.org
Reported-by: Kunwu Chan <kunwu.chan@gmail.com>
Closes: https://lore.kernel.org/all/20260828094823.594279-1-kunwu.chan@linux.dev/
Acked-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Tested-by: Kunwu Chan <kunwu.chan@gmail.com>
Reviewed-by: Kunwu Chan <kunwu.chan@gmail.com>
Cc: Jann Horn <jannh@google.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Pedro Falcato <pfalcato@suse.de>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/mremap.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
--- a/mm/mremap.c
+++ b/mm/mremap.c
@@ -1344,12 +1344,11 @@ static void dontunmap_complete(struct vm
if (vma_is_anonymous(vma) && !vma->vm_file)
vma->vm_pgoff = pgoff_unfaulted;
}
-
- /* Because we won't unmap we don't need to touch locked_vm. */
}
static unsigned long move_vma(struct vma_remap_struct *vrm)
{
+ const bool is_dontunmap = vrm->flags & MREMAP_DONTUNMAP;
struct mm_struct *mm = current->mm;
struct vm_area_struct *new_vma;
unsigned long hiwater_vm;
@@ -1390,10 +1389,10 @@ static unsigned long move_vma(struct vma
*/
hiwater_vm = mm->hiwater_vm;
- vrm_stat_account(vrm, vrm->new_len);
- if (unlikely(!err && (vrm->flags & MREMAP_DONTUNMAP)))
+ if (unlikely(is_dontunmap && !err))
dontunmap_complete(vrm, new_vma);
- else
+ vrm_stat_account(vrm, vrm->new_len);
+ if (!is_dontunmap || err)
unmap_source_vma(vrm);
mm->hiwater_vm = hiwater_vm;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 263/398] KEYS: encrypted: fix integer overflow of datablob_len
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (259 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 262/398] mm: filemap: retain mapped dropbehind folios Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 264/398] keys: translate request_key_auth pid for the reading procfs instance Greg Kroah-Hartman
` (141 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cen Zhang, Francis Perron,
Jarkko Sakkinen, R Nageswara Sastry
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cen Zhang <cenzhang@linux.microsoft.com>
commit 8697c431e297eb0d0ab13dda6bc172b48a34f05c upstream.
encrypted_key_alloc() stores datablob_len in a u16. It is computed from
multiple string and payload lengths. If the result exceeds U16_MAX, the
assignment truncates the allocation size. KASAN reports a 32760-byte
slab-out-of-bounds write when __ekey_init() copies the master key
description into the undersized buffer.
The total payload length stored in key->datalen is also a u16. Use
check_add_overflow() to reject values that do not fit either destination,
and use kzalloc_flex() for the flexible-array allocation.
Fixes: 7e70cb497850 ("keys: add new key-type encrypted")
Cc: stable@vger.kernel.org
Assisted-by: GitHub-Copilot:claude-opus-4.6
Signed-off-by: Cen Zhang <cenzhang@linux.microsoft.com>
Signed-off-by: Francis Perron <francis@akrites.dev>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Link: https://lore.kernel.org/r/20260909153433.83117-1-cenzhang@linux.microsoft.com
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/keys/encrypted-keys/encrypted.c | 20 ++++++++++++++------
1 file changed, 14 insertions(+), 6 deletions(-)
--- a/security/keys/encrypted-keys/encrypted.c
+++ b/security/keys/encrypted-keys/encrypted.c
@@ -18,6 +18,7 @@
#include <linux/parser.h>
#include <linux/string.h>
#include <linux/err.h>
+#include <linux/overflow.h>
#include <keys/user-type.h>
#include <keys/trusted-type.h>
#include <keys/encrypted-type.h>
@@ -578,6 +579,7 @@ static struct encrypted_key_payload *enc
{
struct encrypted_key_payload *epayload = NULL;
unsigned short datablob_len;
+ unsigned short payload_totallen;
unsigned short decrypted_datalen;
unsigned short payload_datalen;
unsigned int encrypted_datalen;
@@ -631,16 +633,22 @@ static struct encrypted_key_payload *enc
encrypted_datalen = roundup(decrypted_datalen, blksize);
- datablob_len = format_len + 1 + strlen(master_desc) + 1
- + strlen(datalen) + 1 + ivsize + 1 + encrypted_datalen;
+ if (check_add_overflow(format_len + 1 + strlen(master_desc) + 1
+ + strlen(datalen) + 1 + ivsize + 1,
+ encrypted_datalen, &datablob_len))
+ return ERR_PTR(-EINVAL);
+
+ if (check_add_overflow(datablob_len,
+ payload_datalen + HASH_SIZE + 1,
+ &payload_totallen))
+ return ERR_PTR(-EINVAL);
- ret = key_payload_reserve(key, payload_datalen + datablob_len
- + HASH_SIZE + 1);
+ ret = key_payload_reserve(key, payload_totallen);
if (ret < 0)
return ERR_PTR(ret);
- epayload = kzalloc(sizeof(*epayload) + payload_datalen +
- datablob_len + HASH_SIZE + 1, GFP_KERNEL);
+ epayload = kzalloc_flex(*epayload, payload_data, payload_totallen,
+ GFP_KERNEL);
if (!epayload)
return ERR_PTR(-ENOMEM);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 317/438] mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (315 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 316/438] mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 318/438] mm/vma: correctly unaccount on mmap_prepare() failure Greg Kroah-Hartman
` (132 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiayuan Chen, Shakeel Butt,
Usama Arif, Dave Chinner, Johannes Weiner, Kairui Song,
Muchun Song, Roman Gushchin, Andrew Morton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiayuan Chen <jiayuan.chen@linux.dev>
commit 932cfb25e7ce98d1f93895671ec186a3087e4f80 upstream.
With cgroup.memory=nokmem, shrinker_memcg_alloc() bails out early and
never allocates an id, so shrinker->id keeps the 0 it got from the
kzalloc() in shrinker_alloc(). __list_lru_init() then copies that 0 into
lru->shrinker_id, where it looks like a valid bit index.
Nothing calls expand_shrinker_info() on nokmem either, so shrinker_nr_max
stays 0 and every memcg ends up with an empty map (map_nr_max == 0).
deferred_split_folio() hands a real memcg to __list_lru_add() regardless
of whether the lru is memcg aware, so the first THP queued in a cgroup
does set_shrinker_bit(memcg, nid, 0) and trips the bounds check:
WARNING: mm/shrinker.c:212 at set_shrinker_bit+0x7d/0x90, CPU#126
Call Trace:
<TASK>
deferred_split_folio+0x18c/0x220
map_anon_folio_pmd_nopf+0xdd/0x130
map_anon_folio_pmd_pf+0x14/0xb0
do_huge_pmd_anonymous_page+0x1a1/0x620
__handle_mm_fault+0xea9/0x10d0
handle_mm_fault+0xe5/0x320
do_user_addr_fault+0x1cc/0x870
exc_page_fault+0x81/0x1b0
asm_exc_page_fault+0x27/0x30
</TASK>
Harmless, the WARN_ON_ONCE() is what keeps the out of bounds unit[] read
from happening, but the id should not look valid in the first place.
Clear it before returning.
Two other spots could paper over this: drop the id in __list_lru_init()
when nokmem turns memcg_aware off, or make deferred_split_folio() pass
NULL like list_lru_add_obj() does. Both leave shrinker->id lying around
for the next caller, so fix it where the id is handed out.
Link: https://lore.kernel.org/20260902073800.305481-1-jiayuan.chen@linux.dev
Fixes: fafaeceb89a5 ("mm: switch deferred split shrinker to list_lru")
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Acked-by: Shakeel Butt <shakeel.butt@linux.dev>
Cc: Usama Arif <usama.arif@linux.dev>
Cc: Dave Chinner <david@fromorbit.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Kairui Song <kasong@tencent.com>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/shrinker.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/mm/shrinker.c b/mm/shrinker.c
index a70aab124a0e..7ec2a9704f6f 100644
--- a/mm/shrinker.c
+++ b/mm/shrinker.c
@@ -227,6 +227,8 @@ static int shrinker_memcg_alloc(struct shrinker *shrinker)
{
int id;
+ shrinker->id = -1;
+
if (mem_cgroup_disabled())
return -ENOSYS;
if (mem_cgroup_kmem_disabled() && !(shrinker->flags & SHRINKER_NONSLAB))
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 264/398] keys: translate request_key_auth pid for the reading procfs instance
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (260 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 263/398] KEYS: encrypted: fix integer overflow of datablob_len Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 265/398] KEYS: trusted: Fix tpm2_load_cmd() boundary check Greg Kroah-Hartman
` (140 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Maoyi Xie, Jarkko Sakkinen
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
commit 0d6a4268b06084baafd8ee5d66955c7e1c2e053b upstream.
request_key_auth_describe() prints rka->pid into /proc/keys as a raw
pid_t in the initial pid namespace. A reader can open /proc/keys through
a mount in another pid namespace. That reader sees a number with no
meaning there. The number can even name an unrelated task. The line
needs VIEW on the key. So the reader either shares the key owner's uid
or possesses the key.
The fix keeps a struct pid. Commit 4f82f45730c6 ("net ip6 flowlabel:
Make owner a union of struct pid * and kuid_t") gave
/proc/net/ip6_flowlabel the same storage. The print goes through
pid_nr_ns(). It renders against the pid namespace of the procfs instance
the line is read through. Commit ad08978ab41c ("ipv6/flowlabel: simplify
pid namespace lookup") moved that print to the same anchor. Output
through an initial namespace /proc does not change. The line shows 0 for
a requestor with no number in that namespace.
Translating at read time was the alternative. find_pid_ns() can resolve
a recycled number. The line would then name a live task with no
connection to the key. A stored struct pid gives 0 instead when the
requestor has no number there.
Link: https://lore.kernel.org/keyrings/20260809110202.2180410-1-maoyixie.tju@gmail.com/
Fixes: 78b7280cce23 ("KEYS: Improve /proc/keys")
Cc: stable@vger.kernel.org # v5.10+
Assisted-by: Claude:claude-opus-5 codeql
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Link: https://lore.kernel.org/r/20260821095935.1864998-1-maoyixie.tju@gmail.com
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/keys/request_key_auth-type.h | 2 +-
security/keys/request_key_auth.c | 12 +++++++++---
2 files changed, 10 insertions(+), 4 deletions(-)
--- a/include/keys/request_key_auth-type.h
+++ b/include/keys/request_key_auth-type.h
@@ -22,7 +22,7 @@ struct request_key_auth {
const struct cred *cred;
void *callout_info;
size_t callout_len;
- pid_t pid;
+ struct pid *pid;
char op[8];
} __randomize_layout;
--- a/security/keys/request_key_auth.c
+++ b/security/keys/request_key_auth.c
@@ -9,6 +9,8 @@
#include <linux/sched.h>
#include <linux/err.h>
+#include <linux/pid.h>
+#include <linux/proc_fs.h>
#include <linux/seq_file.h>
#include <linux/slab.h>
#include <linux/uaccess.h>
@@ -73,7 +75,10 @@ static void request_key_auth_describe(co
seq_puts(m, "key:");
seq_puts(m, key->description);
if (key_is_positive(key))
- seq_printf(m, " pid:%d ci:%zu", rka->pid, rka->callout_len);
+ seq_printf(m, " pid:%d ci:%zu",
+ pid_nr_ns(rka->pid,
+ proc_pid_ns(file_inode(m->file)->i_sb)),
+ rka->callout_len);
}
/*
@@ -113,6 +118,7 @@ static void free_request_key_auth(struct
if (rka->cred)
put_cred(rka->cred);
kfree(rka->callout_info);
+ put_pid(rka->pid);
kfree(rka);
}
@@ -226,14 +232,14 @@ struct key *request_key_auth_new(struct
irka = cred->request_key_auth->payload.data[0];
rka->cred = get_cred(irka->cred);
- rka->pid = irka->pid;
+ rka->pid = get_pid(irka->pid);
up_read(&cred->request_key_auth->sem);
}
else {
/* it isn't - use this process as the context */
rka->cred = get_cred(cred);
- rka->pid = current->pid;
+ rka->pid = get_pid(task_pid(current));
}
rka->target_key = key_get(target);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 318/438] mm/vma: correctly unaccount on mmap_prepare() failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (316 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 317/438] mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 319/438] mm: filemap: retain mapped dropbehind folios Greg Kroah-Hartman
` (131 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM), Jann Horn,
Liam R. Howlett, Pedro Falcato, Vlastimil Babka, Andrew Morton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Stoakes (ARM) <ljs@kernel.org>
commit 6cc27d82196385fe06853319f74312a7d8019726 upstream.
__mmap_setup() accounts memory for relevant mappings via:
security_vm_enough_memory_mm()
-> __vm_enough_memory()
-> vm_acct_memory()
If __mmap_setup() fails, this indicates that this accounting did not take
place, and thus it's appropriate for __mmap_region() to jump to
abort_munmap.
However if call_mmap_prepare() fails, it also jumps there and any accounted
memory is not correctly unaccounted.
Fix this by handling each error separately.
Link: https://lore.kernel.org/20260902-fix-unaccount-mmap_prepare-v1-1-ea070189fdfb@kernel.org
Fixes: c84bf6dd2b83 ("mm: introduce new .mmap_prepare() file callback")
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Cc: Jann Horn <jannh@google.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Pedro Falcato <pfalcato@suse.de>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/vma.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/mm/vma.c
+++ b/mm/vma.c
@@ -2754,10 +2754,12 @@ static unsigned long __mmap_region(struc
map.check_ksm_early = can_set_ksm_flags_early(&map);
error = __mmap_setup(&map, &desc, uf);
- if (!error && have_mmap_prepare)
- error = call_mmap_prepare(&map, &desc);
if (error)
goto abort_munmap;
+ if (have_mmap_prepare)
+ error = call_mmap_prepare(&map, &desc);
+ if (error)
+ goto unacct_error;
if (map.check_ksm_early)
update_ksm_flags(&map);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 265/398] KEYS: trusted: Fix tpm2_load_cmd() boundary check
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (261 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 264/398] keys: translate request_key_auth pid for the reading procfs instance Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 266/398] i2c: at91: release DMA channels on remove and probe error Greg Kroah-Hartman
` (139 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+6a581c4284f721d4,
Stefano Garzarella, Srish Srinivasan, Jarkko Sakkinen
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jarkko Sakkinen <jarkko@kernel.org>
commit 114f00d738f15dd8c7318369edcdc53dd6d08763 upstream.
tpm2_load_cmd() does boundary checks against the ASN.1 size i.e.,
payload->blob_len. Address this by passing the decoded blob size to
tpm2_load_cmd(), and use it for the boundary checks.
Cc: stable@vger.kernel.org # v5.13+
Fixes: f2219745250f ("security: keys: trusted: use ASN.1 TPM2 key format for the blobs")
Reported-by: co+6a581c4284f721d4@bugs.sh
Closes: https://bugs.sh/b/6a581c4284f721d4/
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Tested-by: Srish Srinivasan <ssrish@linux.ibm.com>
Link: https://lore.kernel.org/r/20260901205809.2028454-1-jarkko@kernel.org
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/keys/trusted-keys/trusted_tpm2.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
--- a/security/keys/trusted-keys/trusted_tpm2.c
+++ b/security/keys/trusted-keys/trusted_tpm2.c
@@ -108,7 +108,7 @@ struct tpm2_key_context {
static int tpm2_key_decode(struct trusted_key_payload *payload,
struct trusted_key_options *options,
- u8 **buf)
+ u8 **buf, unsigned int *blob_len)
{
int ret;
struct tpm2_key_context ctx;
@@ -129,6 +129,7 @@ static int tpm2_key_decode(struct truste
return -ENOMEM;
*buf = blob;
+ *blob_len = ctx.priv_len + ctx.pub_len;
options->keyhandle = ctx.parent;
memcpy(blob, ctx.priv, ctx.priv_len);
@@ -402,10 +403,11 @@ static int tpm2_load_cmd(struct tpm_chip
int rc;
u32 attrs;
- rc = tpm2_key_decode(payload, options, &blob);
+ rc = tpm2_key_decode(payload, options, &blob, &blob_len);
if (rc) {
/* old form */
blob = payload->blob;
+ blob_len = payload->blob_len;
payload->old_format = 1;
} else {
/* Bind for cleanup: */
@@ -417,17 +419,17 @@ static int tpm2_load_cmd(struct tpm_chip
return -EINVAL;
/* must be big enough for at least the two be16 size counts */
- if (payload->blob_len < 4)
+ if (blob_len < 4)
return -EINVAL;
private_len = get_unaligned_be16(blob);
/* must be big enough for following public_len */
- if (private_len + 2 + 2 > (payload->blob_len))
+ if (private_len + 2 + 2 > blob_len)
return -E2BIG;
public_len = get_unaligned_be16(blob + 2 + private_len);
- if (private_len + 2 + public_len + 2 > payload->blob_len)
+ if (private_len + 2 + public_len + 2 > blob_len)
return -E2BIG;
pub = blob + 2 + private_len + 2;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 319/438] mm: filemap: retain mapped dropbehind folios
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (317 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 318/438] mm/vma: correctly unaccount on mmap_prepare() failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 320/438] KEYS: encrypted: fix integer overflow of datablob_len Greg Kroah-Hartman
` (130 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wenjie Qi, Matthew Wilcox (Oracle),
Tal Zussman, Barry Song, Jan Kara, Jens Axboe, Trond Myklebust,
Andrew Morton
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wenjie Qi <qiwenjie@xiaomi.com>
commit 848d2ce2fce15fbdc083fbf9691bfa72911033c4 upstream.
Fault-around can map ready dropbehind folios without going through the
normal page-cache lookup that clears dropbehind. A mapping represents a
competing cached user, so retain the folio instead of forcibly unmapping
it when writeback completes.
For a mapped folio, folio_unmap_invalidate() can call
unmap_mapping_folio(), which takes i_mmap_rwsem and may sleep. Retaining
mapped folios avoids this path when folio_end_dropbehind() runs in
non-preemptible task context.
Tal was able to trigger a sleeping-in-atomic warning due to this [1].
Unmapped dropbehind folios continue through the existing invalidation path.
Link: https://lore.kernel.org/4aba05e1a2c3b61cb337d373eb9b7a8db4ddd822.1788024049.git.qiwenjie@xiaomi.com
Link: https://lore.kernel.org/076bb01b-6fcf-4691-be8c-0e8507c9fe64@columbia.edu [1]
Fixes: fb7d3bc41493 ("mm/filemap: drop streaming/uncached pages when writeback completes")
Signed-off-by: Wenjie Qi <qiwenjie@xiaomi.com>
Reviewed-by: Matthew Wilcox (Oracle) <willy@infradead.org>
Reviewed-by: Tal Zussman <tz2294@columbia.edu>
Tested-by: Tal Zussman <tz2294@columbia.edu>
Cc: Barry Song <baohua@kernel.org>
Cc: Jan Kara <jack@suse.cz>
Cc: Jens Axboe <axboe@kernel.dk>
Cc: Trond Myklebust <trond.myklebust@hammerspace.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/filemap.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/mm/filemap.c
+++ b/mm/filemap.c
@@ -1616,7 +1616,7 @@ static void filemap_end_dropbehind(struc
return;
if (!folio_test_clear_dropbehind(folio))
return;
- if (mapping)
+ if (mapping && !folio_mapped(folio))
folio_unmap_invalidate(mapping, folio, 0);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 266/398] i2c: at91: release DMA channels on remove and probe error
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (262 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 265/398] KEYS: trusted: Fix tpm2_load_cmd() boundary check Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 267/398] i2c: atr: fix dangling adapter pointer on add failure Greg Kroah-Hartman
` (138 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shengzhuo Wei, Mukesh Kumar Savaliya,
Andi Shyti
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit f7eeb1af8537b05953fb1c88ab8b59d94059a381 upstream.
at91_twi_configure_dma() requests exclusive tx/rx DMA channels, but
nothing ever releases them on driver detach, and the probe error path
after the channels are acquired (i2c_add_numbered_adapter() failure)
returns without releasing them either, because the remove callback is
not invoked after a failed probe.
Move the release into a helper, call it from the existing
configure-failure path, the adapter-registration failure path, and
at91_twi_remove().
Fixes: 60937b2cdbf9 ("i2c: at91: add dma support")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Cc: <stable@vger.kernel.org> # v3.8+
Acked-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-1-271d4adc03a0@cherr.cc
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-at91-core.c | 3 +++
drivers/i2c/busses/i2c-at91-master.c | 12 +++++++++++-
drivers/i2c/busses/i2c-at91.h | 1 +
3 files changed, 15 insertions(+), 1 deletion(-)
--- a/drivers/i2c/busses/i2c-at91-core.c
+++ b/drivers/i2c/busses/i2c-at91-core.c
@@ -255,6 +255,7 @@ static int at91_twi_probe(struct platfor
if (rc) {
pm_runtime_disable(dev->dev);
pm_runtime_set_suspended(dev->dev);
+ at91_twi_dma_release(dev);
return rc;
}
@@ -270,6 +271,8 @@ static void at91_twi_remove(struct platf
i2c_del_adapter(&dev->adapter);
+ at91_twi_dma_release(dev);
+
pm_runtime_disable(dev->dev);
pm_runtime_set_suspended(dev->dev);
}
--- a/drivers/i2c/busses/i2c-at91-master.c
+++ b/drivers/i2c/busses/i2c-at91-master.c
@@ -817,11 +817,21 @@ static int at91_twi_configure_dma(struct
error:
if (ret != -EPROBE_DEFER)
dev_info(dev->dev, "can't get DMA channel, continue without DMA support\n");
+ at91_twi_dma_release(dev);
+ return ret;
+}
+
+void at91_twi_dma_release(struct at91_twi_dev *dev)
+{
+ struct at91_twi_dma *dma = &dev->dma;
+
if (dma->chan_rx)
dma_release_channel(dma->chan_rx);
if (dma->chan_tx)
dma_release_channel(dma->chan_tx);
- return ret;
+ dma->chan_rx = NULL;
+ dma->chan_tx = NULL;
+ dev->use_dma = false;
}
static int at91_init_twi_recovery_gpio(struct platform_device *pdev,
--- a/drivers/i2c/busses/i2c-at91.h
+++ b/drivers/i2c/busses/i2c-at91.h
@@ -172,6 +172,7 @@ void at91_twi_irq_restore(struct at91_tw
void at91_init_twi_bus(struct at91_twi_dev *dev);
void at91_init_twi_bus_master(struct at91_twi_dev *dev);
+void at91_twi_dma_release(struct at91_twi_dev *dev);
int at91_twi_probe_master(struct platform_device *pdev, u32 phy_addr,
struct at91_twi_dev *dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 320/438] KEYS: encrypted: fix integer overflow of datablob_len
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (318 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 319/438] mm: filemap: retain mapped dropbehind folios Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 321/438] keys: translate request_key_auth pid for the reading procfs instance Greg Kroah-Hartman
` (129 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cen Zhang, Francis Perron,
Jarkko Sakkinen, R Nageswara Sastry
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cen Zhang <cenzhang@linux.microsoft.com>
commit 8697c431e297eb0d0ab13dda6bc172b48a34f05c upstream.
encrypted_key_alloc() stores datablob_len in a u16. It is computed from
multiple string and payload lengths. If the result exceeds U16_MAX, the
assignment truncates the allocation size. KASAN reports a 32760-byte
slab-out-of-bounds write when __ekey_init() copies the master key
description into the undersized buffer.
The total payload length stored in key->datalen is also a u16. Use
check_add_overflow() to reject values that do not fit either destination,
and use kzalloc_flex() for the flexible-array allocation.
Fixes: 7e70cb497850 ("keys: add new key-type encrypted")
Cc: stable@vger.kernel.org
Assisted-by: GitHub-Copilot:claude-opus-4.6
Signed-off-by: Cen Zhang <cenzhang@linux.microsoft.com>
Signed-off-by: Francis Perron <francis@akrites.dev>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Tested-by: R Nageswara Sastry <rnsastry@linux.ibm.com>
Link: https://lore.kernel.org/r/20260909153433.83117-1-cenzhang@linux.microsoft.com
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/keys/encrypted-keys/encrypted.c | 20 ++++++++++++++------
1 file changed, 14 insertions(+), 6 deletions(-)
--- a/security/keys/encrypted-keys/encrypted.c
+++ b/security/keys/encrypted-keys/encrypted.c
@@ -19,6 +19,7 @@
#include <linux/parser.h>
#include <linux/string.h>
#include <linux/err.h>
+#include <linux/overflow.h>
#include <keys/user-type.h>
#include <keys/trusted-type.h>
#include <keys/encrypted-type.h>
@@ -579,6 +580,7 @@ static struct encrypted_key_payload *enc
{
struct encrypted_key_payload *epayload = NULL;
unsigned short datablob_len;
+ unsigned short payload_totallen;
unsigned short decrypted_datalen;
unsigned short payload_datalen;
unsigned int encrypted_datalen;
@@ -632,16 +634,22 @@ static struct encrypted_key_payload *enc
encrypted_datalen = roundup(decrypted_datalen, blksize);
- datablob_len = format_len + 1 + strlen(master_desc) + 1
- + strlen(datalen) + 1 + ivsize + 1 + encrypted_datalen;
+ if (check_add_overflow(format_len + 1 + strlen(master_desc) + 1
+ + strlen(datalen) + 1 + ivsize + 1,
+ encrypted_datalen, &datablob_len))
+ return ERR_PTR(-EINVAL);
+
+ if (check_add_overflow(datablob_len,
+ payload_datalen + HASH_SIZE + 1,
+ &payload_totallen))
+ return ERR_PTR(-EINVAL);
- ret = key_payload_reserve(key, payload_datalen + datablob_len
- + HASH_SIZE + 1);
+ ret = key_payload_reserve(key, payload_totallen);
if (ret < 0)
return ERR_PTR(ret);
- epayload = kzalloc(sizeof(*epayload) + payload_datalen +
- datablob_len + HASH_SIZE + 1, GFP_KERNEL);
+ epayload = kzalloc_flex(*epayload, payload_data, payload_totallen,
+ GFP_KERNEL);
if (!epayload)
return ERR_PTR(-ENOMEM);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 267/398] i2c: atr: fix dangling adapter pointer on add failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (263 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 266/398] i2c: at91: release DMA channels on remove and probe error Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 268/398] i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove() Greg Kroah-Hartman
` (137 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linkai Gong, Andy Shevchenko,
Andi Shyti
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linkai Gong <gonglinkai@kylinos.cn>
commit ad34235808b63a70ca4989b7a2852923193d06ef upstream.
i2c_atr_add_adapter() stores atr->adapter[chan_id] before
i2c_add_adapter() so that the I2C bus notifier can match child clients
during registration. On failure the channel is freed but the slot was
left pointing at freed memory, which can lead to use-after-free in
i2c_atr_del_adapter() / cleanup and also block reuse with -EEXIST.
Clear the slot on the i2c_add_adapter() error path before freeing chan.
Fixes: a076a860acae ("media: i2c: add I2C Address Translator (ATR) support")
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Cc: <stable@vger.kernel.org> # v6.6+
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260907071102.1080840-1-gonglinkai@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/i2c-atr.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/i2c/i2c-atr.c
+++ b/drivers/i2c/i2c-atr.c
@@ -864,6 +864,7 @@ int i2c_atr_add_adapter(struct i2c_atr *
ret = i2c_add_adapter(&chan->adap);
if (ret) {
+ atr->adapter[chan_id] = NULL;
dev_err(dev, "failed to add atr-adapter %u (error=%d)\n",
chan_id, ret);
goto err_free_alias_pool;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 321/438] keys: translate request_key_auth pid for the reading procfs instance
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (319 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 320/438] KEYS: encrypted: fix integer overflow of datablob_len Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 322/438] KEYS: trusted: Fix tpm2_load_cmd() boundary check Greg Kroah-Hartman
` (128 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Maoyi Xie, Jarkko Sakkinen
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
commit 0d6a4268b06084baafd8ee5d66955c7e1c2e053b upstream.
request_key_auth_describe() prints rka->pid into /proc/keys as a raw
pid_t in the initial pid namespace. A reader can open /proc/keys through
a mount in another pid namespace. That reader sees a number with no
meaning there. The number can even name an unrelated task. The line
needs VIEW on the key. So the reader either shares the key owner's uid
or possesses the key.
The fix keeps a struct pid. Commit 4f82f45730c6 ("net ip6 flowlabel:
Make owner a union of struct pid * and kuid_t") gave
/proc/net/ip6_flowlabel the same storage. The print goes through
pid_nr_ns(). It renders against the pid namespace of the procfs instance
the line is read through. Commit ad08978ab41c ("ipv6/flowlabel: simplify
pid namespace lookup") moved that print to the same anchor. Output
through an initial namespace /proc does not change. The line shows 0 for
a requestor with no number in that namespace.
Translating at read time was the alternative. find_pid_ns() can resolve
a recycled number. The line would then name a live task with no
connection to the key. A stored struct pid gives 0 instead when the
requestor has no number there.
Link: https://lore.kernel.org/keyrings/20260809110202.2180410-1-maoyixie.tju@gmail.com/
Fixes: 78b7280cce23 ("KEYS: Improve /proc/keys")
Cc: stable@vger.kernel.org # v5.10+
Assisted-by: Claude:claude-opus-5 codeql
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Link: https://lore.kernel.org/r/20260821095935.1864998-1-maoyixie.tju@gmail.com
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/keys/request_key_auth-type.h | 2 +-
security/keys/request_key_auth.c | 12 +++++++++---
2 files changed, 10 insertions(+), 4 deletions(-)
--- a/include/keys/request_key_auth-type.h
+++ b/include/keys/request_key_auth-type.h
@@ -22,7 +22,7 @@ struct request_key_auth {
const struct cred *cred;
void *callout_info;
size_t callout_len;
- pid_t pid;
+ struct pid *pid;
char op[8];
} __randomize_layout;
--- a/security/keys/request_key_auth.c
+++ b/security/keys/request_key_auth.c
@@ -9,6 +9,8 @@
#include <linux/sched.h>
#include <linux/err.h>
+#include <linux/pid.h>
+#include <linux/proc_fs.h>
#include <linux/seq_file.h>
#include <linux/slab.h>
#include <linux/uaccess.h>
@@ -73,7 +75,10 @@ static void request_key_auth_describe(co
seq_puts(m, "key:");
seq_puts(m, key->description);
if (key_is_positive(key))
- seq_printf(m, " pid:%d ci:%zu", rka->pid, rka->callout_len);
+ seq_printf(m, " pid:%d ci:%zu",
+ pid_nr_ns(rka->pid,
+ proc_pid_ns(file_inode(m->file)->i_sb)),
+ rka->callout_len);
}
/*
@@ -113,6 +118,7 @@ static void free_request_key_auth(struct
if (rka->cred)
put_cred(rka->cred);
kfree(rka->callout_info);
+ put_pid(rka->pid);
kfree(rka);
}
@@ -226,14 +232,14 @@ struct key *request_key_auth_new(struct
irka = cred->request_key_auth->payload.data[0];
rka->cred = get_cred(irka->cred);
- rka->pid = irka->pid;
+ rka->pid = get_pid(irka->pid);
up_read(&cred->request_key_auth->sem);
}
else {
/* it isn't - use this process as the context */
rka->cred = get_cred(cred);
- rka->pid = current->pid;
+ rka->pid = get_pid(task_pid(current));
}
rka->target_key = key_get(target);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 268/398] i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (264 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 267/398] i2c: atr: fix dangling adapter pointer on add failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 269/398] i2c: imx: release DMA channels on probe error Greg Kroah-Hartman
` (136 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Liu Zhenlong,
Vladimir Zapolskiy, Andi Shyti
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Liu Zhenlong <dragonliu2018@gmail.com>
commit 7362a1553eb09a8cdf8be7e509bd5309a8342486 upstream.
The of_node_put() matching of_node_get() runs after i2c_del_adapter(),
whose trailing memset() zeroes adap->dev and thus adap->dev.of_node,
making the put a no-op and leaking the node on every adapter removal
and error cleanup.
Use a devm action: the pointer is captured at registration, out of
reach of that memset(), and devres runs the put once on probe failure
and detach, replacing the three manual of_node_put() calls. The
setup loop uses the scoped iterator form so the child node is released
automatically if devm_add_action_or_reset() fails mid-loop.
Suggested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Fixes: 02a4a69667a2 ("i2c: qcom-cci: don't put a device tree node before i2c_add_adapter()")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Liu Zhenlong <dragonliu2018@gmail.com>
Cc: <stable@vger.kernel.org> # v5.17+
Reviewed-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260818175750.4205-1-dragonliu2018@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-cci.c | 20 +++++++++++---------
1 file changed, 11 insertions(+), 9 deletions(-)
--- a/drivers/i2c/busses/i2c-qcom-cci.c
+++ b/drivers/i2c/busses/i2c-qcom-cci.c
@@ -499,10 +499,14 @@ static const struct dev_pm_ops qcom_cci_
SET_RUNTIME_PM_OPS(cci_suspend_runtime, cci_resume_runtime, NULL)
};
+static void cci_put_of_node(void *data)
+{
+ of_node_put(data);
+}
+
static int cci_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
- struct device_node *child;
struct resource *r;
struct cci *cci;
int ret, i;
@@ -518,7 +522,7 @@ static int cci_probe(struct platform_dev
if (!cci->data)
return -ENOENT;
- for_each_available_child_of_node(dev->of_node, child) {
+ for_each_available_child_of_node_scoped(dev->of_node, child) {
struct cci_master *master;
u32 idx;
@@ -539,6 +543,9 @@ static int cci_probe(struct platform_dev
master->adap.algo = &cci_algo;
master->adap.dev.parent = dev;
master->adap.dev.of_node = of_node_get(child);
+ ret = devm_add_action_or_reset(dev, cci_put_of_node, child);
+ if (ret)
+ return ret;
master->master = idx;
master->cci = cci;
@@ -610,10 +617,8 @@ static int cci_probe(struct platform_dev
continue;
ret = i2c_add_adapter(&cci->master[i].adap);
- if (ret < 0) {
- of_node_put(cci->master[i].adap.dev.of_node);
+ if (ret < 0)
goto error_i2c;
- }
}
return 0;
@@ -621,10 +626,8 @@ static int cci_probe(struct platform_dev
error_i2c:
for (--i ; i >= 0; i--) {
- if (cci->master[i].cci) {
+ if (cci->master[i].cci)
i2c_del_adapter(&cci->master[i].adap);
- of_node_put(cci->master[i].adap.dev.of_node);
- }
}
disable_clocks:
cci_disable_clocks(cci);
@@ -640,7 +643,6 @@ static void cci_remove(struct platform_d
for (i = 0; i < cci->data->num_masters; i++) {
if (cci->master[i].cci) {
i2c_del_adapter(&cci->master[i].adap);
- of_node_put(cci->master[i].adap.dev.of_node);
cci_halt(cci, i);
}
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 322/438] KEYS: trusted: Fix tpm2_load_cmd() boundary check
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (320 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 321/438] keys: translate request_key_auth pid for the reading procfs instance Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 323/438] sched_ext: Fix NULL sched deref in kfunc sub-sched error paths Greg Kroah-Hartman
` (127 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+6a581c4284f721d4,
Stefano Garzarella, Srish Srinivasan, Jarkko Sakkinen
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jarkko Sakkinen <jarkko@kernel.org>
commit 114f00d738f15dd8c7318369edcdc53dd6d08763 upstream.
tpm2_load_cmd() does boundary checks against the ASN.1 size i.e.,
payload->blob_len. Address this by passing the decoded blob size to
tpm2_load_cmd(), and use it for the boundary checks.
Cc: stable@vger.kernel.org # v5.13+
Fixes: f2219745250f ("security: keys: trusted: use ASN.1 TPM2 key format for the blobs")
Reported-by: co+6a581c4284f721d4@bugs.sh
Closes: https://bugs.sh/b/6a581c4284f721d4/
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Tested-by: Srish Srinivasan <ssrish@linux.ibm.com>
Link: https://lore.kernel.org/r/20260901205809.2028454-1-jarkko@kernel.org
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/keys/trusted-keys/trusted_tpm2.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
--- a/security/keys/trusted-keys/trusted_tpm2.c
+++ b/security/keys/trusted-keys/trusted_tpm2.c
@@ -100,7 +100,7 @@ struct tpm2_key_context {
static int tpm2_key_decode(struct trusted_key_payload *payload,
struct trusted_key_options *options,
- u8 **buf)
+ u8 **buf, unsigned int *blob_len)
{
int ret;
struct tpm2_key_context ctx;
@@ -121,6 +121,7 @@ static int tpm2_key_decode(struct truste
return -ENOMEM;
*buf = blob;
+ *blob_len = ctx.priv_len + ctx.pub_len;
options->keyhandle = ctx.parent;
memcpy(blob, ctx.priv, ctx.priv_len);
@@ -381,10 +382,11 @@ static int tpm2_load_cmd(struct tpm_chip
int rc;
u32 attrs;
- rc = tpm2_key_decode(payload, options, &blob);
+ rc = tpm2_key_decode(payload, options, &blob, &blob_len);
if (rc) {
/* old form */
blob = payload->blob;
+ blob_len = payload->blob_len;
payload->old_format = 1;
} else {
/* Bind for cleanup: */
@@ -396,17 +398,17 @@ static int tpm2_load_cmd(struct tpm_chip
return -EINVAL;
/* must be big enough for at least the two be16 size counts */
- if (payload->blob_len < 4)
+ if (blob_len < 4)
return -EINVAL;
private_len = get_unaligned_be16(blob);
/* must be big enough for following public_len */
- if (private_len + 2 + 2 > (payload->blob_len))
+ if (private_len + 2 + 2 > blob_len)
return -E2BIG;
public_len = get_unaligned_be16(blob + 2 + private_len);
- if (private_len + 2 + public_len + 2 > payload->blob_len)
+ if (private_len + 2 + public_len + 2 > blob_len)
return -E2BIG;
pub = blob + 2 + private_len + 2;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 269/398] i2c: imx: release DMA channels on probe error
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (265 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 268/398] i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 270/398] i2c: imx: disable autosuspend on remove Greg Kroah-Hartman
` (135 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shengzhuo Wei, Frank Li, Andi Shyti
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit e9f03b9625e2eeaca357b065c92d5b14064a1583 upstream.
i2c_imx_dma_request() acquires exclusive tx/rx DMA channels and is
optional: on errors other than -EPROBE_DEFER the driver falls back to
PIO mode and probe continues. If i2c_add_numbered_adapter() then fails,
probe returns through clk_notifier_unregister without releasing the
channels, because the remove callback is not invoked after a failed
probe.
Release the channels on the probe error path, mirroring
i2c_imx_remove().
Fixes: ce1a78840ff7 ("i2c: imx: add DMA support for freescale i2c driver")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Cc: <stable@vger.kernel.org> # v3.19+
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-2-271d4adc03a0@cherr.cc
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-imx.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/i2c/busses/i2c-imx.c
+++ b/drivers/i2c/busses/i2c-imx.c
@@ -1880,6 +1880,8 @@ static int i2c_imx_probe(struct platform
clk_notifier_unregister:
clk_notifier_unregister(i2c_imx->clk, &i2c_imx->clk_change_nb);
+ if (i2c_imx->dma)
+ i2c_imx_dma_free(i2c_imx);
free_irq(irq, i2c_imx);
rpm_disable:
pm_runtime_put_noidle(&pdev->dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 323/438] sched_ext: Fix NULL sched deref in kfunc sub-sched error paths
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (321 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 322/438] KEYS: trusted: Fix tpm2_load_cmd() boundary check Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 324/438] sched_ext: Close the pre-enable ops error claim window Greg Kroah-Hartman
` (126 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Andrea Righi, Wanwu Li, Tejun Heo
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wanwu Li <liwanwu@kylinos.cn>
commit 0a85182723b65ad8bee8131bc38fcf0347d6679b upstream.
When the root scheduler has sub-scheds attached, the COMPAT kfunc
wrappers scx_bpf_select_cpu_and() and scx_bpf_dsq_insert_vtime() refuse
the call and report to @p's scheduler:
scx_error(scx_task_sched(p), "... must be used");
The wrappers are reachable with tasks that have no scheduler.
scx_bpf_select_cpu_and() is in the select_cpu kfunc group, which
scx_kfunc_context_filter() opens to BPF_PROG_TYPE_SYSCALL programs;
scx_bpf_dsq_insert_vtime() is in the enqueue_dispatch group, which
ops.enqueue() and ops.dispatch() may call with any KF_RCU task -- the
group has no kf_tasks validation, and scx_dsq_insert_preamble() checks
task ownership with scx_task_on_sched() precisely because @p may be an
arbitrary task.
scx_task_sched(p) is p->scx.sched, which is NULL for tasks past
sched_ext_dead() -- which clears it via scx_disable_and_exit_task() on
exit -- and for idle tasks, which the enable paths skip as they are
never scheduled through SCX. It is also an rcu_dereference_protected()
that expects @p's pi_lock or rq lock, which neither wrapper holds.
Passing NULL to scx_error() reaches scx_vexit(), which dereferences
sch->exit_info, oopsing the kernel.
One concrete trigger exercised while developing the fix: a
BPF_PROG_TYPE_SYSCALL program calling the select_cpu_and wrapper on an
exited-but-not-reaped task while a sub-scheduler was attached (its pid
stays findable while the zombie is unreaped; faulting instruction is
the scx_vexit() prologue "mov r15,[rdi+0x398]" with RDI=NULL and 0x398
the offset of sch->exit_info):
sched_ext: BPF scheduler "kfunc_subsched_null" enabled
sched_ext: BPF sub-scheduler "kfunc_subsched_null" enabled
sched_ext: Unassociated program run_select_cpu_ (id 76)
BUG: kernel NULL pointer dereference, address: 0000000000000398
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
Oops: Oops: 0000 [#1] SMP NOPTI
CPU: 7 UID: 0 PID: 8201 Comm: kfunc_test_runn Tainted: G W
RIP: 0010:scx_vexit+0x25/0xa0
Code: ... <4c> 8b bf 98 03 00 00 ...
CR2: 0000000000000398
Call Trace:
<TASK>
__scx_exit+0x4f/0x70
scx_bpf_select_cpu_and+0xab/0xb0
bpf_prog_430ed61a7b66e03a_run_select_cpu_and+0x9c/0xe7
? __x64_sys_bpf+0x2c/0x40
bpf_prog_test_run_syscall+0x130/0x2f0
__sys_bpf+0x930/0x10d0
? __x64_sys_bpf+0x2c/0x40
__x64_sys_bpf+0x2c/0x40
do_syscall_64+0xbc/0x460
entry_SYSCALL_64_after_hwframe+0x76/0x7e
</TASK>
Read @p's scheduler under RCU instead, which the wrappers can do from
their guard(rcu)(): fault it when it can be determined, and when it
can't be determined -- @p is a task past sched_ext_dead() or an idle
task -- there is nothing obviously wrong to report, so just refuse the
call as before without faulting any scheduler.
These COMPAT wrappers are scheduled for eventual removal once the
deprecation grace period elapses, but until then -- and regardless of
their removal timeline -- they must not oops the kernel on a task they
are handed.
Cc: stable@vger.kernel.org # v7.1+
Fixes: a5fa0708cbfd ("sched_ext: Enforce scheduling authority in dispatch and select_cpu operations")
Suggested-by: Andrea Righi <arighi@nvidia.com>
Signed-off-by: Wanwu Li <liwanwu@kylinos.cn>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/sched/ext/ext.c | 11 +++++++++--
kernel/sched/ext/idle.c | 11 +++++++++--
2 files changed, 18 insertions(+), 4 deletions(-)
--- a/kernel/sched/ext/ext.c
+++ b/kernel/sched/ext/ext.c
@@ -8964,10 +8964,17 @@ __bpf_kfunc void scx_bpf_dsq_insert_vtim
#ifdef CONFIG_EXT_SUB_SCHED
/*
* Disallow if any sub-scheds are attached. There is no way to tell
- * which scheduler called us, just error out @p's scheduler.
+ * which scheduler called us, so error out @p's scheduler -- read it
+ * under RCU as @p's locks aren't necessarily held here. @p may be a
+ * task past sched_ext_dead() or an idle task, in which case its
+ * scheduler can't be determined and there is nothing obviously wrong
+ * to report; just refuse the call.
*/
if (unlikely(!list_empty(&sch->children))) {
- scx_error(scx_task_sched(p), "__scx_bpf_dsq_insert_vtime() must be used");
+ struct scx_sched *tsch = scx_task_sched_rcu(p);
+
+ if (tsch)
+ scx_error(tsch, "__scx_bpf_dsq_insert_vtime() must be used");
return;
}
#endif
--- a/kernel/sched/ext/idle.c
+++ b/kernel/sched/ext/idle.c
@@ -1097,10 +1097,17 @@ __bpf_kfunc s32 scx_bpf_select_cpu_and(s
#ifdef CONFIG_EXT_SUB_SCHED
/*
* Disallow if any sub-scheds are attached. There is no way to tell
- * which scheduler called us, just error out @p's scheduler.
+ * which scheduler called us, so error out @p's scheduler -- read it
+ * under RCU as @p's locks aren't necessarily held here. @p may be a
+ * task past sched_ext_dead() or an idle task, in which case its
+ * scheduler can't be determined and there is nothing obviously wrong
+ * to report; just refuse the call.
*/
if (unlikely(!list_empty(&sch->children))) {
- scx_error(scx_task_sched(p), "__scx_bpf_select_cpu_and() must be used");
+ struct scx_sched *tsch = scx_task_sched_rcu(p);
+
+ if (tsch)
+ scx_error(tsch, "__scx_bpf_select_cpu_and() must be used");
return -EINVAL;
}
#endif
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 270/398] i2c: imx: disable autosuspend on remove
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (266 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 269/398] i2c: imx: release DMA channels on probe error Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 271/398] IB/mlx4: Fix use-after-free on pkey sysfs registration failure Greg Kroah-Hartman
` (134 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Frank Li, Andi Shyti
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit e0c3e9d76adbe522dd420a766ce42d03ce887c29 upstream.
i2c_imx_probe() enables runtime PM autosuspend with
pm_runtime_use_autosuspend(). The probe error path correctly undoes
this setting with pm_runtime_dont_use_autosuspend(), but the normal
remove path only disables runtime PM.
The runtime PM API requires pm_runtime_use_autosuspend() to be undone
with pm_runtime_dont_use_autosuspend() at driver exit unless runtime PM
was enabled with devm_pm_runtime_enable(). Leaving the autosuspend flag
set therefore leaves the runtime PM state incompletely cleaned up after
the driver is unbound.
Add the missing pm_runtime_dont_use_autosuspend() call to the remove
path.
This issue was found by manual code inspection.
Fixes: 588eb93ea49f ("i2c: imx: add runtime pm support to improve the performance")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Cc: <stable@vger.kernel.org> # v4.5+
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260914091544.1667137-1-lgs201920130244@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-imx.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/i2c/busses/i2c-imx.c
+++ b/drivers/i2c/busses/i2c-imx.c
@@ -1922,6 +1922,7 @@ static void i2c_imx_remove(struct platfo
pm_runtime_put_noidle(&pdev->dev);
pm_runtime_disable(&pdev->dev);
+ pm_runtime_dont_use_autosuspend(&pdev->dev);
}
static int i2c_imx_runtime_suspend(struct device *dev)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 324/438] sched_ext: Close the pre-enable ops error claim window
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (322 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 323/438] sched_ext: Fix NULL sched deref in kfunc sub-sched error paths Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 325/438] i2c: at91: release DMA channels on remove and probe error Greg Kroah-Hartman
` (125 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, fangqiurong, Tejun Heo
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: fangqiurong <fangqiurong@kylinos.cn>
commit c7a1c6e8004ab12a9c9bfdcb603f60f9bf4a3cee upstream.
scx_alloc_and_add_sched() publishes ops->priv before
scx_root_enable_workfn() switches the state to SCX_ENABLING. An error
claimed via scx_bpf_error_bstr() from an associated BPF program in that
window is consumed by scx_disable_workfn(), which takes the pre-enable
shortcut in scx_root_disable(). The shortcut returns without any teardown
and restores SCX_DISABLED with an unconditional scx_set_enable_state() xchg
racing the enable workfn's own transition. The enable then completes with
the claim consumed: the scheduler stays up but can never be disabled again,
and bpf_scx_unreg() frees it while still in use, resulting in a
use-after-free. Both WARN_ON_ONCE()s fire back to back:
WARNING: kernel/sched/ext/ext.c:7522 at
scx_root_enable_workfn+0xeec/0x1be0, CPU#3: scx_enable_help/276
WARNING: kernel/sched/ext/ext.c:6398 at scx_root_disable+0xb50/0xdb8,
CPU#0: sched_ext_helpe/664
scx_root_enable_workfn() switches to SCX_ENABLING before the scheduler
allocation, so ops->priv is never visible while SCX_DISABLED. The allocation
failure path restores SCX_DISABLED.
Fixes: 105dcd005be2 ("sched_ext: Introduce scx_prog_sched()")
Cc: stable@vger.kernel.org
Signed-off-by: fangqiurong <fangqiurong@kylinos.cn>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/sched/ext/ext.c | 16 +++++++++-------
1 file changed, 9 insertions(+), 7 deletions(-)
--- a/kernel/sched/ext/ext.c
+++ b/kernel/sched/ext/ext.c
@@ -7282,22 +7282,24 @@ static void scx_root_enable_workfn(struc
#ifdef CONFIG_EXT_SUB_SCHED
cgroup_get(cgrp);
#endif
+ /*
+ * Transition to ENABLING to arm the disable path. Allocation failure
+ * still unwinds locally. Full disabling on failure applies only after
+ * scx_alloc_and_add_sched() succeeds.
+ */
+ WARN_ON_ONCE(scx_set_enable_state(SCX_ENABLING) != SCX_DISABLED);
+ WARN_ON_ONCE(scx_root);
+
sch = scx_alloc_and_add_sched(cmd, cgrp, NULL);
if (IS_ERR(sch)) {
ret = PTR_ERR(sch);
+ WARN_ON_ONCE(scx_set_enable_state(SCX_DISABLED) != SCX_ENABLING);
goto err_free_tid_hash;
}
if (sch->is_cid_type)
static_branch_enable(&__scx_is_cid_type);
- /*
- * Transition to ENABLING and clear exit info to arm the disable path.
- * Failure triggers full disabling from here on.
- */
- WARN_ON_ONCE(scx_set_enable_state(SCX_ENABLING) != SCX_DISABLED);
- WARN_ON_ONCE(scx_root);
-
atomic_long_set(&scx_nr_rejected, 0);
for_each_possible_cpu(cpu) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 271/398] IB/mlx4: Fix use-after-free on pkey sysfs registration failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (267 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 270/398] i2c: imx: disable autosuspend on remove Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 272/398] IB/hfi1: Resolve the credit-return buffer through the send contexts node Greg Kroah-Hartman
` (133 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Leon Romanovsky
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
commit 1af874e9f4ce22ccf8b10ab5462f32c70d3be21a upstream.
register_pkey_tree() ignores errors from register_one_pkey_tree() and
continues registering the remaining slaves. The per-slave error path has
already released the pkey parent kobjects, but their pointers remain
stored in the device. A later device cleanup therefore passes the stale
pointers to kobject_put(), causing a use-after-free.
Clear the parent pointers after releasing a failed slave tree and skip
unregistered trees during device cleanup. This preserves the existing
best-effort registration behavior while preventing a second cleanup of
the failed tree.
Fixes: c1e7e466120b ("IB/mlx4: Add iov directory in sysfs under the ib device")
Cc: stable@vger.kernel.org
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Link: https://patch.msgid.link/20260816044510.3848996-1-shuangpeng.kernel@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/hw/mlx4/sysfs.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/infiniband/hw/mlx4/sysfs.c
+++ b/drivers/infiniband/hw/mlx4/sysfs.c
@@ -753,11 +753,13 @@ err_add:
kobject_put(p);
}
kobject_put(dev->dev_ports_parent[slave]);
+ dev->dev_ports_parent[slave] = NULL;
err_ports:
kobject_put(dev->pkeys.device_parent[slave]);
/* extra put for the device_parent create_and_add */
kobject_put(dev->pkeys.device_parent[slave]);
+ dev->pkeys.device_parent[slave] = NULL;
fail_dev:
kobject_put(dev->iov_parent);
@@ -787,6 +789,8 @@ static void unregister_pkey_tree(struct
return;
for (slave = device->dev->persist->num_vfs; slave >= 0; --slave) {
+ if (!device->pkeys.device_parent[slave])
+ continue;
list_for_each_entry_safe(p, t,
&device->pkeys.pkey_port_list[slave],
entry) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 325/438] i2c: at91: release DMA channels on remove and probe error
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (323 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 324/438] sched_ext: Close the pre-enable ops error claim window Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 326/438] i2c: atr: fix dangling adapter pointer on add failure Greg Kroah-Hartman
` (124 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shengzhuo Wei, Mukesh Kumar Savaliya,
Andi Shyti
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit f7eeb1af8537b05953fb1c88ab8b59d94059a381 upstream.
at91_twi_configure_dma() requests exclusive tx/rx DMA channels, but
nothing ever releases them on driver detach, and the probe error path
after the channels are acquired (i2c_add_numbered_adapter() failure)
returns without releasing them either, because the remove callback is
not invoked after a failed probe.
Move the release into a helper, call it from the existing
configure-failure path, the adapter-registration failure path, and
at91_twi_remove().
Fixes: 60937b2cdbf9 ("i2c: at91: add dma support")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Cc: <stable@vger.kernel.org> # v3.8+
Acked-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-1-271d4adc03a0@cherr.cc
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-at91-core.c | 3 +++
drivers/i2c/busses/i2c-at91-master.c | 12 +++++++++++-
drivers/i2c/busses/i2c-at91.h | 1 +
3 files changed, 15 insertions(+), 1 deletion(-)
--- a/drivers/i2c/busses/i2c-at91-core.c
+++ b/drivers/i2c/busses/i2c-at91-core.c
@@ -255,6 +255,7 @@ static int at91_twi_probe(struct platfor
if (rc) {
pm_runtime_disable(dev->dev);
pm_runtime_set_suspended(dev->dev);
+ at91_twi_dma_release(dev);
return rc;
}
@@ -270,6 +271,8 @@ static void at91_twi_remove(struct platf
i2c_del_adapter(&dev->adapter);
+ at91_twi_dma_release(dev);
+
pm_runtime_disable(dev->dev);
pm_runtime_set_suspended(dev->dev);
}
--- a/drivers/i2c/busses/i2c-at91-master.c
+++ b/drivers/i2c/busses/i2c-at91-master.c
@@ -817,11 +817,21 @@ static int at91_twi_configure_dma(struct
error:
if (ret != -EPROBE_DEFER)
dev_info(dev->dev, "can't get DMA channel, continue without DMA support\n");
+ at91_twi_dma_release(dev);
+ return ret;
+}
+
+void at91_twi_dma_release(struct at91_twi_dev *dev)
+{
+ struct at91_twi_dma *dma = &dev->dma;
+
if (dma->chan_rx)
dma_release_channel(dma->chan_rx);
if (dma->chan_tx)
dma_release_channel(dma->chan_tx);
- return ret;
+ dma->chan_rx = NULL;
+ dma->chan_tx = NULL;
+ dev->use_dma = false;
}
static int at91_init_twi_recovery_gpio(struct platform_device *pdev,
--- a/drivers/i2c/busses/i2c-at91.h
+++ b/drivers/i2c/busses/i2c-at91.h
@@ -172,6 +172,7 @@ void at91_twi_irq_restore(struct at91_tw
void at91_init_twi_bus(struct at91_twi_dev *dev);
void at91_init_twi_bus_master(struct at91_twi_dev *dev);
+void at91_twi_dma_release(struct at91_twi_dev *dev);
int at91_twi_probe_master(struct platform_device *pdev, u32 phy_addr,
struct at91_twi_dev *dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 272/398] IB/hfi1: Resolve the credit-return buffer through the send contexts node
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (268 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 271/398] IB/mlx4: Fix use-after-free on pkey sysfs registration failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 273/398] IB/hfi1: Fix the PIO_CRED credit-return mmap Greg Kroah-Hartman
` (132 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shuhei Takeshita, Leon Romanovsky
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuhei Takeshita <jyohuku.alterego@gmail.com>
commit 975396b9e5a4028e649f4b9a6a5ca5dfb76a824b upstream.
hfi1_file_mmap()'s PIO_CRED case derives this context's credit-return
page offset, and the DMA handle for it, from dd->cr_base[uctxt->numa_id].
uctxt->numa_id is the node of whichever CPU the process happened to be
running on, but the entry itself lives in the credit-return allocation of
the send context's own node:
sc->hw_free = &sc->dd->cr_base[sc->node].va[gc].cr[index];
and user send contexts are allocated with sc_alloc(dd, SC_USER, ...,
dd->node), the HFI-local node. On a multi-socket host with the process
running off that node the two allocations differ, so the subtraction
produces an offset into an unrelated buffer and the DMA handle belongs to
the wrong allocation.
Use the send context's own node for all three references. The
continuation lines are reindented at the same time; they mixed spaces and
tabs.
Fixes: 7724105686e7 ("IB/hfi1: add driver files")
Cc: stable@vger.kernel.org
Signed-off-by: Shuhei Takeshita <jyohuku.alterego@gmail.com>
Link: https://patch.msgid.link/20260809032743.2671579-2-jyohuku.alterego@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/hw/hfi1/file_ops.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/drivers/infiniband/hw/hfi1/file_ops.c
+++ b/drivers/infiniband/hw/hfi1/file_ops.c
@@ -382,10 +382,10 @@ static int hfi1_file_mmap(struct file *f
* of enabled contexts > 64 and 128 respectively).
*/
cr_page_offset = ((u64)uctxt->sc->hw_free -
- (u64)dd->cr_base[uctxt->numa_id].va) &
- PAGE_MASK;
- memvirt = dd->cr_base[uctxt->numa_id].va + cr_page_offset;
- memdma = dd->cr_base[uctxt->numa_id].dma + cr_page_offset;
+ (u64)dd->cr_base[uctxt->sc->node].va) &
+ PAGE_MASK;
+ memvirt = dd->cr_base[uctxt->sc->node].va + cr_page_offset;
+ memdma = dd->cr_base[uctxt->sc->node].dma + cr_page_offset;
memlen = PAGE_SIZE;
flags &= ~VM_MAYWRITE;
flags |= VM_DONTCOPY | VM_DONTEXPAND;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 326/438] i2c: atr: fix dangling adapter pointer on add failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (324 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 325/438] i2c: at91: release DMA channels on remove and probe error Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 327/438] i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove() Greg Kroah-Hartman
` (123 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linkai Gong, Andy Shevchenko,
Andi Shyti
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linkai Gong <gonglinkai@kylinos.cn>
commit ad34235808b63a70ca4989b7a2852923193d06ef upstream.
i2c_atr_add_adapter() stores atr->adapter[chan_id] before
i2c_add_adapter() so that the I2C bus notifier can match child clients
during registration. On failure the channel is freed but the slot was
left pointing at freed memory, which can lead to use-after-free in
i2c_atr_del_adapter() / cleanup and also block reuse with -EEXIST.
Clear the slot on the i2c_add_adapter() error path before freeing chan.
Fixes: a076a860acae ("media: i2c: add I2C Address Translator (ATR) support")
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Cc: <stable@vger.kernel.org> # v6.6+
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260907071102.1080840-1-gonglinkai@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/i2c-atr.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/i2c/i2c-atr.c
+++ b/drivers/i2c/i2c-atr.c
@@ -855,6 +855,7 @@ int i2c_atr_add_adapter(struct i2c_atr *
ret = i2c_add_adapter(&chan->adap);
if (ret) {
+ atr->adapter[chan_id] = NULL;
dev_err(dev, "failed to add atr-adapter %u (error=%d)\n",
chan_id, ret);
goto err_free_alias_pool;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 273/398] IB/hfi1: Fix the PIO_CRED credit-return mmap
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (269 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 272/398] IB/hfi1: Resolve the credit-return buffer through the send contexts node Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 274/398] selinux: preserve user SID across nested backing files Greg Kroah-Hartman
` (131 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shuhei Takeshita, Leon Romanovsky
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuhei Takeshita <jyohuku.alterego@gmail.com>
commit 62f0f34fbd2b2d5653d33d3b9d42fdcabb1c0101 upstream.
hfi1_file_mmap()'s PIO_CRED case must hand user space the single
credit-return page that holds this context's entry. That page is the
second or third page of the per-node credit-return allocation once the
hardware send context index reaches 64 or 128, so the failure below is
intermittent: when the entry lands on the first page the offset is zero
and everything works.
Two things are wrong.
First, cr_page_offset is a byte offset but .va is a struct
credit_return *, so adding it is pointer arithmetic and scales the offset
by sizeof(struct credit_return) == 64. memvirt then lands 256 KiB or
512 KiB past a 10240-byte allocation. With an IOMMU translating, that
address is inside the vmalloc range but in no vm_area, so
dma_mmap_coherent() -> iommu_dma_mmap() finds no pages, vmalloc_to_pfn()
returns page_to_pfn(NULL), and remap_pfn_range() installs a frame above
MAXPHYADDR. The first user read then takes:
psm2_ep_open_pr: Corrupted page table at address 7a14d007e000
PGD 800000013886a067 P4D 800000013886a067 PUD 13886b067 PMD 13886c067
PTE 800049168e911235
Oops: Bad pagetable: 000d [#1] SMP PTI
Second, and still wrong once the arithmetic is corrected,
dma_mmap_coherent() describes a whole coherent buffer and selects the
page within it with vma->vm_pgoff. Offsetting cpu_addr has no effect:
for a vmap'd allocation iommu_dma_mmap() uses cpu_addr only to locate the
vm_area and then maps pages[vm_pgoff], which hfi1_file_mmap() has just
set to 0. User space therefore always receives the first credit-return
page, every credit read is for the wrong context, and send PIO stalls
forever.
Use the DMA API as intended: pass the base of the allocation with its
full length and select the page with vm_pgoff. A separate length is
needed because memlen must keep describing the VMA for the existing size
check. The dma-direct path stays correct as well, since dma_direct_mmap()
adds the same vm_pgoff to the base pfn.
Tested on a Dell T7610 (Xeon E5-2650 v2, Intel IOMMU in DMA-FQ mode)
against a Threadripper PRO 3995WX peer, both Omni-Path 100. Before this
change psm2_ep_open() Oopses the kernel; with only the arithmetic
corrected psm2_ep_open() succeeds but any transfer that uses send PIO
hangs, PSM2_SDMA=2 (send PIO disabled) completing normally while
PSM2_SDMA=0 (send PIO only) hangs every time. With this change send PIO,
send DMA and the default mixed mode all work.
Fixes: 1ec82317a1da ("IB/hfi1: Use dma_mmap_coherent for matching buffers")
Cc: stable@vger.kernel.org
Signed-off-by: Shuhei Takeshita <jyohuku.alterego@gmail.com>
Link: https://patch.msgid.link/20260809032743.2671579-3-jyohuku.alterego@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/hw/hfi1/file_ops.c | 21 ++++++++++++++++-----
1 file changed, 16 insertions(+), 5 deletions(-)
--- a/drivers/infiniband/hw/hfi1/file_ops.c
+++ b/drivers/infiniband/hw/hfi1/file_ops.c
@@ -326,6 +326,7 @@ static int hfi1_file_mmap(struct file *f
void *memvirt = NULL;
dma_addr_t memdma = 0;
u8 subctxt, mapio = 0, vmf = 0, type;
+ size_t memdmalen = 0;
ssize_t memlen = 0;
int ret = 0;
u16 ctxt;
@@ -371,7 +372,9 @@ static int hfi1_file_mmap(struct file *f
mapio = 1;
break;
case PIO_CRED: {
+ struct credit_return_base *cr = &dd->cr_base[uctxt->sc->node];
u64 cr_page_offset;
+
if (flags & VM_WRITE) {
ret = -EPERM;
goto done;
@@ -381,11 +384,18 @@ static int hfi1_file_mmap(struct file *f
* second or third page allocated for credit returns (if number
* of enabled contexts > 64 and 128 respectively).
*/
- cr_page_offset = ((u64)uctxt->sc->hw_free -
- (u64)dd->cr_base[uctxt->sc->node].va) &
+ cr_page_offset = ((u64)uctxt->sc->hw_free - (u64)cr->va) &
PAGE_MASK;
- memvirt = dd->cr_base[uctxt->sc->node].va + cr_page_offset;
- memdma = dd->cr_base[uctxt->sc->node].dma + cr_page_offset;
+ /*
+ * dma_mmap_coherent() describes the whole coherent buffer and
+ * selects the page within it with vma->vm_pgoff, so pass the
+ * base of the allocation and its length and let vm_pgoff pick
+ * the page.
+ */
+ vma->vm_pgoff = cr_page_offset >> PAGE_SHIFT;
+ memvirt = cr->va;
+ memdma = cr->dma;
+ memdmalen = TXE_NUM_CONTEXTS * sizeof(struct credit_return);
memlen = PAGE_SIZE;
flags &= ~VM_MAYWRITE;
flags |= VM_DONTCOPY | VM_DONTEXPAND;
@@ -567,7 +577,8 @@ static int hfi1_file_mmap(struct file *f
ret = 0;
} else if (memdma) {
ret = dma_mmap_coherent(&dd->pcidev->dev, vma,
- memvirt, memdma, memlen);
+ memvirt, memdma,
+ memdmalen ? memdmalen : memlen);
} else if (mapio) {
ret = io_remap_pfn_range(vma, vma->vm_start,
PFN_DOWN(memaddr),
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 327/438] i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (325 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 326/438] i2c: atr: fix dangling adapter pointer on add failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 328/438] i2c: imx: release DMA channels on probe error Greg Kroah-Hartman
` (122 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Liu Zhenlong,
Vladimir Zapolskiy, Andi Shyti
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Liu Zhenlong <dragonliu2018@gmail.com>
commit 7362a1553eb09a8cdf8be7e509bd5309a8342486 upstream.
The of_node_put() matching of_node_get() runs after i2c_del_adapter(),
whose trailing memset() zeroes adap->dev and thus adap->dev.of_node,
making the put a no-op and leaking the node on every adapter removal
and error cleanup.
Use a devm action: the pointer is captured at registration, out of
reach of that memset(), and devres runs the put once on probe failure
and detach, replacing the three manual of_node_put() calls. The
setup loop uses the scoped iterator form so the child node is released
automatically if devm_add_action_or_reset() fails mid-loop.
Suggested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Fixes: 02a4a69667a2 ("i2c: qcom-cci: don't put a device tree node before i2c_add_adapter()")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Liu Zhenlong <dragonliu2018@gmail.com>
Cc: <stable@vger.kernel.org> # v5.17+
Reviewed-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260818175750.4205-1-dragonliu2018@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-cci.c | 20 +++++++++++---------
1 file changed, 11 insertions(+), 9 deletions(-)
--- a/drivers/i2c/busses/i2c-qcom-cci.c
+++ b/drivers/i2c/busses/i2c-qcom-cci.c
@@ -497,10 +497,14 @@ static const struct dev_pm_ops qcom_cci_
SET_RUNTIME_PM_OPS(cci_suspend_runtime, cci_resume_runtime, NULL)
};
+static void cci_put_of_node(void *data)
+{
+ of_node_put(data);
+}
+
static int cci_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
- struct device_node *child;
struct resource *r;
struct cci *cci;
int ret, i;
@@ -516,7 +520,7 @@ static int cci_probe(struct platform_dev
if (!cci->data)
return -ENOENT;
- for_each_available_child_of_node(dev->of_node, child) {
+ for_each_available_child_of_node_scoped(dev->of_node, child) {
struct cci_master *master;
u32 idx;
@@ -537,6 +541,9 @@ static int cci_probe(struct platform_dev
master->adap.algo = &cci_algo;
master->adap.dev.parent = dev;
master->adap.dev.of_node = of_node_get(child);
+ ret = devm_add_action_or_reset(dev, cci_put_of_node, child);
+ if (ret)
+ return ret;
master->master = idx;
master->cci = cci;
@@ -606,10 +613,8 @@ static int cci_probe(struct platform_dev
continue;
ret = i2c_add_adapter(&cci->master[i].adap);
- if (ret < 0) {
- of_node_put(cci->master[i].adap.dev.of_node);
+ if (ret < 0)
goto error_i2c;
- }
}
return 0;
@@ -617,10 +622,8 @@ static int cci_probe(struct platform_dev
error_i2c:
for (--i ; i >= 0; i--) {
- if (cci->master[i].cci) {
+ if (cci->master[i].cci)
i2c_del_adapter(&cci->master[i].adap);
- of_node_put(cci->master[i].adap.dev.of_node);
- }
}
disable_clocks:
cci_disable_clocks(cci);
@@ -636,7 +639,6 @@ static void cci_remove(struct platform_d
for (i = 0; i < cci->data->num_masters; i++) {
if (cci->master[i].cci) {
i2c_del_adapter(&cci->master[i].adap);
- of_node_put(cci->master[i].adap.dev.of_node);
cci_halt(cci, i);
}
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 274/398] selinux: preserve user SID across nested backing files
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (270 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 273/398] IB/hfi1: Fix the PIO_CRED credit-return mmap Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 275/398] selinux: recheck intermediate backing files on mprotect() Greg Kroah-Hartman
` (130 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Amir Goldstein,
Stephen Smalley, Paul Moore
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
commit 8c0c602202b9a4909b00bc3354e3c0355bc69e65 upstream.
SELinux saves the user file SID in a backing-file security blob so it
remains available after mmap() replaces vma->vm_file with a backing file.
For nested backing files (overlayfs over overlayfs, or FUSE passthrough
backed by overlayfs), user_file may itself be a backing file. Its
fsec->sid is the SID of the mounter that opened it, rather than the user
that opened the top-level file. mprotect() then checks fd { use } against
the mounter SID. This can incorrectly deny access without a domain
transition, or check the wrong target SID after one.
Copy the saved user SID when user_file is a backing file. Keep using the
regular file SID for the first backing layer.
With two nested overlayfs mounts and SELinux enforcing,
mprotect(PROT_READ) returns EACCES with an fd { use } denial against the
mounter SID. With this change, mprotect() succeeds.
Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built
SELinux policy. The original test was also repeated with Fedora Cloud
Base 44 userspace and gave the same result.
Cc: stable@vger.kernel.org
Fixes: 82544d36b172 ("selinux: fix overlayfs mmap() and mprotect() access checks")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Amir Goldstein <amir73il@gmail.com>
Reviewed-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/selinux/hooks.c | 9 ++++++++-
security/selinux/include/objsec.h | 2 +-
2 files changed, 9 insertions(+), 2 deletions(-)
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -3822,13 +3822,20 @@ static int selinux_file_alloc_security(s
return 0;
}
+static inline u32 selinux_file_user_sid(const struct file *file)
+{
+ if (unlikely(file->f_mode & FMODE_BACKING))
+ return selinux_backing_file(file)->uf_sid;
+ return selinux_file(file)->sid;
+}
+
static int selinux_backing_file_alloc(struct file *backing_file,
const struct file *user_file)
{
struct backing_file_security_struct *bfsec;
bfsec = selinux_backing_file(backing_file);
- bfsec->uf_sid = selinux_file(user_file)->sid;
+ bfsec->uf_sid = selinux_file_user_sid(user_file);
return 0;
}
--- a/security/selinux/include/objsec.h
+++ b/security/selinux/include/objsec.h
@@ -87,7 +87,7 @@ struct file_security_struct {
};
struct backing_file_security_struct {
- u32 uf_sid; /* associated user file fsec->sid */
+ u32 uf_sid; /* top-level user file fsec->sid */
};
struct superblock_security_struct {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 328/438] i2c: imx: release DMA channels on probe error
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (326 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 327/438] i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 329/438] i2c: imx: disable autosuspend on remove Greg Kroah-Hartman
` (121 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shengzhuo Wei, Frank Li, Andi Shyti
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit e9f03b9625e2eeaca357b065c92d5b14064a1583 upstream.
i2c_imx_dma_request() acquires exclusive tx/rx DMA channels and is
optional: on errors other than -EPROBE_DEFER the driver falls back to
PIO mode and probe continues. If i2c_add_numbered_adapter() then fails,
probe returns through clk_notifier_unregister without releasing the
channels, because the remove callback is not invoked after a failed
probe.
Release the channels on the probe error path, mirroring
i2c_imx_remove().
Fixes: ce1a78840ff7 ("i2c: imx: add DMA support for freescale i2c driver")
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Cc: <stable@vger.kernel.org> # v3.19+
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260827-i2c-dma-channel-leak-v1-2-271d4adc03a0@cherr.cc
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-imx.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/i2c/busses/i2c-imx.c
+++ b/drivers/i2c/busses/i2c-imx.c
@@ -1880,6 +1880,8 @@ static int i2c_imx_probe(struct platform
clk_notifier_unregister:
clk_notifier_unregister(i2c_imx->clk, &i2c_imx->clk_change_nb);
+ if (i2c_imx->dma)
+ i2c_imx_dma_free(i2c_imx);
free_irq(irq, i2c_imx);
rpm_disable:
pm_runtime_put_noidle(&pdev->dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 275/398] selinux: recheck intermediate backing files on mprotect()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (271 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 274/398] selinux: preserve user SID across nested backing files Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 276/398] selinux: always fill AVC decision in avc_has_perm_noaudit() Greg Kroah-Hartman
` (129 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Stephen Smalley,
Paul Moore
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
commit 78fc54b934bfb2c18aad8154c7302067146946f9 upstream.
mprotect() can be used to bypass the SELinux checks that mmap() performs
against the intermediate layers of a stacked filesystem.
mmap() checks every backing layer as the request descends through the
stack. mprotect() only has the lowest backing file in vma->vm_file, so it
rechecks the top-level user and the lowest mounter, but skips the mounters
of every layer in between. With two nested overlayfs mounts and a policy
denying mounter_t -> middle_file_t:file { execute }, a direct
mmap(PROT_EXEC) is denied:
avc: denied { execute } for pid=71 comm="nested_exec"
path="/payload" dev="overlay" ino=9
scontext=user_u:base_r:mounter_t
tcontext=user_u:object_r:middle_file_t tclass=file permissive=0
while mmap(PROT_NONE) followed by mprotect(PROT_EXEC) succeeds.
Preserve each intermediate path, mounter SID and file-description SID in
the backing-file security blob, copying the saved entries when another
backing layer is opened. Allocate the array only for nested backing files,
and release it and the path references in the backing_file_free hook.
During mprotect(), recheck fd { use } and the requested inode permissions
for every saved mounter, and include the intermediate layers in the execmod
checks. Policy for nested stacking may then need to grant intermediate
mounters what a direct mmap() already requires, and execmod on intermediate
labels for binaries using text relocations.
Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built
SELinux policy, on a mainline tree containing
commit f2381b546e7e ("fs: fix user path of nested backing files").
Cc: stable@vger.kernel.org
Fixes: 82544d36b172 ("selinux: fix overlayfs mmap() and mprotect() access checks")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Stephen Smalley <stephen.smalley.work@gmail.com>
[PM: subject tweak]
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/selinux/hooks.c | 141 +++++++++++++++++++++++++++++++++-----
security/selinux/include/objsec.h | 8 ++
2 files changed, 133 insertions(+), 16 deletions(-)
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -1665,26 +1665,32 @@ static int cred_has_capability(const str
return rc;
}
-/* Check whether a task has a particular permission to an inode.
- The 'adp' parameter is optional and allows other audit
- data to be passed (e.g. the dentry). */
-static int inode_has_perm(const struct cred *cred,
- struct inode *inode,
- u32 perms,
- struct common_audit_data *adp)
+/*
+ * Check whether a SID has a particular permission to an inode. The 'adp'
+ * parameter is optional and allows other audit data to be passed (e.g. the
+ * dentry).
+ */
+static int inode_sid_has_perm(u32 sid, struct inode *inode, u32 perms,
+ struct common_audit_data *adp)
{
struct inode_security_struct *isec;
- u32 sid;
if (unlikely(IS_PRIVATE(inode)))
return 0;
- sid = cred_sid(cred);
isec = selinux_inode(inode);
return avc_has_perm(sid, isec->sid, isec->sclass, perms, adp);
}
+static int inode_has_perm(const struct cred *cred,
+ struct inode *inode,
+ u32 perms,
+ struct common_audit_data *adp)
+{
+ return inode_sid_has_perm(cred_sid(cred), inode, perms, adp);
+}
+
/* Same as inode_has_perm, but pass explicit audit data containing
the dentry to help the auditing code to more easily generate the
pathname if needed. */
@@ -3833,13 +3839,63 @@ static int selinux_backing_file_alloc(st
const struct file *user_file)
{
struct backing_file_security_struct *bfsec;
+ const struct backing_file_security_struct *ubfsec;
+ struct backing_file_security_layer *layer;
+ u32 i;
bfsec = selinux_backing_file(backing_file);
bfsec->uf_sid = selinux_file_user_sid(user_file);
+ if (!(user_file->f_mode & FMODE_BACKING))
+ return 0;
+
+ ubfsec = selinux_backing_file(user_file);
+ /* a wrapped count would make kmalloc_array() return ZERO_SIZE_PTR */
+ if (unlikely(ubfsec->layer_count == U32_MAX))
+ return -EOVERFLOW;
+
+ /*
+ * The final VMA only retains the lowest backing file, so record the
+ * whole chain here rather than in the mmap hook, where concurrent
+ * mappings would have to be serialized. Size it dynamically: erofs
+ * inode sharing adds a backing file without bumping s_stack_depth.
+ */
+ bfsec->layers = kmalloc_array(ubfsec->layer_count + 1,
+ sizeof(*bfsec->layers), GFP_KERNEL);
+ if (!bfsec->layers)
+ return -ENOMEM;
+
+ for (i = 0; i < ubfsec->layer_count; i++) {
+ layer = &bfsec->layers[i];
+ *layer = ubfsec->layers[i];
+ path_get(&layer->path);
+ }
+
+ /* f_path, not file_user_path(): this layer, not the top-level file */
+ layer = &bfsec->layers[i];
+ layer->path = user_file->f_path;
+ layer->mounter_sid = cred_sid(user_file->f_cred);
+ layer->fd_sid = selinux_file(user_file)->sid;
+ path_get(&layer->path);
+ bfsec->layer_count = ubfsec->layer_count + 1;
return 0;
}
+static void selinux_backing_file_free(struct file *backing_file)
+{
+ struct backing_file_security_struct *bfsec;
+
+ /* security_backing_file_free() may be called twice after an error */
+ if (!backing_file_security(backing_file))
+ return;
+
+ bfsec = selinux_backing_file(backing_file);
+ while (bfsec->layer_count)
+ path_put(&bfsec->layers[--bfsec->layer_count].path);
+ kfree(bfsec->layers);
+ bfsec->layers = NULL;
+}
+
/*
* Check whether a task has the ioctl permission and cmd
* operation to an inode.
@@ -3957,6 +4013,53 @@ static int selinux_file_ioctl_compat(str
static int default_noexec __ro_after_init;
+static u32 file_map_prot_to_av(unsigned long prot, bool shared)
+{
+ u32 av = FILE__READ;
+
+ if (shared && (prot & PROT_WRITE))
+ av |= FILE__WRITE;
+ if (prot & PROT_EXEC)
+ av |= FILE__EXECUTE;
+
+ return av;
+}
+
+static int backing_mounters_has_perm(const struct file *file, u32 av)
+{
+ const struct backing_file_security_struct *bfsec;
+ const struct backing_file_security_layer *layer;
+ struct common_audit_data ad;
+ struct inode *inode;
+ u32 i;
+ int rc;
+
+ if (WARN_ON_ONCE(!(file->f_mode & FMODE_BACKING)))
+ return -EIO;
+
+ bfsec = selinux_backing_file(file);
+ for (i = 0; i < bfsec->layer_count; i++) {
+ layer = &bfsec->layers[i];
+ inode = d_inode(layer->path.dentry);
+
+ ad.type = LSM_AUDIT_DATA_PATH;
+ ad.u.path = layer->path;
+
+ if (layer->mounter_sid != layer->fd_sid) {
+ rc = avc_has_perm(layer->mounter_sid, layer->fd_sid,
+ SECCLASS_FD, FD__USE, &ad);
+ if (rc)
+ return rc;
+ }
+
+ rc = inode_sid_has_perm(layer->mounter_sid, inode, av, &ad);
+ if (rc)
+ return rc;
+ }
+
+ return 0;
+}
+
static int __file_map_prot_check(const struct file *file, unsigned long prot,
bool shared, bool mounter_check,
bool bf_user_file)
@@ -3990,14 +4093,10 @@ static int __file_map_prot_check(const s
if (file) {
const struct cred *cred = mounter_check ?
file->f_cred : current_cred();
- /* "read" always possible, "write" only if shared */
- u32 av = FILE__READ;
- if (shared && prot_write)
- av |= FILE__WRITE;
- if (prot_exec)
- av |= FILE__EXECUTE;
- return __file_has_perm(cred, file, av, bf_user_file);
+ return __file_has_perm(cred, file,
+ file_map_prot_to_av(prot, shared),
+ bf_user_file);
}
return 0;
@@ -4092,6 +4191,7 @@ static int selinux_file_mprotect(struct
int rc;
const struct cred *cred = current_cred();
u32 sid = cred_sid(cred);
+ u32 av;
const struct file *file = vma->vm_file;
bool backing_file;
bool shared = vma->vm_flags & VM_SHARED;
@@ -4135,6 +4235,10 @@ static int selinux_file_mprotect(struct
if (rc)
return rc;
if (backing_file) {
+ rc = backing_mounters_has_perm(file,
+ FILE__EXECMOD);
+ if (rc)
+ return rc;
rc = file_has_perm(file->f_cred, file,
FILE__EXECMOD);
if (rc)
@@ -4147,6 +4251,10 @@ static int selinux_file_mprotect(struct
if (rc)
return rc;
if (backing_file) {
+ av = file_map_prot_to_av(prot, shared);
+ rc = backing_mounters_has_perm(file, av);
+ if (rc)
+ return rc;
rc = file_map_prot_check(file, prot, shared, true);
if (rc)
return rc;
@@ -7507,6 +7615,7 @@ static struct security_hook_list selinux
LSM_HOOK_INIT(file_permission, selinux_file_permission),
LSM_HOOK_INIT(file_alloc_security, selinux_file_alloc_security),
LSM_HOOK_INIT(backing_file_alloc, selinux_backing_file_alloc),
+ LSM_HOOK_INIT(backing_file_free, selinux_backing_file_free),
LSM_HOOK_INIT(file_ioctl, selinux_file_ioctl),
LSM_HOOK_INIT(file_ioctl_compat, selinux_file_ioctl_compat),
LSM_HOOK_INIT(mmap_file, selinux_mmap_file),
--- a/security/selinux/include/objsec.h
+++ b/security/selinux/include/objsec.h
@@ -86,8 +86,16 @@ struct file_security_struct {
u32 pseqno; /* Policy seqno at the time of file open */
};
+struct backing_file_security_layer {
+ struct path path; /* this layer's real path */
+ u32 mounter_sid; /* SID of the mounter that opened it */
+ u32 fd_sid; /* SID of its open file description */
+};
+
struct backing_file_security_struct {
u32 uf_sid; /* top-level user file fsec->sid */
+ u32 layer_count; /* number of intermediate backing files */
+ struct backing_file_security_layer *layers;
};
struct superblock_security_struct {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 329/438] i2c: imx: disable autosuspend on remove
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (327 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 328/438] i2c: imx: release DMA channels on probe error Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 330/438] IB/mlx4: Fix use-after-free on pkey sysfs registration failure Greg Kroah-Hartman
` (120 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Frank Li, Andi Shyti
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit e0c3e9d76adbe522dd420a766ce42d03ce887c29 upstream.
i2c_imx_probe() enables runtime PM autosuspend with
pm_runtime_use_autosuspend(). The probe error path correctly undoes
this setting with pm_runtime_dont_use_autosuspend(), but the normal
remove path only disables runtime PM.
The runtime PM API requires pm_runtime_use_autosuspend() to be undone
with pm_runtime_dont_use_autosuspend() at driver exit unless runtime PM
was enabled with devm_pm_runtime_enable(). Leaving the autosuspend flag
set therefore leaves the runtime PM state incompletely cleaned up after
the driver is unbound.
Add the missing pm_runtime_dont_use_autosuspend() call to the remove
path.
This issue was found by manual code inspection.
Fixes: 588eb93ea49f ("i2c: imx: add runtime pm support to improve the performance")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Cc: <stable@vger.kernel.org> # v4.5+
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260914091544.1667137-1-lgs201920130244@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-imx.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/i2c/busses/i2c-imx.c
+++ b/drivers/i2c/busses/i2c-imx.c
@@ -1922,6 +1922,7 @@ static void i2c_imx_remove(struct platfo
pm_runtime_put_noidle(&pdev->dev);
pm_runtime_disable(&pdev->dev);
+ pm_runtime_dont_use_autosuspend(&pdev->dev);
}
static int i2c_imx_runtime_suspend(struct device *dev)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 276/398] selinux: always fill AVC decision in avc_has_perm_noaudit()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (272 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 275/398] selinux: recheck intermediate backing files on mprotect() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 277/398] power: sequencing: dont call .post_enable() if pwrseq_unit_enable() failed Greg Kroah-Hartman
` (128 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Göttsche,
Stephen Smalley, Paul Moore
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Göttsche <cgzones@googlemail.com>
commit 8861db305103107199b1426f25fde1fb6d465583 upstream.
avc_has_perm_noaudit() is documented to return a copy of the access
decision in @avd, but its early return for an empty requested permission
set leaves the buffer untouched. All callers pass an uninitialized
stack variable and afterwards feed it to avc_audit(), and the inode hook
even stores it in the per-task decision cache.
Fill in a deny-all, audit-all decision, similar to avd_init(), so every
caller receives a defined value at no cost on the hot path.
Cc: stable@vger.kernel.org
Fixes: e6f2f381e4015386 ("selinux: replace BUG_ONs with WARN_ONs in avc.c")
Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Reviewed-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/selinux/avc.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/security/selinux/avc.c
+++ b/security/selinux/avc.c
@@ -1149,8 +1149,11 @@ inline int avc_has_perm_noaudit(u32 ssid
u32 denied;
struct avc_node *node;
- if (WARN_ON(!requested))
+ if (WARN_ON(!requested)) {
+ /* Provide a deny-all, audit-all decision to the caller. */
+ *avd = (struct av_decision){ .auditdeny = 0xffffffff };
return -EACCES;
+ }
rcu_read_lock();
node = avc_lookup(ssid, tsid, tclass);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 330/438] IB/mlx4: Fix use-after-free on pkey sysfs registration failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (328 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 329/438] i2c: imx: disable autosuspend on remove Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 331/438] IB/hfi1: Resolve the credit-return buffer through the send contexts node Greg Kroah-Hartman
` (119 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Leon Romanovsky
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
commit 1af874e9f4ce22ccf8b10ab5462f32c70d3be21a upstream.
register_pkey_tree() ignores errors from register_one_pkey_tree() and
continues registering the remaining slaves. The per-slave error path has
already released the pkey parent kobjects, but their pointers remain
stored in the device. A later device cleanup therefore passes the stale
pointers to kobject_put(), causing a use-after-free.
Clear the parent pointers after releasing a failed slave tree and skip
unregistered trees during device cleanup. This preserves the existing
best-effort registration behavior while preventing a second cleanup of
the failed tree.
Fixes: c1e7e466120b ("IB/mlx4: Add iov directory in sysfs under the ib device")
Cc: stable@vger.kernel.org
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Link: https://patch.msgid.link/20260816044510.3848996-1-shuangpeng.kernel@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/hw/mlx4/sysfs.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/infiniband/hw/mlx4/sysfs.c
+++ b/drivers/infiniband/hw/mlx4/sysfs.c
@@ -751,11 +751,13 @@ err_add:
kobject_put(p);
}
kobject_put(dev->dev_ports_parent[slave]);
+ dev->dev_ports_parent[slave] = NULL;
err_ports:
kobject_put(dev->pkeys.device_parent[slave]);
/* extra put for the device_parent create_and_add */
kobject_put(dev->pkeys.device_parent[slave]);
+ dev->pkeys.device_parent[slave] = NULL;
fail_dev:
kobject_put(dev->iov_parent);
@@ -785,6 +787,8 @@ static void unregister_pkey_tree(struct
return;
for (slave = device->dev->persist->num_vfs; slave >= 0; --slave) {
+ if (!device->pkeys.device_parent[slave])
+ continue;
list_for_each_entry_safe(p, t,
&device->pkeys.pkey_port_list[slave],
entry) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 277/398] power: sequencing: dont call .post_enable() if pwrseq_unit_enable() failed
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (273 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 276/398] selinux: always fill AVC decision in avc_has_perm_noaudit() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 278/398] power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new() Greg Kroah-Hartman
` (127 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
commit 5f90f85eae4e9d2e9628b2019870994ba830b533 upstream.
If the call to pwrseq_unit_enable() failed in pwrseq_enable(), bail out
instead of calling target->post_enable() which assumes the target was
successfully enabled.
Fixes: 249ebf3f65f8 ("power: sequencing: implement the pwrseq core")
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260909-pwrseq-kunit-v2-1-ef496afc89d2@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/power/sequencing/core.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/power/sequencing/core.c
+++ b/drivers/power/sequencing/core.c
@@ -913,6 +913,8 @@ int pwrseq_power_on(struct pwrseq_desc *
if (!ret)
desc->powered_on = true;
}
+ if (ret)
+ return ret;
if (target->post_enable) {
ret = target->post_enable(pwrseq);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 331/438] IB/hfi1: Resolve the credit-return buffer through the send contexts node
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (329 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 330/438] IB/mlx4: Fix use-after-free on pkey sysfs registration failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 332/438] IB/hfi1: Fix the PIO_CRED credit-return mmap Greg Kroah-Hartman
` (118 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shuhei Takeshita, Leon Romanovsky
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuhei Takeshita <jyohuku.alterego@gmail.com>
commit 975396b9e5a4028e649f4b9a6a5ca5dfb76a824b upstream.
hfi1_file_mmap()'s PIO_CRED case derives this context's credit-return
page offset, and the DMA handle for it, from dd->cr_base[uctxt->numa_id].
uctxt->numa_id is the node of whichever CPU the process happened to be
running on, but the entry itself lives in the credit-return allocation of
the send context's own node:
sc->hw_free = &sc->dd->cr_base[sc->node].va[gc].cr[index];
and user send contexts are allocated with sc_alloc(dd, SC_USER, ...,
dd->node), the HFI-local node. On a multi-socket host with the process
running off that node the two allocations differ, so the subtraction
produces an offset into an unrelated buffer and the DMA handle belongs to
the wrong allocation.
Use the send context's own node for all three references. The
continuation lines are reindented at the same time; they mixed spaces and
tabs.
Fixes: 7724105686e7 ("IB/hfi1: add driver files")
Cc: stable@vger.kernel.org
Signed-off-by: Shuhei Takeshita <jyohuku.alterego@gmail.com>
Link: https://patch.msgid.link/20260809032743.2671579-2-jyohuku.alterego@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/hw/hfi1/file_ops.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/drivers/infiniband/hw/hfi1/file_ops.c
+++ b/drivers/infiniband/hw/hfi1/file_ops.c
@@ -382,10 +382,10 @@ static int hfi1_file_mmap(struct file *f
* of enabled contexts > 64 and 128 respectively).
*/
cr_page_offset = ((u64)uctxt->sc->hw_free -
- (u64)dd->cr_base[uctxt->numa_id].va) &
- PAGE_MASK;
- memvirt = dd->cr_base[uctxt->numa_id].va + cr_page_offset;
- memdma = dd->cr_base[uctxt->numa_id].dma + cr_page_offset;
+ (u64)dd->cr_base[uctxt->sc->node].va) &
+ PAGE_MASK;
+ memvirt = dd->cr_base[uctxt->sc->node].va + cr_page_offset;
+ memdma = dd->cr_base[uctxt->sc->node].dma + cr_page_offset;
memlen = PAGE_SIZE;
flags &= ~VM_MAYWRITE;
flags |= VM_DONTCOPY | VM_DONTEXPAND;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 278/398] power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (274 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 277/398] power: sequencing: dont call .post_enable() if pwrseq_unit_enable() failed Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 279/398] power: sequencing: fix NULL-pointer dereference in pwrseq_device_register() Greg Kroah-Hartman
` (126 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Bartosz Golaszewski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
commit 115b303e8e093d964089ec6f3c40d984d77b33d0 upstream.
If memory allocation fails in pwrseq_unit_setup_deps(), pwrseq_unit_put()
is called to release the partially initialized unit. However, we've
never initialized unit->list and pwrseq_unit_release() will
unconditionally call list_del() on it. Initialize unit->list right after
allocating the unit struct.
Fixes: 249ebf3f65f8 ("power: sequencing: implement the pwrseq core")
Cc: stable@vger.kernel.org
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260903-pwrseq-kunit-v1-0-1f893d2cabc2%40oss.qualcomm.com?part=1
Link: https://patch.msgid.link/20260909-pwrseq-kunit-v2-2-ef496afc89d2@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/power/sequencing/core.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/power/sequencing/core.c
+++ b/drivers/power/sequencing/core.c
@@ -101,6 +101,7 @@ static struct pwrseq_unit *pwrseq_unit_n
}
kref_init(&unit->ref);
+ INIT_LIST_HEAD(&unit->list);
INIT_LIST_HEAD(&unit->deps);
unit->enable = data->enable;
unit->disable = data->disable;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 332/438] IB/hfi1: Fix the PIO_CRED credit-return mmap
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (330 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 331/438] IB/hfi1: Resolve the credit-return buffer through the send contexts node Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 333/438] selinux: preserve user SID across nested backing files Greg Kroah-Hartman
` (117 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shuhei Takeshita, Leon Romanovsky
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuhei Takeshita <jyohuku.alterego@gmail.com>
commit 62f0f34fbd2b2d5653d33d3b9d42fdcabb1c0101 upstream.
hfi1_file_mmap()'s PIO_CRED case must hand user space the single
credit-return page that holds this context's entry. That page is the
second or third page of the per-node credit-return allocation once the
hardware send context index reaches 64 or 128, so the failure below is
intermittent: when the entry lands on the first page the offset is zero
and everything works.
Two things are wrong.
First, cr_page_offset is a byte offset but .va is a struct
credit_return *, so adding it is pointer arithmetic and scales the offset
by sizeof(struct credit_return) == 64. memvirt then lands 256 KiB or
512 KiB past a 10240-byte allocation. With an IOMMU translating, that
address is inside the vmalloc range but in no vm_area, so
dma_mmap_coherent() -> iommu_dma_mmap() finds no pages, vmalloc_to_pfn()
returns page_to_pfn(NULL), and remap_pfn_range() installs a frame above
MAXPHYADDR. The first user read then takes:
psm2_ep_open_pr: Corrupted page table at address 7a14d007e000
PGD 800000013886a067 P4D 800000013886a067 PUD 13886b067 PMD 13886c067
PTE 800049168e911235
Oops: Bad pagetable: 000d [#1] SMP PTI
Second, and still wrong once the arithmetic is corrected,
dma_mmap_coherent() describes a whole coherent buffer and selects the
page within it with vma->vm_pgoff. Offsetting cpu_addr has no effect:
for a vmap'd allocation iommu_dma_mmap() uses cpu_addr only to locate the
vm_area and then maps pages[vm_pgoff], which hfi1_file_mmap() has just
set to 0. User space therefore always receives the first credit-return
page, every credit read is for the wrong context, and send PIO stalls
forever.
Use the DMA API as intended: pass the base of the allocation with its
full length and select the page with vm_pgoff. A separate length is
needed because memlen must keep describing the VMA for the existing size
check. The dma-direct path stays correct as well, since dma_direct_mmap()
adds the same vm_pgoff to the base pfn.
Tested on a Dell T7610 (Xeon E5-2650 v2, Intel IOMMU in DMA-FQ mode)
against a Threadripper PRO 3995WX peer, both Omni-Path 100. Before this
change psm2_ep_open() Oopses the kernel; with only the arithmetic
corrected psm2_ep_open() succeeds but any transfer that uses send PIO
hangs, PSM2_SDMA=2 (send PIO disabled) completing normally while
PSM2_SDMA=0 (send PIO only) hangs every time. With this change send PIO,
send DMA and the default mixed mode all work.
Fixes: 1ec82317a1da ("IB/hfi1: Use dma_mmap_coherent for matching buffers")
Cc: stable@vger.kernel.org
Signed-off-by: Shuhei Takeshita <jyohuku.alterego@gmail.com>
Link: https://patch.msgid.link/20260809032743.2671579-3-jyohuku.alterego@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/infiniband/hw/hfi1/file_ops.c | 21 ++++++++++++++++-----
1 file changed, 16 insertions(+), 5 deletions(-)
--- a/drivers/infiniband/hw/hfi1/file_ops.c
+++ b/drivers/infiniband/hw/hfi1/file_ops.c
@@ -326,6 +326,7 @@ static int hfi1_file_mmap(struct file *f
void *memvirt = NULL;
dma_addr_t memdma = 0;
u8 subctxt, mapio = 0, vmf = 0, type;
+ size_t memdmalen = 0;
ssize_t memlen = 0;
int ret = 0;
u16 ctxt;
@@ -371,7 +372,9 @@ static int hfi1_file_mmap(struct file *f
mapio = 1;
break;
case PIO_CRED: {
+ struct credit_return_base *cr = &dd->cr_base[uctxt->sc->node];
u64 cr_page_offset;
+
if (flags & VM_WRITE) {
ret = -EPERM;
goto done;
@@ -381,11 +384,18 @@ static int hfi1_file_mmap(struct file *f
* second or third page allocated for credit returns (if number
* of enabled contexts > 64 and 128 respectively).
*/
- cr_page_offset = ((u64)uctxt->sc->hw_free -
- (u64)dd->cr_base[uctxt->sc->node].va) &
+ cr_page_offset = ((u64)uctxt->sc->hw_free - (u64)cr->va) &
PAGE_MASK;
- memvirt = dd->cr_base[uctxt->sc->node].va + cr_page_offset;
- memdma = dd->cr_base[uctxt->sc->node].dma + cr_page_offset;
+ /*
+ * dma_mmap_coherent() describes the whole coherent buffer and
+ * selects the page within it with vma->vm_pgoff, so pass the
+ * base of the allocation and its length and let vm_pgoff pick
+ * the page.
+ */
+ vma->vm_pgoff = cr_page_offset >> PAGE_SHIFT;
+ memvirt = cr->va;
+ memdma = cr->dma;
+ memdmalen = TXE_NUM_CONTEXTS * sizeof(struct credit_return);
memlen = PAGE_SIZE;
flags &= ~VM_MAYWRITE;
flags |= VM_DONTCOPY | VM_DONTEXPAND;
@@ -567,7 +577,8 @@ static int hfi1_file_mmap(struct file *f
ret = 0;
} else if (memdma) {
ret = dma_mmap_coherent(&dd->pcidev->dev, vma,
- memvirt, memdma, memlen);
+ memvirt, memdma,
+ memdmalen ? memdmalen : memlen);
} else if (mapio) {
ret = io_remap_pfn_range(vma, vma->vm_start,
PFN_DOWN(memaddr),
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 279/398] power: sequencing: fix NULL-pointer dereference in pwrseq_device_register()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (275 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 278/398] power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 280/398] mmc: core: Cancel SDIO IRQ work before freeing host Greg Kroah-Hartman
` (125 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Bartosz Golaszewski
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
commit 242da4318d97380741516b595af3920207b2f0f1 upstream.
If dev_set_name() fails in pwrseq_device_register(), we jump to the
err_put_pwrseq label before initializing pwrseq->targets.
pwrseq_release() will try to iterate over targets unconditionally and
subsequently dereference an invalid pointer. Move the call to
dev_set_name() after the list head is initialized.
Fixes: 249ebf3f65f8 ("power: sequencing: implement the pwrseq core")
Cc: stable@vger.kernel.org
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260903-pwrseq-kunit-v1-0-1f893d2cabc2%40oss.qualcomm.com?part=2
Link: https://patch.msgid.link/20260909-pwrseq-kunit-v2-3-ef496afc89d2@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/power/sequencing/core.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/drivers/power/sequencing/core.c
+++ b/drivers/power/sequencing/core.c
@@ -505,10 +505,6 @@ pwrseq_device_register(const struct pwrs
*/
device_initialize(&pwrseq->dev);
- ret = dev_set_name(&pwrseq->dev, "pwrseq.%d", pwrseq->id);
- if (ret)
- goto err_put_pwrseq;
-
pwrseq->owner = config->owner ?: THIS_MODULE;
pwrseq->match = config->match;
@@ -517,6 +513,10 @@ pwrseq_device_register(const struct pwrs
INIT_LIST_HEAD(&pwrseq->targets);
INIT_LIST_HEAD(&pwrseq->units);
+ ret = dev_set_name(&pwrseq->dev, "pwrseq.%d", pwrseq->id);
+ if (ret)
+ goto err_put_pwrseq;
+
ret = pwrseq_setup_targets(config->targets, pwrseq);
if (ret)
goto err_put_pwrseq;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 333/438] selinux: preserve user SID across nested backing files
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (331 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 332/438] IB/hfi1: Fix the PIO_CRED credit-return mmap Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 334/438] selinux: recheck intermediate backing files on mprotect() Greg Kroah-Hartman
` (116 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Amir Goldstein,
Stephen Smalley, Paul Moore
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
commit 8c0c602202b9a4909b00bc3354e3c0355bc69e65 upstream.
SELinux saves the user file SID in a backing-file security blob so it
remains available after mmap() replaces vma->vm_file with a backing file.
For nested backing files (overlayfs over overlayfs, or FUSE passthrough
backed by overlayfs), user_file may itself be a backing file. Its
fsec->sid is the SID of the mounter that opened it, rather than the user
that opened the top-level file. mprotect() then checks fd { use } against
the mounter SID. This can incorrectly deny access without a domain
transition, or check the wrong target SID after one.
Copy the saved user SID when user_file is a backing file. Keep using the
regular file SID for the first backing layer.
With two nested overlayfs mounts and SELinux enforcing,
mprotect(PROT_READ) returns EACCES with an fd { use } denial against the
mounter SID. With this change, mprotect() succeeds.
Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built
SELinux policy. The original test was also repeated with Fedora Cloud
Base 44 userspace and gave the same result.
Cc: stable@vger.kernel.org
Fixes: 82544d36b172 ("selinux: fix overlayfs mmap() and mprotect() access checks")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Amir Goldstein <amir73il@gmail.com>
Reviewed-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/selinux/hooks.c | 9 ++++++++-
security/selinux/include/objsec.h | 2 +-
2 files changed, 9 insertions(+), 2 deletions(-)
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -3841,13 +3841,20 @@ static int selinux_file_alloc_security(s
return 0;
}
+static inline u32 selinux_file_user_sid(const struct file *file)
+{
+ if (unlikely(file->f_mode & FMODE_BACKING))
+ return selinux_backing_file(file)->uf_sid;
+ return selinux_file(file)->sid;
+}
+
static int selinux_backing_file_alloc(struct file *backing_file,
const struct file *user_file)
{
struct backing_file_security_struct *bfsec;
bfsec = selinux_backing_file(backing_file);
- bfsec->uf_sid = selinux_file(user_file)->sid;
+ bfsec->uf_sid = selinux_file_user_sid(user_file);
return 0;
}
--- a/security/selinux/include/objsec.h
+++ b/security/selinux/include/objsec.h
@@ -87,7 +87,7 @@ struct file_security_struct {
};
struct backing_file_security_struct {
- u32 uf_sid; /* associated user file fsec->sid */
+ u32 uf_sid; /* top-level user file fsec->sid */
};
struct superblock_security_struct {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 280/398] mmc: core: Cancel SDIO IRQ work before freeing host
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (276 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 279/398] power: sequencing: fix NULL-pointer dereference in pwrseq_device_register() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 281/398] mmc: core: Fix OF node reference leak on card add failure Greg Kroah-Hartman
` (124 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit 6feadbecdae60a6324c967f3b1493741083793a3 upstream.
A host controller that uses sdio_signal_irq() schedules host->sdio_irq_work
from its interrupt handler. That work is only cancelled on the suspend
path (mmc_sdio_suspend()), not on the remove/free path, so a worker armed
just before the controller freed its IRQ can run after
mmc_host_classdev_release() has freed the host and dereference it through
container_of().
Cancel host->sdio_irq_work in mmc_free_host(), like the existing
host->detect drain added by commit 1036f69e2513 ("mmc: core: Cancel
delayed work before releasing host").
This issue was found by an in-house static analysis tool.
Fixes: 682696605c70 ("mmc: sdio: Add API to manage SDIO IRQs from a workqueue")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/core/host.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/mmc/core/host.c
+++ b/drivers/mmc/core/host.c
@@ -693,6 +693,7 @@ EXPORT_SYMBOL(mmc_remove_host);
void mmc_free_host(struct mmc_host *host)
{
cancel_delayed_work_sync(&host->detect);
+ cancel_work_sync(&host->sdio_irq_work);
mmc_pwrseq_free(host);
put_device(&host->class_dev);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 334/438] selinux: recheck intermediate backing files on mprotect()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (332 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 333/438] selinux: preserve user SID across nested backing files Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 335/438] selinux: always fill AVC decision in avc_has_perm_noaudit() Greg Kroah-Hartman
` (115 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Stephen Smalley,
Paul Moore
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
commit 78fc54b934bfb2c18aad8154c7302067146946f9 upstream.
mprotect() can be used to bypass the SELinux checks that mmap() performs
against the intermediate layers of a stacked filesystem.
mmap() checks every backing layer as the request descends through the
stack. mprotect() only has the lowest backing file in vma->vm_file, so it
rechecks the top-level user and the lowest mounter, but skips the mounters
of every layer in between. With two nested overlayfs mounts and a policy
denying mounter_t -> middle_file_t:file { execute }, a direct
mmap(PROT_EXEC) is denied:
avc: denied { execute } for pid=71 comm="nested_exec"
path="/payload" dev="overlay" ino=9
scontext=user_u:base_r:mounter_t
tcontext=user_u:object_r:middle_file_t tclass=file permissive=0
while mmap(PROT_NONE) followed by mprotect(PROT_EXEC) succeeds.
Preserve each intermediate path, mounter SID and file-description SID in
the backing-file security blob, copying the saved entries when another
backing layer is opened. Allocate the array only for nested backing files,
and release it and the path references in the backing_file_free hook.
During mprotect(), recheck fd { use } and the requested inode permissions
for every saved mounter, and include the intermediate layers in the execmod
checks. Policy for nested stacking may then need to grant intermediate
mounters what a direct mmap() already requires, and execmod on intermediate
labels for binaries using text relocations.
Tested on arm64 QEMU with a small BusyBox initramfs and a purpose-built
SELinux policy, on a mainline tree containing
commit f2381b546e7e ("fs: fix user path of nested backing files").
Cc: stable@vger.kernel.org
Fixes: 82544d36b172 ("selinux: fix overlayfs mmap() and mprotect() access checks")
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Stephen Smalley <stephen.smalley.work@gmail.com>
[PM: subject tweak]
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/selinux/hooks.c | 141 +++++++++++++++++++++++++++++++++-----
security/selinux/include/objsec.h | 8 ++
2 files changed, 133 insertions(+), 16 deletions(-)
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -1672,26 +1672,32 @@ static int cred_has_capability(const str
return rc;
}
-/* Check whether a task has a particular permission to an inode.
- The 'adp' parameter is optional and allows other audit
- data to be passed (e.g. the dentry). */
-static int inode_has_perm(const struct cred *cred,
- struct inode *inode,
- u32 perms,
- struct common_audit_data *adp)
+/*
+ * Check whether a SID has a particular permission to an inode. The 'adp'
+ * parameter is optional and allows other audit data to be passed (e.g. the
+ * dentry).
+ */
+static int inode_sid_has_perm(u32 sid, struct inode *inode, u32 perms,
+ struct common_audit_data *adp)
{
struct inode_security_struct *isec;
- u32 sid;
if (unlikely(IS_PRIVATE(inode)))
return 0;
- sid = cred_sid(cred);
isec = selinux_inode(inode);
return avc_has_perm(sid, isec->sid, isec->sclass, perms, adp);
}
+static int inode_has_perm(const struct cred *cred,
+ struct inode *inode,
+ u32 perms,
+ struct common_audit_data *adp)
+{
+ return inode_sid_has_perm(cred_sid(cred), inode, perms, adp);
+}
+
/* Same as inode_has_perm, but pass explicit audit data containing
the dentry to help the auditing code to more easily generate the
pathname if needed. */
@@ -3852,13 +3858,63 @@ static int selinux_backing_file_alloc(st
const struct file *user_file)
{
struct backing_file_security_struct *bfsec;
+ const struct backing_file_security_struct *ubfsec;
+ struct backing_file_security_layer *layer;
+ u32 i;
bfsec = selinux_backing_file(backing_file);
bfsec->uf_sid = selinux_file_user_sid(user_file);
+ if (!(user_file->f_mode & FMODE_BACKING))
+ return 0;
+
+ ubfsec = selinux_backing_file(user_file);
+ /* a wrapped count would make kmalloc_array() return ZERO_SIZE_PTR */
+ if (unlikely(ubfsec->layer_count == U32_MAX))
+ return -EOVERFLOW;
+
+ /*
+ * The final VMA only retains the lowest backing file, so record the
+ * whole chain here rather than in the mmap hook, where concurrent
+ * mappings would have to be serialized. Size it dynamically: erofs
+ * inode sharing adds a backing file without bumping s_stack_depth.
+ */
+ bfsec->layers = kmalloc_array(ubfsec->layer_count + 1,
+ sizeof(*bfsec->layers), GFP_KERNEL);
+ if (!bfsec->layers)
+ return -ENOMEM;
+
+ for (i = 0; i < ubfsec->layer_count; i++) {
+ layer = &bfsec->layers[i];
+ *layer = ubfsec->layers[i];
+ path_get(&layer->path);
+ }
+
+ /* f_path, not file_user_path(): this layer, not the top-level file */
+ layer = &bfsec->layers[i];
+ layer->path = user_file->f_path;
+ layer->mounter_sid = cred_sid(user_file->f_cred);
+ layer->fd_sid = selinux_file(user_file)->sid;
+ path_get(&layer->path);
+ bfsec->layer_count = ubfsec->layer_count + 1;
return 0;
}
+static void selinux_backing_file_free(struct file *backing_file)
+{
+ struct backing_file_security_struct *bfsec;
+
+ /* security_backing_file_free() may be called twice after an error */
+ if (!backing_file_security(backing_file))
+ return;
+
+ bfsec = selinux_backing_file(backing_file);
+ while (bfsec->layer_count)
+ path_put(&bfsec->layers[--bfsec->layer_count].path);
+ kfree(bfsec->layers);
+ bfsec->layers = NULL;
+}
+
/*
* Check whether a task has the ioctl permission and cmd
* operation to an inode.
@@ -3976,6 +4032,53 @@ static int selinux_file_ioctl_compat(str
static int default_noexec __ro_after_init;
+static u32 file_map_prot_to_av(unsigned long prot, bool shared)
+{
+ u32 av = FILE__READ;
+
+ if (shared && (prot & PROT_WRITE))
+ av |= FILE__WRITE;
+ if (prot & PROT_EXEC)
+ av |= FILE__EXECUTE;
+
+ return av;
+}
+
+static int backing_mounters_has_perm(const struct file *file, u32 av)
+{
+ const struct backing_file_security_struct *bfsec;
+ const struct backing_file_security_layer *layer;
+ struct common_audit_data ad;
+ struct inode *inode;
+ u32 i;
+ int rc;
+
+ if (WARN_ON_ONCE(!(file->f_mode & FMODE_BACKING)))
+ return -EIO;
+
+ bfsec = selinux_backing_file(file);
+ for (i = 0; i < bfsec->layer_count; i++) {
+ layer = &bfsec->layers[i];
+ inode = d_inode(layer->path.dentry);
+
+ ad.type = LSM_AUDIT_DATA_PATH;
+ ad.u.path = layer->path;
+
+ if (layer->mounter_sid != layer->fd_sid) {
+ rc = avc_has_perm(layer->mounter_sid, layer->fd_sid,
+ SECCLASS_FD, FD__USE, &ad);
+ if (rc)
+ return rc;
+ }
+
+ rc = inode_sid_has_perm(layer->mounter_sid, inode, av, &ad);
+ if (rc)
+ return rc;
+ }
+
+ return 0;
+}
+
static int __file_map_prot_check(const struct file *file, unsigned long prot,
bool shared, bool mounter_check,
bool bf_user_file)
@@ -4009,14 +4112,10 @@ static int __file_map_prot_check(const s
if (file) {
const struct cred *cred = mounter_check ?
file->f_cred : current_cred();
- /* "read" always possible, "write" only if shared */
- u32 av = FILE__READ;
- if (shared && prot_write)
- av |= FILE__WRITE;
- if (prot_exec)
- av |= FILE__EXECUTE;
- return __file_has_perm(cred, file, av, bf_user_file);
+ return __file_has_perm(cred, file,
+ file_map_prot_to_av(prot, shared),
+ bf_user_file);
}
return 0;
@@ -4111,6 +4210,7 @@ static int selinux_file_mprotect(struct
int rc;
const struct cred *cred = current_cred();
u32 sid = cred_sid(cred);
+ u32 av;
const struct file *file = vma->vm_file;
bool backing_file;
bool shared = vma->vm_flags & VM_SHARED;
@@ -4154,6 +4254,10 @@ static int selinux_file_mprotect(struct
if (rc)
return rc;
if (backing_file) {
+ rc = backing_mounters_has_perm(file,
+ FILE__EXECMOD);
+ if (rc)
+ return rc;
rc = file_has_perm(file->f_cred, file,
FILE__EXECMOD);
if (rc)
@@ -4166,6 +4270,10 @@ static int selinux_file_mprotect(struct
if (rc)
return rc;
if (backing_file) {
+ av = file_map_prot_to_av(prot, shared);
+ rc = backing_mounters_has_perm(file, av);
+ if (rc)
+ return rc;
rc = file_map_prot_check(file, prot, shared, true);
if (rc)
return rc;
@@ -7635,6 +7743,7 @@ static struct security_hook_list selinux
LSM_HOOK_INIT(file_permission, selinux_file_permission),
LSM_HOOK_INIT(file_alloc_security, selinux_file_alloc_security),
LSM_HOOK_INIT(backing_file_alloc, selinux_backing_file_alloc),
+ LSM_HOOK_INIT(backing_file_free, selinux_backing_file_free),
LSM_HOOK_INIT(file_ioctl, selinux_file_ioctl),
LSM_HOOK_INIT(file_ioctl_compat, selinux_file_ioctl_compat),
LSM_HOOK_INIT(mmap_file, selinux_mmap_file),
--- a/security/selinux/include/objsec.h
+++ b/security/selinux/include/objsec.h
@@ -86,8 +86,16 @@ struct file_security_struct {
u32 pseqno; /* Policy seqno at the time of file open */
};
+struct backing_file_security_layer {
+ struct path path; /* this layer's real path */
+ u32 mounter_sid; /* SID of the mounter that opened it */
+ u32 fd_sid; /* SID of its open file description */
+};
+
struct backing_file_security_struct {
u32 uf_sid; /* top-level user file fsec->sid */
+ u32 layer_count; /* number of intermediate backing files */
+ struct backing_file_security_layer *layers;
};
struct superblock_security_struct {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 281/398] mmc: core: Fix OF node reference leak on card add failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (277 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 280/398] mmc: core: Cancel SDIO IRQ work before freeing host Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 282/398] mmc: hsq: Fix use-after-free in retry work Greg Kroah-Hartman
` (123 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhu Ling, Shawn Lin, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhu Ling <zhuling0805@qq.com>
commit 08b54e16d547d5c1aa61bf7a3595bb1620975eeb upstream.
mmc_of_find_child_device() returns a device node with its reference count
incremented. mmc_add_card() stores the reference before calling
device_add(), while the card is marked present only after device_add()
succeeds.
If device_add() fails, the callers release the card through
mmc_remove_card(). However, mmc_remove_card() only drops the OF node
reference for a present card, leaking the reference on this error path.
Move of_node_put() outside the present-card conditional so the reference
is released for both registered cards and card-add failures.
Fixes: 25185f3f31c9 ("mmc: Add SDIO function devicetree subnode parsing")
Cc: stable@vger.kernel.org
Signed-off-by: Zhu Ling <zhuling0805@qq.com>
Reviewed-by: Shawn Lin <shawn.lin@linux.dev>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/core/bus.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/mmc/core/bus.c
+++ b/drivers/mmc/core/bus.c
@@ -417,8 +417,8 @@ void mmc_remove_card(struct mmc_card *ca
mmc_hostname(card->host), card->rca);
}
device_del(&card->dev);
- of_node_put(card->dev.of_node);
}
+ of_node_put(card->dev.of_node);
if (host->cqe_enabled) {
host->cqe_ops->cqe_disable(host);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 335/438] selinux: always fill AVC decision in avc_has_perm_noaudit()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (333 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 334/438] selinux: recheck intermediate backing files on mprotect() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 336/438] power: sequencing: dont call .post_enable() if pwrseq_unit_enable() failed Greg Kroah-Hartman
` (114 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Göttsche,
Stephen Smalley, Paul Moore
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Göttsche <cgzones@googlemail.com>
commit 8861db305103107199b1426f25fde1fb6d465583 upstream.
avc_has_perm_noaudit() is documented to return a copy of the access
decision in @avd, but its early return for an empty requested permission
set leaves the buffer untouched. All callers pass an uninitialized
stack variable and afterwards feed it to avc_audit(), and the inode hook
even stores it in the per-task decision cache.
Fill in a deny-all, audit-all decision, similar to avd_init(), so every
caller receives a defined value at no cost on the hot path.
Cc: stable@vger.kernel.org
Fixes: e6f2f381e4015386 ("selinux: replace BUG_ONs with WARN_ONs in avc.c")
Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Reviewed-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
security/selinux/avc.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/security/selinux/avc.c
+++ b/security/selinux/avc.c
@@ -1150,8 +1150,11 @@ inline int avc_has_perm_noaudit(u32 ssid
u32 denied;
struct avc_node *node;
- if (WARN_ON(!requested))
+ if (WARN_ON(!requested)) {
+ /* Provide a deny-all, audit-all decision to the caller. */
+ *avd = (struct av_decision){ .auditdeny = 0xffffffff };
return -EACCES;
+ }
rcu_read_lock();
node = avc_lookup(ssid, tsid, tclass);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 282/398] mmc: hsq: Fix use-after-free in retry work
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (278 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 281/398] mmc: core: Fix OF node reference leak on card add failure Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 283/398] mmc: mmci: Fix use-after-free in busy-timeout work Greg Kroah-Hartman
` (122 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit 5d132990475f02cfa1debe03d50b479432864ebd upstream.
mmc_hsq_pump_requests() queues retry_work when request_atomic() returns
-EBUSY; today sdhci-sprd is the only consumer that implements
request_atomic(). The work is embedded in a devm-allocated mmc_hsq, but
is never cancelled during driver removal. Work still pending at unbind
can therefore run after the devm allocation has been released and
dereference hsq->mmc and hsq->mrq.
Use devm_work_autocancel() to cancel and drain retry_work before the devm
allocation is released. By the time devres cleanup begins,
mmc_remove_host() has already stopped the host, so no new requests can
arm the work.
This issue was found by an in-house static analysis tool.
Fixes: 6db96e5810e0 ("mmc: host: Introduce the request_atomic() for the host")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/mmc_hsq.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
--- a/drivers/mmc/host/mmc_hsq.c
+++ b/drivers/mmc/host/mmc_hsq.c
@@ -7,6 +7,7 @@
* Author: Baolin Wang <baolin.wang@linaro.org>
*/
+#include <linux/devm-helpers.h>
#include <linux/mmc/card.h>
#include <linux/mmc/host.h>
#include <linux/module.h>
@@ -345,6 +346,7 @@ static const struct mmc_cqe_ops mmc_hsq_
int mmc_hsq_init(struct mmc_hsq *hsq, struct mmc_host *mmc)
{
+ int ret;
int i;
hsq->num_slots = HSQ_NUM_SLOTS;
hsq->next_tag = HSQ_INVALID_TAG;
@@ -363,7 +365,11 @@ int mmc_hsq_init(struct mmc_hsq *hsq, st
for (i = 0; i < HSQ_NUM_SLOTS; i++)
hsq->tag_slot[i] = HSQ_INVALID_TAG;
- INIT_WORK(&hsq->retry_work, mmc_hsq_retry_handler);
+ ret = devm_work_autocancel(mmc_dev(mmc), &hsq->retry_work,
+ mmc_hsq_retry_handler);
+ if (ret)
+ return ret;
+
spin_lock_init(&hsq->lock);
init_waitqueue_head(&hsq->wait_queue);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 336/438] power: sequencing: dont call .post_enable() if pwrseq_unit_enable() failed
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (334 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 335/438] selinux: always fill AVC decision in avc_has_perm_noaudit() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 337/438] power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new() Greg Kroah-Hartman
` (113 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
commit 5f90f85eae4e9d2e9628b2019870994ba830b533 upstream.
If the call to pwrseq_unit_enable() failed in pwrseq_enable(), bail out
instead of calling target->post_enable() which assumes the target was
successfully enabled.
Fixes: 249ebf3f65f8 ("power: sequencing: implement the pwrseq core")
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260909-pwrseq-kunit-v2-1-ef496afc89d2@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/power/sequencing/core.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/power/sequencing/core.c
+++ b/drivers/power/sequencing/core.c
@@ -912,6 +912,8 @@ int pwrseq_power_on(struct pwrseq_desc *
if (!ret)
desc->powered_on = true;
}
+ if (ret)
+ return ret;
if (target->post_enable) {
ret = target->post_enable(pwrseq);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 283/398] mmc: mmci: Fix use-after-free in busy-timeout work
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (279 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 282/398] mmc: hsq: Fix use-after-free in retry work Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 284/398] mmc: mxcmmc: cancel data work and watchdog on remove Greg Kroah-Hartman
` (121 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Linus Walleij, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit 2b19cf3e50cddaff07b657dae1a8f30f06032852 upstream.
ux500_busy_complete() can queue ux500_busy_timeout_work for an R1b
command, but mmci_remove() never cancels it. The work can subsequently
dereference the devm-allocated mmci_host after it has been released.
Mask the controller interrupts and disable the delayed work during
removal. This drains any queued instance and stops an IRQ handler that
is still in progress from queueing the work again once it has been
disabled.
This issue was found by an in-house static analysis tool.
Fixes: b1a665932dc2 ("mmc: mmci: Add support for SW busy-end timeouts")
Cc: stable@vger.kernel.org # v6.10+
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/mmci.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/mmc/host/mmci.c
+++ b/drivers/mmc/host/mmci.c
@@ -2511,6 +2511,9 @@ static void mmci_remove(struct amba_devi
writel(0, host->base + MMCICOMMAND);
writel(0, host->base + MMCIDATACTRL);
+ if (variant->busy_detect)
+ disable_delayed_work_sync(&host->ux500_busy_timeout_work);
+
mmci_dma_release(host);
clk_disable_unprepare(host->clk);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 337/438] power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (335 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 336/438] power: sequencing: dont call .post_enable() if pwrseq_unit_enable() failed Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 338/438] power: sequencing: fix NULL-pointer dereference in pwrseq_device_register() Greg Kroah-Hartman
` (112 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
commit 115b303e8e093d964089ec6f3c40d984d77b33d0 upstream.
If memory allocation fails in pwrseq_unit_setup_deps(), pwrseq_unit_put()
is called to release the partially initialized unit. However, we've
never initialized unit->list and pwrseq_unit_release() will
unconditionally call list_del() on it. Initialize unit->list right after
allocating the unit struct.
Fixes: 249ebf3f65f8 ("power: sequencing: implement the pwrseq core")
Cc: stable@vger.kernel.org
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260903-pwrseq-kunit-v1-0-1f893d2cabc2%40oss.qualcomm.com?part=1
Link: https://patch.msgid.link/20260909-pwrseq-kunit-v2-2-ef496afc89d2@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/power/sequencing/core.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/power/sequencing/core.c
+++ b/drivers/power/sequencing/core.c
@@ -101,6 +101,7 @@ static struct pwrseq_unit *pwrseq_unit_n
}
kref_init(&unit->ref);
+ INIT_LIST_HEAD(&unit->list);
INIT_LIST_HEAD(&unit->deps);
unit->enable = data->enable;
unit->disable = data->disable;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 284/398] mmc: mxcmmc: cancel data work and watchdog on remove
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (280 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 283/398] mmc: mmci: Fix use-after-free in busy-timeout work Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 285/398] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 Greg Kroah-Hartman
` (120 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit d3a421c82412344022982d5b91ba23194a0a6f29 upstream.
mxcmci_remove() frees the host through the devm tail, but neither it nor
mmc_remove_host() drains the driver's own asynchronous state.
host->watchdog, a 10 s timer armed on the DMA path in mxcmci_setup_data(),
is deleted only by the DMA- and IRQ-complete paths, which the remove path
does not explicitly drain; it can therefore fire after the host is freed
and dereference it in mxcmci_watchdog(). host->datawork, armed from the
IRQ handler on the PIO path, is not cancelled by the remove path either.
Free the devm-registered IRQ, then cancel datawork and delete the watchdog
in mxcmci_remove(), before dma_release_channel(). Freeing the IRQ first
keeps a trailing handler from re-arming datawork between the cancel and
the host free. Both callbacks are non-self-rearming.
This issue was found by an in-house static analysis tool.
Fixes: f6ad0a481342 ("mmc: mxcmmc: fix bug that may block a data transfer forever")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/mxcmmc.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/mmc/host/mxcmmc.c
+++ b/drivers/mmc/host/mxcmmc.c
@@ -1173,6 +1173,10 @@ static void mxcmci_remove(struct platfor
mmc_remove_host(mmc);
+ devm_free_irq(&pdev->dev, platform_get_irq(pdev, 0), host);
+ cancel_work_sync(&host->datawork);
+ timer_delete_sync(&host->watchdog);
+
if (host->pdata && host->pdata->exit)
host->pdata->exit(&pdev->dev, mmc);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 338/438] power: sequencing: fix NULL-pointer dereference in pwrseq_device_register()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (336 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 337/438] power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new() Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 339/438] mmc: core: Cancel SDIO IRQ work before freeing host Greg Kroah-Hartman
` (111 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Bartosz Golaszewski
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
commit 242da4318d97380741516b595af3920207b2f0f1 upstream.
If dev_set_name() fails in pwrseq_device_register(), we jump to the
err_put_pwrseq label before initializing pwrseq->targets.
pwrseq_release() will try to iterate over targets unconditionally and
subsequently dereference an invalid pointer. Move the call to
dev_set_name() after the list head is initialized.
Fixes: 249ebf3f65f8 ("power: sequencing: implement the pwrseq core")
Cc: stable@vger.kernel.org
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260903-pwrseq-kunit-v1-0-1f893d2cabc2%40oss.qualcomm.com?part=2
Link: https://patch.msgid.link/20260909-pwrseq-kunit-v2-3-ef496afc89d2@oss.qualcomm.com
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/power/sequencing/core.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
--- a/drivers/power/sequencing/core.c
+++ b/drivers/power/sequencing/core.c
@@ -505,10 +505,6 @@ pwrseq_device_register(const struct pwrs
*/
device_initialize(&pwrseq->dev);
- ret = dev_set_name(&pwrseq->dev, "pwrseq.%d", pwrseq->id);
- if (ret)
- goto err_put_pwrseq;
-
pwrseq->owner = config->owner ?: THIS_MODULE;
pwrseq->match = config->match;
@@ -517,6 +513,10 @@ pwrseq_device_register(const struct pwrs
INIT_LIST_HEAD(&pwrseq->targets);
INIT_LIST_HEAD(&pwrseq->units);
+ ret = dev_set_name(&pwrseq->dev, "pwrseq.%d", pwrseq->id);
+ if (ret)
+ goto err_put_pwrseq;
+
ret = pwrseq_setup_targets(config->targets, pwrseq);
if (ret)
goto err_put_pwrseq;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 285/398] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (281 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 284/398] mmc: mxcmmc: cancel data work and watchdog on remove Greg Kroah-Hartman
@ 2026-09-23 14:05 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 286/398] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources Greg Kroah-Hartman
` (119 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:05 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Florian Maillard, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Maillard <florian.maillard@mailoo.org>
commit 9c182bc5d7817437a7d04ab96133f9191846d93d upstream.
The Realtek RTS522A card reader in the Lenovo ThinkPad X260
(subsystem 17aa:504a) incorrectly reports inserted SD cards as
write-protected.
This causes the MMC core to expose the card as read-only:
mmcblk0: mmc0:aaaa SN256 238 GiB (ro)
and /sys/block/mmcblk0/ro reports 1.
Setting MMC_CAP2_NO_WRITE_PROTECT makes the card writable again.
Limit the quirk to the affected Lenovo subsystem.
Assisted-by: ChatGPT:GPT-5.6 Sol
Signed-off-by: Florian Maillard <florian.maillard@mailoo.org>
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/rtsx_pci_sdmmc.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/drivers/mmc/host/rtsx_pci_sdmmc.c
+++ b/drivers/mmc/host/rtsx_pci_sdmmc.c
@@ -1501,6 +1501,11 @@ static void realtek_init_host(struct rea
mmc->caps = mmc->caps | MMC_CAP_AGGRESSIVE_PM;
mmc->caps2 = MMC_CAP2_NO_PRESCAN_POWERUP | MMC_CAP2_FULL_PWR_CYCLE |
MMC_CAP2_NO_SDIO;
+
+ if (pcr->pci->device == 0x522a &&
+ pcr->pci->subsystem_vendor == PCI_VENDOR_ID_LENOVO &&
+ pcr->pci->subsystem_device == 0x504a)
+ mmc->caps2 |= MMC_CAP2_NO_WRITE_PROTECT;
mmc->max_current_330 = 400;
mmc->max_current_180 = 800;
mmc->ops = &realtek_pci_sdmmc_ops;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 339/438] mmc: core: Cancel SDIO IRQ work before freeing host
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (337 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 7.2 338/438] power: sequencing: fix NULL-pointer dereference in pwrseq_device_register() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 340/438] mmc: core: Fix OF node reference leak on card add failure Greg Kroah-Hartman
` (110 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit 6feadbecdae60a6324c967f3b1493741083793a3 upstream.
A host controller that uses sdio_signal_irq() schedules host->sdio_irq_work
from its interrupt handler. That work is only cancelled on the suspend
path (mmc_sdio_suspend()), not on the remove/free path, so a worker armed
just before the controller freed its IRQ can run after
mmc_host_classdev_release() has freed the host and dereference it through
container_of().
Cancel host->sdio_irq_work in mmc_free_host(), like the existing
host->detect drain added by commit 1036f69e2513 ("mmc: core: Cancel
delayed work before releasing host").
This issue was found by an in-house static analysis tool.
Fixes: 682696605c70 ("mmc: sdio: Add API to manage SDIO IRQs from a workqueue")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/core/host.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/mmc/core/host.c
+++ b/drivers/mmc/core/host.c
@@ -698,6 +698,7 @@ EXPORT_SYMBOL(mmc_remove_host);
void mmc_free_host(struct mmc_host *host)
{
cancel_delayed_work_sync(&host->detect);
+ cancel_work_sync(&host->sdio_irq_work);
mmc_pwrseq_free(host);
put_device(&host->class_dev);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 286/398] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (282 preceding siblings ...)
2026-09-23 14:05 ` [PATCH 6.18 285/398] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 287/398] mmc: sdio_uart: fix xmit_fifo leak when the port table is full Greg Kroah-Hartman
` (118 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit 4396d70bb7fec531bcf934fed016b2f3300c670b upstream.
Probe failure and removal leave SDHCI child devices registered after the
parent clock and managed resources are released.
Unregister the OF children in reverse order before disabling the parent
clock on both paths. Use of_platform_device_destroy() because manual
child creation does not set the flag required by of_platform_depopulate().
This issue was identified during our ongoing static-analysis research
while reviewing kernel code.
Fixes: bb7b8ec62dfb ("mmc: sdhci-of-aspeed: Add support for the ASPEED SD controller")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Assisted-by: OpenAI:GPT-5.6
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci-of-aspeed.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/drivers/mmc/host/sdhci-of-aspeed.c
+++ b/drivers/mmc/host/sdhci-of-aspeed.c
@@ -555,12 +555,14 @@ static int aspeed_sdc_probe(struct platf
if (!cpdev) {
of_node_put(child);
ret = -ENODEV;
- goto err_clk;
+ goto err_children;
}
}
return 0;
+err_children:
+ device_for_each_child_reverse(&pdev->dev, NULL, of_platform_device_destroy);
err_clk:
clk_disable_unprepare(sdc->clk);
return ret;
@@ -570,6 +572,7 @@ static void aspeed_sdc_remove(struct pla
{
struct aspeed_sdc *sdc = dev_get_drvdata(&pdev->dev);
+ device_for_each_child_reverse(&pdev->dev, NULL, of_platform_device_destroy);
clk_disable_unprepare(sdc->clk);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 340/438] mmc: core: Fix OF node reference leak on card add failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (338 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 339/438] mmc: core: Cancel SDIO IRQ work before freeing host Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 341/438] mmc: hsq: Fix use-after-free in retry work Greg Kroah-Hartman
` (109 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhu Ling, Shawn Lin, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhu Ling <zhuling0805@qq.com>
commit 08b54e16d547d5c1aa61bf7a3595bb1620975eeb upstream.
mmc_of_find_child_device() returns a device node with its reference count
incremented. mmc_add_card() stores the reference before calling
device_add(), while the card is marked present only after device_add()
succeeds.
If device_add() fails, the callers release the card through
mmc_remove_card(). However, mmc_remove_card() only drops the OF node
reference for a present card, leaking the reference on this error path.
Move of_node_put() outside the present-card conditional so the reference
is released for both registered cards and card-add failures.
Fixes: 25185f3f31c9 ("mmc: Add SDIO function devicetree subnode parsing")
Cc: stable@vger.kernel.org
Signed-off-by: Zhu Ling <zhuling0805@qq.com>
Reviewed-by: Shawn Lin <shawn.lin@linux.dev>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/core/bus.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/mmc/core/bus.c
+++ b/drivers/mmc/core/bus.c
@@ -417,8 +417,8 @@ void mmc_remove_card(struct mmc_card *ca
mmc_hostname(card->host), card->rca);
}
device_del(&card->dev);
- of_node_put(card->dev.of_node);
}
+ of_node_put(card->dev.of_node);
if (host->cqe_enabled) {
host->cqe_ops->cqe_disable(host);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 287/398] mmc: sdio_uart: fix xmit_fifo leak when the port table is full
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (283 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 286/398] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 288/398] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt Greg Kroah-Hartman
` (117 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Gu <ustc.gu@gmail.com>
commit 53823e25793a97d07e6e98e0904bbf74cac8bc76 upstream.
sdio_uart_add_port() allocates the transmit fifo before claiming a
slot in sdio_uart_table[]. When all UART_NR slots are taken, it
returns -EBUSY with the fifo still allocated, but the probe error
path only kfree()s the port, leaking the transmit fifo.
Free the fifo in the failure path of sdio_uart_add_port() itself so
the function retains nothing on error.
Fixes: 8b197a5ce7a7 ("sdio_uart: Use kfifo instead of the messy circ stuff")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/core/sdio_uart.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/mmc/core/sdio_uart.c
+++ b/drivers/mmc/core/sdio_uart.c
@@ -104,6 +104,9 @@ static int sdio_uart_add_port(struct sdi
}
spin_unlock(&sdio_uart_table_lock);
+ if (ret)
+ kfifo_free(&port->xmit_fifo);
+
return ret;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 341/438] mmc: hsq: Fix use-after-free in retry work
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (339 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 340/438] mmc: core: Fix OF node reference leak on card add failure Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 342/438] mmc: mmci: Fix use-after-free in busy-timeout work Greg Kroah-Hartman
` (108 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit 5d132990475f02cfa1debe03d50b479432864ebd upstream.
mmc_hsq_pump_requests() queues retry_work when request_atomic() returns
-EBUSY; today sdhci-sprd is the only consumer that implements
request_atomic(). The work is embedded in a devm-allocated mmc_hsq, but
is never cancelled during driver removal. Work still pending at unbind
can therefore run after the devm allocation has been released and
dereference hsq->mmc and hsq->mrq.
Use devm_work_autocancel() to cancel and drain retry_work before the devm
allocation is released. By the time devres cleanup begins,
mmc_remove_host() has already stopped the host, so no new requests can
arm the work.
This issue was found by an in-house static analysis tool.
Fixes: 6db96e5810e0 ("mmc: host: Introduce the request_atomic() for the host")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/mmc_hsq.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
--- a/drivers/mmc/host/mmc_hsq.c
+++ b/drivers/mmc/host/mmc_hsq.c
@@ -7,6 +7,7 @@
* Author: Baolin Wang <baolin.wang@linaro.org>
*/
+#include <linux/devm-helpers.h>
#include <linux/mmc/card.h>
#include <linux/mmc/host.h>
#include <linux/module.h>
@@ -345,6 +346,7 @@ static const struct mmc_cqe_ops mmc_hsq_
int mmc_hsq_init(struct mmc_hsq *hsq, struct mmc_host *mmc)
{
+ int ret;
int i;
hsq->num_slots = HSQ_NUM_SLOTS;
hsq->next_tag = HSQ_INVALID_TAG;
@@ -363,7 +365,11 @@ int mmc_hsq_init(struct mmc_hsq *hsq, st
for (i = 0; i < HSQ_NUM_SLOTS; i++)
hsq->tag_slot[i] = HSQ_INVALID_TAG;
- INIT_WORK(&hsq->retry_work, mmc_hsq_retry_handler);
+ ret = devm_work_autocancel(mmc_dev(mmc), &hsq->retry_work,
+ mmc_hsq_retry_handler);
+ if (ret)
+ return ret;
+
spin_lock_init(&hsq->lock);
init_waitqueue_head(&hsq->wait_queue);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 288/398] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (284 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 287/398] mmc: sdio_uart: fix xmit_fifo leak when the port table is full Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 289/398] mmc: spi: reset bytes_xfered before retrying CRC failures Greg Kroah-Hartman
` (116 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
commit d5ea0d226e8f0801d78702142a124d78c317d822 upstream.
The threaded IRQ handler can run before devm_request_threaded_irq()
returns, but thread_lock was initialized afterwards. Initialize it before
requesting either interrupt.
Fixes: 8047310ee984 ("mmc: sh_mmcif: fix a race, causing an Oops on SMP")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sh_mmcif.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
--- a/drivers/mmc/host/sh_mmcif.c
+++ b/drivers/mmc/host/sh_mmcif.c
@@ -1462,6 +1462,7 @@ static int sh_mmcif_probe(struct platfor
host->pd = pdev;
spin_lock_init(&host->lock);
+ mutex_init(&host->thread_lock);
mmc->ops = &sh_mmcif_ops;
sh_mmcif_init_ocr(host);
@@ -1520,8 +1521,6 @@ static int sh_mmcif_probe(struct platfor
}
}
- mutex_init(&host->thread_lock);
-
ret = mmc_add_host(mmc);
if (ret < 0)
goto err_clk;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 342/438] mmc: mmci: Fix use-after-free in busy-timeout work
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (340 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 341/438] mmc: hsq: Fix use-after-free in retry work Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 343/438] mmc: mxcmmc: cancel data work and watchdog on remove Greg Kroah-Hartman
` (107 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Linus Walleij, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit 2b19cf3e50cddaff07b657dae1a8f30f06032852 upstream.
ux500_busy_complete() can queue ux500_busy_timeout_work for an R1b
command, but mmci_remove() never cancels it. The work can subsequently
dereference the devm-allocated mmci_host after it has been released.
Mask the controller interrupts and disable the delayed work during
removal. This drains any queued instance and stops an IRQ handler that
is still in progress from queueing the work again once it has been
disabled.
This issue was found by an in-house static analysis tool.
Fixes: b1a665932dc2 ("mmc: mmci: Add support for SW busy-end timeouts")
Cc: stable@vger.kernel.org # v6.10+
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/mmci.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/mmc/host/mmci.c
+++ b/drivers/mmc/host/mmci.c
@@ -2511,6 +2511,9 @@ static void mmci_remove(struct amba_devi
writel(0, host->base + MMCICOMMAND);
writel(0, host->base + MMCIDATACTRL);
+ if (variant->busy_detect)
+ disable_delayed_work_sync(&host->ux500_busy_timeout_work);
+
mmci_dma_release(host);
clk_disable_unprepare(host->clk);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 289/398] mmc: spi: reset bytes_xfered before retrying CRC failures
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (285 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 288/398] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 290/398] mmc: sdhci_am654: Move tuning_loop to local variable Greg Kroah-Hartman
` (115 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Rao, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xu Rao <raoxu@uniontech.com>
commit 8b0cc8707f65e0f51912e764e1b309b2559db1ec upstream.
mmc_spi_data_do() updates data->bytes_xfered after each block has been
transferred successfully. If a later block in the same data request
fails with a CRC error, data->bytes_xfered may therefore contain the
number of bytes completed before the failing block.
mmc_spi_request() has a private recovery path for such CRC failures. It
sends STOP_TRANSMISSION, clears data->error and jumps back to
crc_recover to issue the same command and data request again. However,
it does not clear data->bytes_xfered before the retry.
If the retry succeeds, the request is completed with the bytes from the
failed attempt still included in data->bytes_xfered. For a multi-block
request this can make the completed request report more bytes than were
transferred by the successful retry, and can even exceed the request size
when most blocks completed before the CRC error.
This is most likely to be observed on MMC-over-SPI systems where long
multi-block transfers occasionally hit a data CRC error but the
mmc_spi-internal retry succeeds. The data itself is retried, but the
completion accounting is not.
Clear data->bytes_xfered together with data->error before repeating the
request so the final completion reports only the bytes transferred by the
successful attempt.
Fixes: 061c6c847eeb ("mmc_spi: Recover from CRC errors for r/w operation over SPI.")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/mmc_spi.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/mmc/host/mmc_spi.c
+++ b/drivers/mmc/host/mmc_spi.c
@@ -952,6 +952,7 @@ crc_recover:
status = mmc_spi_command_send(host, mrq, &stop, 0);
crc_retry--;
mrq->data->error = 0;
+ mrq->data->bytes_xfered = 0;
goto crc_recover;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 343/438] mmc: mxcmmc: cancel data work and watchdog on remove
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (341 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 342/438] mmc: mmci: Fix use-after-free in busy-timeout work Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 344/438] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 Greg Kroah-Hartman
` (106 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit d3a421c82412344022982d5b91ba23194a0a6f29 upstream.
mxcmci_remove() frees the host through the devm tail, but neither it nor
mmc_remove_host() drains the driver's own asynchronous state.
host->watchdog, a 10 s timer armed on the DMA path in mxcmci_setup_data(),
is deleted only by the DMA- and IRQ-complete paths, which the remove path
does not explicitly drain; it can therefore fire after the host is freed
and dereference it in mxcmci_watchdog(). host->datawork, armed from the
IRQ handler on the PIO path, is not cancelled by the remove path either.
Free the devm-registered IRQ, then cancel datawork and delete the watchdog
in mxcmci_remove(), before dma_release_channel(). Freeing the IRQ first
keeps a trailing handler from re-arming datawork between the cancel and
the host free. Both callbacks are non-self-rearming.
This issue was found by an in-house static analysis tool.
Fixes: f6ad0a481342 ("mmc: mxcmmc: fix bug that may block a data transfer forever")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/mxcmmc.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/mmc/host/mxcmmc.c
+++ b/drivers/mmc/host/mxcmmc.c
@@ -1173,6 +1173,10 @@ static void mxcmci_remove(struct platfor
mmc_remove_host(mmc);
+ devm_free_irq(&pdev->dev, platform_get_irq(pdev, 0), host);
+ cancel_work_sync(&host->datawork);
+ timer_delete_sync(&host->watchdog);
+
if (host->pdata && host->pdata->exit)
host->pdata->exit(&pdev->dev, mmc);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 290/398] mmc: sdhci_am654: Move tuning_loop to local variable
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (286 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 289/398] mmc: spi: reset bytes_xfered before retrying CRC failures Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 291/398] mmc: sdhci_am654: Reset command and data lines on failed tuning Greg Kroah-Hartman
` (114 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Diogo Ivo (Schneider Electric),
Judith Mendez, Adrian Hunter, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
commit ff894dced1a7ad7523f9c65dbdb53d02474cca0f upstream.
The tuning_loop field in struct sdhci_am654_data is only used within
sdhci_am654_platform_execute_tuning() as a loop counter that is
initialized to 0 in sdhci_am654_init(). Since it shouldn't persist across
function calls, otherwise every failure expends its "budget", move it to a
local variable and remove the struct field along with the now-unnecessary
initialization.
Signed-off-by: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
Reviewed-by: Judith Mendez <jm@ti.com>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Fixes: de31f6ab68a3 ("mmc: sdhci_am654: Reset Command and Data line after tuning")
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci_am654.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
--- a/drivers/mmc/host/sdhci_am654.c
+++ b/drivers/mmc/host/sdhci_am654.c
@@ -151,7 +151,6 @@ struct sdhci_am654_data {
u32 flags;
u32 quirks;
bool dll_enable;
- u32 tuning_loop;
#define SDHCI_AM654_QUIRK_FORCE_CDTEST BIT(0)
#define SDHCI_AM654_QUIRK_SUPPRESS_V1P8_ENA BIT(1)
@@ -576,13 +575,14 @@ static int sdhci_am654_platform_execute_
struct sdhci_am654_data *sdhci_am654 = sdhci_pltfm_priv(pltfm_host);
unsigned char timing = host->mmc->ios.timing;
struct device *dev = mmc_dev(host->mmc);
+ unsigned int tuning_loop = 0;
int itapdly;
do {
itapdly = sdhci_am654_do_tuning(host, opcode);
if (itapdly >= 0)
break;
- } while (++sdhci_am654->tuning_loop < RETRY_TUNING_MAX);
+ } while (++tuning_loop < RETRY_TUNING_MAX);
if (itapdly < 0) {
dev_err(dev, "Failed to find itapdly, fail tuning\n");
@@ -806,9 +806,6 @@ static int sdhci_am654_init(struct sdhci
regmap_update_bits(sdhci_am654->base, CTL_CFG_3, TUNINGFORSDR50_MASK,
TUNINGFORSDR50_MASK);
- /* Use to re-execute tuning */
- sdhci_am654->tuning_loop = 0;
-
ret = sdhci_setup_host(host);
if (ret)
return ret;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 344/438] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (342 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 343/438] mmc: mxcmmc: cancel data work and watchdog on remove Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 345/438] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources Greg Kroah-Hartman
` (105 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Florian Maillard, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Maillard <florian.maillard@mailoo.org>
commit 9c182bc5d7817437a7d04ab96133f9191846d93d upstream.
The Realtek RTS522A card reader in the Lenovo ThinkPad X260
(subsystem 17aa:504a) incorrectly reports inserted SD cards as
write-protected.
This causes the MMC core to expose the card as read-only:
mmcblk0: mmc0:aaaa SN256 238 GiB (ro)
and /sys/block/mmcblk0/ro reports 1.
Setting MMC_CAP2_NO_WRITE_PROTECT makes the card writable again.
Limit the quirk to the affected Lenovo subsystem.
Assisted-by: ChatGPT:GPT-5.6 Sol
Signed-off-by: Florian Maillard <florian.maillard@mailoo.org>
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/rtsx_pci_sdmmc.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/drivers/mmc/host/rtsx_pci_sdmmc.c
+++ b/drivers/mmc/host/rtsx_pci_sdmmc.c
@@ -1425,6 +1425,11 @@ static void realtek_init_host(struct rea
mmc->caps = mmc->caps | MMC_CAP_AGGRESSIVE_PM;
mmc->caps2 = MMC_CAP2_NO_PRESCAN_POWERUP | MMC_CAP2_FULL_PWR_CYCLE |
MMC_CAP2_NO_SDIO;
+
+ if (pcr->pci->device == 0x522a &&
+ pcr->pci->subsystem_vendor == PCI_VENDOR_ID_LENOVO &&
+ pcr->pci->subsystem_device == 0x504a)
+ mmc->caps2 |= MMC_CAP2_NO_WRITE_PROTECT;
mmc->max_current_330 = 400;
mmc->max_current_180 = 800;
mmc->ops = &realtek_pci_sdmmc_ops;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 291/398] mmc: sdhci_am654: Reset command and data lines on failed tuning
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (287 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 290/398] mmc: sdhci_am654: Move tuning_loop to local variable Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 292/398] mmc: sdhci_am654: Clear ITAPDLY on tuning failure Greg Kroah-Hartman
` (113 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Diogo Ivo (Schneider Electric),
Judith Mendez, Adrian Hunter, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
commit 7197d9107d9545730153b82ea5a411c5208b443f upstream.
The CMD/DATA reset after tuning should be performed regardless of
whether tuning succeeded or failed, since tuning data may remain in
the buffer in either case. Move the error return after the reset so
that the controller is always cleaned up.
Fixes: de31f6ab68a3 ("mmc: sdhci_am654: Reset Command and Data line after tuning")
Cc: stable@vger.kernel.org
Signed-off-by: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
Reviewed-by: Judith Mendez <jm@ti.com>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci_am654.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
--- a/drivers/mmc/host/sdhci_am654.c
+++ b/drivers/mmc/host/sdhci_am654.c
@@ -442,15 +442,13 @@ static int sdhci_am654_execute_tuning(st
struct sdhci_host *host = mmc_priv(mmc);
int err = sdhci_execute_tuning(mmc, opcode);
- if (err)
- return err;
/*
* Tuning data remains in the buffer after tuning.
* Do a command and data reset to get rid of it
*/
sdhci_reset(host, SDHCI_RESET_CMD | SDHCI_RESET_DATA);
- return 0;
+ return err;
}
static u32 sdhci_am654_cqhci_irq(struct sdhci_host *host, u32 intmask)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 345/438] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (343 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 344/438] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 346/438] mmc: sdio_uart: fix xmit_fifo leak when the port table is full Greg Kroah-Hartman
` (104 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
commit 4396d70bb7fec531bcf934fed016b2f3300c670b upstream.
Probe failure and removal leave SDHCI child devices registered after the
parent clock and managed resources are released.
Unregister the OF children in reverse order before disabling the parent
clock on both paths. Use of_platform_device_destroy() because manual
child creation does not set the flag required by of_platform_depopulate().
This issue was identified during our ongoing static-analysis research
while reviewing kernel code.
Fixes: bb7b8ec62dfb ("mmc: sdhci-of-aspeed: Add support for the ASPEED SD controller")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Assisted-by: OpenAI:GPT-5.6
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci-of-aspeed.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
--- a/drivers/mmc/host/sdhci-of-aspeed.c
+++ b/drivers/mmc/host/sdhci-of-aspeed.c
@@ -560,12 +560,14 @@ static int aspeed_sdc_probe(struct platf
cpdev = of_platform_device_create(child, NULL, &pdev->dev);
if (!cpdev) {
ret = -ENODEV;
- goto err_clk;
+ goto err_children;
}
}
return 0;
+err_children:
+ device_for_each_child_reverse(&pdev->dev, NULL, of_platform_device_destroy);
err_clk:
clk_disable_unprepare(sdc->clk);
return ret;
@@ -575,6 +577,7 @@ static void aspeed_sdc_remove(struct pla
{
struct aspeed_sdc *sdc = dev_get_drvdata(&pdev->dev);
+ device_for_each_child_reverse(&pdev->dev, NULL, of_platform_device_destroy);
clk_disable_unprepare(sdc->clk);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 292/398] mmc: sdhci_am654: Clear ITAPDLY on tuning failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (288 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 291/398] mmc: sdhci_am654: Reset command and data lines on failed tuning Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 293/398] mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 " Greg Kroah-Hartman
` (112 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Diogo Ivo (Schneider Electric),
Judith Mendez, Adrian Hunter, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
commit c9f47cc8c37f7659897142ffe216c250fbc1d4ed upstream.
When tuning fails, stale ITAPDLY values can persist and interfere with
subsequent I/O accesses, for example in DDR50 mode in cards with no tuning
support. Move the ITAPDLY enable setting out of the tuning loop to after
successful tuning, and explicitly clear ITAPDLY (delay and enable) when
tuning fails so that we are sure only working values are actually left in
hardware.
Fixes: 901d16e46296 ("mmc: sdhci_am654: Add retry tuning")
Cc: stable@vger.kernel.org
Signed-off-by: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
Reviewed-by: Judith Mendez <jm@ti.com>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci_am654.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
--- a/drivers/mmc/host/sdhci_am654.c
+++ b/drivers/mmc/host/sdhci_am654.c
@@ -527,7 +527,6 @@ static int sdhci_am654_do_tuning(struct
{
struct sdhci_pltfm_host *pltfm_host = sdhci_priv(host);
struct sdhci_am654_data *sdhci_am654 = sdhci_pltfm_priv(pltfm_host);
- unsigned char timing = host->mmc->ios.timing;
struct window fail_window[ITAPDLY_LENGTH];
struct device *dev = mmc_dev(host->mmc);
u8 curr_pass, itap;
@@ -536,11 +535,8 @@ static int sdhci_am654_do_tuning(struct
memset(fail_window, 0, sizeof(fail_window));
- /* Enable ITAPDLY */
- sdhci_am654->itap_del_ena[timing] = 0x1;
-
for (itap = 0; itap < ITAPDLY_LENGTH; itap++) {
- sdhci_am654_write_itapdly(sdhci_am654, itap, sdhci_am654->itap_del_ena[timing]);
+ sdhci_am654_write_itapdly(sdhci_am654, itap, 0x1);
curr_pass = !mmc_send_tuning(host->mmc, opcode, NULL);
@@ -584,10 +580,16 @@ static int sdhci_am654_platform_execute_
if (itapdly < 0) {
dev_err(dev, "Failed to find itapdly, fail tuning\n");
+ sdhci_am654_write_itapdly(sdhci_am654, 0, 0);
+ sdhci_am654->itap_del_ena[timing] = 0;
+ sdhci_am654->itap_del_sel[timing] = 0;
return -1;
}
dev_dbg(dev, "Passed tuning, final itapdly=%d\n", itapdly);
+
+ /* Enable ITAPDLY */
+ sdhci_am654->itap_del_ena[timing] = 0x1;
sdhci_am654_write_itapdly(sdhci_am654, itapdly, sdhci_am654->itap_del_ena[timing]);
/* Save ITAPDLY */
sdhci_am654->itap_del_sel[timing] = itapdly;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 346/438] mmc: sdio_uart: fix xmit_fifo leak when the port table is full
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (344 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 345/438] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 347/438] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt Greg Kroah-Hartman
` (103 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Gu <ustc.gu@gmail.com>
commit 53823e25793a97d07e6e98e0904bbf74cac8bc76 upstream.
sdio_uart_add_port() allocates the transmit fifo before claiming a
slot in sdio_uart_table[]. When all UART_NR slots are taken, it
returns -EBUSY with the fifo still allocated, but the probe error
path only kfree()s the port, leaking the transmit fifo.
Free the fifo in the failure path of sdio_uart_add_port() itself so
the function retains nothing on error.
Fixes: 8b197a5ce7a7 ("sdio_uart: Use kfifo instead of the messy circ stuff")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/core/sdio_uart.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/mmc/core/sdio_uart.c
+++ b/drivers/mmc/core/sdio_uart.c
@@ -104,6 +104,9 @@ static int sdio_uart_add_port(struct sdi
}
spin_unlock(&sdio_uart_table_lock);
+ if (ret)
+ kfifo_free(&port->xmit_fifo);
+
return ret;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 293/398] mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (289 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 292/398] mmc: sdhci_am654: Clear ITAPDLY on tuning failure Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 294/398] Input: adp5588-keys - cache GPIO state before registering the gpiochip Greg Kroah-Hartman
` (111 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Diogo Ivo (Schneider Electric),
Adrian Hunter, Judith Mendez, Ulf Hansson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
commit 308d05225281d86150d88141990d6caf8c902349 upstream.
DDR50 mode is not required to support the tuning command CMD19, meaning
that calibration may fail on cards that do not implement it, in which
case a known-good itap delay value should be programmed into the host
controller.
Do this by reading the (already defined) itap delay DT property for DDR50
and, if tuning fails for this mode, fall back to the DT-provided itap delay
value. If the DT does not provide a value for DDR50 fallback then this
simply disables using itapdly.
Fixes: 901d16e46296 ("mmc: sdhci_am654: Add retry tuning")
Cc: stable@vger.kernel.org
Signed-off-by: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Reviewed-by: Judith Mendez <jm@ti.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci_am654.c | 26 +++++++++++++++++++++-----
1 file changed, 21 insertions(+), 5 deletions(-)
--- a/drivers/mmc/host/sdhci_am654.c
+++ b/drivers/mmc/host/sdhci_am654.c
@@ -126,7 +126,7 @@ static const struct timing_data td[] = {
NULL,
MMC_CAP_UHS_SDR104},
[MMC_TIMING_UHS_DDR50] = {"ti,otap-del-sel-ddr50",
- NULL,
+ "ti,itap-del-sel-ddr50",
MMC_CAP_UHS_DDR50},
[MMC_TIMING_MMC_DDR52] = {"ti,otap-del-sel-ddr52",
"ti,itap-del-sel-ddr52",
@@ -144,6 +144,8 @@ struct sdhci_am654_data {
u32 otap_del_sel[ARRAY_SIZE(td)];
u32 itap_del_sel[ARRAY_SIZE(td)];
u32 itap_del_ena[ARRAY_SIZE(td)];
+ u32 itap_del_sel_dt_ddr50;
+ u32 itap_del_ena_dt_ddr50;
int clkbuf_sel;
int trm_icp;
int drv_strength;
@@ -579,10 +581,19 @@ static int sdhci_am654_platform_execute_
} while (++tuning_loop < RETRY_TUNING_MAX);
if (itapdly < 0) {
- dev_err(dev, "Failed to find itapdly, fail tuning\n");
- sdhci_am654_write_itapdly(sdhci_am654, 0, 0);
- sdhci_am654->itap_del_ena[timing] = 0;
- sdhci_am654->itap_del_sel[timing] = 0;
+ if (timing == MMC_TIMING_UHS_DDR50) {
+ dev_dbg(dev, "Failed DDR50 tuning, fallback to DT ITAP\n");
+ sdhci_am654->itap_del_sel[timing] = sdhci_am654->itap_del_sel_dt_ddr50;
+ sdhci_am654->itap_del_ena[timing] = sdhci_am654->itap_del_ena_dt_ddr50;
+ } else {
+ dev_err(dev, "Failed to find itapdly, fail tuning\n");
+ sdhci_am654->itap_del_ena[timing] = 0;
+ sdhci_am654->itap_del_sel[timing] = 0;
+ }
+
+ sdhci_am654_write_itapdly(sdhci_am654,
+ sdhci_am654->itap_del_sel[timing],
+ sdhci_am654->itap_del_ena[timing]);
return -1;
}
@@ -758,6 +769,11 @@ static int sdhci_am654_get_otap_delay(st
}
}
+ sdhci_am654->itap_del_sel_dt_ddr50 =
+ sdhci_am654->itap_del_sel[MMC_TIMING_UHS_DDR50];
+ sdhci_am654->itap_del_ena_dt_ddr50 =
+ sdhci_am654->itap_del_ena[MMC_TIMING_UHS_DDR50];
+
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 347/438] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (345 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 346/438] mmc: sdio_uart: fix xmit_fifo leak when the port table is full Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 348/438] mmc: spi: reset bytes_xfered before retrying CRC failures Greg Kroah-Hartman
` (102 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
commit d5ea0d226e8f0801d78702142a124d78c317d822 upstream.
The threaded IRQ handler can run before devm_request_threaded_irq()
returns, but thread_lock was initialized afterwards. Initialize it before
requesting either interrupt.
Fixes: 8047310ee984 ("mmc: sh_mmcif: fix a race, causing an Oops on SMP")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sh_mmcif.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
--- a/drivers/mmc/host/sh_mmcif.c
+++ b/drivers/mmc/host/sh_mmcif.c
@@ -1461,6 +1461,7 @@ static int sh_mmcif_probe(struct platfor
host->pd = pdev;
spin_lock_init(&host->lock);
+ mutex_init(&host->thread_lock);
mmc->ops = &sh_mmcif_ops;
sh_mmcif_init_ocr(host);
@@ -1519,8 +1520,6 @@ static int sh_mmcif_probe(struct platfor
}
}
- mutex_init(&host->thread_lock);
-
ret = mmc_add_host(mmc);
if (ret < 0)
goto err_clk;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 294/398] Input: adp5588-keys - cache GPIO state before registering the gpiochip
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (290 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 293/398] mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 " Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 295/398] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 Greg Kroah-Hartman
` (110 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alvin Šipraga, Nuno Sá,
Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alvin Šipraga <alvin.sipraga@analog.com>
commit 21efadc62272cabee9bec27777ae75d84a9ca8a8 upstream.
So as not to clobber any pre-programmed GPIO state in the execution
of its gpiochip ops, the driver caches things during probe time.
However, since those ops can be called both during and immediately after
the call to devm_gpiochip_add_data(), it is imperative that things are
cached before that. That's not the case right now, so reorder the two
steps to prevent any clobbering.
In the concrete example which motivated this change, a bootloader was
preconfiguring an important GPIO output to HIGH before booting the
kernel. Linux would then inadvertently set that output to LOW while
configuring a GPIO hog on a discrete GPIO line within the same 8-bit
bank (because the cached value was 0=LOW).
Fixes: ba9f507a1bea ("Input: adp5588-keys - export unused GPIO pins")
Signed-off-by: Alvin Šipraga <alvin.sipraga@analog.com>
Reviewed-by: Nuno Sá <nuno.sa@analog.com>
Link: https://patch.msgid.link/20260818-adp5588-gpio-cache-v1-1-650a2674fc0d@analog.com
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/keyboard/adp5588-keys.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
--- a/drivers/input/keyboard/adp5588-keys.c
+++ b/drivers/input/keyboard/adp5588-keys.c
@@ -447,12 +447,6 @@ static int adp5588_gpio_add(struct adp55
mutex_init(&kpad->gpio_lock);
- error = devm_gpiochip_add_data(dev, &kpad->gc, kpad);
- if (error) {
- dev_err(dev, "gpiochip_add failed: %d\n", error);
- return error;
- }
-
for (i = 0; i <= ADP5588_BANK(ADP5588_MAXGPIO); i++) {
kpad->dat_out[i] = adp5588_read(kpad->client,
GPIO_DAT_OUT1 + i);
@@ -460,6 +454,12 @@ static int adp5588_gpio_add(struct adp55
kpad->pull_dis[i] = adp5588_read(kpad->client, GPIO_PULL1 + i);
}
+ error = devm_gpiochip_add_data(dev, &kpad->gc, kpad);
+ if (error) {
+ dev_err(dev, "gpiochip_add failed: %d\n", error);
+ return error;
+ }
+
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 348/438] mmc: spi: reset bytes_xfered before retrying CRC failures
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (346 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 347/438] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 349/438] mmc: sdhci_am654: Move tuning_loop to local variable Greg Kroah-Hartman
` (101 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Rao, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xu Rao <raoxu@uniontech.com>
commit 8b0cc8707f65e0f51912e764e1b309b2559db1ec upstream.
mmc_spi_data_do() updates data->bytes_xfered after each block has been
transferred successfully. If a later block in the same data request
fails with a CRC error, data->bytes_xfered may therefore contain the
number of bytes completed before the failing block.
mmc_spi_request() has a private recovery path for such CRC failures. It
sends STOP_TRANSMISSION, clears data->error and jumps back to
crc_recover to issue the same command and data request again. However,
it does not clear data->bytes_xfered before the retry.
If the retry succeeds, the request is completed with the bytes from the
failed attempt still included in data->bytes_xfered. For a multi-block
request this can make the completed request report more bytes than were
transferred by the successful retry, and can even exceed the request size
when most blocks completed before the CRC error.
This is most likely to be observed on MMC-over-SPI systems where long
multi-block transfers occasionally hit a data CRC error but the
mmc_spi-internal retry succeeds. The data itself is retried, but the
completion accounting is not.
Clear data->bytes_xfered together with data->error before repeating the
request so the final completion reports only the bytes transferred by the
successful attempt.
Fixes: 061c6c847eeb ("mmc_spi: Recover from CRC errors for r/w operation over SPI.")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/mmc_spi.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/mmc/host/mmc_spi.c
+++ b/drivers/mmc/host/mmc_spi.c
@@ -952,6 +952,7 @@ crc_recover:
status = mmc_spi_command_send(host, mrq, &stop, 0);
crc_retry--;
mrq->data->error = 0;
+ mrq->data->bytes_xfered = 0;
goto crc_recover;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 295/398] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (291 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 294/398] Input: adp5588-keys - cache GPIO state before registering the gpiochip Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 296/398] Input: cyttsp5 - clamp the HID report size before memcpy Greg Kroah-Hartman
` (109 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Alexei Turtanov, Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexei Turtanov <9alexei9@gmail.com>
commit aefbda23eeba234c3ff0f135dc5be6e294bd25a6 upstream.
The internal keyboard of the Xiaomi Redmi Book Pro 16 2026 (board TM2425)
does not work: atkbd_probe() succeeds and every command is ACKed, but no
scancodes ever arrive afterwards.
Testing on the hardware through serio_raw shows that ATKBD_CMD_RESET_DIS
(0xF5) is the culprit. After 0xF5 the embedded controller keeps ACKing
commands but stops delivering scancodes, and neither ATKBD_CMD_ENABLE
(0xF4) nor ATKBD_CMD_RESET_BAT (0xFF) bring them back. Only re-enabling
the keyboard interface at the controller level (i8042 command 0xAE, or
rewriting the command byte as i8042_port_close() does) revives it.
Running the init sequence without 0xF5 (0xED 0x00, 0xF3 0x00, 0xF4)
keeps the keyboard working.
'i8042.dumbkbd=1' also works around this, but then the driver never
writes to the keyboard and the LEDs cannot be controlled. Use the
existing atkbd_deactivate_fixup quirk instead, as done for the sibling
TM2424 by commit 3a046db33bb9 ("Input: atkbd - skip deactivate for
Xiaomi Book Pro 14's internal keyboard"). Tested on v7.2: keyboard,
Caps Lock LED and s2idle suspend/resume all work.
DMI: XIAOMI REDMI Book Pro 16 2026/TM2425, BIOS RMAPT6B0P0909 05/22/2026
Fixes: 9cf6e24c9fbf ("Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID")
Cc: stable@vger.kernel.org
Signed-off-by: Alexei Turtanov <9alexei9@gmail.com>
Link: https://patch.msgid.link/20260828112239.18081-1-9alexei9@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/keyboard/atkbd.c | 8 ++++++++
1 file changed, 8 insertions(+)
--- a/drivers/input/keyboard/atkbd.c
+++ b/drivers/input/keyboard/atkbd.c
@@ -1975,6 +1975,14 @@ static const struct dmi_system_id atkbd_
},
.callback = atkbd_deactivate_fixup,
},
+ {
+ /* Xiaomi Redmi Book Pro 16 2026 (TM2425) */
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "XIAOMI"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "REDMI Book Pro 16 2026"),
+ },
+ .callback = atkbd_deactivate_fixup,
+ },
{ }
};
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 349/438] mmc: sdhci_am654: Move tuning_loop to local variable
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (347 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 348/438] mmc: spi: reset bytes_xfered before retrying CRC failures Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 350/438] mmc: sdhci_am654: Reset command and data lines on failed tuning Greg Kroah-Hartman
` (100 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Diogo Ivo (Schneider Electric),
Judith Mendez, Adrian Hunter, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
commit ff894dced1a7ad7523f9c65dbdb53d02474cca0f upstream.
The tuning_loop field in struct sdhci_am654_data is only used within
sdhci_am654_platform_execute_tuning() as a loop counter that is
initialized to 0 in sdhci_am654_init(). Since it shouldn't persist across
function calls, otherwise every failure expends its "budget", move it to a
local variable and remove the struct field along with the now-unnecessary
initialization.
Signed-off-by: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
Reviewed-by: Judith Mendez <jm@ti.com>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Fixes: de31f6ab68a3 ("mmc: sdhci_am654: Reset Command and Data line after tuning")
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci_am654.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
--- a/drivers/mmc/host/sdhci_am654.c
+++ b/drivers/mmc/host/sdhci_am654.c
@@ -151,7 +151,6 @@ struct sdhci_am654_data {
u32 flags;
u32 quirks;
bool dll_enable;
- u32 tuning_loop;
#define SDHCI_AM654_QUIRK_FORCE_CDTEST BIT(0)
#define SDHCI_AM654_QUIRK_SUPPRESS_V1P8_ENA BIT(1)
@@ -576,13 +575,14 @@ static int sdhci_am654_platform_execute_
struct sdhci_am654_data *sdhci_am654 = sdhci_pltfm_priv(pltfm_host);
unsigned char timing = host->mmc->ios.timing;
struct device *dev = mmc_dev(host->mmc);
+ unsigned int tuning_loop = 0;
int itapdly;
do {
itapdly = sdhci_am654_do_tuning(host, opcode);
if (itapdly >= 0)
break;
- } while (++sdhci_am654->tuning_loop < RETRY_TUNING_MAX);
+ } while (++tuning_loop < RETRY_TUNING_MAX);
if (itapdly < 0) {
dev_err(dev, "Failed to find itapdly, fail tuning\n");
@@ -806,9 +806,6 @@ static int sdhci_am654_init(struct sdhci
regmap_update_bits(sdhci_am654->base, CTL_CFG_3, TUNINGFORSDR50_MASK,
TUNINGFORSDR50_MASK);
- /* Use to re-execute tuning */
- sdhci_am654->tuning_loop = 0;
-
ret = sdhci_setup_host(host);
if (ret)
return ret;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 296/398] Input: cyttsp5 - clamp the HID report size before memcpy
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (292 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 295/398] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 297/398] Input: evdev - zero absinfo before partial copy in EVIOCSABS Greg Kroah-Hartman
` (108 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linkai Gong, Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linkai Gong <gonglinkai@kylinos.cn>
commit 85f080fb87ed5cd3e46121be677f52c82f26a0ab upstream.
The size field comes from the device and is used as the memcpy()
length into response_buf, which is CY_MAX_INPUT bytes.
Fixes: 5b0c03e24a06 ("Input: Add driver for Cypress Generation 5 touchscreen")
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Link: https://patch.msgid.link/20260901122649.1173066-1-gonglinkai@kylinos.cn
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/touchscreen/cyttsp5.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/input/touchscreen/cyttsp5.c
+++ b/drivers/input/touchscreen/cyttsp5.c
@@ -711,6 +711,7 @@ static irqreturn_t cyttsp5_handle_irq(in
size = 2;
} else {
report_id = ts->input_buf[2];
+ size = min(size, CY_MAX_INPUT);
}
switch (report_id) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 350/438] mmc: sdhci_am654: Reset command and data lines on failed tuning
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (348 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 349/438] mmc: sdhci_am654: Move tuning_loop to local variable Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 351/438] mmc: sdhci_am654: Clear ITAPDLY on tuning failure Greg Kroah-Hartman
` (99 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Diogo Ivo (Schneider Electric),
Judith Mendez, Adrian Hunter, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
commit 7197d9107d9545730153b82ea5a411c5208b443f upstream.
The CMD/DATA reset after tuning should be performed regardless of
whether tuning succeeded or failed, since tuning data may remain in
the buffer in either case. Move the error return after the reset so
that the controller is always cleaned up.
Fixes: de31f6ab68a3 ("mmc: sdhci_am654: Reset Command and Data line after tuning")
Cc: stable@vger.kernel.org
Signed-off-by: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
Reviewed-by: Judith Mendez <jm@ti.com>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci_am654.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
--- a/drivers/mmc/host/sdhci_am654.c
+++ b/drivers/mmc/host/sdhci_am654.c
@@ -442,15 +442,13 @@ static int sdhci_am654_execute_tuning(st
struct sdhci_host *host = mmc_priv(mmc);
int err = sdhci_execute_tuning(mmc, opcode);
- if (err)
- return err;
/*
* Tuning data remains in the buffer after tuning.
* Do a command and data reset to get rid of it
*/
sdhci_reset(host, SDHCI_RESET_CMD | SDHCI_RESET_DATA);
- return 0;
+ return err;
}
static u32 sdhci_am654_cqhci_irq(struct sdhci_host *host, u32 intmask)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 297/398] Input: evdev - zero absinfo before partial copy in EVIOCSABS
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (293 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 296/398] Input: cyttsp5 - clamp the HID report size before memcpy Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 298/398] Input: hp_sdc - shut down kicker timer on module exit Greg Kroah-Hartman
` (107 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Iván Ezequiel Rodriguez,
Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
commit 8b852965b8eaf910c314dc346967ed82c8d4f235 upstream.
The EVIOCSABS handler copies at most the user supplied ioctl size into
an uninitialized on-stack struct input_absinfo:
if (copy_from_user(&abs, p, min_t(size_t,
size, sizeof(struct input_absinfo))))
The size comes from _IOC_SIZE() of the ioctl command and is therefore
fully controlled by userspace. A short size leaves the trailing part of
the structure holding whatever was on the kernel stack, and the whole
structure is then stored into the device:
dev->absinfo[t] = abs;
EVIOCGABS hands that back to userspace, disclosing the stale stack
bytes. Only the resolution field is currently cleared, which covers the
legacy struct layout but not an arbitrarily short size.
Zero the structure before the copy so any part not supplied by the
caller reads back as zero. The existing resolution fixup is kept, since
it also handles a size that partially overlaps that field.
Fixes: 448cd1664a57 ("Input: evdev - rearrange ioctl handling")
Cc: stable@vger.kernel.org
Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Link: https://patch.msgid.link/20260901130629.24078-2-ivanrwcm25@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/evdev.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/input/evdev.c
+++ b/drivers/input/evdev.c
@@ -1229,6 +1229,8 @@ static long evdev_do_ioctl(struct file *
t = _IOC_NR(cmd) & ABS_MAX;
+ memset(&abs, 0, sizeof(abs));
+
if (copy_from_user(&abs, p, min_t(size_t,
size, sizeof(struct input_absinfo))))
return -EFAULT;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 351/438] mmc: sdhci_am654: Clear ITAPDLY on tuning failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (349 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 350/438] mmc: sdhci_am654: Reset command and data lines on failed tuning Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 352/438] mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 " Greg Kroah-Hartman
` (98 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Diogo Ivo (Schneider Electric),
Judith Mendez, Adrian Hunter, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
commit c9f47cc8c37f7659897142ffe216c250fbc1d4ed upstream.
When tuning fails, stale ITAPDLY values can persist and interfere with
subsequent I/O accesses, for example in DDR50 mode in cards with no tuning
support. Move the ITAPDLY enable setting out of the tuning loop to after
successful tuning, and explicitly clear ITAPDLY (delay and enable) when
tuning fails so that we are sure only working values are actually left in
hardware.
Fixes: 901d16e46296 ("mmc: sdhci_am654: Add retry tuning")
Cc: stable@vger.kernel.org
Signed-off-by: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
Reviewed-by: Judith Mendez <jm@ti.com>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci_am654.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
--- a/drivers/mmc/host/sdhci_am654.c
+++ b/drivers/mmc/host/sdhci_am654.c
@@ -527,7 +527,6 @@ static int sdhci_am654_do_tuning(struct
{
struct sdhci_pltfm_host *pltfm_host = sdhci_priv(host);
struct sdhci_am654_data *sdhci_am654 = sdhci_pltfm_priv(pltfm_host);
- unsigned char timing = host->mmc->ios.timing;
struct window fail_window[ITAPDLY_LENGTH];
struct device *dev = mmc_dev(host->mmc);
u8 curr_pass, itap;
@@ -536,11 +535,8 @@ static int sdhci_am654_do_tuning(struct
memset(fail_window, 0, sizeof(fail_window));
- /* Enable ITAPDLY */
- sdhci_am654->itap_del_ena[timing] = 0x1;
-
for (itap = 0; itap < ITAPDLY_LENGTH; itap++) {
- sdhci_am654_write_itapdly(sdhci_am654, itap, sdhci_am654->itap_del_ena[timing]);
+ sdhci_am654_write_itapdly(sdhci_am654, itap, 0x1);
curr_pass = !mmc_send_tuning(host->mmc, opcode, NULL);
@@ -584,10 +580,16 @@ static int sdhci_am654_platform_execute_
if (itapdly < 0) {
dev_err(dev, "Failed to find itapdly, fail tuning\n");
+ sdhci_am654_write_itapdly(sdhci_am654, 0, 0);
+ sdhci_am654->itap_del_ena[timing] = 0;
+ sdhci_am654->itap_del_sel[timing] = 0;
return -1;
}
dev_dbg(dev, "Passed tuning, final itapdly=%d\n", itapdly);
+
+ /* Enable ITAPDLY */
+ sdhci_am654->itap_del_ena[timing] = 0x1;
sdhci_am654_write_itapdly(sdhci_am654, itapdly, sdhci_am654->itap_del_ena[timing]);
/* Save ITAPDLY */
sdhci_am654->itap_del_sel[timing] = itapdly;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 298/398] Input: hp_sdc - shut down kicker timer on module exit
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (294 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 297/398] Input: evdev - zero absinfo before partial copy in EVIOCSABS Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 299/398] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Greg Kroah-Hartman
` (106 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Helge Deller,
Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
commit 309731e95917125bbd13626a7a5600490a5bf44f upstream.
hp_sdc_kicker() rearms hp_sdc.kicker with mod_timer() after scheduling the
tasklet. The module exit path uses timer_delete_sync(). That waits for a
callback already running but can still leave the timer rearmed.
A callback can therefore leave the timer pending while hp_sdc_exit() tears
down the driver, allowing timer activity to access dismantled driver state.
Use timer_shutdown_sync() for final teardown. It waits for a running
callback and prevents rearming after module exit begins.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Acked-by: Helge Deller <deller@gmx.de>
Link: https://patch.msgid.link/20260902154004.3595416-1-runyu.xiao@seu.edu.cn
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/serio/hp_sdc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/input/serio/hp_sdc.c
+++ b/drivers/input/serio/hp_sdc.c
@@ -981,7 +981,7 @@ static void hp_sdc_exit(void)
free_irq(hp_sdc.irq, &hp_sdc);
write_unlock_irq(&hp_sdc.lock);
- timer_delete_sync(&hp_sdc.kicker);
+ timer_shutdown_sync(&hp_sdc.kicker);
tasklet_kill(&hp_sdc.task);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 352/438] mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 tuning failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (350 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 351/438] mmc: sdhci_am654: Clear ITAPDLY on tuning failure Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 353/438] Input: adp5588-keys - cache GPIO state before registering the gpiochip Greg Kroah-Hartman
` (97 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Diogo Ivo (Schneider Electric),
Adrian Hunter, Judith Mendez, Ulf Hansson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
commit 308d05225281d86150d88141990d6caf8c902349 upstream.
DDR50 mode is not required to support the tuning command CMD19, meaning
that calibration may fail on cards that do not implement it, in which
case a known-good itap delay value should be programmed into the host
controller.
Do this by reading the (already defined) itap delay DT property for DDR50
and, if tuning fails for this mode, fall back to the DT-provided itap delay
value. If the DT does not provide a value for DDR50 fallback then this
simply disables using itapdly.
Fixes: 901d16e46296 ("mmc: sdhci_am654: Add retry tuning")
Cc: stable@vger.kernel.org
Signed-off-by: Diogo Ivo (Schneider Electric) <diogo.ivo@bootlin.com>
Acked-by: Adrian Hunter <adrian.hunter@intel.com>
Reviewed-by: Judith Mendez <jm@ti.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mmc/host/sdhci_am654.c | 26 +++++++++++++++++++++-----
1 file changed, 21 insertions(+), 5 deletions(-)
--- a/drivers/mmc/host/sdhci_am654.c
+++ b/drivers/mmc/host/sdhci_am654.c
@@ -126,7 +126,7 @@ static const struct timing_data td[] = {
NULL,
MMC_CAP_UHS_SDR104},
[MMC_TIMING_UHS_DDR50] = {"ti,otap-del-sel-ddr50",
- NULL,
+ "ti,itap-del-sel-ddr50",
MMC_CAP_UHS_DDR50},
[MMC_TIMING_MMC_DDR52] = {"ti,otap-del-sel-ddr52",
"ti,itap-del-sel-ddr52",
@@ -144,6 +144,8 @@ struct sdhci_am654_data {
u32 otap_del_sel[ARRAY_SIZE(td)];
u32 itap_del_sel[ARRAY_SIZE(td)];
u32 itap_del_ena[ARRAY_SIZE(td)];
+ u32 itap_del_sel_dt_ddr50;
+ u32 itap_del_ena_dt_ddr50;
int clkbuf_sel;
int trm_icp;
int drv_strength;
@@ -579,10 +581,19 @@ static int sdhci_am654_platform_execute_
} while (++tuning_loop < RETRY_TUNING_MAX);
if (itapdly < 0) {
- dev_err(dev, "Failed to find itapdly, fail tuning\n");
- sdhci_am654_write_itapdly(sdhci_am654, 0, 0);
- sdhci_am654->itap_del_ena[timing] = 0;
- sdhci_am654->itap_del_sel[timing] = 0;
+ if (timing == MMC_TIMING_UHS_DDR50) {
+ dev_dbg(dev, "Failed DDR50 tuning, fallback to DT ITAP\n");
+ sdhci_am654->itap_del_sel[timing] = sdhci_am654->itap_del_sel_dt_ddr50;
+ sdhci_am654->itap_del_ena[timing] = sdhci_am654->itap_del_ena_dt_ddr50;
+ } else {
+ dev_err(dev, "Failed to find itapdly, fail tuning\n");
+ sdhci_am654->itap_del_ena[timing] = 0;
+ sdhci_am654->itap_del_sel[timing] = 0;
+ }
+
+ sdhci_am654_write_itapdly(sdhci_am654,
+ sdhci_am654->itap_del_sel[timing],
+ sdhci_am654->itap_del_ena[timing]);
return -1;
}
@@ -758,6 +769,11 @@ static int sdhci_am654_get_otap_delay(st
}
}
+ sdhci_am654->itap_del_sel_dt_ddr50 =
+ sdhci_am654->itap_del_sel[MMC_TIMING_UHS_DDR50];
+ sdhci_am654->itap_del_ena_dt_ddr50 =
+ sdhci_am654->itap_del_ena[MMC_TIMING_UHS_DDR50];
+
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 299/398] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (295 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 298/398] Input: hp_sdc - shut down kicker timer on module exit Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 300/398] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Greg Kroah-Hartman
` (105 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chris Sommers, Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Sommers <chris.sommers@icloud.com>
commit 25e424eb4ae1a662d9c3573218d06ac32f797fc5 upstream.
On the Acer Aspire Go 15 (AG15-42P), the internal keyboard drops out
~5 seconds after boot on both Linux and Linux-LTS kernels. Keystrokes on
the built-in keyboard stop registering while the trackpad and external
keyboards remain functional.
Testing confirms that booting with the i8042.reset kernel parameter
resolves the issue and keeps the internal keyboard responsive.
Add SERIO_QUIRK_RESET_ALWAYS to i8042_dmi_quirk_table for the Acer
Aspire AG15-42P to automatically apply this quirk on boot.
Signed-off-by: Chris Sommers <chris.sommers@icloud.com>
Link: https://patch.msgid.link/20260907182723.2709981-1-chris.sommers@icloud.com
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/serio/i8042-acpipnpio.h | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/input/serio/i8042-acpipnpio.h
+++ b/drivers/input/serio/i8042-acpipnpio.h
@@ -261,6 +261,13 @@ static const struct dmi_system_id i8042_
{
.matches = {
DMI_MATCH(DMI_SYS_VENDOR, "Acer"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "Aspire AG15-42P"),
+ },
+ .driver_data = (void *)(SERIO_QUIRK_RESET_ALWAYS)
+ },
+ {
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "Acer"),
DMI_MATCH(DMI_PRODUCT_NAME, "Aspire ES1-132"),
},
.driver_data = (void *)(SERIO_QUIRK_RESET_ALWAYS)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 353/438] Input: adp5588-keys - cache GPIO state before registering the gpiochip
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (351 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 352/438] mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 " Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 354/438] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 Greg Kroah-Hartman
` (96 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alvin Šipraga, Nuno Sá,
Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alvin Šipraga <alvin.sipraga@analog.com>
commit 21efadc62272cabee9bec27777ae75d84a9ca8a8 upstream.
So as not to clobber any pre-programmed GPIO state in the execution
of its gpiochip ops, the driver caches things during probe time.
However, since those ops can be called both during and immediately after
the call to devm_gpiochip_add_data(), it is imperative that things are
cached before that. That's not the case right now, so reorder the two
steps to prevent any clobbering.
In the concrete example which motivated this change, a bootloader was
preconfiguring an important GPIO output to HIGH before booting the
kernel. Linux would then inadvertently set that output to LOW while
configuring a GPIO hog on a discrete GPIO line within the same 8-bit
bank (because the cached value was 0=LOW).
Fixes: ba9f507a1bea ("Input: adp5588-keys - export unused GPIO pins")
Signed-off-by: Alvin Šipraga <alvin.sipraga@analog.com>
Reviewed-by: Nuno Sá <nuno.sa@analog.com>
Link: https://patch.msgid.link/20260818-adp5588-gpio-cache-v1-1-650a2674fc0d@analog.com
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/keyboard/adp5588-keys.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
--- a/drivers/input/keyboard/adp5588-keys.c
+++ b/drivers/input/keyboard/adp5588-keys.c
@@ -446,12 +446,6 @@ static int adp5588_gpio_add(struct adp55
mutex_init(&kpad->gpio_lock);
- error = devm_gpiochip_add_data(dev, &kpad->gc, kpad);
- if (error) {
- dev_err(dev, "gpiochip_add failed: %d\n", error);
- return error;
- }
-
for (i = 0; i <= ADP5588_BANK(ADP5588_MAXGPIO); i++) {
kpad->dat_out[i] = adp5588_read(kpad->client,
GPIO_DAT_OUT1 + i);
@@ -459,6 +453,12 @@ static int adp5588_gpio_add(struct adp55
kpad->pull_dis[i] = adp5588_read(kpad->client, GPIO_PULL1 + i);
}
+ error = devm_gpiochip_add_data(dev, &kpad->gc, kpad);
+ if (error) {
+ dev_err(dev, "gpiochip_add failed: %d\n", error);
+ return error;
+ }
+
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 300/398] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (296 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 299/398] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 301/398] Input: soc_button_array - fix MS Surface Pro 11 probe failure Greg Kroah-Hartman
` (104 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
commit 51cfe54f815ae175c7d1126b983d4d7c89715004 upstream.
When chunking writes into SMBus blocks in rmi_smb_write_block(), the
loop calculates block_len using the original total length (len) instead
of the remaining length (cur_len).
If len is greater than 32 bytes (SMB_MAX_COUNT), block_len remains 32
for every iteration, even on the final partial chunk where fewer than 32
bytes remain. This causes smb_block_write() to read 32 bytes from the
advanced data buffer pointer, reading past the end of the input buffer.
Fix this by calculating block_len using cur_len and advancing the buffer
and address pointers by block_len.
Fixes: 82264d0cf7ae ("Input: synaptics-rmi4 - add SMBus support")
Cc: stable@vger.kernel.org
Reported-by: sashiko-bot@kernel.org
Assisted-by: LLM
Link: https://patch.msgid.link/anLFSMKSoKyyZ272@google.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/rmi4/rmi_smbus.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
--- a/drivers/input/rmi4/rmi_smbus.c
+++ b/drivers/input/rmi4/rmi_smbus.c
@@ -140,7 +140,7 @@ static int rmi_smb_write_block(struct rm
u8 commandcode;
struct rmi_smb_xport *rmi_smb =
container_of(xport, struct rmi_smb_xport, xport);
- int cur_len = (int)len;
+ size_t cur_len = len;
mutex_lock(&rmi_smb->page_mutex);
@@ -148,7 +148,7 @@ static int rmi_smb_write_block(struct rm
/*
* break into 32 bytes chunks to write get command code
*/
- int block_len = min_t(int, len, SMB_MAX_COUNT);
+ int block_len = min_t(size_t, cur_len, SMB_MAX_COUNT);
retval = rmi_smb_get_command_code(xport, rmiaddr, block_len,
false, &commandcode);
@@ -161,9 +161,9 @@ static int rmi_smb_write_block(struct rm
goto exit;
/* prepare to write next block of bytes */
- cur_len -= SMB_MAX_COUNT;
- databuff += SMB_MAX_COUNT;
- rmiaddr += SMB_MAX_COUNT;
+ cur_len -= block_len;
+ databuff += block_len;
+ rmiaddr += block_len;
}
exit:
mutex_unlock(&rmi_smb->page_mutex);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 354/438] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (352 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 353/438] Input: adp5588-keys - cache GPIO state before registering the gpiochip Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 355/438] Input: cyttsp5 - clamp the HID report size before memcpy Greg Kroah-Hartman
` (95 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Alexei Turtanov, Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexei Turtanov <9alexei9@gmail.com>
commit aefbda23eeba234c3ff0f135dc5be6e294bd25a6 upstream.
The internal keyboard of the Xiaomi Redmi Book Pro 16 2026 (board TM2425)
does not work: atkbd_probe() succeeds and every command is ACKed, but no
scancodes ever arrive afterwards.
Testing on the hardware through serio_raw shows that ATKBD_CMD_RESET_DIS
(0xF5) is the culprit. After 0xF5 the embedded controller keeps ACKing
commands but stops delivering scancodes, and neither ATKBD_CMD_ENABLE
(0xF4) nor ATKBD_CMD_RESET_BAT (0xFF) bring them back. Only re-enabling
the keyboard interface at the controller level (i8042 command 0xAE, or
rewriting the command byte as i8042_port_close() does) revives it.
Running the init sequence without 0xF5 (0xED 0x00, 0xF3 0x00, 0xF4)
keeps the keyboard working.
'i8042.dumbkbd=1' also works around this, but then the driver never
writes to the keyboard and the LEDs cannot be controlled. Use the
existing atkbd_deactivate_fixup quirk instead, as done for the sibling
TM2424 by commit 3a046db33bb9 ("Input: atkbd - skip deactivate for
Xiaomi Book Pro 14's internal keyboard"). Tested on v7.2: keyboard,
Caps Lock LED and s2idle suspend/resume all work.
DMI: XIAOMI REDMI Book Pro 16 2026/TM2425, BIOS RMAPT6B0P0909 05/22/2026
Fixes: 9cf6e24c9fbf ("Input: atkbd - do not skip atkbd_deactivate() when skipping ATKBD_CMD_GETID")
Cc: stable@vger.kernel.org
Signed-off-by: Alexei Turtanov <9alexei9@gmail.com>
Link: https://patch.msgid.link/20260828112239.18081-1-9alexei9@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/keyboard/atkbd.c | 8 ++++++++
1 file changed, 8 insertions(+)
--- a/drivers/input/keyboard/atkbd.c
+++ b/drivers/input/keyboard/atkbd.c
@@ -1954,6 +1954,14 @@ static const struct dmi_system_id atkbd_
},
.callback = atkbd_deactivate_fixup,
},
+ {
+ /* Xiaomi Redmi Book Pro 16 2026 (TM2425) */
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "XIAOMI"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "REDMI Book Pro 16 2026"),
+ },
+ .callback = atkbd_deactivate_fixup,
+ },
{ }
};
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 301/398] Input: soc_button_array - fix MS Surface Pro 11 probe failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (297 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 300/398] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 302/398] Input: soc_button_array - check btns_desc->package.count Greg Kroah-Hartman
` (103 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sergey Lebedev, Hans de Goede,
Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <johannes.goede@oss.qualcomm.com>
commit ed22ad5fdbdbf9b4cb4ad3003f60314b5a5eb89d upstream.
On the MS Surface Pro 11 soc_button_array probing races with the GPIO
driver probing. If soc_button_array wins the race then gpiod_get() returns
EPROBE_DEFER, which should normally take care of retrying later, but
the soc_button_array code deliberately ignores EPROBE_DEFER causing it
to fail its probe() which causes the volume and power buttons to now work.
The ignoring of EPROBE_DEFER is there to deal with a problem specific to
older Bay Trail (BYT) and Cherry Trail (CHT) tablets which often use this
driver. Modify the error handling to only ignore EPROBE_DEFER on BYT and
CHT platforms and propagate EPROBE_DEFER normally on other platforms.
Fixes: bcf059578980 ("Input: soc_button_array - partial revert of support for newer surface devices")
Cc: stable@vger.kernel.org
Reported-by: Sergey Lebedev <lsa.uz@pm.me>
Closes: https://lore.kernel.org/lkml/20260830141355.55898-1-lsa.uz@pm.me/
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Tested-by: Sergey Lebedev <lsa.uz@pm.me>
Link: https://patch.msgid.link/20260909093934.29411-1-johannes.goede@oss.qualcomm.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/misc/soc_button_array.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
--- a/drivers/input/misc/soc_button_array.c
+++ b/drivers/input/misc/soc_button_array.c
@@ -16,6 +16,7 @@
#include <linux/gpio/consumer.h>
#include <linux/gpio_keys.h>
#include <linux/gpio.h>
+#include <linux/platform_data/x86/soc.h>
#include <linux/platform_device.h>
static bool use_low_level_irq;
@@ -160,7 +161,7 @@ soc_button_device_create(struct platform
struct gpio_keys_platform_data *gpio_keys_pdata;
const struct dmi_system_id *dmi_id;
int invalid_acpi_index = -1;
- int error, gpio, irq;
+ int error, gpio, irq = 0;
int n_buttons = 0;
for (info = button_info; info->name; info++)
@@ -191,8 +192,9 @@ soc_button_device_create(struct platform
error = soc_button_lookup_gpio(&pdev->dev, info->acpi_index, &gpio, &irq);
if (error || irq < 0) {
/*
- * Skip GPIO if not present. Note we deliberately
- * ignore -EPROBE_DEFER errors here. On some devices
+ * Propagate -EPROBE_DEFER, skip button on other errors.
+ *
+ * -EPROBE_DEFER is ignored on Bay & Cherry Trail. Here
* Intel is using so called virtual GPIOs which are not
* GPIOs at all but some way for AML code to check some
* random status bits without need a custom opregion.
@@ -201,6 +203,12 @@ soc_button_device_create(struct platform
* we do not have a driver for these so they will never
* show up, therefore we ignore -EPROBE_DEFER.
*/
+ if ((error == -EPROBE_DEFER || irq == -EPROBE_DEFER) &&
+ !(soc_intel_is_byt() || soc_intel_is_cht())) {
+ error = -EPROBE_DEFER;
+ goto err_free_mem;
+ }
+
continue;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 355/438] Input: cyttsp5 - clamp the HID report size before memcpy
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (353 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 354/438] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 356/438] Input: evdev - zero absinfo before partial copy in EVIOCSABS Greg Kroah-Hartman
` (94 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linkai Gong, Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linkai Gong <gonglinkai@kylinos.cn>
commit 85f080fb87ed5cd3e46121be677f52c82f26a0ab upstream.
The size field comes from the device and is used as the memcpy()
length into response_buf, which is CY_MAX_INPUT bytes.
Fixes: 5b0c03e24a06 ("Input: Add driver for Cypress Generation 5 touchscreen")
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Link: https://patch.msgid.link/20260901122649.1173066-1-gonglinkai@kylinos.cn
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/touchscreen/cyttsp5.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/input/touchscreen/cyttsp5.c
+++ b/drivers/input/touchscreen/cyttsp5.c
@@ -710,6 +710,7 @@ static irqreturn_t cyttsp5_handle_irq(in
size = 2;
} else {
report_id = ts->input_buf[2];
+ size = min(size, CY_MAX_INPUT);
}
switch (report_id) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 302/398] Input: soc_button_array - check btns_desc->package.count
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (298 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 301/398] Input: soc_button_array - fix MS Surface Pro 11 probe failure Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 303/398] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Greg Kroah-Hartman
` (102 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shashiko, Hans de Goede,
Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <johannes.goede@oss.qualcomm.com>
commit fb5022278b6ea7f1838e3ef78028d5d5e3375f65 upstream.
Check that btns_desc->package.count is not 0 before accessing
btns_desc->package.elements[0].
Fixes: 4c3362f44980 ("Input: soc_button_array - add support for ACPI 6.0 Generic Button Device")
Cc: stable@vger.kernel.org
Reported-by: Shashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/linux-input/20260909091440.3384C1F00A3A@smtp.kernel.org/
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Link: https://patch.msgid.link/20260909093934.29411-2-johannes.goede@oss.qualcomm.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/misc/soc_button_array.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/input/misc/soc_button_array.c
+++ b/drivers/input/misc/soc_button_array.c
@@ -377,7 +377,7 @@ static struct soc_button_info *soc_butto
}
}
- if (!btns_desc) {
+ if (!btns_desc || !btns_desc->package.count) {
dev_err(dev, "ACPI Button Descriptors not found\n");
button_info = ERR_PTR(-ENODEV);
goto out;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 356/438] Input: evdev - zero absinfo before partial copy in EVIOCSABS
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (354 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 355/438] Input: cyttsp5 - clamp the HID report size before memcpy Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 357/438] Input: hp_sdc - shut down kicker timer on module exit Greg Kroah-Hartman
` (93 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Iván Ezequiel Rodriguez,
Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
commit 8b852965b8eaf910c314dc346967ed82c8d4f235 upstream.
The EVIOCSABS handler copies at most the user supplied ioctl size into
an uninitialized on-stack struct input_absinfo:
if (copy_from_user(&abs, p, min_t(size_t,
size, sizeof(struct input_absinfo))))
The size comes from _IOC_SIZE() of the ioctl command and is therefore
fully controlled by userspace. A short size leaves the trailing part of
the structure holding whatever was on the kernel stack, and the whole
structure is then stored into the device:
dev->absinfo[t] = abs;
EVIOCGABS hands that back to userspace, disclosing the stale stack
bytes. Only the resolution field is currently cleared, which covers the
legacy struct layout but not an arbitrarily short size.
Zero the structure before the copy so any part not supplied by the
caller reads back as zero. The existing resolution fixup is kept, since
it also handles a size that partially overlaps that field.
Fixes: 448cd1664a57 ("Input: evdev - rearrange ioctl handling")
Cc: stable@vger.kernel.org
Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Link: https://patch.msgid.link/20260901130629.24078-2-ivanrwcm25@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/evdev.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/input/evdev.c
+++ b/drivers/input/evdev.c
@@ -1229,6 +1229,8 @@ static long evdev_do_ioctl(struct file *
t = _IOC_NR(cmd) & ABS_MAX;
+ memset(&abs, 0, sizeof(abs));
+
if (copy_from_user(&abs, p, min_t(size_t,
size, sizeof(struct input_absinfo))))
return -EFAULT;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 303/398] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (299 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 302/398] Input: soc_button_array - check btns_desc->package.count Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-26 23:19 ` Daniel Salmun
2026-09-23 14:06 ` [PATCH 6.18 304/398] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Greg Kroah-Hartman
` (101 subsequent siblings)
402 siblings, 1 reply; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Raphaël Larocque,
Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Raphaël Larocque <rlarocque@disroot.org>
commit 26eb3d92c7a4d7adb1ae1740ca6e8e100b11d1ec upstream.
The Lenovo ThinkPad T440p (PNP ID LEN0036, board id 2722) has a
Synaptics touchpad whose SMBus companion is not ready at boot and
takes roughly 200 seconds to appear. During this window the touchpad
and TrackPoint are completely unresponsive on approximately 50% of
boots, making the machine unusable until the companion finally
registers.
The device is in the topbuttonpad_pnp_ids[] SMBus allowlist, so the
kernel attempts to use SMBus/RMI4 mode by default. When the companion
is not ready, psmouse_smbus_init() leaves breadcrumbs and returns
-EAGAIN, the PS/2 fallback path is taken, but the device does not
function properly until the companion appears and RMI4 takes over.
Disable SMBus InterTouch for board id 2722 so the touchpad and
TrackPoint work immediately via PS/2 from boot. Users can still force
SMBus with psmouse.synaptics_intertouch=1 if needed.
Tested-by: Raphaël Larocque <rlarocque@disroot.org>
Signed-off-by: Raphaël Larocque <rlarocque@disroot.org>
Link: https://patch.msgid.link/20260910164425.12832-1-rlarocque@disroot.org
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/mouse/synaptics.c | 8 ++++++++
1 file changed, 8 insertions(+)
--- a/drivers/input/mouse/synaptics.c
+++ b/drivers/input/mouse/synaptics.c
@@ -1837,6 +1837,14 @@ static int synaptics_setup_intertouch(st
return -ENXIO;
}
+
+ /* Disable intertouch on known-broken board revisions */
+ if (info->board_id == 2722) {
+ psmouse_info(psmouse,
+ "Disabling intertouch for board id %u\n",
+ info->board_id);
+ return -ENXIO;
+ }
}
psmouse_info(psmouse, "Trying to set up SMBus access\n");
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 357/438] Input: hp_sdc - shut down kicker timer on module exit
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (355 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 356/438] Input: evdev - zero absinfo before partial copy in EVIOCSABS Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 358/438] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Greg Kroah-Hartman
` (92 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Helge Deller,
Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
commit 309731e95917125bbd13626a7a5600490a5bf44f upstream.
hp_sdc_kicker() rearms hp_sdc.kicker with mod_timer() after scheduling the
tasklet. The module exit path uses timer_delete_sync(). That waits for a
callback already running but can still leave the timer rearmed.
A callback can therefore leave the timer pending while hp_sdc_exit() tears
down the driver, allowing timer activity to access dismantled driver state.
Use timer_shutdown_sync() for final teardown. It waits for a running
callback and prevents rearming after module exit begins.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Acked-by: Helge Deller <deller@gmx.de>
Link: https://patch.msgid.link/20260902154004.3595416-1-runyu.xiao@seu.edu.cn
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/serio/hp_sdc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/input/serio/hp_sdc.c
+++ b/drivers/input/serio/hp_sdc.c
@@ -981,7 +981,7 @@ static void hp_sdc_exit(void)
free_irq(hp_sdc.irq, &hp_sdc);
write_unlock_irq(&hp_sdc.lock);
- timer_delete_sync(&hp_sdc.kicker);
+ timer_shutdown_sync(&hp_sdc.kicker);
tasklet_kill(&hp_sdc.task);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 304/398] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (300 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 303/398] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 305/398] Input: zero ff_effect before compat copy in input_ff_effect_from_user Greg Kroah-Hartman
` (100 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+09103639e39c989e3ed3,
Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
commit fe10579b6dc3f0dac61e51e1797cacbba5039ac2 upstream.
Transport drivers (such as rmi_i2c and rmi_spi) invoke
rmi_driver_suspend() and rmi_driver_resume() on their child rmi_dev
device during system power management events. However, transport drivers
are fully registered and operational even if the physical RMI driver
failed to bind or probe the rmi_dev device.
When rmi_driver_suspend() or rmi_driver_resume() is called on an unbound
rmi_dev, dev_get_drvdata() returns NULL. Calling rmi_disable_irq() or
rmi_enable_irq() without driver data attached causes a NULL pointer
dereference and General Protection Fault when attempting to lock
data->enabled_mutex.
Fix this by checking if driver data is attached to rmi_dev in
rmi_driver_suspend() and rmi_driver_resume(), exiting early if
no driver data is present.
Fixes: 2b6a321da9a2 ("Input: synaptics-rmi4 - add support for Synaptics RMI4 devices")
Reported-by: syzbot+09103639e39c989e3ed3@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=09103639e39c989e3ed3
Cc: stable@vger.kernel.org
Assisted-by: LLM
Link: https://patch.msgid.link/anQe8UiyUR4x0flD@google.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/rmi4/rmi_driver.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
--- a/drivers/input/rmi4/rmi_driver.c
+++ b/drivers/input/rmi4/rmi_driver.c
@@ -947,6 +947,15 @@ int rmi_driver_suspend(struct rmi_device
{
int retval;
+ /*
+ * Transport driver will try to suspend RMI device even if physical
+ * driver did not bind to the RMI device, because transport device
+ * (I2C, SPI) is fully registered and operational. Exit early if
+ * there is no driver data attached to the RMI device.
+ */
+ if (!dev_get_drvdata(&rmi_dev->dev))
+ return 0;
+
retval = rmi_suspend_functions(rmi_dev);
if (retval)
dev_warn(&rmi_dev->dev, "Failed to suspend functions: %d\n",
@@ -961,6 +970,10 @@ int rmi_driver_resume(struct rmi_device
{
int retval;
+ /* Skip if not fully bound to RMI driver */
+ if (!dev_get_drvdata(&rmi_dev->dev))
+ return 0;
+
rmi_enable_irq(rmi_dev, clear_wake);
retval = rmi_resume_functions(rmi_dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 358/438] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (356 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 357/438] Input: hp_sdc - shut down kicker timer on module exit Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 359/438] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Greg Kroah-Hartman
` (91 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chris Sommers, Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chris Sommers <chris.sommers@icloud.com>
commit 25e424eb4ae1a662d9c3573218d06ac32f797fc5 upstream.
On the Acer Aspire Go 15 (AG15-42P), the internal keyboard drops out
~5 seconds after boot on both Linux and Linux-LTS kernels. Keystrokes on
the built-in keyboard stop registering while the trackpad and external
keyboards remain functional.
Testing confirms that booting with the i8042.reset kernel parameter
resolves the issue and keeps the internal keyboard responsive.
Add SERIO_QUIRK_RESET_ALWAYS to i8042_dmi_quirk_table for the Acer
Aspire AG15-42P to automatically apply this quirk on boot.
Signed-off-by: Chris Sommers <chris.sommers@icloud.com>
Link: https://patch.msgid.link/20260907182723.2709981-1-chris.sommers@icloud.com
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/serio/i8042-acpipnpio.h | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/input/serio/i8042-acpipnpio.h
+++ b/drivers/input/serio/i8042-acpipnpio.h
@@ -261,6 +261,13 @@ static const struct dmi_system_id i8042_
{
.matches = {
DMI_MATCH(DMI_SYS_VENDOR, "Acer"),
+ DMI_MATCH(DMI_PRODUCT_NAME, "Aspire AG15-42P"),
+ },
+ .driver_data = (void *)(SERIO_QUIRK_RESET_ALWAYS)
+ },
+ {
+ .matches = {
+ DMI_MATCH(DMI_SYS_VENDOR, "Acer"),
DMI_MATCH(DMI_PRODUCT_NAME, "Aspire ES1-132"),
},
.driver_data = (void *)(SERIO_QUIRK_RESET_ALWAYS)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 305/398] Input: zero ff_effect before compat copy in input_ff_effect_from_user
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (301 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 304/398] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 306/398] hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() Greg Kroah-Hartman
` (99 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Iván Ezequiel Rodriguez,
Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
commit f84819ef8d66931ee3998fee3c4f03230f4cb6cc upstream.
In the compat path input_ff_effect_from_user() aliases the caller's
native struct ff_effect with the smaller struct ff_effect_compat and
copies only the compat sized prefix:
compat_effect = (struct ff_effect_compat *)effect;
if (copy_from_user(compat_effect, buffer,
sizeof(struct ff_effect_compat)))
The tail of the native structure is never written. Callers pass an
uninitialized on-stack object, for example evdev_do_ioctl() for
EVIOCSFF, so those bytes keep their previous stack contents.
input_ff_upload() then stores the full native structure in
ff->effects[id], from where a uinput based force feedback daemon can
read it back via UI_BEGIN_FF_UPLOAD, disclosing kernel stack memory to
userspace.
Zero the effect before the compat copy.
Fixes: 2d56f3a32c0e ("Input: refactor evdev 32bit compat to be shareable with uinput")
Cc: stable@vger.kernel.org
Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Link: https://patch.msgid.link/20260901130629.24078-3-ivanrwcm25@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/input-compat.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/input/input-compat.c
+++ b/drivers/input/input-compat.c
@@ -76,6 +76,8 @@ int input_ff_effect_from_user(const char
*/
compat_effect = (struct ff_effect_compat *)effect;
+ memset(effect, 0, sizeof(*effect));
+
if (copy_from_user(compat_effect, buffer,
sizeof(struct ff_effect_compat)))
return -EFAULT;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 359/438] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (357 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 358/438] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 360/438] Input: soc_button_array - fix MS Surface Pro 11 probe failure Greg Kroah-Hartman
` (90 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
commit 51cfe54f815ae175c7d1126b983d4d7c89715004 upstream.
When chunking writes into SMBus blocks in rmi_smb_write_block(), the
loop calculates block_len using the original total length (len) instead
of the remaining length (cur_len).
If len is greater than 32 bytes (SMB_MAX_COUNT), block_len remains 32
for every iteration, even on the final partial chunk where fewer than 32
bytes remain. This causes smb_block_write() to read 32 bytes from the
advanced data buffer pointer, reading past the end of the input buffer.
Fix this by calculating block_len using cur_len and advancing the buffer
and address pointers by block_len.
Fixes: 82264d0cf7ae ("Input: synaptics-rmi4 - add SMBus support")
Cc: stable@vger.kernel.org
Reported-by: sashiko-bot@kernel.org
Assisted-by: LLM
Link: https://patch.msgid.link/anLFSMKSoKyyZ272@google.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/rmi4/rmi_smbus.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
--- a/drivers/input/rmi4/rmi_smbus.c
+++ b/drivers/input/rmi4/rmi_smbus.c
@@ -140,7 +140,7 @@ static int rmi_smb_write_block(struct rm
u8 commandcode;
struct rmi_smb_xport *rmi_smb =
container_of(xport, struct rmi_smb_xport, xport);
- int cur_len = (int)len;
+ size_t cur_len = len;
mutex_lock(&rmi_smb->page_mutex);
@@ -148,7 +148,7 @@ static int rmi_smb_write_block(struct rm
/*
* break into 32 bytes chunks to write get command code
*/
- int block_len = min_t(int, len, SMB_MAX_COUNT);
+ int block_len = min_t(size_t, cur_len, SMB_MAX_COUNT);
retval = rmi_smb_get_command_code(xport, rmiaddr, block_len,
false, &commandcode);
@@ -161,9 +161,9 @@ static int rmi_smb_write_block(struct rm
goto exit;
/* prepare to write next block of bytes */
- cur_len -= SMB_MAX_COUNT;
- databuff += SMB_MAX_COUNT;
- rmiaddr += SMB_MAX_COUNT;
+ cur_len -= block_len;
+ databuff += block_len;
+ rmiaddr += block_len;
}
exit:
mutex_unlock(&rmi_smb->page_mutex);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 306/398] hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (302 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 305/398] Input: zero ff_effect before compat copy in input_ff_effect_from_user Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 307/398] hwmon: (pmbus/core) increase number of phases and add new mask Greg Kroah-Hartman
` (98 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Muhammad Bilal, James Seo,
Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Muhammad Bilal <meatuni001@gmail.com>
commit e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69 upstream.
nsensor->current_state is dynamically replaced as the sensor's state
changes. update_numeric_sensor_from_wobj() does this by freeing the
old string and installing a new one:
if (strcmp(trimmed, nsensor->current_state)) {
new_string = hp_wmi_strdup(dev, trimmed);
if (new_string) {
devm_kfree(dev, nsensor->current_state);
nsensor->current_state = new_string;
}
}
This function is only ever called from hp_wmi_update_info() while
state->lock is held, so the free-and-replace itself is properly
serialized against concurrent updates.
fungible_show(), however, reads the same pointer after the lock has
already been dropped:
err = hp_wmi_update_info(state, info);
if (err)
return err;
switch (prop) {
...
case HP_WMI_PROPERTY_CURRENT_STATE:
seq_printf(seqf, "%s\n", nsensor->current_state);
break;
hp_wmi_update_info() takes state->lock internally and releases it
before returning, so by the time fungible_show() dereferences
nsensor->current_state in seq_printf(), no lock is held. Two
processes reading a sensor's current_state debugfs entry at
overlapping times (or one reading it while another read of the same
sensor triggers a refresh) can race: one thread's seq_printf() can
be part-way through printing the string at the moment another
thread's call into update_numeric_sensor_from_wobj() frees it with
devm_kfree() and installs a new pointer, causing a use-after-free
read.
Take state->lock around the read in fungible_show() as well, so it
can never run concurrently with the free-and-replace in
update_numeric_sensor_from_wobj().
Fixes: 23902f98f8d4 ("hwmon: add HP WMI Sensors driver")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
Acked-by: James Seo <james@equiv.tech>
Link: https://patch.msgid.link/20260916002926.161595-1-meatuni001@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/hp-wmi-sensors.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/hwmon/hp-wmi-sensors.c
+++ b/drivers/hwmon/hp-wmi-sensors.c
@@ -1261,7 +1261,9 @@ static int fungible_show(struct seq_file
break;
case HP_WMI_PROPERTY_CURRENT_STATE:
+ mutex_lock(&state->lock);
seq_printf(seqf, "%s\n", nsensor->current_state);
+ mutex_unlock(&state->lock);
break;
case HP_WMI_PROPERTY_UNIT_MODIFIER:
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 360/438] Input: soc_button_array - fix MS Surface Pro 11 probe failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (358 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 359/438] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 361/438] Input: soc_button_array - check btns_desc->package.count Greg Kroah-Hartman
` (89 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sergey Lebedev, Hans de Goede,
Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <johannes.goede@oss.qualcomm.com>
commit ed22ad5fdbdbf9b4cb4ad3003f60314b5a5eb89d upstream.
On the MS Surface Pro 11 soc_button_array probing races with the GPIO
driver probing. If soc_button_array wins the race then gpiod_get() returns
EPROBE_DEFER, which should normally take care of retrying later, but
the soc_button_array code deliberately ignores EPROBE_DEFER causing it
to fail its probe() which causes the volume and power buttons to now work.
The ignoring of EPROBE_DEFER is there to deal with a problem specific to
older Bay Trail (BYT) and Cherry Trail (CHT) tablets which often use this
driver. Modify the error handling to only ignore EPROBE_DEFER on BYT and
CHT platforms and propagate EPROBE_DEFER normally on other platforms.
Fixes: bcf059578980 ("Input: soc_button_array - partial revert of support for newer surface devices")
Cc: stable@vger.kernel.org
Reported-by: Sergey Lebedev <lsa.uz@pm.me>
Closes: https://lore.kernel.org/lkml/20260830141355.55898-1-lsa.uz@pm.me/
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Tested-by: Sergey Lebedev <lsa.uz@pm.me>
Link: https://patch.msgid.link/20260909093934.29411-1-johannes.goede@oss.qualcomm.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/misc/soc_button_array.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
--- a/drivers/input/misc/soc_button_array.c
+++ b/drivers/input/misc/soc_button_array.c
@@ -16,6 +16,7 @@
#include <linux/gpio/consumer.h>
#include <linux/gpio_keys.h>
#include <linux/gpio.h>
+#include <linux/platform_data/x86/soc.h>
#include <linux/platform_device.h>
static bool use_low_level_irq;
@@ -160,7 +161,7 @@ soc_button_device_create(struct platform
struct gpio_keys_platform_data *gpio_keys_pdata;
const struct dmi_system_id *dmi_id;
int invalid_acpi_index = -1;
- int error, gpio, irq;
+ int error, gpio, irq = 0;
int n_buttons = 0;
for (info = button_info; info->name; info++)
@@ -191,8 +192,9 @@ soc_button_device_create(struct platform
error = soc_button_lookup_gpio(&pdev->dev, info->acpi_index, &gpio, &irq);
if (error || irq < 0) {
/*
- * Skip GPIO if not present. Note we deliberately
- * ignore -EPROBE_DEFER errors here. On some devices
+ * Propagate -EPROBE_DEFER, skip button on other errors.
+ *
+ * -EPROBE_DEFER is ignored on Bay & Cherry Trail. Here
* Intel is using so called virtual GPIOs which are not
* GPIOs at all but some way for AML code to check some
* random status bits without need a custom opregion.
@@ -201,6 +203,12 @@ soc_button_device_create(struct platform
* we do not have a driver for these so they will never
* show up, therefore we ignore -EPROBE_DEFER.
*/
+ if ((error == -EPROBE_DEFER || irq == -EPROBE_DEFER) &&
+ !(soc_intel_is_byt() || soc_intel_is_cht())) {
+ error = -EPROBE_DEFER;
+ goto err_free_mem;
+ }
+
continue;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 307/398] hwmon: (pmbus/core) increase number of phases and add new mask
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (303 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 306/398] hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 308/398] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding Greg Kroah-Hartman
` (97 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nuno Sá, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nuno Sá <nuno.sa@analog.com>
commit 06bd6794b5fd2163880ac3bfe973d4cc61f359f3 upstream.
Increase the number of phases to 16 as a new upcoming device supports
such a number.
While at it, add a new mask for controlling the source of the output
voltage.
Note (groeck):
This patch was meant to prepare for support of MAX20826 and compatible
devices, which support more than 10 phases per page. However, Sashiko
reports that the mp2975 driver already supports up to 14 phases, and the
mp2856 driver supports up to 12 phases. This already has the potential for
out-of-bounds writes when probing the affected chips, making this patch a
bug fix.
Fixes: 2c6fcbb21149 ("hwmon: (pmbus) Add support for MPS Multi-phase mp2975 controller")
Fixes: f9e5f289b686 ("hwmon: (pmbus) Add support for MPS Multi-phase mp2856/mp2857 controller")
Signed-off-by: Nuno Sá <nuno.sa@analog.com>
Link: https://patch.msgid.link/20260911-hwmon-max20826-support-v2-1-5e30cbd97d84@analog.com
Cc: stable@vger.kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/pmbus.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/pmbus/pmbus.h
+++ b/drivers/hwmon/pmbus/pmbus.h
@@ -242,6 +242,7 @@ enum pmbus_regs {
/*
* OPERATION
*/
+#define PB_OPERATION_CONTROL_V_SRC GENMASK(5, 4)
#define PB_OPERATION_CONTROL_ON BIT(7)
/*
@@ -386,7 +387,7 @@ enum pmbus_sensor_classes {
};
#define PMBUS_PAGES 32 /* Per PMBus specification */
-#define PMBUS_PHASES 10 /* Maximum number of phases per page */
+#define PMBUS_PHASES 16 /* Maximum number of phases per page */
/* Functionality bit mask */
#define PMBUS_HAVE_VIN BIT(0)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 361/438] Input: soc_button_array - check btns_desc->package.count
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (359 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 360/438] Input: soc_button_array - fix MS Surface Pro 11 probe failure Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 362/438] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Greg Kroah-Hartman
` (88 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shashiko, Hans de Goede,
Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans de Goede <johannes.goede@oss.qualcomm.com>
commit fb5022278b6ea7f1838e3ef78028d5d5e3375f65 upstream.
Check that btns_desc->package.count is not 0 before accessing
btns_desc->package.elements[0].
Fixes: 4c3362f44980 ("Input: soc_button_array - add support for ACPI 6.0 Generic Button Device")
Cc: stable@vger.kernel.org
Reported-by: Shashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/linux-input/20260909091440.3384C1F00A3A@smtp.kernel.org/
Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com>
Link: https://patch.msgid.link/20260909093934.29411-2-johannes.goede@oss.qualcomm.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/misc/soc_button_array.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/input/misc/soc_button_array.c
+++ b/drivers/input/misc/soc_button_array.c
@@ -377,7 +377,7 @@ static struct soc_button_info *soc_butto
}
}
- if (!btns_desc) {
+ if (!btns_desc || !btns_desc->package.count) {
dev_err(dev, "ACPI Button Descriptors not found\n");
button_info = ERR_PTR(-ENODEV);
goto out;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 308/398] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (304 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 307/398] hwmon: (pmbus/core) increase number of phases and add new mask Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 309/398] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676 Greg Kroah-Hartman
` (96 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sanman Pradhan, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanman Pradhan <psanman@juniper.net>
commit 1d12fb94ac0975566545871dda100df34df5f845 upstream.
tps53676_identify() reads the USER_DATA_03 phase configuration to count
the phases assigned to each channel and derive the number of PMBus pages.
In each 16-bit phase descriptor the channel (PAGE) is encoded in bit 4 and
the firing order in bits 3:0, but the code tested bit 3 (0x08), which is
part of the firing-order field.
TPS53676 supports up to seven phases, so firing-order bit 3 is never set.
As a result the existing test classifies every enabled phase as channel A.
On a dual-channel configuration the phases assigned to channel B are
therefore miscounted as channel A and page 1 is not exposed.
Test the PAGE field (bit 4) instead.
Fixes: cb3d37b59012 ("hwmon: (pmbus/tps53679) Add support for TI TPS53676")
Cc: stable@vger.kernel.org
Signed-off-by: Sanman Pradhan <psanman@juniper.net>
Link: https://patch.msgid.link/20260915164823.160977-2-sanman.pradhan@hpe.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/tps53679.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/hwmon/pmbus/tps53679.c
+++ b/drivers/hwmon/pmbus/tps53679.c
@@ -187,7 +187,7 @@ static int tps53676_identify(struct i2c_
return -EIO;
for (i = 0; i < 2 * TPS53676_MAX_PHASES; i += 2) {
if (buf[i + 1] & 0x80) {
- if (buf[i] & 0x08)
+ if (buf[i] & BIT(4))
phases_b++;
else
phases_a++;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 362/438] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (360 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 361/438] Input: soc_button_array - check btns_desc->package.count Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 363/438] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Greg Kroah-Hartman
` (87 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Raphaël Larocque,
Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Raphaël Larocque <rlarocque@disroot.org>
commit 26eb3d92c7a4d7adb1ae1740ca6e8e100b11d1ec upstream.
The Lenovo ThinkPad T440p (PNP ID LEN0036, board id 2722) has a
Synaptics touchpad whose SMBus companion is not ready at boot and
takes roughly 200 seconds to appear. During this window the touchpad
and TrackPoint are completely unresponsive on approximately 50% of
boots, making the machine unusable until the companion finally
registers.
The device is in the topbuttonpad_pnp_ids[] SMBus allowlist, so the
kernel attempts to use SMBus/RMI4 mode by default. When the companion
is not ready, psmouse_smbus_init() leaves breadcrumbs and returns
-EAGAIN, the PS/2 fallback path is taken, but the device does not
function properly until the companion appears and RMI4 takes over.
Disable SMBus InterTouch for board id 2722 so the touchpad and
TrackPoint work immediately via PS/2 from boot. Users can still force
SMBus with psmouse.synaptics_intertouch=1 if needed.
Tested-by: Raphaël Larocque <rlarocque@disroot.org>
Signed-off-by: Raphaël Larocque <rlarocque@disroot.org>
Link: https://patch.msgid.link/20260910164425.12832-1-rlarocque@disroot.org
Cc: stable@vger.kernel.org
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/mouse/synaptics.c | 8 ++++++++
1 file changed, 8 insertions(+)
--- a/drivers/input/mouse/synaptics.c
+++ b/drivers/input/mouse/synaptics.c
@@ -1837,6 +1837,14 @@ static int synaptics_setup_intertouch(st
return -ENXIO;
}
+
+ /* Disable intertouch on known-broken board revisions */
+ if (info->board_id == 2722) {
+ psmouse_info(psmouse,
+ "Disabling intertouch for board id %u\n",
+ info->board_id);
+ return -ENXIO;
+ }
}
psmouse_info(psmouse, "Trying to set up SMBus access\n");
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 309/398] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (305 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 308/398] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 310/398] hwmon: (pwm-fan) Stop RPM timer before freeing tach data Greg Kroah-Hartman
` (95 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sanman Pradhan, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanman Pradhan <psanman@juniper.net>
commit 089070b51ccbac411462a30a454690274c6e4270 upstream.
tps53676_identify() derives the number of PMBus pages but does not
ensure that page 0 is selected for single-page configurations.
pmbus_set_page() does not update the PAGE register when info->pages is
1, so if boot firmware leaves PAGE set to another value subsequent
register accesses may target the wrong page.
For single-page devices, select page 0 explicitly.
Fixes: cb3d37b59012 ("hwmon: (pmbus/tps53679) Add support for TI TPS53676")
Cc: stable@vger.kernel.org
Signed-off-by: Sanman Pradhan <psanman@juniper.net>
Link: https://patch.msgid.link/20260916235406.681131-2-sanman.pradhan@hpe.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/tps53679.c | 9 +++++++++
1 file changed, 9 insertions(+)
--- a/drivers/hwmon/pmbus/tps53679.c
+++ b/drivers/hwmon/pmbus/tps53679.c
@@ -200,6 +200,15 @@ static int tps53676_identify(struct i2c_
if (phases_b > 0) {
info->pages = 2;
info->phases[1] = phases_b;
+ } else {
+ /*
+ * pmbus_set_page() does not update the PAGE register on
+ * single-page devices, so select page 0 explicitly in case
+ * the boot firmware left the device on another page.
+ */
+ ret = i2c_smbus_write_byte_data(client, PMBUS_PAGE, 0);
+ if (ret < 0)
+ return ret;
}
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 363/438] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (361 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 362/438] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 364/438] Input: zero ff_effect before compat copy in input_ff_effect_from_user Greg Kroah-Hartman
` (86 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+09103639e39c989e3ed3,
Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Torokhov <dmitry.torokhov@gmail.com>
commit fe10579b6dc3f0dac61e51e1797cacbba5039ac2 upstream.
Transport drivers (such as rmi_i2c and rmi_spi) invoke
rmi_driver_suspend() and rmi_driver_resume() on their child rmi_dev
device during system power management events. However, transport drivers
are fully registered and operational even if the physical RMI driver
failed to bind or probe the rmi_dev device.
When rmi_driver_suspend() or rmi_driver_resume() is called on an unbound
rmi_dev, dev_get_drvdata() returns NULL. Calling rmi_disable_irq() or
rmi_enable_irq() without driver data attached causes a NULL pointer
dereference and General Protection Fault when attempting to lock
data->enabled_mutex.
Fix this by checking if driver data is attached to rmi_dev in
rmi_driver_suspend() and rmi_driver_resume(), exiting early if
no driver data is present.
Fixes: 2b6a321da9a2 ("Input: synaptics-rmi4 - add support for Synaptics RMI4 devices")
Reported-by: syzbot+09103639e39c989e3ed3@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=09103639e39c989e3ed3
Cc: stable@vger.kernel.org
Assisted-by: LLM
Link: https://patch.msgid.link/anQe8UiyUR4x0flD@google.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/rmi4/rmi_driver.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
--- a/drivers/input/rmi4/rmi_driver.c
+++ b/drivers/input/rmi4/rmi_driver.c
@@ -991,6 +991,15 @@ int rmi_driver_suspend(struct rmi_device
{
int retval;
+ /*
+ * Transport driver will try to suspend RMI device even if physical
+ * driver did not bind to the RMI device, because transport device
+ * (I2C, SPI) is fully registered and operational. Exit early if
+ * there is no driver data attached to the RMI device.
+ */
+ if (!dev_get_drvdata(&rmi_dev->dev))
+ return 0;
+
retval = rmi_suspend_functions(rmi_dev);
if (retval)
dev_warn(&rmi_dev->dev, "Failed to suspend functions: %d\n",
@@ -1005,6 +1014,10 @@ int rmi_driver_resume(struct rmi_device
{
int retval;
+ /* Skip if not fully bound to RMI driver */
+ if (!dev_get_drvdata(&rmi_dev->dev))
+ return 0;
+
rmi_enable_irq(rmi_dev, clear_wake);
retval = rmi_resume_functions(rmi_dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 310/398] hwmon: (pwm-fan) Stop RPM timer before freeing tach data
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (306 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 309/398] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676 Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 311/398] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove Greg Kroah-Hartman
` (94 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yibo Tan, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yibo Tan <lhfff@tju.edu.cn>
commit 26d5ff79768548efb1e604bb6e8697c101e06269 upstream.
sample_timer() rearms the RPM timer and accesses the devm-managed
ctx->tachs and ctx->pulses_per_revolution arrays. The cleanup action
which stops the timer is registered before those arrays are allocated.
Since devres releases entries in reverse order, driver detach can free
the arrays before pwm_fan_cleanup() shuts down the timer. A timer expiry
in that window accesses the freed tach data.
With a KASAN kernel, a test-only kprobe delayed entry to
pwm_fan_cleanup() while normal sysfs unbind ran. Each of three runs
reported three four-byte reads and two four-byte writes in sample_timer()
after its backing devm allocations had been freed. The helper did not
invoke the timer callback, cleanup actions or free functions.
With the fix, three matching unbind runs completed without KASAN, BUG,
WARNING, Oops or panic. Instrumentation confirmed that timer retirement
completed before the first timer backing allocation was released.
Split timer retirement from the power cleanup and register its devres
action after the timer backing data and IRQ actions are installed. This
preserves the early power rollback action while ensuring the timer is
retired before its backing data is released. Use timer_shutdown_sync()
because the callback can rearm itself.
Fixes: 01695410d452 ("hwmon: (pwm-fan) Store tach data separately")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Yibo Tan <lhfff@tju.edu.cn>
Link: https://patch.msgid.link/20260911071809.130151-1-lhfff@tju.edu.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pwm-fan.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/pwm-fan.c
+++ b/drivers/hwmon/pwm-fan.c
@@ -484,7 +484,6 @@ static void pwm_fan_cleanup(void *__ctx)
{
struct pwm_fan_ctx *ctx = __ctx;
- timer_delete_sync(&ctx->rpm_timer);
if (ctx->pwm_shutdown) {
ctx->enable_mode = pwm_enable_reg_enable;
__set_pwm(ctx, ctx->pwm_shutdown);
@@ -495,6 +494,13 @@ static void pwm_fan_cleanup(void *__ctx)
}
}
+static void pwm_fan_timer_cleanup(void *__ctx)
+{
+ struct pwm_fan_ctx *ctx = __ctx;
+
+ timer_shutdown_sync(&ctx->rpm_timer);
+}
+
static int pwm_fan_probe(struct platform_device *pdev)
{
struct thermal_cooling_device *cdev;
@@ -649,6 +655,10 @@ static int pwm_fan_probe(struct platform
}
if (ctx->tach_count > 0) {
+ ret = devm_add_action_or_reset(dev, pwm_fan_timer_cleanup, ctx);
+ if (ret)
+ return ret;
+
ctx->sample_start = ktime_get();
mod_timer(&ctx->rpm_timer, jiffies + HZ);
@@ -704,6 +714,7 @@ static void pwm_fan_shutdown(struct plat
{
struct pwm_fan_ctx *ctx = platform_get_drvdata(pdev);
+ pwm_fan_timer_cleanup(ctx);
pwm_fan_cleanup(ctx);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 364/438] Input: zero ff_effect before compat copy in input_ff_effect_from_user
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (362 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 363/438] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 365/438] hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() Greg Kroah-Hartman
` (85 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Iván Ezequiel Rodriguez,
Dmitry Torokhov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
commit f84819ef8d66931ee3998fee3c4f03230f4cb6cc upstream.
In the compat path input_ff_effect_from_user() aliases the caller's
native struct ff_effect with the smaller struct ff_effect_compat and
copies only the compat sized prefix:
compat_effect = (struct ff_effect_compat *)effect;
if (copy_from_user(compat_effect, buffer,
sizeof(struct ff_effect_compat)))
The tail of the native structure is never written. Callers pass an
uninitialized on-stack object, for example evdev_do_ioctl() for
EVIOCSFF, so those bytes keep their previous stack contents.
input_ff_upload() then stores the full native structure in
ff->effects[id], from where a uinput based force feedback daemon can
read it back via UI_BEGIN_FF_UPLOAD, disclosing kernel stack memory to
userspace.
Zero the effect before the compat copy.
Fixes: 2d56f3a32c0e ("Input: refactor evdev 32bit compat to be shareable with uinput")
Cc: stable@vger.kernel.org
Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Link: https://patch.msgid.link/20260901130629.24078-3-ivanrwcm25@gmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/input/input-compat.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/input/input-compat.c
+++ b/drivers/input/input-compat.c
@@ -76,6 +76,8 @@ int input_ff_effect_from_user(const char
*/
compat_effect = (struct ff_effect_compat *)effect;
+ memset(effect, 0, sizeof(*effect));
+
if (copy_from_user(compat_effect, buffer,
sizeof(struct ff_effect_compat)))
return -EFAULT;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 311/398] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (307 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 310/398] hwmon: (pwm-fan) Stop RPM timer before freeing tach data Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 312/398] hwmon: (w83793) release probe data through kref Greg Kroah-Hartman
` (93 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit 0ff9c7775e51ac6d47b1bb5c46f06b1434fe58a8 upstream.
When the fan/pwm 4-5 pins are not used as GPIO, w83791d_probe()
creates the w83791d_group_fanpwm45 sysfs group on the I2C client
device.
The probe error path removes this group when a later initialization
step fails, but the normal remove path only removes w83791d_group.
As a result, the optional fan/pwm 4-5 sysfs files can remain after the
driver is unbound.
The callbacks associated with these files access the driver data,
which is devm allocated and released after driver unbind. Leaving the
sysfs files behind can therefore result in accesses to stale driver
data.
Remove w83791d_group_fanpwm45 during normal teardown as well.
This issue was found by manual code inspection.
Fixes: 6e1ecd9b8f13 ("hwmon: (w83791d) fan 4/5 pins can also be used for gpio")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260914062809.1650538-1-lgs201920130244@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/w83791d.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/hwmon/w83791d.c
+++ b/drivers/hwmon/w83791d.c
@@ -1415,6 +1415,7 @@ static void w83791d_remove(struct i2c_cl
struct w83791d_data *data = i2c_get_clientdata(client);
hwmon_device_unregister(data->hwmon_dev);
+ sysfs_remove_group(&client->dev.kobj, &w83791d_group_fanpwm45);
sysfs_remove_group(&client->dev.kobj, &w83791d_group);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 365/438] hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (363 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 364/438] Input: zero ff_effect before compat copy in input_ff_effect_from_user Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 366/438] hwmon: (pmbus/core) increase number of phases and add new mask Greg Kroah-Hartman
` (84 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Muhammad Bilal, James Seo,
Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Muhammad Bilal <meatuni001@gmail.com>
commit e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69 upstream.
nsensor->current_state is dynamically replaced as the sensor's state
changes. update_numeric_sensor_from_wobj() does this by freeing the
old string and installing a new one:
if (strcmp(trimmed, nsensor->current_state)) {
new_string = hp_wmi_strdup(dev, trimmed);
if (new_string) {
devm_kfree(dev, nsensor->current_state);
nsensor->current_state = new_string;
}
}
This function is only ever called from hp_wmi_update_info() while
state->lock is held, so the free-and-replace itself is properly
serialized against concurrent updates.
fungible_show(), however, reads the same pointer after the lock has
already been dropped:
err = hp_wmi_update_info(state, info);
if (err)
return err;
switch (prop) {
...
case HP_WMI_PROPERTY_CURRENT_STATE:
seq_printf(seqf, "%s\n", nsensor->current_state);
break;
hp_wmi_update_info() takes state->lock internally and releases it
before returning, so by the time fungible_show() dereferences
nsensor->current_state in seq_printf(), no lock is held. Two
processes reading a sensor's current_state debugfs entry at
overlapping times (or one reading it while another read of the same
sensor triggers a refresh) can race: one thread's seq_printf() can
be part-way through printing the string at the moment another
thread's call into update_numeric_sensor_from_wobj() frees it with
devm_kfree() and installs a new pointer, causing a use-after-free
read.
Take state->lock around the read in fungible_show() as well, so it
can never run concurrently with the free-and-replace in
update_numeric_sensor_from_wobj().
Fixes: 23902f98f8d4 ("hwmon: add HP WMI Sensors driver")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
Acked-by: James Seo <james@equiv.tech>
Link: https://patch.msgid.link/20260916002926.161595-1-meatuni001@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/hp-wmi-sensors.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/hwmon/hp-wmi-sensors.c
+++ b/drivers/hwmon/hp-wmi-sensors.c
@@ -1261,7 +1261,9 @@ static int fungible_show(struct seq_file
break;
case HP_WMI_PROPERTY_CURRENT_STATE:
+ mutex_lock(&state->lock);
seq_printf(seqf, "%s\n", nsensor->current_state);
+ mutex_unlock(&state->lock);
break;
case HP_WMI_PROPERTY_UNIT_MODIFIER:
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 312/398] hwmon: (w83793) release probe data through kref
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (308 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 311/398] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 313/398] hwmon: (cgbc-hwmon) Fix current sensors ID lookup Greg Kroah-Hartman
` (92 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit c702a5f18b780e477eccbbab558e590e9673e4cb upstream.
w83793_probe() initializes data->kref to manage the lifetime of the
driver data. The normal remove path drops the driver-owned reference
with kref_put(), while watchdog users take and release additional
references through the same kref.
However, the probe error path still frees data directly with kfree().
This bypasses the kref-managed lifetime and discards the initial
reference without a matching kref_put(), leaving the reference
accounting unbalanced.
Drop the probe-owned reference with kref_put() instead and let
w83793_release_resources() perform the final free, matching the normal
remove path.
This issue was found by manual code inspection.
Fixes: 5852f9609d21 ("hwmon: (w83793) Add watchdog functionality")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260914073638.1662500-1-lgs201920130244@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/w83793.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/w83793.c
+++ b/drivers/hwmon/w83793.c
@@ -1928,7 +1928,9 @@ exit_remove:
for (i = 0; i < ARRAY_SIZE(w83793_temp); i++)
device_remove_file(dev, &w83793_temp[i].dev_attr);
free_mem:
- kfree(data);
+ mutex_lock(&watchdog_data_mutex);
+ kref_put(&data->kref, w83793_release_resources);
+ mutex_unlock(&watchdog_data_mutex);
exit:
return err;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 366/438] hwmon: (pmbus/core) increase number of phases and add new mask
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (364 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 365/438] hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 367/438] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding Greg Kroah-Hartman
` (83 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nuno Sá, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nuno Sá <nuno.sa@analog.com>
commit 06bd6794b5fd2163880ac3bfe973d4cc61f359f3 upstream.
Increase the number of phases to 16 as a new upcoming device supports
such a number.
While at it, add a new mask for controlling the source of the output
voltage.
Note (groeck):
This patch was meant to prepare for support of MAX20826 and compatible
devices, which support more than 10 phases per page. However, Sashiko
reports that the mp2975 driver already supports up to 14 phases, and the
mp2856 driver supports up to 12 phases. This already has the potential for
out-of-bounds writes when probing the affected chips, making this patch a
bug fix.
Fixes: 2c6fcbb21149 ("hwmon: (pmbus) Add support for MPS Multi-phase mp2975 controller")
Fixes: f9e5f289b686 ("hwmon: (pmbus) Add support for MPS Multi-phase mp2856/mp2857 controller")
Signed-off-by: Nuno Sá <nuno.sa@analog.com>
Link: https://patch.msgid.link/20260911-hwmon-max20826-support-v2-1-5e30cbd97d84@analog.com
Cc: stable@vger.kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/pmbus.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/pmbus/pmbus.h
+++ b/drivers/hwmon/pmbus/pmbus.h
@@ -242,6 +242,7 @@ enum pmbus_regs {
/*
* OPERATION
*/
+#define PB_OPERATION_CONTROL_V_SRC GENMASK(5, 4)
#define PB_OPERATION_CONTROL_ON BIT(7)
/*
@@ -386,7 +387,7 @@ enum pmbus_sensor_classes {
};
#define PMBUS_PAGES 32 /* Per PMBus specification */
-#define PMBUS_PHASES 10 /* Maximum number of phases per page */
+#define PMBUS_PHASES 16 /* Maximum number of phases per page */
/* Functionality bit mask */
#define PMBUS_HAVE_VIN BIT(0)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 313/398] hwmon: (cgbc-hwmon) Fix current sensors ID lookup
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (309 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 312/398] hwmon: (w83793) release probe data through kref Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 314/398] hwmon: (cgbc-hwmon) Add missing sensors Greg Kroah-Hartman
` (91 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, stable,
Thomas Richard (congatec GmbH), Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
commit 7bae83ffb133bc373d098fa6828cef2ef4da49fe upstream.
Current sensors on the Congatec Board Controller don't use consecutive IDs,
unlike other sensor types (voltage, temperature, fan). The driver assumed
consecutive IDs and performed a simple lookup, which caused an unknown
sensor warning. Define current sensor IDs explicitly.
Changes the warning on conga-SA7 (type and channel are correct now).
Before:
Board Controller returned an unknown sensor (type=2, channel=17), ignore it
After:
Board Controller returned an unknown sensor (bc_type=1, bc_id=11), ignore it
Cc: stable@kernel.org
Fixes: 08ebc9def79f ("hwmon: Add Congatec Board Controller monitoring driver")
Signed-off-by: Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
Link: https://patch.msgid.link/20260911-cgbc-hwmon-fix-and-new-sensors-v2-1-0c6bf078d173@bootlin.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/cgbc-hwmon.c | 93 ++++++++++++++++++++++++++-------------------
1 file changed, 54 insertions(+), 39 deletions(-)
--- a/drivers/hwmon/cgbc-hwmon.c
+++ b/drivers/hwmon/cgbc-hwmon.c
@@ -52,31 +52,36 @@ static const char * const cgbc_hwmon_lab
"BOTTOMDIM Temperature",
};
+static const char * const cgbc_hwmon_labels_in[] = {
+ "CPU Voltage",
+ "DC Runtime Voltage",
+ "DC Standby Voltage",
+ "CMOS Battery Voltage",
+ "Battery Voltage",
+ "AC Voltage",
+ "Other Voltage",
+ "5V Voltage",
+ "5V Standby Voltage",
+ "3V3 Voltage",
+ "3V3 Standby Voltage",
+ "VCore A Voltage",
+ "VCore B Voltage",
+ "12V Voltage",
+};
+
+/*
+ * Current sensors are a bit special, they don't have consecutive IDs like
+ * other types of sensors. So they need to be defined explicitly.
+ */
static const struct {
- enum hwmon_sensor_types type;
const char *label;
-} cgbc_hwmon_labels_in[] = {
- { hwmon_in, "CPU Voltage" },
- { hwmon_in, "DC Runtime Voltage" },
- { hwmon_in, "DC Standby Voltage" },
- { hwmon_in, "CMOS Battery Voltage" },
- { hwmon_in, "Battery Voltage" },
- { hwmon_in, "AC Voltage" },
- { hwmon_in, "Other Voltage" },
- { hwmon_in, "5V Voltage" },
- { hwmon_in, "5V Standby Voltage" },
- { hwmon_in, "3V3 Voltage" },
- { hwmon_in, "3V3 Standby Voltage" },
- { hwmon_in, "VCore A Voltage" },
- { hwmon_in, "VCore B Voltage" },
- { hwmon_in, "12V Voltage" },
- { hwmon_curr, "DC Current" },
- { hwmon_curr, "5V Current" },
- { hwmon_curr, "12V Current" },
+ int id;
+} cgbc_hwmon_labels_curr[] = {
+ { "DC Current", 0x12 },
+ { "5V Current", 0x18 },
+ { "12V Current", 0x1E },
};
-#define CGBC_HWMON_NB_IN_SENSORS 14
-
static const char * const cgbc_hwmon_labels_fan[] = {
"CPU Fan",
"Box Fan",
@@ -114,7 +119,8 @@ static int cgbc_hwmon_probe_sensors(stru
for (i = 0; i < nb_sensors; i++) {
enum cgbc_sensor_types type;
- unsigned int channel;
+ unsigned int channel, id;
+ int j;
/*
* No need to request data for the first sensor.
@@ -128,32 +134,49 @@ static int cgbc_hwmon_probe_sensors(stru
}
type = FIELD_GET(CGBC_HWMON_TYPE_MASK, data[1]);
- channel = FIELD_GET(CGBC_HWMON_ID_MASK, data[1]) - 1;
+ id = FIELD_GET(CGBC_HWMON_ID_MASK, data[1]);
+ channel = id - 1;
if (type == CGBC_HWMON_TYPE_TEMP && channel < ARRAY_SIZE(cgbc_hwmon_labels_temp)) {
sensor->type = hwmon_temp;
sensor->label = cgbc_hwmon_labels_temp[channel];
- } else if (type == CGBC_HWMON_TYPE_IN &&
- channel < ARRAY_SIZE(cgbc_hwmon_labels_in)) {
+ } else if (type == CGBC_HWMON_TYPE_IN) {
/*
* The Board Controller doesn't differentiate current and voltage sensors.
- * Get the sensor type from cgbc_hwmon_labels_in[channel].type instead.
+ * First check if it is a current sensor.
*/
- sensor->type = cgbc_hwmon_labels_in[channel].type;
- sensor->label = cgbc_hwmon_labels_in[channel].label;
+ for (j = 0; j < ARRAY_SIZE(cgbc_hwmon_labels_curr); j++) {
+ if (id == cgbc_hwmon_labels_curr[j].id) {
+ sensor->type = hwmon_curr;
+ sensor->label = cgbc_hwmon_labels_curr[j].label;
+ channel = j;
+ }
+ }
+
+ /* If it's not a current sensor, it may be a voltage sensor. */
+ if (!sensor->label && channel < ARRAY_SIZE(cgbc_hwmon_labels_in)) {
+ sensor->type = hwmon_in;
+ sensor->label = cgbc_hwmon_labels_in[channel];
+ }
} else if (type == CGBC_HWMON_TYPE_FAN &&
channel < ARRAY_SIZE(cgbc_hwmon_labels_fan)) {
sensor->type = hwmon_fan;
sensor->label = cgbc_hwmon_labels_fan[channel];
- } else {
- dev_warn(dev, "Board Controller returned an unknown sensor (type=%d, channel=%d), ignore it",
- type, channel);
+ }
+
+ if (!sensor->label) {
+ dev_warn(dev, "Board Controller returned an unknown sensor (bc_type=%d, bc_id=%d), ignore it",
+ type, id);
continue;
}
sensor->active = FIELD_GET(CGBC_HWMON_ACTIVE_BIT, data[1]);
sensor->channel = channel;
sensor->index = i;
+
+ dev_dbg(dev, "Found sensor: bc_type=%d, bc_id=%d, hwmon_type=%d, hwmon_channel=%d, hwmon_label='%s', active=%d\n",
+ type, id, sensor->type, sensor->channel, sensor->label, sensor->active);
+
sensor++;
hwmon->nb_sensors++;
}
@@ -167,14 +190,6 @@ static struct cgbc_hwmon_sensor *cgbc_hw
struct cgbc_hwmon_sensor *sensor = NULL;
int i;
- /*
- * The Board Controller doesn't differentiate current and voltage sensors.
- * The channel value (from the Board Controller point of view) shall be computed for current
- * sensors.
- */
- if (type == hwmon_curr)
- channel += CGBC_HWMON_NB_IN_SENSORS;
-
for (i = 0; i < hwmon->nb_sensors; i++) {
if (hwmon->sensors[i].type == type && hwmon->sensors[i].channel == channel) {
sensor = &hwmon->sensors[i];
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 367/438] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (365 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 366/438] hwmon: (pmbus/core) increase number of phases and add new mask Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 368/438] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676 Greg Kroah-Hartman
` (82 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sanman Pradhan, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanman Pradhan <psanman@juniper.net>
commit 1d12fb94ac0975566545871dda100df34df5f845 upstream.
tps53676_identify() reads the USER_DATA_03 phase configuration to count
the phases assigned to each channel and derive the number of PMBus pages.
In each 16-bit phase descriptor the channel (PAGE) is encoded in bit 4 and
the firing order in bits 3:0, but the code tested bit 3 (0x08), which is
part of the firing-order field.
TPS53676 supports up to seven phases, so firing-order bit 3 is never set.
As a result the existing test classifies every enabled phase as channel A.
On a dual-channel configuration the phases assigned to channel B are
therefore miscounted as channel A and page 1 is not exposed.
Test the PAGE field (bit 4) instead.
Fixes: cb3d37b59012 ("hwmon: (pmbus/tps53679) Add support for TI TPS53676")
Cc: stable@vger.kernel.org
Signed-off-by: Sanman Pradhan <psanman@juniper.net>
Link: https://patch.msgid.link/20260915164823.160977-2-sanman.pradhan@hpe.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/tps53679.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/hwmon/pmbus/tps53679.c
+++ b/drivers/hwmon/pmbus/tps53679.c
@@ -187,7 +187,7 @@ static int tps53676_identify(struct i2c_
return -EIO;
for (i = 0; i < 2 * TPS53676_MAX_PHASES; i += 2) {
if (buf[i + 1] & 0x80) {
- if (buf[i] & 0x08)
+ if (buf[i] & BIT(4))
phases_b++;
else
phases_a++;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 314/398] hwmon: (cgbc-hwmon) Add missing sensors
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (310 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 313/398] hwmon: (cgbc-hwmon) Fix current sensors ID lookup Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 315/398] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
` (90 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, stable,
Thomas Richard (congatec GmbH), Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
commit 3550d1dbbcb9f51b77e077e8958423ee2c401c6c upstream.
Add the following sensors:
- Alternate Board Temperature (temp11_input)
- Top DIMM 1-7 Temperature (temp12_input to temp18_input)
- Bottom DIMM 1 Temperature (temp19_input)
- 12V Standby Voltage (in14_input)
This fixes the following warning on conga-SA7:
Board Controller returned an unknown sensor (bc_type=1, bc_id=11), ignore it
Also update existing labels to match Congatec documentation.
Cc: stable@kernel.org
Fixes: 08ebc9def79f ("hwmon: Add Congatec Board Controller monitoring driver")
Signed-off-by: Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
Link: https://patch.msgid.link/20260911-cgbc-hwmon-fix-and-new-sensors-v2-2-0c6bf078d173@bootlin.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
Documentation/hwmon/cgbc-hwmon.rst | 42 ++++++++++++++++++-----------
drivers/hwmon/cgbc-hwmon.c | 52 ++++++++++++++++++++++++-------------
2 files changed, 60 insertions(+), 34 deletions(-)
--- a/Documentation/hwmon/cgbc-hwmon.rst
+++ b/Documentation/hwmon/cgbc-hwmon.rst
@@ -28,34 +28,44 @@ system.
Name Description
============= ======================
temp1_input CPU temperature
-temp2_input Box temperature
+temp2_input Case temperature
temp3_input Ambient temperature
-temp4_input Board temperature
-temp5_input Carrier temperature
-temp6_input Chipset temperature
-temp7_input Video temperature
+temp4_input CPU Board temperature
+temp5_input Carrier Board temperature
+temp6_input System Chipset temperature
+temp7_input Video Controller/Board temperature
temp8_input Other temperature
-temp9_input TOPDIM temperature
-temp10_input BOTTOMDIM temperature
-in0_input CPU voltage
+temp9_input Top DIMM 0 temperature
+temp10_input Bottom DIMM 0 temperature
+temp11_input Alternate Board temperature
+temp12_input Top DIMM 1 temperature
+temp13_input Top DIMM 2 temperature
+temp14_input Top DIMM 3 temperature
+temp15_input Top DIMM 4 temperature
+temp16_input Top DIMM 5 temperature
+temp17_input Top DIMM 6 temperature
+temp18_input Top DIMM 7 temperature
+temp19_input Bottom DIMM 1 temperature
+in0_input CPU Core voltage
in1_input DC Runtime voltage
in2_input DC Standby voltage
in3_input CMOS Battery voltage
-in4_input Battery voltage
+in4_input Battery Supply voltage
in5_input AC voltage
in6_input Other voltage
-in7_input 5V voltage
+in7_input 5V Runtime voltage
in8_input 5V Standby voltage
-in9_input 3V3 voltage
+in9_input 3V3 Runtime voltage
in10_input 3V3 Standby voltage
in11_input VCore A voltage
in12_input VCore B voltage
-in13_input 12V voltage
-curr1_input DC current
-curr2_input 5V current
-curr3_input 12V current
+in13_input 12V Runtime voltage
+in14_input 12V Standby voltage
+curr1_input DC Runtime current
+curr2_input 5V Runtime current
+curr3_input 12V Runtime current
fan1_input CPU fan
-fan2_input Box fan
+fan2_input Case fan
fan3_input Ambient fan
fan4_input Chiptset fan
fan5_input Video fan
--- a/drivers/hwmon/cgbc-hwmon.c
+++ b/drivers/hwmon/cgbc-hwmon.c
@@ -41,32 +41,42 @@ enum cgbc_sensor_types {
static const char * const cgbc_hwmon_labels_temp[] = {
"CPU Temperature",
- "Box Temperature",
+ "Case Temperature",
"Ambient Temperature",
- "Board Temperature",
- "Carrier Temperature",
- "Chipset Temperature",
- "Video Temperature",
+ "CPU Board Temperature",
+ "Carrier Board Temperature",
+ "System Chipset Temperature",
+ "Video Controller/Board Temperature",
"Other Temperature",
- "TOPDIM Temperature",
- "BOTTOMDIM Temperature",
+ "Top DIMM 0 Temperature",
+ "Bottom DIMM 0 Temperature",
+ "Alternate Board Temperature",
+ "Top DIMM 1 Temperature",
+ "Top DIMM 2 Temperature",
+ "Top DIMM 3 Temperature",
+ "Top DIMM 4 Temperature",
+ "Top DIMM 5 Temperature",
+ "Top DIMM 6 Temperature",
+ "Top DIMM 7 Temperature",
+ "Bottom DIMM 1 Temperature",
};
static const char * const cgbc_hwmon_labels_in[] = {
- "CPU Voltage",
+ "CPU Core Voltage",
"DC Runtime Voltage",
"DC Standby Voltage",
"CMOS Battery Voltage",
- "Battery Voltage",
+ "Battery Supply Voltage",
"AC Voltage",
"Other Voltage",
- "5V Voltage",
+ "5V Runtime Voltage",
"5V Standby Voltage",
- "3V3 Voltage",
+ "3V3 Runtime Voltage",
"3V3 Standby Voltage",
"VCore A Voltage",
"VCore B Voltage",
- "12V Voltage",
+ "12V Runtime Voltage",
+ "12V Standby Voltage",
};
/*
@@ -77,14 +87,14 @@ static const struct {
const char *label;
int id;
} cgbc_hwmon_labels_curr[] = {
- { "DC Current", 0x12 },
- { "5V Current", 0x18 },
- { "12V Current", 0x1E },
+ { "DC Runtime Current", 0x12 },
+ { "5V Runtime Current", 0x18 },
+ { "12V Runtime Current", 0x1E },
};
static const char * const cgbc_hwmon_labels_fan[] = {
"CPU Fan",
- "Box Fan",
+ "Case Fan",
"Ambient Fan",
"Chipset Fan",
"Video Fan",
@@ -255,7 +265,12 @@ static const struct hwmon_channel_info *
HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
- HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL),
+ HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
+ HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
+ HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
+ HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
+ HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
+ HWMON_T_INPUT | HWMON_T_LABEL),
HWMON_CHANNEL_INFO(in,
HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
@@ -263,7 +278,8 @@ static const struct hwmon_channel_info *
HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
- HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL),
+ HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
+ HWMON_I_INPUT | HWMON_I_LABEL),
HWMON_CHANNEL_INFO(curr,
HWMON_C_INPUT | HWMON_C_LABEL, HWMON_C_INPUT | HWMON_C_LABEL,
HWMON_C_INPUT | HWMON_C_LABEL),
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 368/438] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (366 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 367/438] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 369/438] hwmon: (pwm-fan) Stop RPM timer before freeing tach data Greg Kroah-Hartman
` (81 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sanman Pradhan, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanman Pradhan <psanman@juniper.net>
commit 089070b51ccbac411462a30a454690274c6e4270 upstream.
tps53676_identify() derives the number of PMBus pages but does not
ensure that page 0 is selected for single-page configurations.
pmbus_set_page() does not update the PAGE register when info->pages is
1, so if boot firmware leaves PAGE set to another value subsequent
register accesses may target the wrong page.
For single-page devices, select page 0 explicitly.
Fixes: cb3d37b59012 ("hwmon: (pmbus/tps53679) Add support for TI TPS53676")
Cc: stable@vger.kernel.org
Signed-off-by: Sanman Pradhan <psanman@juniper.net>
Link: https://patch.msgid.link/20260916235406.681131-2-sanman.pradhan@hpe.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pmbus/tps53679.c | 9 +++++++++
1 file changed, 9 insertions(+)
--- a/drivers/hwmon/pmbus/tps53679.c
+++ b/drivers/hwmon/pmbus/tps53679.c
@@ -200,6 +200,15 @@ static int tps53676_identify(struct i2c_
if (phases_b > 0) {
info->pages = 2;
info->phases[1] = phases_b;
+ } else {
+ /*
+ * pmbus_set_page() does not update the PAGE register on
+ * single-page devices, so select page 0 explicitly in case
+ * the boot firmware left the device on another page.
+ */
+ ret = i2c_smbus_write_byte_data(client, PMBUS_PAGE, 0);
+ if (ret < 0)
+ return ret;
}
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 315/398] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (311 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 314/398] hwmon: (cgbc-hwmon) Add missing sensors Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 316/398] watchdog: digicolor: Avoid division by zero Greg Kroah-Hartman
` (89 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Li Jun, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Jun <lijun01@kylinos.cn>
commit 7cb575b71ab98194d2e040bded3a7281e089c5ed upstream.
da9063_wdt_suspend() and da9063_wdt_resume() only check watchdog_active(),
when the watchdog is left running by the driver sets
WDOG_HW_RUNNING in da9063_wdt_probe() but userspace never opens the
device, so WDOG_ACTIVE remains cleared, the wdt_disable() will not be
executed in da9063_wdt_suspend. In this case, the suspend callback is
a no-op and the watchdog keeps counting during system suspend,
leading to an unexpected system reset.
Check WDOG_HW_RUNNING and wdd,can fix this issue.
Fixes: a7ceca4398bc8 ("watchdog: da9063: optionally disable watchdog during suspend")
Cc: stable@vger.kernel.org
Signed-off-by: Li Jun <lijun01@kylinos.cn>
Link: https://patch.msgid.link/20260917013710.2754679-1-lijun01@kylinos.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/da9063_wdt.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/watchdog/da9063_wdt.c
+++ b/drivers/watchdog/da9063_wdt.c
@@ -271,7 +271,7 @@ static int da9063_wdt_suspend(struct dev
if (!da9063->use_sw_pm)
return 0;
- if (watchdog_active(wdd))
+ if (watchdog_active(wdd) || watchdog_hw_running(wdd))
return da9063_wdt_stop(wdd);
return 0;
@@ -285,7 +285,7 @@ static int da9063_wdt_resume(struct devi
if (!da9063->use_sw_pm)
return 0;
- if (watchdog_active(wdd))
+ if (watchdog_active(wdd) || watchdog_hw_running(wdd))
return da9063_wdt_start(wdd);
return 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 369/438] hwmon: (pwm-fan) Stop RPM timer before freeing tach data
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (367 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 368/438] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676 Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 370/438] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove Greg Kroah-Hartman
` (80 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yibo Tan, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yibo Tan <lhfff@tju.edu.cn>
commit 26d5ff79768548efb1e604bb6e8697c101e06269 upstream.
sample_timer() rearms the RPM timer and accesses the devm-managed
ctx->tachs and ctx->pulses_per_revolution arrays. The cleanup action
which stops the timer is registered before those arrays are allocated.
Since devres releases entries in reverse order, driver detach can free
the arrays before pwm_fan_cleanup() shuts down the timer. A timer expiry
in that window accesses the freed tach data.
With a KASAN kernel, a test-only kprobe delayed entry to
pwm_fan_cleanup() while normal sysfs unbind ran. Each of three runs
reported three four-byte reads and two four-byte writes in sample_timer()
after its backing devm allocations had been freed. The helper did not
invoke the timer callback, cleanup actions or free functions.
With the fix, three matching unbind runs completed without KASAN, BUG,
WARNING, Oops or panic. Instrumentation confirmed that timer retirement
completed before the first timer backing allocation was released.
Split timer retirement from the power cleanup and register its devres
action after the timer backing data and IRQ actions are installed. This
preserves the early power rollback action while ensuring the timer is
retired before its backing data is released. Use timer_shutdown_sync()
because the callback can rearm itself.
Fixes: 01695410d452 ("hwmon: (pwm-fan) Store tach data separately")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Yibo Tan <lhfff@tju.edu.cn>
Link: https://patch.msgid.link/20260911071809.130151-1-lhfff@tju.edu.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/pwm-fan.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/pwm-fan.c
+++ b/drivers/hwmon/pwm-fan.c
@@ -483,7 +483,6 @@ static void pwm_fan_cleanup(void *__ctx)
{
struct pwm_fan_ctx *ctx = __ctx;
- timer_delete_sync(&ctx->rpm_timer);
if (ctx->pwm_shutdown) {
ctx->enable_mode = pwm_enable_reg_enable;
__set_pwm(ctx, ctx->pwm_shutdown);
@@ -494,6 +493,13 @@ static void pwm_fan_cleanup(void *__ctx)
}
}
+static void pwm_fan_timer_cleanup(void *__ctx)
+{
+ struct pwm_fan_ctx *ctx = __ctx;
+
+ timer_shutdown_sync(&ctx->rpm_timer);
+}
+
static int pwm_fan_probe(struct platform_device *pdev)
{
struct thermal_cooling_device *cdev;
@@ -648,6 +654,10 @@ static int pwm_fan_probe(struct platform
}
if (ctx->tach_count > 0) {
+ ret = devm_add_action_or_reset(dev, pwm_fan_timer_cleanup, ctx);
+ if (ret)
+ return ret;
+
ctx->sample_start = ktime_get();
mod_timer(&ctx->rpm_timer, jiffies + HZ);
@@ -704,6 +714,7 @@ static void pwm_fan_shutdown(struct plat
{
struct pwm_fan_ctx *ctx = platform_get_drvdata(pdev);
+ pwm_fan_timer_cleanup(ctx);
pwm_fan_cleanup(ctx);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 316/398] watchdog: digicolor: Avoid division by zero
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (312 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 315/398] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 317/398] watchdog: msc313e: Fix premature reset during timeout update Greg Kroah-Hartman
` (88 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Baruch Siach,
Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 400cb663ca019bae6eb878f06f1094ddf7c0b0df upstream.
clk_get_rate() could return 0. Avoid a division by zero panic.
Since get_timeleft() cannot propagate errors, check the clock rate early
in probe() and cache the rate in the driver data as it is unlikely to
change at runtime.
Fixes: 336694a01dae ("watchdog: digicolor: driver for Conexant Digicolor CX92755 SoC")
Cc: stable@vger.kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Acked-by: Baruch Siach <baruch@tkos.co.il>
Link: https://patch.msgid.link/20260913064851.8239-2-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/digicolor_wdt.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
--- a/drivers/watchdog/digicolor_wdt.c
+++ b/drivers/watchdog/digicolor_wdt.c
@@ -25,6 +25,7 @@ struct dc_wdt {
void __iomem *base;
struct clk *clk;
spinlock_t lock;
+ unsigned long rate;
};
static unsigned timeout;
@@ -61,7 +62,7 @@ static int dc_wdt_start(struct watchdog_
{
struct dc_wdt *wdt = watchdog_get_drvdata(wdog);
- dc_wdt_set(wdt, wdog->timeout * clk_get_rate(wdt->clk));
+ dc_wdt_set(wdt, wdog->timeout * wdt->rate);
return 0;
}
@@ -79,7 +80,7 @@ static int dc_wdt_set_timeout(struct wat
{
struct dc_wdt *wdt = watchdog_get_drvdata(wdog);
- dc_wdt_set(wdt, t * clk_get_rate(wdt->clk));
+ dc_wdt_set(wdt, t * wdt->rate);
wdog->timeout = t;
return 0;
@@ -90,7 +91,7 @@ static unsigned int dc_wdt_get_timeleft(
struct dc_wdt *wdt = watchdog_get_drvdata(wdog);
uint32_t count = readl_relaxed(wdt->base + TIMER_A_COUNT);
- return count / clk_get_rate(wdt->clk);
+ return count / wdt->rate;
}
static const struct watchdog_ops dc_wdt_ops = {
@@ -130,7 +131,11 @@ static int dc_wdt_probe(struct platform_
wdt->clk = devm_clk_get(dev, NULL);
if (IS_ERR(wdt->clk))
return PTR_ERR(wdt->clk);
- dc_wdt_wdd.max_timeout = U32_MAX / clk_get_rate(wdt->clk);
+
+ wdt->rate = clk_get_rate(wdt->clk);
+ if (!wdt->rate)
+ return -EINVAL;
+ dc_wdt_wdd.max_timeout = U32_MAX / wdt->rate;
dc_wdt_wdd.timeout = dc_wdt_wdd.max_timeout;
dc_wdt_wdd.parent = dev;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 370/438] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (368 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 369/438] hwmon: (pwm-fan) Stop RPM timer before freeing tach data Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 371/438] hwmon: (w83793) release probe data through kref Greg Kroah-Hartman
` (79 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit 0ff9c7775e51ac6d47b1bb5c46f06b1434fe58a8 upstream.
When the fan/pwm 4-5 pins are not used as GPIO, w83791d_probe()
creates the w83791d_group_fanpwm45 sysfs group on the I2C client
device.
The probe error path removes this group when a later initialization
step fails, but the normal remove path only removes w83791d_group.
As a result, the optional fan/pwm 4-5 sysfs files can remain after the
driver is unbound.
The callbacks associated with these files access the driver data,
which is devm allocated and released after driver unbind. Leaving the
sysfs files behind can therefore result in accesses to stale driver
data.
Remove w83791d_group_fanpwm45 during normal teardown as well.
This issue was found by manual code inspection.
Fixes: 6e1ecd9b8f13 ("hwmon: (w83791d) fan 4/5 pins can also be used for gpio")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260914062809.1650538-1-lgs201920130244@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/w83791d.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/hwmon/w83791d.c
+++ b/drivers/hwmon/w83791d.c
@@ -1415,6 +1415,7 @@ static void w83791d_remove(struct i2c_cl
struct w83791d_data *data = i2c_get_clientdata(client);
hwmon_device_unregister(data->hwmon_dev);
+ sysfs_remove_group(&client->dev.kobj, &w83791d_group_fanpwm45);
sysfs_remove_group(&client->dev.kobj, &w83791d_group);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 317/398] watchdog: msc313e: Fix premature reset during timeout update
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (313 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 316/398] watchdog: digicolor: Avoid division by zero Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 318/398] watchdog: msc313e: Propagate error code in resume() Greg Kroah-Hartman
` (87 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 22737cfced627ffcb4b5c36d63bb3d4476f63213 upstream.
Updating the 32-bit hardware timeout requires writing to two 16-bit
registers sequentially. If the watchdog is actively running, this
non-atomic update might trigger a premature system reset.
Clear the watchdog counter before updating the registers to prevent the
timer from timing out prematurely against an intermediate threshold.
Fixes: e9800b799464 ("watchdog: Add Mstar MSC313e WDT driver")
Cc: stable@vger.kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260913065126.8350-1-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/msc313e_wdt.c | 6 ++++++
1 file changed, 6 insertions(+)
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -47,6 +47,9 @@ static void msc313e_wdt_set_hw_timeout(s
{
u32 t = timeout * clk_get_rate(priv->clk);
+ /* Clear before to prevent premature reset during non-atomic updates. */
+ writew(1, priv->base + REG_WDT_CLR);
+
writew(t & 0xffff, priv->base + REG_WDT_MAX_PRD_L);
writew((t >> 16) & 0xffff, priv->base + REG_WDT_MAX_PRD_H);
writew(1, priv->base + REG_WDT_CLR);
@@ -77,6 +80,9 @@ static int msc313e_wdt_stop(struct watch
{
struct msc313e_wdt_priv *priv = watchdog_get_drvdata(wdev);
+ /* Clear before to prevent premature reset during non-atomic updates. */
+ writew(1, priv->base + REG_WDT_CLR);
+
writew(0, priv->base + REG_WDT_MAX_PRD_L);
writew(0, priv->base + REG_WDT_MAX_PRD_H);
writew(0, priv->base + REG_WDT_CLR);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 371/438] hwmon: (w83793) release probe data through kref
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (369 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 370/438] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 372/438] hwmon: (cgbc-hwmon) Fix current sensors ID lookup Greg Kroah-Hartman
` (78 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit c702a5f18b780e477eccbbab558e590e9673e4cb upstream.
w83793_probe() initializes data->kref to manage the lifetime of the
driver data. The normal remove path drops the driver-owned reference
with kref_put(), while watchdog users take and release additional
references through the same kref.
However, the probe error path still frees data directly with kfree().
This bypasses the kref-managed lifetime and discards the initial
reference without a matching kref_put(), leaving the reference
accounting unbalanced.
Drop the probe-owned reference with kref_put() instead and let
w83793_release_resources() perform the final free, matching the normal
remove path.
This issue was found by manual code inspection.
Fixes: 5852f9609d21 ("hwmon: (w83793) Add watchdog functionality")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260914073638.1662500-1-lgs201920130244@gmail.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/w83793.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/drivers/hwmon/w83793.c
+++ b/drivers/hwmon/w83793.c
@@ -1928,7 +1928,9 @@ exit_remove:
for (i = 0; i < ARRAY_SIZE(w83793_temp); i++)
device_remove_file(dev, &w83793_temp[i].dev_attr);
free_mem:
- kfree(data);
+ mutex_lock(&watchdog_data_mutex);
+ kref_put(&data->kref, w83793_release_resources);
+ mutex_unlock(&watchdog_data_mutex);
exit:
return err;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 318/398] watchdog: msc313e: Propagate error code in resume()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (314 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 317/398] watchdog: msc313e: Fix premature reset during timeout update Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 319/398] watchdog: rtd119x: Avoid division by zero Greg Kroah-Hartman
` (86 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 1d9763f34a85680db1e8233d654fdb85e5f897cc upstream.
If msc313e_wdt_start() fails during system resume, the error is
currently ignored. Consequently, the watchdog isn't running without the
user's knowledge.
Propagate the error code and print a message if msc313e_wdt_start()
fails.
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Fixes: e9800b7994642 ("watchdog: Add Mstar MSC313e WDT driver")
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260912163334.28636-1-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/msc313e_wdt.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -198,11 +198,15 @@ static int __maybe_unused msc313e_wdt_su
static int __maybe_unused msc313e_wdt_resume(struct device *dev)
{
struct msc313e_wdt_priv *priv = dev_get_drvdata(dev);
+ int ret = 0;
- if (watchdog_active(&priv->wdev) || watchdog_hw_running(&priv->wdev))
- msc313e_wdt_start(&priv->wdev);
+ if (watchdog_active(&priv->wdev) || watchdog_hw_running(&priv->wdev)) {
+ ret = msc313e_wdt_start(&priv->wdev);
+ if (ret)
+ dev_err(dev, "Failed to restart watchdog (err=%d)\n", ret);
+ }
- return 0;
+ return ret;
}
static SIMPLE_DEV_PM_OPS(msc313e_wdt_pm_ops, msc313e_wdt_suspend, msc313e_wdt_resume);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 372/438] hwmon: (cgbc-hwmon) Fix current sensors ID lookup
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (370 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 371/438] hwmon: (w83793) release probe data through kref Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 373/438] hwmon: (cgbc-hwmon) Add missing sensors Greg Kroah-Hartman
` (77 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, stable,
Thomas Richard (congatec GmbH), Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
commit 7bae83ffb133bc373d098fa6828cef2ef4da49fe upstream.
Current sensors on the Congatec Board Controller don't use consecutive IDs,
unlike other sensor types (voltage, temperature, fan). The driver assumed
consecutive IDs and performed a simple lookup, which caused an unknown
sensor warning. Define current sensor IDs explicitly.
Changes the warning on conga-SA7 (type and channel are correct now).
Before:
Board Controller returned an unknown sensor (type=2, channel=17), ignore it
After:
Board Controller returned an unknown sensor (bc_type=1, bc_id=11), ignore it
Cc: stable@kernel.org
Fixes: 08ebc9def79f ("hwmon: Add Congatec Board Controller monitoring driver")
Signed-off-by: Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
Link: https://patch.msgid.link/20260911-cgbc-hwmon-fix-and-new-sensors-v2-1-0c6bf078d173@bootlin.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/hwmon/cgbc-hwmon.c | 93 ++++++++++++++++++++++++++-------------------
1 file changed, 54 insertions(+), 39 deletions(-)
--- a/drivers/hwmon/cgbc-hwmon.c
+++ b/drivers/hwmon/cgbc-hwmon.c
@@ -52,31 +52,36 @@ static const char * const cgbc_hwmon_lab
"BOTTOMDIM Temperature",
};
+static const char * const cgbc_hwmon_labels_in[] = {
+ "CPU Voltage",
+ "DC Runtime Voltage",
+ "DC Standby Voltage",
+ "CMOS Battery Voltage",
+ "Battery Voltage",
+ "AC Voltage",
+ "Other Voltage",
+ "5V Voltage",
+ "5V Standby Voltage",
+ "3V3 Voltage",
+ "3V3 Standby Voltage",
+ "VCore A Voltage",
+ "VCore B Voltage",
+ "12V Voltage",
+};
+
+/*
+ * Current sensors are a bit special, they don't have consecutive IDs like
+ * other types of sensors. So they need to be defined explicitly.
+ */
static const struct {
- enum hwmon_sensor_types type;
const char *label;
-} cgbc_hwmon_labels_in[] = {
- { hwmon_in, "CPU Voltage" },
- { hwmon_in, "DC Runtime Voltage" },
- { hwmon_in, "DC Standby Voltage" },
- { hwmon_in, "CMOS Battery Voltage" },
- { hwmon_in, "Battery Voltage" },
- { hwmon_in, "AC Voltage" },
- { hwmon_in, "Other Voltage" },
- { hwmon_in, "5V Voltage" },
- { hwmon_in, "5V Standby Voltage" },
- { hwmon_in, "3V3 Voltage" },
- { hwmon_in, "3V3 Standby Voltage" },
- { hwmon_in, "VCore A Voltage" },
- { hwmon_in, "VCore B Voltage" },
- { hwmon_in, "12V Voltage" },
- { hwmon_curr, "DC Current" },
- { hwmon_curr, "5V Current" },
- { hwmon_curr, "12V Current" },
+ int id;
+} cgbc_hwmon_labels_curr[] = {
+ { "DC Current", 0x12 },
+ { "5V Current", 0x18 },
+ { "12V Current", 0x1E },
};
-#define CGBC_HWMON_NB_IN_SENSORS 14
-
static const char * const cgbc_hwmon_labels_fan[] = {
"CPU Fan",
"Box Fan",
@@ -114,7 +119,8 @@ static int cgbc_hwmon_probe_sensors(stru
for (i = 0; i < nb_sensors; i++) {
enum cgbc_sensor_types type;
- unsigned int channel;
+ unsigned int channel, id;
+ int j;
/*
* No need to request data for the first sensor.
@@ -128,32 +134,49 @@ static int cgbc_hwmon_probe_sensors(stru
}
type = FIELD_GET(CGBC_HWMON_TYPE_MASK, data[1]);
- channel = FIELD_GET(CGBC_HWMON_ID_MASK, data[1]) - 1;
+ id = FIELD_GET(CGBC_HWMON_ID_MASK, data[1]);
+ channel = id - 1;
if (type == CGBC_HWMON_TYPE_TEMP && channel < ARRAY_SIZE(cgbc_hwmon_labels_temp)) {
sensor->type = hwmon_temp;
sensor->label = cgbc_hwmon_labels_temp[channel];
- } else if (type == CGBC_HWMON_TYPE_IN &&
- channel < ARRAY_SIZE(cgbc_hwmon_labels_in)) {
+ } else if (type == CGBC_HWMON_TYPE_IN) {
/*
* The Board Controller doesn't differentiate current and voltage sensors.
- * Get the sensor type from cgbc_hwmon_labels_in[channel].type instead.
+ * First check if it is a current sensor.
*/
- sensor->type = cgbc_hwmon_labels_in[channel].type;
- sensor->label = cgbc_hwmon_labels_in[channel].label;
+ for (j = 0; j < ARRAY_SIZE(cgbc_hwmon_labels_curr); j++) {
+ if (id == cgbc_hwmon_labels_curr[j].id) {
+ sensor->type = hwmon_curr;
+ sensor->label = cgbc_hwmon_labels_curr[j].label;
+ channel = j;
+ }
+ }
+
+ /* If it's not a current sensor, it may be a voltage sensor. */
+ if (!sensor->label && channel < ARRAY_SIZE(cgbc_hwmon_labels_in)) {
+ sensor->type = hwmon_in;
+ sensor->label = cgbc_hwmon_labels_in[channel];
+ }
} else if (type == CGBC_HWMON_TYPE_FAN &&
channel < ARRAY_SIZE(cgbc_hwmon_labels_fan)) {
sensor->type = hwmon_fan;
sensor->label = cgbc_hwmon_labels_fan[channel];
- } else {
- dev_warn(dev, "Board Controller returned an unknown sensor (type=%d, channel=%d), ignore it",
- type, channel);
+ }
+
+ if (!sensor->label) {
+ dev_warn(dev, "Board Controller returned an unknown sensor (bc_type=%d, bc_id=%d), ignore it",
+ type, id);
continue;
}
sensor->active = FIELD_GET(CGBC_HWMON_ACTIVE_BIT, data[1]);
sensor->channel = channel;
sensor->index = i;
+
+ dev_dbg(dev, "Found sensor: bc_type=%d, bc_id=%d, hwmon_type=%d, hwmon_channel=%d, hwmon_label='%s', active=%d\n",
+ type, id, sensor->type, sensor->channel, sensor->label, sensor->active);
+
sensor++;
hwmon->nb_sensors++;
}
@@ -167,14 +190,6 @@ static struct cgbc_hwmon_sensor *cgbc_hw
struct cgbc_hwmon_sensor *sensor = NULL;
int i;
- /*
- * The Board Controller doesn't differentiate current and voltage sensors.
- * The channel value (from the Board Controller point of view) shall be computed for current
- * sensors.
- */
- if (type == hwmon_curr)
- channel += CGBC_HWMON_NB_IN_SENSORS;
-
for (i = 0; i < hwmon->nb_sensors; i++) {
if (hwmon->sensors[i].type == type && hwmon->sensors[i].channel == channel) {
sensor = &hwmon->sensors[i];
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 319/398] watchdog: rtd119x: Avoid division by zero
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (315 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 318/398] watchdog: msc313e: Propagate error code in resume() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 320/398] watchdog: rzv2h: " Greg Kroah-Hartman
` (85 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 5af7d2cbd20f893def03c8310a460ade66a5d822 upstream.
clk_get_rate() could return 0. Avoid a division by zero panic.
Fixes: 2bdf6acbfead ("watchdog: Add Realtek RTD1295")
Cc: stable@vger.kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260913064851.8239-3-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/rtd119x_wdt.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
--- a/drivers/watchdog/rtd119x_wdt.c
+++ b/drivers/watchdog/rtd119x_wdt.c
@@ -98,6 +98,7 @@ static int rtd119x_wdt_probe(struct plat
{
struct device *dev = &pdev->dev;
struct rtd119x_watchdog_device *data;
+ unsigned long rate;
data = devm_kzalloc(dev, sizeof(*data), GFP_KERNEL);
if (!data)
@@ -111,10 +112,14 @@ static int rtd119x_wdt_probe(struct plat
if (IS_ERR(data->clk))
return PTR_ERR(data->clk);
+ rate = clk_get_rate(data->clk);
+ if (!rate)
+ return -EINVAL;
+
data->wdt_dev.info = &rtd119x_wdt_info;
data->wdt_dev.ops = &rtd119x_wdt_ops;
data->wdt_dev.timeout = 120;
- data->wdt_dev.max_timeout = 0xffffffff / clk_get_rate(data->clk);
+ data->wdt_dev.max_timeout = 0xffffffff / rate;
data->wdt_dev.min_timeout = 1;
data->wdt_dev.parent = dev;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 373/438] hwmon: (cgbc-hwmon) Add missing sensors
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (371 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 372/438] hwmon: (cgbc-hwmon) Fix current sensors ID lookup Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 374/438] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
` (76 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, stable,
Thomas Richard (congatec GmbH), Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
commit 3550d1dbbcb9f51b77e077e8958423ee2c401c6c upstream.
Add the following sensors:
- Alternate Board Temperature (temp11_input)
- Top DIMM 1-7 Temperature (temp12_input to temp18_input)
- Bottom DIMM 1 Temperature (temp19_input)
- 12V Standby Voltage (in14_input)
This fixes the following warning on conga-SA7:
Board Controller returned an unknown sensor (bc_type=1, bc_id=11), ignore it
Also update existing labels to match Congatec documentation.
Cc: stable@kernel.org
Fixes: 08ebc9def79f ("hwmon: Add Congatec Board Controller monitoring driver")
Signed-off-by: Thomas Richard (congatec GmbH) <thomas.richard@bootlin.com>
Link: https://patch.msgid.link/20260911-cgbc-hwmon-fix-and-new-sensors-v2-2-0c6bf078d173@bootlin.com
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
Documentation/hwmon/cgbc-hwmon.rst | 42 ++++++++++++++++++-----------
drivers/hwmon/cgbc-hwmon.c | 52 ++++++++++++++++++++++++-------------
2 files changed, 60 insertions(+), 34 deletions(-)
--- a/Documentation/hwmon/cgbc-hwmon.rst
+++ b/Documentation/hwmon/cgbc-hwmon.rst
@@ -28,34 +28,44 @@ system.
Name Description
============= ======================
temp1_input CPU temperature
-temp2_input Box temperature
+temp2_input Case temperature
temp3_input Ambient temperature
-temp4_input Board temperature
-temp5_input Carrier temperature
-temp6_input Chipset temperature
-temp7_input Video temperature
+temp4_input CPU Board temperature
+temp5_input Carrier Board temperature
+temp6_input System Chipset temperature
+temp7_input Video Controller/Board temperature
temp8_input Other temperature
-temp9_input TOPDIM temperature
-temp10_input BOTTOMDIM temperature
-in0_input CPU voltage
+temp9_input Top DIMM 0 temperature
+temp10_input Bottom DIMM 0 temperature
+temp11_input Alternate Board temperature
+temp12_input Top DIMM 1 temperature
+temp13_input Top DIMM 2 temperature
+temp14_input Top DIMM 3 temperature
+temp15_input Top DIMM 4 temperature
+temp16_input Top DIMM 5 temperature
+temp17_input Top DIMM 6 temperature
+temp18_input Top DIMM 7 temperature
+temp19_input Bottom DIMM 1 temperature
+in0_input CPU Core voltage
in1_input DC Runtime voltage
in2_input DC Standby voltage
in3_input CMOS Battery voltage
-in4_input Battery voltage
+in4_input Battery Supply voltage
in5_input AC voltage
in6_input Other voltage
-in7_input 5V voltage
+in7_input 5V Runtime voltage
in8_input 5V Standby voltage
-in9_input 3V3 voltage
+in9_input 3V3 Runtime voltage
in10_input 3V3 Standby voltage
in11_input VCore A voltage
in12_input VCore B voltage
-in13_input 12V voltage
-curr1_input DC current
-curr2_input 5V current
-curr3_input 12V current
+in13_input 12V Runtime voltage
+in14_input 12V Standby voltage
+curr1_input DC Runtime current
+curr2_input 5V Runtime current
+curr3_input 12V Runtime current
fan1_input CPU fan
-fan2_input Box fan
+fan2_input Case fan
fan3_input Ambient fan
fan4_input Chiptset fan
fan5_input Video fan
--- a/drivers/hwmon/cgbc-hwmon.c
+++ b/drivers/hwmon/cgbc-hwmon.c
@@ -41,32 +41,42 @@ enum cgbc_sensor_types {
static const char * const cgbc_hwmon_labels_temp[] = {
"CPU Temperature",
- "Box Temperature",
+ "Case Temperature",
"Ambient Temperature",
- "Board Temperature",
- "Carrier Temperature",
- "Chipset Temperature",
- "Video Temperature",
+ "CPU Board Temperature",
+ "Carrier Board Temperature",
+ "System Chipset Temperature",
+ "Video Controller/Board Temperature",
"Other Temperature",
- "TOPDIM Temperature",
- "BOTTOMDIM Temperature",
+ "Top DIMM 0 Temperature",
+ "Bottom DIMM 0 Temperature",
+ "Alternate Board Temperature",
+ "Top DIMM 1 Temperature",
+ "Top DIMM 2 Temperature",
+ "Top DIMM 3 Temperature",
+ "Top DIMM 4 Temperature",
+ "Top DIMM 5 Temperature",
+ "Top DIMM 6 Temperature",
+ "Top DIMM 7 Temperature",
+ "Bottom DIMM 1 Temperature",
};
static const char * const cgbc_hwmon_labels_in[] = {
- "CPU Voltage",
+ "CPU Core Voltage",
"DC Runtime Voltage",
"DC Standby Voltage",
"CMOS Battery Voltage",
- "Battery Voltage",
+ "Battery Supply Voltage",
"AC Voltage",
"Other Voltage",
- "5V Voltage",
+ "5V Runtime Voltage",
"5V Standby Voltage",
- "3V3 Voltage",
+ "3V3 Runtime Voltage",
"3V3 Standby Voltage",
"VCore A Voltage",
"VCore B Voltage",
- "12V Voltage",
+ "12V Runtime Voltage",
+ "12V Standby Voltage",
};
/*
@@ -77,14 +87,14 @@ static const struct {
const char *label;
int id;
} cgbc_hwmon_labels_curr[] = {
- { "DC Current", 0x12 },
- { "5V Current", 0x18 },
- { "12V Current", 0x1E },
+ { "DC Runtime Current", 0x12 },
+ { "5V Runtime Current", 0x18 },
+ { "12V Runtime Current", 0x1E },
};
static const char * const cgbc_hwmon_labels_fan[] = {
"CPU Fan",
- "Box Fan",
+ "Case Fan",
"Ambient Fan",
"Chipset Fan",
"Video Fan",
@@ -255,7 +265,12 @@ static const struct hwmon_channel_info *
HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
- HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL),
+ HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
+ HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
+ HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
+ HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
+ HWMON_T_INPUT | HWMON_T_LABEL, HWMON_T_INPUT | HWMON_T_LABEL,
+ HWMON_T_INPUT | HWMON_T_LABEL),
HWMON_CHANNEL_INFO(in,
HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
@@ -263,7 +278,8 @@ static const struct hwmon_channel_info *
HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
- HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL),
+ HWMON_I_INPUT | HWMON_I_LABEL, HWMON_I_INPUT | HWMON_I_LABEL,
+ HWMON_I_INPUT | HWMON_I_LABEL),
HWMON_CHANNEL_INFO(curr,
HWMON_C_INPUT | HWMON_C_LABEL, HWMON_C_INPUT | HWMON_C_LABEL,
HWMON_C_INPUT | HWMON_C_LABEL),
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 320/398] watchdog: rzv2h: Avoid division by zero
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (316 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 319/398] watchdog: rtd119x: Avoid division by zero Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 321/398] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() Greg Kroah-Hartman
` (84 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 6274281c41efa8dd1aa5234c59ad904ff89d7af4 upstream.
clk_get_rate() could return 0. Avoid a division by zero panic.
Fixes: f6febd0a30b6 ("watchdog: Add Watchdog Timer driver for RZ/V2H(P)")
Cc: stable@vger.kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260913064851.8239-4-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/rzv2h_wdt.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
--- a/drivers/watchdog/rzv2h_wdt.c
+++ b/drivers/watchdog/rzv2h_wdt.c
@@ -280,6 +280,7 @@ static int rzv2h_wdt_probe(struct platfo
struct device *dev = &pdev->dev;
struct rzv2h_wdt_priv *priv;
struct clk *count_clk;
+ unsigned long rate;
int ret;
priv = devm_kzalloc(dev, sizeof(*priv), GFP_KERNEL);
@@ -316,8 +317,12 @@ static int rzv2h_wdt_probe(struct platfo
return dev_err_probe(dev, -EINVAL, "Invalid count source\n");
}
+ rate = clk_get_rate(count_clk);
+ if (!rate)
+ return dev_err_probe(dev, -EINVAL, "Invalid clock rate\n");
+
priv->wdev.max_hw_heartbeat_ms = (MILLI * priv->of_data->timeout_cycles *
- priv->of_data->cks_div) / clk_get_rate(count_clk);
+ priv->of_data->cks_div) / rate;
dev_dbg(dev, "max hw timeout of %dms\n", priv->wdev.max_hw_heartbeat_ms);
ret = devm_pm_runtime_enable(dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 374/438] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (372 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 373/438] hwmon: (cgbc-hwmon) Add missing sensors Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 375/438] watchdog: digicolor: Avoid division by zero Greg Kroah-Hartman
` (75 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Li Jun, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Jun <lijun01@kylinos.cn>
commit 7cb575b71ab98194d2e040bded3a7281e089c5ed upstream.
da9063_wdt_suspend() and da9063_wdt_resume() only check watchdog_active(),
when the watchdog is left running by the driver sets
WDOG_HW_RUNNING in da9063_wdt_probe() but userspace never opens the
device, so WDOG_ACTIVE remains cleared, the wdt_disable() will not be
executed in da9063_wdt_suspend. In this case, the suspend callback is
a no-op and the watchdog keeps counting during system suspend,
leading to an unexpected system reset.
Check WDOG_HW_RUNNING and wdd,can fix this issue.
Fixes: a7ceca4398bc8 ("watchdog: da9063: optionally disable watchdog during suspend")
Cc: stable@vger.kernel.org
Signed-off-by: Li Jun <lijun01@kylinos.cn>
Link: https://patch.msgid.link/20260917013710.2754679-1-lijun01@kylinos.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/da9063_wdt.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/watchdog/da9063_wdt.c
+++ b/drivers/watchdog/da9063_wdt.c
@@ -271,7 +271,7 @@ static int da9063_wdt_suspend(struct dev
if (!da9063->use_sw_pm)
return 0;
- if (watchdog_active(wdd))
+ if (watchdog_active(wdd) || watchdog_hw_running(wdd))
return da9063_wdt_stop(wdd);
return 0;
@@ -285,7 +285,7 @@ static int da9063_wdt_resume(struct devi
if (!da9063->use_sw_pm)
return 0;
- if (watchdog_active(wdd))
+ if (watchdog_active(wdd) || watchdog_hw_running(wdd))
return da9063_wdt_start(wdd);
return 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 321/398] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (317 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 320/398] watchdog: rzv2h: " Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 322/398] watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start() Greg Kroah-Hartman
` (83 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 88f113634028ca90a857031837d8061d1a9e1a7b upstream.
sp5100_tco_init() stores the PCI device matched by for_each_pci_dev()
in the global sp5100_tco_pci and keeps its reference for the lifetime
of the driver, but neither sp5100_tco_exit() nor the error paths of
sp5100_tco_init() call pci_dev_put(), leaking the reference on driver
registration failure and on every module load/unload cycle.
Drop the reference when the platform driver or device registration
fails and when the module is unloaded.
Fixes: 15e28bf13008 ("watchdog: Add support for sp5100 chipset TCO")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://patch.msgid.link/20260916170511.2086199-1-vulab@iscas.ac.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/sp5100_tco.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/drivers/watchdog/sp5100_tco.c
+++ b/drivers/watchdog/sp5100_tco.c
@@ -605,8 +605,10 @@ static int __init sp5100_tco_init(void)
pr_info("SP5100/SB800 TCO WatchDog Timer Driver\n");
err = platform_driver_register(&sp5100_tco_driver);
- if (err)
+ if (err) {
+ pci_dev_put(sp5100_tco_pci);
return err;
+ }
sp5100_tco_platform_device =
platform_device_register_simple(TCO_DRIVER_NAME, -1, NULL, 0);
@@ -619,6 +621,7 @@ static int __init sp5100_tco_init(void)
unreg_platform_driver:
platform_driver_unregister(&sp5100_tco_driver);
+ pci_dev_put(sp5100_tco_pci);
return err;
}
@@ -626,6 +629,7 @@ static void __exit sp5100_tco_exit(void)
{
platform_device_unregister(sp5100_tco_platform_device);
platform_driver_unregister(&sp5100_tco_driver);
+ pci_dev_put(sp5100_tco_pci);
}
module_init(sp5100_tco_init);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 375/438] watchdog: digicolor: Avoid division by zero
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (373 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 374/438] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 376/438] watchdog: msc313e: Fix premature reset during timeout update Greg Kroah-Hartman
` (74 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Baruch Siach,
Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 400cb663ca019bae6eb878f06f1094ddf7c0b0df upstream.
clk_get_rate() could return 0. Avoid a division by zero panic.
Since get_timeleft() cannot propagate errors, check the clock rate early
in probe() and cache the rate in the driver data as it is unlikely to
change at runtime.
Fixes: 336694a01dae ("watchdog: digicolor: driver for Conexant Digicolor CX92755 SoC")
Cc: stable@vger.kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Acked-by: Baruch Siach <baruch@tkos.co.il>
Link: https://patch.msgid.link/20260913064851.8239-2-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/digicolor_wdt.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
--- a/drivers/watchdog/digicolor_wdt.c
+++ b/drivers/watchdog/digicolor_wdt.c
@@ -25,6 +25,7 @@ struct dc_wdt {
void __iomem *base;
struct clk *clk;
spinlock_t lock;
+ unsigned long rate;
};
static unsigned timeout;
@@ -61,7 +62,7 @@ static int dc_wdt_start(struct watchdog_
{
struct dc_wdt *wdt = watchdog_get_drvdata(wdog);
- dc_wdt_set(wdt, wdog->timeout * clk_get_rate(wdt->clk));
+ dc_wdt_set(wdt, wdog->timeout * wdt->rate);
return 0;
}
@@ -79,7 +80,7 @@ static int dc_wdt_set_timeout(struct wat
{
struct dc_wdt *wdt = watchdog_get_drvdata(wdog);
- dc_wdt_set(wdt, t * clk_get_rate(wdt->clk));
+ dc_wdt_set(wdt, t * wdt->rate);
wdog->timeout = t;
return 0;
@@ -90,7 +91,7 @@ static unsigned int dc_wdt_get_timeleft(
struct dc_wdt *wdt = watchdog_get_drvdata(wdog);
uint32_t count = readl_relaxed(wdt->base + TIMER_A_COUNT);
- return count / clk_get_rate(wdt->clk);
+ return count / wdt->rate;
}
static const struct watchdog_ops dc_wdt_ops = {
@@ -130,7 +131,11 @@ static int dc_wdt_probe(struct platform_
wdt->clk = devm_clk_get(dev, NULL);
if (IS_ERR(wdt->clk))
return PTR_ERR(wdt->clk);
- dc_wdt_wdd.max_timeout = U32_MAX / clk_get_rate(wdt->clk);
+
+ wdt->rate = clk_get_rate(wdt->clk);
+ if (!wdt->rate)
+ return -EINVAL;
+ dc_wdt_wdd.max_timeout = U32_MAX / wdt->rate;
dc_wdt_wdd.timeout = dc_wdt_wdd.max_timeout;
dc_wdt_wdd.parent = dev;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 322/398] watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (318 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 321/398] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 323/398] wifi: brcmsmac: fix UAF in brcms_free_timer() Greg Kroah-Hartman
` (82 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Guenter Roeck
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 8f0ca55016a7647109ae2bc91bcb346fc8b13785 upstream.
starfive_wdt_pm_start() takes a runtime PM reference with
pm_runtime_get_sync(), which increments the usage counter even when it
fails, and returns the error without dropping it again. The watchdog
core does not invoke the stop callback when start fails, so the
reference taken on the error path is leaked.
Use pm_runtime_resume_and_get() instead, which keeps the usage counter
balanced when the resume fails.
Fixes: db728ea9c7be ("drivers: watchdog: Add StarFive Watchdog driver")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://patch.msgid.link/20260916170704.2086331-1-vulab@iscas.ac.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/starfive-wdt.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/watchdog/starfive-wdt.c
+++ b/drivers/watchdog/starfive-wdt.c
@@ -371,7 +371,7 @@ static void starfive_wdt_stop(struct sta
static int starfive_wdt_pm_start(struct watchdog_device *wdd)
{
struct starfive_wdt *wdt = watchdog_get_drvdata(wdd);
- int ret = pm_runtime_get_sync(wdd->parent);
+ int ret = pm_runtime_resume_and_get(wdd->parent);
if (ret < 0)
return ret;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 376/438] watchdog: msc313e: Fix premature reset during timeout update
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (374 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 375/438] watchdog: digicolor: Avoid division by zero Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 377/438] watchdog: msc313e: Propagate error code in resume() Greg Kroah-Hartman
` (73 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 22737cfced627ffcb4b5c36d63bb3d4476f63213 upstream.
Updating the 32-bit hardware timeout requires writing to two 16-bit
registers sequentially. If the watchdog is actively running, this
non-atomic update might trigger a premature system reset.
Clear the watchdog counter before updating the registers to prevent the
timer from timing out prematurely against an intermediate threshold.
Fixes: e9800b799464 ("watchdog: Add Mstar MSC313e WDT driver")
Cc: stable@vger.kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260913065126.8350-1-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/msc313e_wdt.c | 6 ++++++
1 file changed, 6 insertions(+)
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -46,6 +46,9 @@ static void msc313e_wdt_set_hw_timeout(s
{
u32 t = timeout * clk_get_rate(priv->clk);
+ /* Clear before to prevent premature reset during non-atomic updates. */
+ writew(1, priv->base + REG_WDT_CLR);
+
writew(t & 0xffff, priv->base + REG_WDT_MAX_PRD_L);
writew((t >> 16) & 0xffff, priv->base + REG_WDT_MAX_PRD_H);
writew(1, priv->base + REG_WDT_CLR);
@@ -76,6 +79,9 @@ static int msc313e_wdt_stop(struct watch
{
struct msc313e_wdt_priv *priv = watchdog_get_drvdata(wdev);
+ /* Clear before to prevent premature reset during non-atomic updates. */
+ writew(1, priv->base + REG_WDT_CLR);
+
writew(0, priv->base + REG_WDT_MAX_PRD_L);
writew(0, priv->base + REG_WDT_MAX_PRD_H);
writew(0, priv->base + REG_WDT_CLR);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 323/398] wifi: brcmsmac: fix UAF in brcms_free_timer()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (319 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 322/398] watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 324/398] wifi: iwlegacy: fix broadcast stations deallocation Greg Kroah-Hartman
` (81 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiangshan Yi, Arend van Spriel,
Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiangshan Yi <yijiangshan@kylinos.cn>
commit 1eeca1d5e0920fbdad6449768fd2d4364e714180 upstream.
brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous
cancel_delayed_work() to cancel the timer's underlying delayed work. If
the work callback (_brcms_timer) is already running, cancel_delayed_work()
returns false without waiting, and brcms_free_timer() proceeds to kfree(t)
while the callback still accesses t through container_of().
Add an explicit cancel_delayed_work_sync() after brcms_del_timer() to
guarantee that any in-flight callback has completed before the timer
structure is freed.
Fixes: 5b435de0d786 ("net: wireless: add brcm80211 drivers")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260815121043.938414-1-yijiangshan@kylinos.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/broadcom/brcm80211/brcmsmac/mac80211_if.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/net/wireless/broadcom/brcm80211/brcmsmac/mac80211_if.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmsmac/mac80211_if.c
@@ -1571,6 +1571,10 @@ void brcms_free_timer(struct brcms_timer
/* delete the timer in case it is active */
brcms_del_timer(t);
+ /* Ensure the callback has finished before freeing the timer
+ * structure, since brcms_del_timer() uses non-synchronous cancel.
+ */
+ cancel_delayed_work_sync(&t->dly_wrk);
if (wl->timers == t) {
wl->timers = wl->timers->next;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 377/438] watchdog: msc313e: Propagate error code in resume()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (375 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 376/438] watchdog: msc313e: Fix premature reset during timeout update Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 378/438] watchdog: rtd119x: Avoid division by zero Greg Kroah-Hartman
` (72 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 1d9763f34a85680db1e8233d654fdb85e5f897cc upstream.
If msc313e_wdt_start() fails during system resume, the error is
currently ignored. Consequently, the watchdog isn't running without the
user's knowledge.
Propagate the error code and print a message if msc313e_wdt_start()
fails.
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Fixes: e9800b7994642 ("watchdog: Add Mstar MSC313e WDT driver")
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260912163334.28636-1-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/msc313e_wdt.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
--- a/drivers/watchdog/msc313e_wdt.c
+++ b/drivers/watchdog/msc313e_wdt.c
@@ -197,11 +197,15 @@ static int __maybe_unused msc313e_wdt_su
static int __maybe_unused msc313e_wdt_resume(struct device *dev)
{
struct msc313e_wdt_priv *priv = dev_get_drvdata(dev);
+ int ret = 0;
- if (watchdog_active(&priv->wdev) || watchdog_hw_running(&priv->wdev))
- msc313e_wdt_start(&priv->wdev);
+ if (watchdog_active(&priv->wdev) || watchdog_hw_running(&priv->wdev)) {
+ ret = msc313e_wdt_start(&priv->wdev);
+ if (ret)
+ dev_err(dev, "Failed to restart watchdog (err=%d)\n", ret);
+ }
- return 0;
+ return ret;
}
static SIMPLE_DEV_PM_OPS(msc313e_wdt_pm_ops, msc313e_wdt_suspend, msc313e_wdt_resume);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 324/398] wifi: iwlegacy: fix broadcast stations deallocation
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (320 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 323/398] wifi: brcmsmac: fix UAF in brcms_free_timer() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 325/398] wifi: libertas_tf: fix UAF in lbtf_free_adapter() Greg Kroah-Hartman
` (80 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislaw Gruszka, Johannes Berg,
Martin-Éric Racine
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislaw Gruszka <stf_xl@wp.pl>
commit b5526b780f8b297a76030410b96ba29153afb98f upstream.
On the error path of __il4965_up(), il_dealloc_bcast_stations() clears
only IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the
same broadcast stations to be deallocated again by __il4965_down().
This can occur when RF_KILL is toggled during driver startup.
To fix clear the entire 'used' field, since we will not do any
other operations on the station.
Reported-and-tested-by: Martin-Éric Racine <martin-eric.racine+kernel-bugzilla@iki.fi>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221733
Fixes: c2fd34469d16 ("iwl4965: Fix a memory leak in error handling code of __il4965_up")
Cc: <stable@vger.kernel.org> # 7.1.x: 57aa1718d595 wifi: iwlegacy: replace BUG_ON() with WARN_ON() on num_stations check
Cc: <stable@vger.kernel.org> # 6.x.x: 57aa1718d595 wifi: iwlegacy: replace BUG_ON() with WARN_ON() on num_stations check
Cc: <stable@vger.kernel.org> # 5.x.x: 57aa1718d595 wifi: iwlegacy: replace BUG_ON() with WARN_ON() on num_stations check
Signed-off-by: Stanislaw Gruszka <stf_xl@wp.pl>
Link: https://patch.msgid.link/20260820093059.18779-1-stf_xl@wp.pl
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intel/iwlegacy/common.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/wireless/intel/iwlegacy/common.c
+++ b/drivers/net/wireless/intel/iwlegacy/common.c
@@ -2327,7 +2327,7 @@ il_dealloc_bcast_stations(struct il_priv
if (!(il->stations[i].used & IL_STA_BCAST))
continue;
- il->stations[i].used &= ~IL_STA_UCODE_ACTIVE;
+ il->stations[i].used = 0;
il->num_stations--;
BUG_ON(il->num_stations < 0);
kfree(il->stations[i].lq);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 378/438] watchdog: rtd119x: Avoid division by zero
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (376 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 377/438] watchdog: msc313e: Propagate error code in resume() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 379/438] watchdog: rzv2h: " Greg Kroah-Hartman
` (71 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 5af7d2cbd20f893def03c8310a460ade66a5d822 upstream.
clk_get_rate() could return 0. Avoid a division by zero panic.
Fixes: 2bdf6acbfead ("watchdog: Add Realtek RTD1295")
Cc: stable@vger.kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260913064851.8239-3-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/rtd119x_wdt.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
--- a/drivers/watchdog/rtd119x_wdt.c
+++ b/drivers/watchdog/rtd119x_wdt.c
@@ -98,6 +98,7 @@ static int rtd119x_wdt_probe(struct plat
{
struct device *dev = &pdev->dev;
struct rtd119x_watchdog_device *data;
+ unsigned long rate;
data = devm_kzalloc(dev, sizeof(*data), GFP_KERNEL);
if (!data)
@@ -111,10 +112,14 @@ static int rtd119x_wdt_probe(struct plat
if (IS_ERR(data->clk))
return PTR_ERR(data->clk);
+ rate = clk_get_rate(data->clk);
+ if (!rate)
+ return -EINVAL;
+
data->wdt_dev.info = &rtd119x_wdt_info;
data->wdt_dev.ops = &rtd119x_wdt_ops;
data->wdt_dev.timeout = 120;
- data->wdt_dev.max_timeout = 0xffffffff / clk_get_rate(data->clk);
+ data->wdt_dev.max_timeout = 0xffffffff / rate;
data->wdt_dev.min_timeout = 1;
data->wdt_dev.parent = dev;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 325/398] wifi: libertas_tf: fix UAF in lbtf_free_adapter()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (321 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 324/398] wifi: iwlegacy: fix broadcast stations deallocation Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 326/398] wifi: rsi: fix heap OOB write on key removal Greg Kroah-Hartman
` (79 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jiangshan Yi, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiangshan Yi <yijiangshan@kylinos.cn>
commit bbb9a0ab96d44a64529aafc7a16de460a1712f6a upstream.
lbtf_free_adapter() calls lbtf_free_cmd_buffer() to free the command
buffers before calling timer_delete_sync() to wait for the command
timer callback. If the timer callback (command_timer_fn) is already
running when lbtf_free_cmd_buffer() frees the command array, the
callback dereferences priv->cur_cmd->cmdbuf which points to freed
memory.
Swap the order so that timer_delete_sync() runs first, ensuring any
in-flight callback has completed before the command buffers are freed.
Fixes: 06b16ae53192 ("libertas_tf: main.c, data paths and mac80211 handlers")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Link: https://patch.msgid.link/20260815115724.920628-1-yijiangshan@kylinos.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/libertas_tf/main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/wireless/marvell/libertas_tf/main.c
+++ b/drivers/net/wireless/marvell/libertas_tf/main.c
@@ -173,8 +173,8 @@ static int lbtf_init_adapter(struct lbtf
static void lbtf_free_adapter(struct lbtf_private *priv)
{
lbtf_deb_enter(LBTF_DEB_MAIN);
- lbtf_free_cmd_buffer(priv);
timer_delete_sync(&priv->command_timer);
+ lbtf_free_cmd_buffer(priv);
lbtf_deb_leave(LBTF_DEB_MAIN);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 379/438] watchdog: rzv2h: Avoid division by zero
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (377 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 378/438] watchdog: rtd119x: Avoid division by zero Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 380/438] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() Greg Kroah-Hartman
` (70 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tzung-Bi Shih, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
commit 6274281c41efa8dd1aa5234c59ad904ff89d7af4 upstream.
clk_get_rate() could return 0. Avoid a division by zero panic.
Fixes: f6febd0a30b6 ("watchdog: Add Watchdog Timer driver for RZ/V2H(P)")
Cc: stable@vger.kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://patch.msgid.link/20260913064851.8239-4-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/rzv2h_wdt.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
--- a/drivers/watchdog/rzv2h_wdt.c
+++ b/drivers/watchdog/rzv2h_wdt.c
@@ -278,6 +278,7 @@ static int rzv2h_wdt_probe(struct platfo
struct device *dev = &pdev->dev;
struct rzv2h_wdt_priv *priv;
struct clk *count_clk;
+ unsigned long rate;
int ret;
priv = devm_kzalloc(dev, sizeof(*priv), GFP_KERNEL);
@@ -314,8 +315,12 @@ static int rzv2h_wdt_probe(struct platfo
return dev_err_probe(dev, -EINVAL, "Invalid count source\n");
}
+ rate = clk_get_rate(count_clk);
+ if (!rate)
+ return dev_err_probe(dev, -EINVAL, "Invalid clock rate\n");
+
priv->wdev.max_hw_heartbeat_ms = (MILLI * priv->of_data->timeout_cycles *
- priv->of_data->cks_div) / clk_get_rate(count_clk);
+ priv->of_data->cks_div) / rate;
dev_dbg(dev, "max hw timeout of %dms\n", priv->wdev.max_hw_heartbeat_ms);
ret = devm_pm_runtime_enable(dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 326/398] wifi: rsi: fix heap OOB write on key removal
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (322 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 325/398] wifi: libertas_tf: fix UAF in lbtf_free_adapter() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 327/398] wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown Greg Kroah-Hartman
` (78 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tianchu Chen, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tianchu Chen <flynnnchen@tencent.com>
commit e6c5ed7a98d7bc8b0f7918246f1c90ddb3f79dfa upstream.
When a key is removed (data == NULL), rsi_hal_load_key() runs:
memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ);
set_key is a struct rsi_set_key *, so the subscript is scaled by
sizeof(struct rsi_set_key) (160 bytes): &set_key[FRAME_DESC_SZ] is
skb->data + 2560, and the memset writes 144 zero bytes starting
2.4KB past the end of the 160-byte skb data buffer, corrupting
unrelated heap objects. The intended byte offset would have been
(u8 *)set_key + FRAME_DESC_SZ.
The write fires on every DISABLE_KEY callback, so plain disconnects,
roams and interface teardowns trigger it on real networks.
The memset is redundant: the whole buffer is zeroed right after
allocation, so the frame sent to the device is byte-identical
without it. Drop the else branch; normal operation is unaffected.
Discovered by Atuin - Automated Vulnerability Discovery Engine.
Fixes: dad0d04fa7ba ("rsi: Add RS9113 wireless driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Tianchu Chen <flynnnchen@tencent.com>
Link: https://patch.msgid.link/90bb2b07007942064c04aa3729cedd9eb1e930b1@linux.dev
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/rsi/rsi_91x_mgmt.c | 2 --
1 file changed, 2 deletions(-)
--- a/drivers/net/wireless/rsi/rsi_91x_mgmt.c
+++ b/drivers/net/wireless/rsi/rsi_91x_mgmt.c
@@ -852,8 +852,6 @@ int rsi_hal_load_key(struct rsi_common *
memcpy(set_key->tx_mic_key, &data[16], 8);
memcpy(set_key->rx_mic_key, &data[24], 8);
}
- } else {
- memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ);
}
skb_put(skb, frame_len);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 380/438] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (378 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 379/438] watchdog: rzv2h: " Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 381/438] watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start() Greg Kroah-Hartman
` (69 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 88f113634028ca90a857031837d8061d1a9e1a7b upstream.
sp5100_tco_init() stores the PCI device matched by for_each_pci_dev()
in the global sp5100_tco_pci and keeps its reference for the lifetime
of the driver, but neither sp5100_tco_exit() nor the error paths of
sp5100_tco_init() call pci_dev_put(), leaking the reference on driver
registration failure and on every module load/unload cycle.
Drop the reference when the platform driver or device registration
fails and when the module is unloaded.
Fixes: 15e28bf13008 ("watchdog: Add support for sp5100 chipset TCO")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://patch.msgid.link/20260916170511.2086199-1-vulab@iscas.ac.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/sp5100_tco.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
--- a/drivers/watchdog/sp5100_tco.c
+++ b/drivers/watchdog/sp5100_tco.c
@@ -605,8 +605,10 @@ static int __init sp5100_tco_init(void)
pr_info("SP5100/SB800 TCO WatchDog Timer Driver\n");
err = platform_driver_register(&sp5100_tco_driver);
- if (err)
+ if (err) {
+ pci_dev_put(sp5100_tco_pci);
return err;
+ }
sp5100_tco_platform_device =
platform_device_register_simple(TCO_DRIVER_NAME, -1, NULL, 0);
@@ -619,6 +621,7 @@ static int __init sp5100_tco_init(void)
unreg_platform_driver:
platform_driver_unregister(&sp5100_tco_driver);
+ pci_dev_put(sp5100_tco_pci);
return err;
}
@@ -626,6 +629,7 @@ static void __exit sp5100_tco_exit(void)
{
platform_device_unregister(sp5100_tco_platform_device);
platform_driver_unregister(&sp5100_tco_driver);
+ pci_dev_put(sp5100_tco_pci);
}
module_init(sp5100_tco_init);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 327/398] wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (323 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 326/398] wifi: rsi: fix heap OOB write on key removal Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 328/398] wifi: wlcore: release runtime PM ref on regdomain config failure Greg Kroah-Hartman
` (77 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Song Li, Fan Wu, Loic Poulain,
Jeff Johnson
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit d9be5e75530772fc31637070d51e5717d6aeaa2a upstream.
wcn36xx_dxe_deinit() tears down the TX ack timer with timer_delete(),
which only dequeues the timer and does not wait for a callback that is
already executing; the preceding free_irq() calls synchronize the
interrupt handlers only. The callback, wcn36xx_dxe_tx_timer(), can
therefore be running past the teardown and use the wcn freed along
with the ieee80211_hw in wcn36xx_remove(): it takes wcn->dxe_lock,
reads wcn->tx_ack_skb and passes wcn->hw to
ieee80211_tx_status_irqsafe().
Fix this by using timer_shutdown_sync(), which waits for a running
callback and also prevents the timer from being rearmed again. The
timer is set up again by wcn36xx_dxe_init() on the next start, so the
start/stop cycle is unaffected.
This issue was found by an in-house static analysis tool.
Fixes: fdf21cc37149 ("wcn36xx: Add TX ack support")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Co-developed-by: Song Li <songl@zju.edu.cn>
Signed-off-by: Song Li <songl@zju.edu.cn>
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260910020907.3353-1-fanwu01@zju.edu.cn
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/ath/wcn36xx/dxe.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/wireless/ath/wcn36xx/dxe.c
+++ b/drivers/net/wireless/ath/wcn36xx/dxe.c
@@ -1055,7 +1055,7 @@ void wcn36xx_dxe_deinit(struct wcn36xx *
free_irq(wcn->tx_irq, wcn);
free_irq(wcn->rx_irq, wcn);
- timer_delete(&wcn->tx_ack_timer);
+ timer_shutdown_sync(&wcn->tx_ack_timer);
if (wcn->tx_ack_skb) {
ieee80211_tx_status_irqsafe(wcn->hw, wcn->tx_ack_skb);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 381/438] watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (379 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 380/438] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 382/438] wifi: brcmsmac: fix UAF in brcms_free_timer() Greg Kroah-Hartman
` (68 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Liang, Guenter Roeck
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wentao Liang <vulab@iscas.ac.cn>
commit 8f0ca55016a7647109ae2bc91bcb346fc8b13785 upstream.
starfive_wdt_pm_start() takes a runtime PM reference with
pm_runtime_get_sync(), which increments the usage counter even when it
fails, and returns the error without dropping it again. The watchdog
core does not invoke the stop callback when start fails, so the
reference taken on the error path is leaked.
Use pm_runtime_resume_and_get() instead, which keeps the usage counter
balanced when the resume fails.
Fixes: db728ea9c7be ("drivers: watchdog: Add StarFive Watchdog driver")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Link: https://patch.msgid.link/20260916170704.2086331-1-vulab@iscas.ac.cn
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/watchdog/starfive-wdt.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/watchdog/starfive-wdt.c
+++ b/drivers/watchdog/starfive-wdt.c
@@ -371,7 +371,7 @@ static void starfive_wdt_stop(struct sta
static int starfive_wdt_pm_start(struct watchdog_device *wdd)
{
struct starfive_wdt *wdt = watchdog_get_drvdata(wdd);
- int ret = pm_runtime_get_sync(wdd->parent);
+ int ret = pm_runtime_resume_and_get(wdd->parent);
if (ret < 0)
return ret;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 328/398] wifi: wlcore: release runtime PM ref on regdomain config failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (324 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 327/398] wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 329/398] wifi: wilc1000: fix out-of-bounds read in P2P public action frames Greg Kroah-Hartman
` (76 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
commit 8a1f3cf89ddcc700e25afe42cfad333059adcc94 upstream.
wlcore_regdomain_config() gets a runtime PM reference before sending
the regulatory-domain command. When
wlcore_cmd_regdomain_config_locked() fails, the function queues recovery
and returns without dropping that reference.
Release the reference after handling the command result so both success
and failure paths balance the preceding
pm_runtime_resume_and_get(). The recovery worker takes a separate
runtime PM reference and cannot release the reference held here.
Fixes: fa2648a34e73 ("wlcore: Add support for runtime PM")
Cc: stable@vger.kernel.org
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260820125126.12757-1-runyu.xiao@seu.edu.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/ti/wlcore/main.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
--- a/drivers/net/wireless/ti/wlcore/main.c
+++ b/drivers/net/wireless/ti/wlcore/main.c
@@ -3719,10 +3719,8 @@ void wlcore_regdomain_config(struct wl12
goto out;
ret = wlcore_cmd_regdomain_config_locked(wl);
- if (ret < 0) {
+ if (ret < 0)
wl12xx_queue_recovery_work(wl);
- goto out;
- }
pm_runtime_mark_last_busy(wl->dev);
pm_runtime_put_autosuspend(wl->dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 382/438] wifi: brcmsmac: fix UAF in brcms_free_timer()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (380 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 381/438] watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 383/438] wifi: iwlegacy: fix broadcast stations deallocation Greg Kroah-Hartman
` (67 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiangshan Yi, Arend van Spriel,
Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiangshan Yi <yijiangshan@kylinos.cn>
commit 1eeca1d5e0920fbdad6449768fd2d4364e714180 upstream.
brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous
cancel_delayed_work() to cancel the timer's underlying delayed work. If
the work callback (_brcms_timer) is already running, cancel_delayed_work()
returns false without waiting, and brcms_free_timer() proceeds to kfree(t)
while the callback still accesses t through container_of().
Add an explicit cancel_delayed_work_sync() after brcms_del_timer() to
guarantee that any in-flight callback has completed before the timer
structure is freed.
Fixes: 5b435de0d786 ("net: wireless: add brcm80211 drivers")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260815121043.938414-1-yijiangshan@kylinos.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/broadcom/brcm80211/brcmsmac/mac80211_if.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/net/wireless/broadcom/brcm80211/brcmsmac/mac80211_if.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmsmac/mac80211_if.c
@@ -1571,6 +1571,10 @@ void brcms_free_timer(struct brcms_timer
/* delete the timer in case it is active */
brcms_del_timer(t);
+ /* Ensure the callback has finished before freeing the timer
+ * structure, since brcms_del_timer() uses non-synchronous cancel.
+ */
+ cancel_delayed_work_sync(&t->dly_wrk);
if (wl->timers == t) {
wl->timers = wl->timers->next;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 329/398] wifi: wilc1000: fix out-of-bounds read in P2P public action frames
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (325 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 328/398] wifi: wlcore: release runtime PM ref on regdomain config failure Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 330/398] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() Greg Kroah-Hartman
` (75 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ali Ahmet Memis, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ali Ahmet Memis <ali@iusegentoo.com>
commit ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14 upstream.
wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once
ieee80211_is_public_action() returns true. That helper only verifies the
frame is long enough for the action category field, that is
offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both
functions then read the P2P public action header up to oui_subtype at
offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where
ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32.
A public action frame of 25 to 31 bytes passes the check but is shorter
than that 32 byte header, so oui_subtype can be read out of bounds, and
because the length is unsigned, "size - ie_offset" underflows to a value
close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length,
so even the size_t subtraction in mgmt_tx() is truncated to the same
value. It then walks far past the buffer searching for a vendor element
until it reaches unmapped memory.
In the receive path the frame arrives over the air and needs no
association, so a nearby unauthenticated device can crash the host while
it is in P2P listen. Reject frames shorter than the P2P public action
header in both paths before dereferencing it.
Fixes: 4fb8b5aa2a11 ("staging: wilc1000: refactor p2p action frames handling API's")
Cc: stable@vger.kernel.org
Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>
Link: https://patch.msgid.link/20260807115230.136767-1-ali@iusegentoo.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/microchip/wilc1000/cfg80211.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
--- a/drivers/net/wireless/microchip/wilc1000/cfg80211.c
+++ b/drivers/net/wireless/microchip/wilc1000/cfg80211.c
@@ -1060,6 +1060,13 @@ void wilc_wfi_p2p_rx(struct wilc_vif *vi
if (!ieee80211_is_public_action((struct ieee80211_hdr *)buff, size))
goto out_rx_mgmt;
+ /* ieee80211_is_public_action() only validates up to the category
+ * byte, so reject frames too short for the P2P public action header
+ * before dereferencing it or computing size - ie_offset.
+ */
+ if (size < ie_offset)
+ goto out_rx_mgmt;
+
d = (struct wilc_p2p_pub_act_frame *)(&mgmt->u.action);
if (d->oui_subtype != GO_NEG_REQ && d->oui_subtype != GO_NEG_RSP &&
d->oui_subtype != P2P_INV_REQ && d->oui_subtype != P2P_INV_RSP)
@@ -1208,6 +1215,13 @@ static int mgmt_tx(struct wiphy *wiphy,
goto out_set_timeout;
}
+ /* ieee80211_is_public_action() only validates up to the category
+ * byte, so reject frames too short for the P2P public action header
+ * before dereferencing it or computing len - ie_offset.
+ */
+ if (len < ie_offset)
+ goto out_set_timeout;
+
d = (struct wilc_p2p_pub_act_frame *)(&mgmt->u.action);
if (d->oui_type != WLAN_OUI_TYPE_WFA_P2P ||
d->oui_subtype != GO_NEG_CONF) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 383/438] wifi: iwlegacy: fix broadcast stations deallocation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (381 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 382/438] wifi: brcmsmac: fix UAF in brcms_free_timer() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 384/438] wifi: libertas_tf: fix UAF in lbtf_free_adapter() Greg Kroah-Hartman
` (66 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislaw Gruszka, Johannes Berg,
Martin-Éric Racine
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislaw Gruszka <stf_xl@wp.pl>
commit b5526b780f8b297a76030410b96ba29153afb98f upstream.
On the error path of __il4965_up(), il_dealloc_bcast_stations() clears
only IL_STA_UCODE_ACTIVE, leaving IL_STA_BCAST set. This causes the
same broadcast stations to be deallocated again by __il4965_down().
This can occur when RF_KILL is toggled during driver startup.
To fix clear the entire 'used' field, since we will not do any
other operations on the station.
Reported-and-tested-by: Martin-Éric Racine <martin-eric.racine+kernel-bugzilla@iki.fi>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221733
Fixes: c2fd34469d16 ("iwl4965: Fix a memory leak in error handling code of __il4965_up")
Cc: <stable@vger.kernel.org> # 7.1.x: 57aa1718d595 wifi: iwlegacy: replace BUG_ON() with WARN_ON() on num_stations check
Cc: <stable@vger.kernel.org> # 6.x.x: 57aa1718d595 wifi: iwlegacy: replace BUG_ON() with WARN_ON() on num_stations check
Cc: <stable@vger.kernel.org> # 5.x.x: 57aa1718d595 wifi: iwlegacy: replace BUG_ON() with WARN_ON() on num_stations check
Signed-off-by: Stanislaw Gruszka <stf_xl@wp.pl>
Link: https://patch.msgid.link/20260820093059.18779-1-stf_xl@wp.pl
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intel/iwlegacy/common.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/wireless/intel/iwlegacy/common.c
+++ b/drivers/net/wireless/intel/iwlegacy/common.c
@@ -2326,7 +2326,7 @@ il_dealloc_bcast_stations(struct il_priv
if (!(il->stations[i].used & IL_STA_BCAST))
continue;
- il->stations[i].used &= ~IL_STA_UCODE_ACTIVE;
+ il->stations[i].used = 0;
il->num_stations--;
if (WARN_ON(il->num_stations < 0))
il->num_stations = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 330/398] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (326 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 329/398] wifi: wilc1000: fix out-of-bounds read in P2P public action frames Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 331/398] wifi: p54: validate curve data length in the calibration curve converters Greg Kroah-Hartman
` (74 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tianchu Chen, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tianchu Chen <flynnnchen@tencent.com>
commit c1ba7f7f18465e259cf1b4d9c73fc73853d7f790 upstream.
wilc_wlan_handle_isr_ext() takes the RX transfer size from the
device-reported interrupt status register (a 15-bit field shifted left by 2,
up to 131068 bytes) and reads that many bytes from the device into
rx_buffer, which is only WILC_RX_BUFF_SIZE (96K) large. The wrap
check only handles the current offset; the size itself is never
compared against the buffer, so a bogus SDIO device can make the driver
OOB-write rx_buffer by up to ~32K with data it controls.
The oversized transfer also leaves rx_buffer_offset past the end of
the buffer, after which the unsigned wrap check stops working and
the overflow can repeat.
Drop any transfer whose size exceeds the RX buffer, acknowledging
the data interrupt and re-arming the RX engine so the bogus frame is
discarded and reception can continue. This also restores the
rx_buffer_offset <= WILC_RX_BUFF_SIZE invariant the wrap check
relies on.
This is not expected to change driver behavior in most cases:
without this check, an oversized transfer would most likely
corrupt neighboring kernel memory instead of completing anyway, and
the drop path performs the same interrupt acknowledgment and RX
engine re-arming as the normal path, so subsequent transfers are
received unaffected.
Discovered by Atuin - Automated Vulnerability Discovery Engine.
Fixes: c5c77ba18ea6 ("staging: wilc1000: Add SDIO/SPI 802.11 driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Tianchu Chen <flynnnchen@tencent.com>
Link: https://patch.msgid.link/7c971924c6bdccf6c2f75704a5a746e9303aaf64@linux.dev
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/microchip/wilc1000/wlan.c | 9 +++++++++
1 file changed, 9 insertions(+)
--- a/drivers/net/wireless/microchip/wilc1000/wlan.c
+++ b/drivers/net/wireless/microchip/wilc1000/wlan.c
@@ -1197,6 +1197,15 @@ static void wilc_wlan_handle_isr_ext(str
if (size <= 0)
return;
+ /* A size exceeding the RX buffer is bogus; drop the transfer
+ * instead of overflowing the buffer.
+ */
+ if (size > WILC_RX_BUFF_SIZE) {
+ wilc->hif_func->hif_clear_int_ext(wilc,
+ DATA_INT_CLR | ENABLE_RX_VMM);
+ return;
+ }
+
if (WILC_RX_BUFF_SIZE - offset < size)
offset = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 384/438] wifi: libertas_tf: fix UAF in lbtf_free_adapter()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (382 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 383/438] wifi: iwlegacy: fix broadcast stations deallocation Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 385/438] wifi: libipw: reject TKIP frames without a full MIC Greg Kroah-Hartman
` (65 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jiangshan Yi, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiangshan Yi <yijiangshan@kylinos.cn>
commit bbb9a0ab96d44a64529aafc7a16de460a1712f6a upstream.
lbtf_free_adapter() calls lbtf_free_cmd_buffer() to free the command
buffers before calling timer_delete_sync() to wait for the command
timer callback. If the timer callback (command_timer_fn) is already
running when lbtf_free_cmd_buffer() frees the command array, the
callback dereferences priv->cur_cmd->cmdbuf which points to freed
memory.
Swap the order so that timer_delete_sync() runs first, ensuring any
in-flight callback has completed before the command buffers are freed.
Fixes: 06b16ae53192 ("libertas_tf: main.c, data paths and mac80211 handlers")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Link: https://patch.msgid.link/20260815115724.920628-1-yijiangshan@kylinos.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/libertas_tf/main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/wireless/marvell/libertas_tf/main.c
+++ b/drivers/net/wireless/marvell/libertas_tf/main.c
@@ -173,8 +173,8 @@ static int lbtf_init_adapter(struct lbtf
static void lbtf_free_adapter(struct lbtf_private *priv)
{
lbtf_deb_enter(LBTF_DEB_MAIN);
- lbtf_free_cmd_buffer(priv);
timer_delete_sync(&priv->command_timer);
+ lbtf_free_cmd_buffer(priv);
lbtf_deb_leave(LBTF_DEB_MAIN);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 331/398] wifi: p54: validate curve data length in the calibration curve converters
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (327 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 330/398] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 332/398] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST Greg Kroah-Hartman
` (73 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shengzhuo Wei, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit ce858fa6b8a214dee5adb82358885fa024cdd887 upstream.
p54_convert_rev0() and p54_convert_rev1() read calibration curve
data from the device-supplied EEPROM entry using channel and
points-per-channel counts taken verbatim from that same entry, so
an entry that declares more data than it carries drives an
out-of-bounds read past the EEPROM buffer (verified with a KASAN
reproducer of the conversion loop). The sibling converters
p54_convert_output_limits() and p54_convert_db() already validate
their counts against the entry length; this path was missed.
Reject the entry when the counts do not fit in the entry data.
Fixes: eff1a59c48e3 ("[P54]: add mac80211-based driver for prism54 softmac hardware")
Cc: stable@vger.kernel.org
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Link: https://patch.msgid.link/20260831-p54-pda-validation-v2-1-dae566b388c8@cherr.cc
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intersil/p54/eeprom.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
--- a/drivers/net/wireless/intersil/p54/eeprom.c
+++ b/drivers/net/wireless/intersil/p54/eeprom.c
@@ -418,17 +418,22 @@ free:
}
static int p54_convert_rev0(struct ieee80211_hw *dev,
- struct pda_pa_curve_data *curve_data)
+ struct pda_pa_curve_data *curve_data, size_t len)
{
struct p54_common *priv = dev->priv;
struct p54_pa_curve_data_sample *dst;
struct pda_pa_curve_data_sample_rev0 *src;
+ size_t needed = curve_data->channels *
+ (sizeof(*src) * curve_data->points_per_channel + 2);
size_t cd_len = sizeof(*curve_data) +
(curve_data->points_per_channel*sizeof(*dst) + 2) *
curve_data->channels;
unsigned int i, j;
void *source, *target;
+ if (len < sizeof(*curve_data) + needed)
+ return -EINVAL;
+
priv->curve_data = kmalloc(sizeof(*priv->curve_data) + cd_len,
GFP_KERNEL);
if (!priv->curve_data)
@@ -470,17 +475,22 @@ static int p54_convert_rev0(struct ieee8
}
static int p54_convert_rev1(struct ieee80211_hw *dev,
- struct pda_pa_curve_data *curve_data)
+ struct pda_pa_curve_data *curve_data, size_t len)
{
struct p54_common *priv = dev->priv;
struct p54_pa_curve_data_sample *dst;
struct pda_pa_curve_data_sample_rev1 *src;
+ size_t needed = curve_data->channels *
+ (sizeof(*src) * curve_data->points_per_channel + 3);
size_t cd_len = sizeof(*curve_data) +
(curve_data->points_per_channel*sizeof(*dst) + 2) *
curve_data->channels;
unsigned int i, j;
void *source, *target;
+ if (len < sizeof(*curve_data) + needed)
+ return -EINVAL;
+
priv->curve_data = kzalloc(cd_len + sizeof(*priv->curve_data),
GFP_KERNEL);
if (!priv->curve_data)
@@ -767,6 +777,7 @@ int p54_parse_eeprom(struct ieee80211_hw
case PDR_PRISM_PA_CAL_CURVE_DATA: {
struct pda_pa_curve_data *curve_data =
(struct pda_pa_curve_data *)entry->data;
+
if (data_len < sizeof(*curve_data)) {
err = -EINVAL;
goto err;
@@ -774,10 +785,10 @@ int p54_parse_eeprom(struct ieee80211_hw
switch (curve_data->cal_method_rev) {
case 0:
- err = p54_convert_rev0(dev, curve_data);
+ err = p54_convert_rev0(dev, curve_data, data_len);
break;
case 1:
- err = p54_convert_rev1(dev, curve_data);
+ err = p54_convert_rev1(dev, curve_data, data_len);
break;
default:
wiphy_err(dev->wiphy,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 385/438] wifi: libipw: reject TKIP frames without a full MIC
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (383 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 384/438] wifi: libertas_tf: fix UAF in lbtf_free_adapter() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 386/438] wifi: rsi: fix heap OOB write on key removal Greg Kroah-Hartman
` (64 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Daehyeon Ko, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daehyeon Ko <4ncienth@gmail.com>
commit 06f42accaf3c6aecab1dcc57f68dde6c06c8b380 upstream.
libipw_michael_mic_verify() assumes that an skb contains an eight-byte
Michael MIC. A short TKIP frame makes the unsigned payload length wrap,
causing michael_mic() to read past the skb.
Check that the MIC is present before verifying it, and use the existing
MICHAEL_MIC_LEN constant for all MIC lengths in the verifier.
Fixes: b453872c35cf ("[NET] ieee80211 subsystem")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
Link: https://patch.msgid.link/20260909061124.3802517-1-4ncienth@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
--- a/drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c
@@ -474,14 +474,16 @@ static int libipw_michael_mic_verify(str
int hdr_len, void *priv)
{
struct libipw_tkip_data *tkey = priv;
- u8 mic[8];
+ u8 mic[MICHAEL_MIC_LEN];
- if (!tkey->key_set)
+ if (!tkey->key_set || skb->len < hdr_len + MICHAEL_MIC_LEN)
return -1;
michael_mic(&tkey->key[24], (struct ieee80211_hdr *)skb->data,
- skb->data + hdr_len, skb->len - 8 - hdr_len, mic);
- if (memcmp(mic, skb->data + skb->len - 8, 8) != 0) {
+ skb->data + hdr_len,
+ skb->len - MICHAEL_MIC_LEN - hdr_len, mic);
+ if (memcmp(mic, skb->data + skb->len - MICHAEL_MIC_LEN,
+ MICHAEL_MIC_LEN) != 0) {
struct ieee80211_hdr *hdr;
hdr = (struct ieee80211_hdr *)skb->data;
printk(KERN_DEBUG "%s: Michael MIC verification failed for "
@@ -499,7 +501,7 @@ static int libipw_michael_mic_verify(str
tkey->rx_iv32 = tkey->rx_iv32_new;
tkey->rx_iv16 = tkey->rx_iv16_new;
- skb_trim(skb, skb->len - 8);
+ skb_trim(skb, skb->len - MICHAEL_MIC_LEN);
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 332/398] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (328 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 331/398] wifi: p54: validate curve data length in the calibration curve converters Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 333/398] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length Greg Kroah-Hartman
` (72 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Lamparter, Shengzhuo Wei,
Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit d8efd84f49379ed28624098821f80e992657d935 upstream.
The PDR_INTERFACE_LIST loop only checks that the record start is within
the entry before reading an entire struct exp_if from it. A truncated
trailing record makes the if_id/variant reads cross the entry boundary
into the heap beyond the EEPROM buffer (verified with a KASAN
reproducer of the loop). The variant also feeds the synth front-end
selection, so this is not only a leak.
Advance only while a full record still fits in the entry.
Fixes: eff1a59c48e3 ("[P54]: add mac80211-based driver for prism54 softmac hardware")
Cc: stable@vger.kernel.org
Acked-by: Christian Lamparter <chunkeey@gmail.com>
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Link: https://patch.msgid.link/20260831-p54-pda-validation-v2-2-dae566b388c8@cherr.cc
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intersil/p54/eeprom.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/net/wireless/intersil/p54/eeprom.c
+++ b/drivers/net/wireless/intersil/p54/eeprom.c
@@ -816,7 +816,8 @@ int p54_parse_eeprom(struct ieee80211_hw
break;
case PDR_INTERFACE_LIST:
tmp = entry->data;
- while ((u8 *)tmp < entry->data + data_len) {
+ while ((u8 *)tmp + sizeof(struct exp_if) <=
+ entry->data + data_len) {
struct exp_if *exp_if = tmp;
if (exp_if->if_id == cpu_to_le16(IF_ID_ISL39000))
synth = le16_to_cpu(exp_if->variant);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 386/438] wifi: rsi: fix heap OOB write on key removal
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (384 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 385/438] wifi: libipw: reject TKIP frames without a full MIC Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 387/438] wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown Greg Kroah-Hartman
` (63 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tianchu Chen, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tianchu Chen <flynnnchen@tencent.com>
commit e6c5ed7a98d7bc8b0f7918246f1c90ddb3f79dfa upstream.
When a key is removed (data == NULL), rsi_hal_load_key() runs:
memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ);
set_key is a struct rsi_set_key *, so the subscript is scaled by
sizeof(struct rsi_set_key) (160 bytes): &set_key[FRAME_DESC_SZ] is
skb->data + 2560, and the memset writes 144 zero bytes starting
2.4KB past the end of the 160-byte skb data buffer, corrupting
unrelated heap objects. The intended byte offset would have been
(u8 *)set_key + FRAME_DESC_SZ.
The write fires on every DISABLE_KEY callback, so plain disconnects,
roams and interface teardowns trigger it on real networks.
The memset is redundant: the whole buffer is zeroed right after
allocation, so the frame sent to the device is byte-identical
without it. Drop the else branch; normal operation is unaffected.
Discovered by Atuin - Automated Vulnerability Discovery Engine.
Fixes: dad0d04fa7ba ("rsi: Add RS9113 wireless driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Tianchu Chen <flynnnchen@tencent.com>
Link: https://patch.msgid.link/90bb2b07007942064c04aa3729cedd9eb1e930b1@linux.dev
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/rsi/rsi_91x_mgmt.c | 2 --
1 file changed, 2 deletions(-)
--- a/drivers/net/wireless/rsi/rsi_91x_mgmt.c
+++ b/drivers/net/wireless/rsi/rsi_91x_mgmt.c
@@ -852,8 +852,6 @@ int rsi_hal_load_key(struct rsi_common *
memcpy(set_key->tx_mic_key, &data[16], 8);
memcpy(set_key->rx_mic_key, &data[24], 8);
}
- } else {
- memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ);
}
skb_put(skb, frame_len);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 333/398] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (329 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 332/398] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 334/398] wifi: mwifiex: validate scan response extents Greg Kroah-Hartman
` (71 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Doruk Tan Ozturk, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Doruk Tan Ozturk <doruk@0sec.ai>
commit e667aee1c192d67d27c803007bfa9c6e0873e959 upstream.
mwifiex_search_oui_in_ie() reads a pairwise-cipher (PTK) count from a
beacon/probe-response RSN or WPA information element and then walks that
many 4-byte OUIs, comparing each with memcmp(). The count comes straight
from the (attacker-supplied) IE and is never checked against the
element's own length, and the callers admit the element on element_id
alone (has_ieee_hdr() / has_vendor_hdr(), no length check). A crafted
RSN/WPA IE with a large pairwise count therefore makes the walk read up
to 255 * 4 bytes past the element -- an out-of-bounds read of the
kmemdup()'d beacon buffer, reachable from any AP whose beacon/probe
response is processed during scan-result parsing.
Pass the number of IE bytes available at the OUI list and bound the walk
to the element. Keep the length signed and reject a negative value
before any unsigned arithmetic, so a small or zero IE length cannot
underflow to a large size_t and defeat the bound.
Found by 0sec automated security-research tooling (https://0sec.ai).
Fixes: 5e6e3a92b9a4 ("wireless: mwifiex: initial commit for Marvell mwifiex driver")
Cc: stable@vger.kernel.org
Assisted-by: 0sec:multi-model
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
Link: https://patch.msgid.link/20260814134704.85902-1-doruk@0sec.ai
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/scan.c | 25 ++++++++++++++++++++++---
1 file changed, 22 insertions(+), 3 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/scan.c
+++ b/drivers/net/wireless/marvell/mwifiex/scan.c
@@ -104,12 +104,24 @@ has_vendor_hdr(struct ieee_types_vendor_
* a given oui in PTK.
*/
static u8
-mwifiex_search_oui_in_ie(struct ie_body *iebody, u8 *oui)
+mwifiex_search_oui_in_ie(struct ie_body *iebody, u8 *oui, int ie_len)
{
+ const size_t ptk_body_offset = offsetof(struct ie_body, ptk_body);
u8 count;
+ /* ie_len is the number of bytes available at iebody. Keep it signed
+ * and reject a negative (underflowed) length before the unsigned
+ * comparisons below, so a small or zero IE length cannot wrap.
+ */
+ if (ie_len < 0 || (size_t)ie_len < ptk_body_offset)
+ return MWIFIEX_OUI_NOT_PRESENT;
+
count = iebody->ptk_cnt[0];
+ /* Reject an OUI count whose list would run past the element. */
+ if (ptk_body_offset + count * sizeof(iebody->ptk_body) > (size_t)ie_len)
+ return MWIFIEX_OUI_NOT_PRESENT;
+
/* There could be multiple OUIs for PTK hence
1) Take the length.
2) Check all the OUIs for AES.
@@ -143,11 +155,14 @@ mwifiex_is_rsn_oui_present(struct mwifie
u8 ret = MWIFIEX_OUI_NOT_PRESENT;
if (has_ieee_hdr(bss_desc->bcn_rsn_ie, WLAN_EID_RSN)) {
+ int ie_len = (int)bss_desc->bcn_rsn_ie->ieee_hdr.len -
+ RSN_GTK_OUI_OFFSET;
+
iebody = (struct ie_body *)
(((u8 *) bss_desc->bcn_rsn_ie->data) +
RSN_GTK_OUI_OFFSET);
oui = &mwifiex_rsn_oui[cipher][0];
- ret = mwifiex_search_oui_in_ie(iebody, oui);
+ ret = mwifiex_search_oui_in_ie(iebody, oui, ie_len);
if (ret)
return ret;
}
@@ -169,10 +184,14 @@ mwifiex_is_wpa_oui_present(struct mwifie
u8 ret = MWIFIEX_OUI_NOT_PRESENT;
if (has_vendor_hdr(bss_desc->bcn_wpa_ie, WLAN_EID_VENDOR_SPECIFIC)) {
+ int ie_len = (int)bss_desc->bcn_wpa_ie->vend_hdr.len -
+ (int)sizeof(bss_desc->bcn_wpa_ie->vend_hdr.oui) -
+ WPA_GTK_OUI_OFFSET;
+
iebody = (struct ie_body *)((u8 *)bss_desc->bcn_wpa_ie->data +
WPA_GTK_OUI_OFFSET);
oui = &mwifiex_wpa_oui[cipher][0];
- ret = mwifiex_search_oui_in_ie(iebody, oui);
+ ret = mwifiex_search_oui_in_ie(iebody, oui, ie_len);
if (ret)
return ret;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 387/438] wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (385 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 386/438] wifi: rsi: fix heap OOB write on key removal Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 388/438] wifi: wlcore: release runtime PM ref on regdomain config failure Greg Kroah-Hartman
` (62 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Song Li, Fan Wu, Loic Poulain,
Jeff Johnson
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
commit d9be5e75530772fc31637070d51e5717d6aeaa2a upstream.
wcn36xx_dxe_deinit() tears down the TX ack timer with timer_delete(),
which only dequeues the timer and does not wait for a callback that is
already executing; the preceding free_irq() calls synchronize the
interrupt handlers only. The callback, wcn36xx_dxe_tx_timer(), can
therefore be running past the teardown and use the wcn freed along
with the ieee80211_hw in wcn36xx_remove(): it takes wcn->dxe_lock,
reads wcn->tx_ack_skb and passes wcn->hw to
ieee80211_tx_status_irqsafe().
Fix this by using timer_shutdown_sync(), which waits for a running
callback and also prevents the timer from being rearmed again. The
timer is set up again by wcn36xx_dxe_init() on the next start, so the
start/stop cycle is unaffected.
This issue was found by an in-house static analysis tool.
Fixes: fdf21cc37149 ("wcn36xx: Add TX ack support")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Co-developed-by: Song Li <songl@zju.edu.cn>
Signed-off-by: Song Li <songl@zju.edu.cn>
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260910020907.3353-1-fanwu01@zju.edu.cn
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/ath/wcn36xx/dxe.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/net/wireless/ath/wcn36xx/dxe.c
+++ b/drivers/net/wireless/ath/wcn36xx/dxe.c
@@ -1055,7 +1055,7 @@ void wcn36xx_dxe_deinit(struct wcn36xx *
free_irq(wcn->tx_irq, wcn);
free_irq(wcn->rx_irq, wcn);
- timer_delete(&wcn->tx_ack_timer);
+ timer_shutdown_sync(&wcn->tx_ack_timer);
if (wcn->tx_ack_skb) {
ieee80211_tx_status_irqsafe(wcn->hw, wcn->tx_ack_skb);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 334/398] wifi: mwifiex: validate scan response extents
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (330 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 333/398] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 335/398] wifi: mwifiex: prevent authentication frame length truncation Greg Kroah-Hartman
` (70 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
commit 3687d7d48070838cc2953431b3a27717cab0aaf6 upstream.
mwifiex_ret_802_11_scan() subtracts the fixed response fields and the
firmware-provided BSS length from resp->size without first proving that
either extent fits. A short response or oversized BSS length can
therefore underflow tlv_buf_size and make the TLV parser walk beyond the
command response.
Compute the fixed extent from the selected normal or background scan
response. Validate that the fixed fields and BSS data fit before deriving
the TLV extent and entering the parser.
Fixes: 5e6e3a92b9a4 ("wireless: mwifiex: initial commit for Marvell mwifiex driver")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260815135227.50392-1-pengpeng@iscas.ac.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/scan.c | 29 ++++++++++++++++++----------
1 file changed, 19 insertions(+), 10 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/scan.c
+++ b/drivers/net/wireless/marvell/mwifiex/scan.c
@@ -2117,6 +2117,7 @@ int mwifiex_ret_802_11_scan(struct mwifi
u32 bytes_left;
u32 idx;
u32 tlv_buf_size;
+ size_t fixed_size;
struct mwifiex_ie_types_chan_band_list_param_set *chan_band_tlv;
struct chan_band_param_set *chan_band;
u8 is_bgscan_resp;
@@ -2132,6 +2133,14 @@ int mwifiex_ret_802_11_scan(struct mwifi
else
scan_rsp = &resp->params.scan_resp;
+ scan_resp_size = le16_to_cpu(resp->size);
+ fixed_size = scan_rsp->bss_desc_and_tlv_buffer - (u8 *)resp;
+ if (scan_resp_size < fixed_size) {
+ mwifiex_dbg(adapter, ERROR,
+ "SCAN_RESP: response is too short\n");
+ ret = -1;
+ goto check_next_scan;
+ }
if (scan_rsp->number_of_sets > MWIFIEX_MAX_AP) {
mwifiex_dbg(adapter, ERROR,
@@ -2149,8 +2158,6 @@ int mwifiex_ret_802_11_scan(struct mwifi
"info: SCAN_RESP: bss_descript_size %d\n",
bytes_left);
- scan_resp_size = le16_to_cpu(resp->size);
-
mwifiex_dbg(adapter, INFO,
"info: SCAN_RESP: returned %d APs before parsing\n",
scan_rsp->number_of_sets);
@@ -2158,15 +2165,17 @@ int mwifiex_ret_802_11_scan(struct mwifi
bss_info = scan_rsp->bss_desc_and_tlv_buffer;
/*
- * The size of the TLV buffer is equal to the entire command response
- * size (scan_resp_size) minus the fixed fields (sizeof()'s), the
- * BSS Descriptions (bss_descript_size as bytesLef) and the command
- * response header (S_DS_GEN)
+ * The TLV buffer follows the command-specific fixed fields and the BSS
+ * descriptions. Background-scan responses have an additional fixed
+ * field before scan_rsp, which is included in fixed_size.
*/
- tlv_buf_size = scan_resp_size - (bytes_left
- + sizeof(scan_rsp->bss_descript_size)
- + sizeof(scan_rsp->number_of_sets)
- + S_DS_GEN);
+ if (bytes_left > scan_resp_size - fixed_size) {
+ mwifiex_dbg(adapter, ERROR,
+ "SCAN_RESP: BSS data exceeds response\n");
+ ret = -1;
+ goto check_next_scan;
+ }
+ tlv_buf_size = scan_resp_size - fixed_size - bytes_left;
tlv_data = (struct mwifiex_ie_types_data *) (scan_rsp->
bss_desc_and_tlv_buffer +
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 388/438] wifi: wlcore: release runtime PM ref on regdomain config failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (386 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 387/438] wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 389/438] wifi: wilc1000: fix out-of-bounds read in P2P public action frames Greg Kroah-Hartman
` (61 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
commit 8a1f3cf89ddcc700e25afe42cfad333059adcc94 upstream.
wlcore_regdomain_config() gets a runtime PM reference before sending
the regulatory-domain command. When
wlcore_cmd_regdomain_config_locked() fails, the function queues recovery
and returns without dropping that reference.
Release the reference after handling the command result so both success
and failure paths balance the preceding
pm_runtime_resume_and_get(). The recovery worker takes a separate
runtime PM reference and cannot release the reference held here.
Fixes: fa2648a34e73 ("wlcore: Add support for runtime PM")
Cc: stable@vger.kernel.org
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260820125126.12757-1-runyu.xiao@seu.edu.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/ti/wlcore/main.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
--- a/drivers/net/wireless/ti/wlcore/main.c
+++ b/drivers/net/wireless/ti/wlcore/main.c
@@ -3724,10 +3724,8 @@ void wlcore_regdomain_config(struct wl12
goto out;
ret = wlcore_cmd_regdomain_config_locked(wl);
- if (ret < 0) {
+ if (ret < 0)
wl12xx_queue_recovery_work(wl);
- goto out;
- }
pm_runtime_put_autosuspend(wl->dev);
out:
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 335/398] wifi: mwifiex: prevent authentication frame length truncation
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (331 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 334/398] wifi: mwifiex: validate scan response extents Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 336/398] wifi: mwifiex: validate action frame fixed fields Greg Kroah-Hartman
` (69 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linmao Li, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linmao Li <lilinmao@kylinos.cn>
commit fa00193eb991f92b007aefe7afb6a7566976dacf upstream.
mwifiex_cfg80211_authenticate() derives the authentication frame length
from req->ie_len and req->auth_data_len, both of type size_t, but stores
it in a u16.
NL80211_ATTR_AUTH_DATA only has a minimum length policy. Since nla_len is
a u16, a single attribute can carry up to 65531 bytes of payload, so the
sum can exceed U16_MAX before it is assigned to pkt_len. The truncated
pkt_len determines the skb frame area, while the copy length remains
req->auth_data_len - 4, resulting in a heap buffer overflow.
For example, with auth_data_len equal to 65510 and no IEs, the sum is
65546. It is truncated to 10 and then reduced by four to 6. The driver
appends only six bytes to the skb with skb_put(), but then copies 65506
user-provided bytes into the authentication body.
Reaching this path requires CAP_NET_ADMIN in the user namespace owning
the network namespace, an up station netdev, and a suitable BSS/SAE
authentication request.
Compute the length in size_t, reject values that cannot be represented by
the firmware's u16 frame length field, and only then assign it to pkt_len.
Fixes: 36995892c271 ("wifi: mwifiex: add host mlme for client mode")
Cc: stable@vger.kernel.org # 6.12+
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Link: https://patch.msgid.link/20260820062155.3981976-1-lilinmao@kylinos.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/cfg80211.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/cfg80211.c
+++ b/drivers/net/wireless/marvell/mwifiex/cfg80211.c
@@ -4271,6 +4271,7 @@ mwifiex_cfg80211_authenticate(struct wip
struct mwifiex_adapter *adapter = priv->adapter;
struct sk_buff *skb;
u16 pkt_len, auth_alg;
+ size_t frame_len;
int ret;
struct mwifiex_ieee80211_mgmt *mgmt;
struct mwifiex_txinfo *tx_info;
@@ -4343,10 +4344,17 @@ mwifiex_cfg80211_authenticate(struct wip
mwifiex_cancel_scan(adapter);
- pkt_len = (u16)req->ie_len + req->auth_data_len +
+ frame_len = req->ie_len + req->auth_data_len +
MWIFIEX_MGMT_HEADER_LEN + MWIFIEX_AUTH_BODY_LEN;
if (req->auth_data_len >= 4)
- pkt_len -= 4;
+ frame_len -= 4;
+
+ if (frame_len > U16_MAX) {
+ mwifiex_dbg(priv->adapter, ERROR,
+ "auth frame too long: %zu bytes\n", frame_len);
+ return -EINVAL;
+ }
+ pkt_len = frame_len;
skb = dev_alloc_skb(MWIFIEX_MIN_DATA_HEADER_LEN +
MWIFIEX_MGMT_FRAME_HEADER_SIZE +
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 389/438] wifi: wilc1000: fix out-of-bounds read in P2P public action frames
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (387 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 388/438] wifi: wlcore: release runtime PM ref on regdomain config failure Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 390/438] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() Greg Kroah-Hartman
` (60 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ali Ahmet Memis, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ali Ahmet Memis <ali@iusegentoo.com>
commit ba6cb7c0868a412c2eb68e8efd5aa38bfb258a14 upstream.
wilc_wfi_p2p_rx() and mgmt_tx() start parsing a frame once
ieee80211_is_public_action() returns true. That helper only verifies the
frame is long enough for the action category field, that is
offsetofend(struct ieee80211_mgmt, u.action.category), 25 bytes. Both
functions then read the P2P public action header up to oui_subtype at
offset 30 and pass "size - ie_offset" to cfg80211_find_vendor_ie(), where
ie_offset is offsetof(struct ieee80211_mgmt, u) + sizeof(*d), i.e. 32.
A public action frame of 25 to 31 bytes passes the check but is shorter
than that 32 byte header, so oui_subtype can be read out of bounds, and
because the length is unsigned, "size - ie_offset" underflows to a value
close to 4 GiB. cfg80211_find_vendor_ie() takes an unsigned int length,
so even the size_t subtraction in mgmt_tx() is truncated to the same
value. It then walks far past the buffer searching for a vendor element
until it reaches unmapped memory.
In the receive path the frame arrives over the air and needs no
association, so a nearby unauthenticated device can crash the host while
it is in P2P listen. Reject frames shorter than the P2P public action
header in both paths before dereferencing it.
Fixes: 4fb8b5aa2a11 ("staging: wilc1000: refactor p2p action frames handling API's")
Cc: stable@vger.kernel.org
Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>
Link: https://patch.msgid.link/20260807115230.136767-1-ali@iusegentoo.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/microchip/wilc1000/cfg80211.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
--- a/drivers/net/wireless/microchip/wilc1000/cfg80211.c
+++ b/drivers/net/wireless/microchip/wilc1000/cfg80211.c
@@ -1058,6 +1058,13 @@ void wilc_wfi_p2p_rx(struct wilc_vif *vi
if (!ieee80211_is_public_action((struct ieee80211_hdr *)buff, size))
goto out_rx_mgmt;
+ /* ieee80211_is_public_action() only validates up to the category
+ * byte, so reject frames too short for the P2P public action header
+ * before dereferencing it or computing size - ie_offset.
+ */
+ if (size < ie_offset)
+ goto out_rx_mgmt;
+
d = (struct wilc_p2p_pub_act_frame *)(&mgmt->u.action);
if (d->oui_subtype != GO_NEG_REQ && d->oui_subtype != GO_NEG_RSP &&
d->oui_subtype != P2P_INV_REQ && d->oui_subtype != P2P_INV_RSP)
@@ -1207,6 +1214,13 @@ static int mgmt_tx(struct wiphy *wiphy,
goto out_set_timeout;
}
+ /* ieee80211_is_public_action() only validates up to the category
+ * byte, so reject frames too short for the P2P public action header
+ * before dereferencing it or computing len - ie_offset.
+ */
+ if (len < ie_offset)
+ goto out_set_timeout;
+
d = (struct wilc_p2p_pub_act_frame *)(&mgmt->u.action);
if (d->oui_type != WLAN_OUI_TYPE_WFA_P2P ||
d->oui_subtype != GO_NEG_CONF) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 336/398] wifi: mwifiex: validate action frame fixed fields
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (332 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 335/398] wifi: mwifiex: prevent authentication frame length truncation Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 337/398] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver Greg Kroah-Hartman
` (68 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johannes Berg, Brian Norris, Zhao Li,
Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
commit 1c25bfad93e69ce13f744a2fb919f02ea396a985 upstream.
mwifiex_process_mgmt_packet() accepts an rx_pkt_length as small as a
four-address struct ieee80211_hdr plus the two-byte firmware length prefix.
After stripping the prefix, mwifiex_parse_mgmt_packet() can receive a
frame equal to sizeof(struct ieee80211_hdr).
For action frames, the parser reads the category byte immediately after
that header and, for a public action frame, reads the following action
code byte without verifying that either field is present. A truncated frame
can therefore make the parser consume up to two bytes past the
firmware-declared frame length. If those bytes look like a TDLS discovery
response, the malformed frame can spuriously update peer signal state.
Require the category and public action-code fields before reading them.
Use sizeof(*ieee_hdr) so the checks and field accesses directly match the
firmware four-address layout being parsed before address4 is removed.
Suggested-by: Johannes Berg <johannes@sipsolutions.net>
Suggested-by: Brian Norris <briannorris@chromium.org>
Fixes: 72e5aa8d2a6d ("mwifiex: support for parsing TDLS discovery frames")
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/all/66f148d83eb9f0970b9abbccc85d1b61244e54ad.camel@sipsolutions.net/
Link: https://lore.kernel.org/all/20260708195911.84365-8-enderaoelyther@gmail.com/
Link: https://lore.kernel.org/all/20260723011013.76968-1-enderaoelyther@gmail.com/
Link: https://lore.kernel.org/all/20260723202257.688-1-enderaoelyther@gmail.com/
Link: https://lore.kernel.org/all/anuWyiPQja6_5vly@google.com/
Assisted-by: Codex:gpt-5
Assisted-by: Kimi:K3
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260825112523.95774-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/util.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/util.c
+++ b/drivers/net/wireless/marvell/mwifiex/util.c
@@ -317,10 +317,16 @@ mwifiex_parse_mgmt_packet(struct mwifiex
switch (stype) {
case IEEE80211_STYPE_ACTION:
- category = *(payload + sizeof(struct ieee80211_hdr));
+ if (len < sizeof(*ieee_hdr) + 1)
+ return -1;
+
+ category = *(payload + sizeof(*ieee_hdr));
switch (category) {
case WLAN_CATEGORY_PUBLIC:
- action_code = *(payload + sizeof(struct ieee80211_hdr)
+ if (len < sizeof(*ieee_hdr) + 2)
+ return -1;
+
+ action_code = *(payload + sizeof(*ieee_hdr)
+ 1);
if (action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) {
addr2 = ieee_hdr->addr2;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 390/438] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (388 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 389/438] wifi: wilc1000: fix out-of-bounds read in P2P public action frames Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 391/438] wifi: p54: validate curve data length in the calibration curve converters Greg Kroah-Hartman
` (59 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tianchu Chen, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tianchu Chen <flynnnchen@tencent.com>
commit c1ba7f7f18465e259cf1b4d9c73fc73853d7f790 upstream.
wilc_wlan_handle_isr_ext() takes the RX transfer size from the
device-reported interrupt status register (a 15-bit field shifted left by 2,
up to 131068 bytes) and reads that many bytes from the device into
rx_buffer, which is only WILC_RX_BUFF_SIZE (96K) large. The wrap
check only handles the current offset; the size itself is never
compared against the buffer, so a bogus SDIO device can make the driver
OOB-write rx_buffer by up to ~32K with data it controls.
The oversized transfer also leaves rx_buffer_offset past the end of
the buffer, after which the unsigned wrap check stops working and
the overflow can repeat.
Drop any transfer whose size exceeds the RX buffer, acknowledging
the data interrupt and re-arming the RX engine so the bogus frame is
discarded and reception can continue. This also restores the
rx_buffer_offset <= WILC_RX_BUFF_SIZE invariant the wrap check
relies on.
This is not expected to change driver behavior in most cases:
without this check, an oversized transfer would most likely
corrupt neighboring kernel memory instead of completing anyway, and
the drop path performs the same interrupt acknowledgment and RX
engine re-arming as the normal path, so subsequent transfers are
received unaffected.
Discovered by Atuin - Automated Vulnerability Discovery Engine.
Fixes: c5c77ba18ea6 ("staging: wilc1000: Add SDIO/SPI 802.11 driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Tianchu Chen <flynnnchen@tencent.com>
Link: https://patch.msgid.link/7c971924c6bdccf6c2f75704a5a746e9303aaf64@linux.dev
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/microchip/wilc1000/wlan.c | 9 +++++++++
1 file changed, 9 insertions(+)
--- a/drivers/net/wireless/microchip/wilc1000/wlan.c
+++ b/drivers/net/wireless/microchip/wilc1000/wlan.c
@@ -1197,6 +1197,15 @@ static void wilc_wlan_handle_isr_ext(str
if (size <= 0)
return;
+ /* A size exceeding the RX buffer is bogus; drop the transfer
+ * instead of overflowing the buffer.
+ */
+ if (size > WILC_RX_BUFF_SIZE) {
+ wilc->hif_func->hif_clear_int_ext(wilc,
+ DATA_INT_CLR | ENABLE_RX_VMM);
+ return;
+ }
+
if (WILC_RX_BUFF_SIZE - offset < size)
offset = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 337/398] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (333 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 336/398] wifi: mwifiex: validate action frame fixed fields Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 338/398] drm/gud: fix out-of-bounds write in gud_plane_atomic_check() Greg Kroah-Hartman
` (67 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+af177aa139efdd13a9da,
Rik van Riel, syzbot+dcaca020ca8377e7ced0, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rik van Riel <riel@surriel.com>
commit da2ca406f45a6e21760243152ed8d2e8e72915c2 upstream.
ieee80211_set_bitrate_mask() checks if the interface is running via
ieee80211_sdata_running(), but it does not check if the interface is
still present in the driver.
When sdata is running but IEEE80211_SDATA_IN_DRIVER is not set, the
call reaches drv_set_bitrate_mask() in driver-ops.h which hits
wlan1: Failed check-sdata-in-driver check, flags: 0x0
WARNING: net/mac80211/driver-ops.h:884 at drv_set_bitrate_mask
Syzkaller triggers this via wext SIOCSIWRATE ioctl. The Call Trace shows
wext_ioctl_dispatch() in wext-core.c dispatching the ioctl, calling
ioctl_standard_call() for SIOCSIWRATE, which calls cfg80211_wext_siwrate()
in wext-compat.c. That builds a bitrate mask and calls
rdev_set_bitrate_mask() which ends up in ieee80211_set_bitrate_mask() in
cfg.c. The interface is marked running via SDATA_STATE_RUNNING but
flags is 0, so check_sdata_in_driver() fails.
When the interface is being torn down, or when wext ioctl is issued
during interface bringup before drv_add_interface() sets IN_DRIVER, the
running check passes while IN_DRIVER is clear.
Check IEEE80211_SDATA_IN_DRIVER in ieee80211_set_bitrate_mask() before
calling the driver, returning -ENETDOWN. This avoids the WARN_ONCE in
driver-ops.h and matches other cfg.c operations that bail early when not
in driver.
This change should be safe because wiphy mutex is held in
cfg80211_wext_siwrate() via guard(wiphy), and IN_DRIVER is set/cleared
under RTNL and wiphy paths in drv_add_interface() and
drv_remove_interface() in driver-ops.c, so the check is race-free
against driver add/remove. Returning -ENETDOWN is the same error other
not-running paths use and does not introduce new locking.
Reported-by: syzbot+af177aa139efdd13a9da@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=af177aa139efdd13a9da
Link: https://lore.kernel.org/all/6a75205c.59b6c763.2bba34.00c3.GAE@google.com/
Fixes: 554a43d5e77e ("mac80211: check sdata_running on ieee80211_set_bitrate_mask")
Cc: stable@vger.kernel.org
Assisted-by: Hermes:muse-spark-1.2 syzkaller
Signed-off-by: Rik van Riel <riel@surriel.com>
Link: https://patch.msgid.link/20260808104755.319c686e@fangorn
Reported-by: syzbot+dcaca020ca8377e7ced0@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dcaca020ca8377e7ced0
[also add second syzbot report]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mac80211/cfg.c | 3 +++
1 file changed, 3 insertions(+)
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -3738,6 +3738,9 @@ static int ieee80211_set_bitrate_mask(st
if (!ieee80211_sdata_running(sdata))
return -ENETDOWN;
+ if (!(sdata->flags & IEEE80211_SDATA_IN_DRIVER))
+ return -ENETDOWN;
+
/*
* If active validate the setting and reject it if it doesn't leave
* at least one basic rate usable, since we really have to be able
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 391/438] wifi: p54: validate curve data length in the calibration curve converters
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (389 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 390/438] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 392/438] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST Greg Kroah-Hartman
` (58 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shengzhuo Wei, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit ce858fa6b8a214dee5adb82358885fa024cdd887 upstream.
p54_convert_rev0() and p54_convert_rev1() read calibration curve
data from the device-supplied EEPROM entry using channel and
points-per-channel counts taken verbatim from that same entry, so
an entry that declares more data than it carries drives an
out-of-bounds read past the EEPROM buffer (verified with a KASAN
reproducer of the conversion loop). The sibling converters
p54_convert_output_limits() and p54_convert_db() already validate
their counts against the entry length; this path was missed.
Reject the entry when the counts do not fit in the entry data.
Fixes: eff1a59c48e3 ("[P54]: add mac80211-based driver for prism54 softmac hardware")
Cc: stable@vger.kernel.org
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Link: https://patch.msgid.link/20260831-p54-pda-validation-v2-1-dae566b388c8@cherr.cc
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intersil/p54/eeprom.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
--- a/drivers/net/wireless/intersil/p54/eeprom.c
+++ b/drivers/net/wireless/intersil/p54/eeprom.c
@@ -414,17 +414,22 @@ free:
}
static int p54_convert_rev0(struct ieee80211_hw *dev,
- struct pda_pa_curve_data *curve_data)
+ struct pda_pa_curve_data *curve_data, size_t len)
{
struct p54_common *priv = dev->priv;
struct p54_pa_curve_data_sample *dst;
struct pda_pa_curve_data_sample_rev0 *src;
+ size_t needed = curve_data->channels *
+ (sizeof(*src) * curve_data->points_per_channel + 2);
size_t cd_len = sizeof(*curve_data) +
(curve_data->points_per_channel*sizeof(*dst) + 2) *
curve_data->channels;
unsigned int i, j;
void *source, *target;
+ if (len < sizeof(*curve_data) + needed)
+ return -EINVAL;
+
priv->curve_data = kmalloc(sizeof(*priv->curve_data) + cd_len,
GFP_KERNEL);
if (!priv->curve_data)
@@ -466,17 +471,22 @@ static int p54_convert_rev0(struct ieee8
}
static int p54_convert_rev1(struct ieee80211_hw *dev,
- struct pda_pa_curve_data *curve_data)
+ struct pda_pa_curve_data *curve_data, size_t len)
{
struct p54_common *priv = dev->priv;
struct p54_pa_curve_data_sample *dst;
struct pda_pa_curve_data_sample_rev1 *src;
+ size_t needed = curve_data->channels *
+ (sizeof(*src) * curve_data->points_per_channel + 3);
size_t cd_len = sizeof(*curve_data) +
(curve_data->points_per_channel*sizeof(*dst) + 2) *
curve_data->channels;
unsigned int i, j;
void *source, *target;
+ if (len < sizeof(*curve_data) + needed)
+ return -EINVAL;
+
priv->curve_data = kzalloc(cd_len + sizeof(*priv->curve_data),
GFP_KERNEL);
if (!priv->curve_data)
@@ -763,6 +773,7 @@ int p54_parse_eeprom(struct ieee80211_hw
case PDR_PRISM_PA_CAL_CURVE_DATA: {
struct pda_pa_curve_data *curve_data =
(struct pda_pa_curve_data *)entry->data;
+
if (data_len < sizeof(*curve_data)) {
err = -EINVAL;
goto err;
@@ -770,10 +781,10 @@ int p54_parse_eeprom(struct ieee80211_hw
switch (curve_data->cal_method_rev) {
case 0:
- err = p54_convert_rev0(dev, curve_data);
+ err = p54_convert_rev0(dev, curve_data, data_len);
break;
case 1:
- err = p54_convert_rev1(dev, curve_data);
+ err = p54_convert_rev1(dev, curve_data, data_len);
break;
default:
wiphy_err(dev->wiphy,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 338/398] drm/gud: fix out-of-bounds write in gud_plane_atomic_check()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (334 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 337/398] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 339/398] drm/gud: Ignore damage clips in full update mode Greg Kroah-Hartman
` (66 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sajal Gupta, Ruben Wauters
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sajal Gupta <sajal2005gupta@gmail.com>
commit 59ced288fcba9e91bd38e61a972ad782c4edb7d0 upstream.
The plane property loop uses req->properties[num_properties + i] as write
index while simultaneously incrementing `num_properties` inside the loop.
At iteration i, num_properties has also incremented by i, so the write
is done at `initial_num_properties + 2*i`, skipping every other index and
advancing by 2 per iteration.
With just 2 connector and 32 plane properties the last write happens at
index 64, one slot past the end of the 64-slot (indices 0–63)
allocation. A USB device can trigger OOB by advertising the maximum
number of properties.
Fix by dropping the redundant `+ i`; num_properties is already the correct
running index, as gud_connector_fill_properties() fills the preceding
slots.
Fixes: 40e1a70b4aed ("drm: Add GUD USB Display driver")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260821071812.16500-1-sajal2005gupta%40gmail.com?part=1
Signed-off-by: Sajal Gupta <sajal2005gupta@gmail.com>
Cc: <stable@vger.kernel.org>
Acked-by: Ruben Wauters <rubenru09@aol.com>
Signed-off-by: Ruben Wauters <rubenru09@aol.com>
Link: https://patch.msgid.link/20260902123254.36987-1-sajal2005gupta@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/gud/gud_pipe.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/gud/gud_pipe.c
+++ b/drivers/gpu/drm/gud/gud_pipe.c
@@ -562,8 +562,8 @@ int gud_plane_atomic_check(struct drm_pl
goto out;
}
- req->properties[num_properties + i].prop = cpu_to_le16(prop);
- req->properties[num_properties + i].val = cpu_to_le64(val);
+ req->properties[num_properties].prop = cpu_to_le16(prop);
+ req->properties[num_properties].val = cpu_to_le64(val);
num_properties++;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 392/438] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (390 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 391/438] wifi: p54: validate curve data length in the calibration curve converters Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 393/438] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length Greg Kroah-Hartman
` (57 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Lamparter, Shengzhuo Wei,
Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengzhuo Wei <me@cherr.cc>
commit d8efd84f49379ed28624098821f80e992657d935 upstream.
The PDR_INTERFACE_LIST loop only checks that the record start is within
the entry before reading an entire struct exp_if from it. A truncated
trailing record makes the if_id/variant reads cross the entry boundary
into the heap beyond the EEPROM buffer (verified with a KASAN
reproducer of the loop). The variant also feeds the synth front-end
selection, so this is not only a leak.
Advance only while a full record still fits in the entry.
Fixes: eff1a59c48e3 ("[P54]: add mac80211-based driver for prism54 softmac hardware")
Cc: stable@vger.kernel.org
Acked-by: Christian Lamparter <chunkeey@gmail.com>
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Link: https://patch.msgid.link/20260831-p54-pda-validation-v2-2-dae566b388c8@cherr.cc
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intersil/p54/eeprom.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/net/wireless/intersil/p54/eeprom.c
+++ b/drivers/net/wireless/intersil/p54/eeprom.c
@@ -812,7 +812,8 @@ int p54_parse_eeprom(struct ieee80211_hw
break;
case PDR_INTERFACE_LIST:
tmp = entry->data;
- while ((u8 *)tmp < entry->data + data_len) {
+ while ((u8 *)tmp + sizeof(struct exp_if) <=
+ entry->data + data_len) {
struct exp_if *exp_if = tmp;
if (exp_if->if_id == cpu_to_le16(IF_ID_ISL39000))
synth = le16_to_cpu(exp_if->variant);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 339/398] drm/gud: Ignore damage clips in full update mode
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (335 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 338/398] drm/gud: fix out-of-bounds write in gud_plane_atomic_check() Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 340/398] drm/msm/adreno: fix autosuspend cleanup during teardown Greg Kroah-Hartman
` (65 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sophie D, Thomas Zimmermann,
Ruben Wauters
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sophie D <patches@scd31.com>
commit effce1cb87ee0d8b3a8cbe7722968f4ea7efd360 upstream.
When running in full update mode, previously small updates (such as
moving the mouse across the screen) would cause many full frames to be
generated. This would bog down the bus and lower the effective framerate
significantly - I was seeing a drop from 60 FPS to 2 FPS.
Set ignore_damage_clips in full update mode so the damage iterator
yields a single full-plane rectangle instead of one per clip.
Fixes: 73cfd166e045 ("drm/gud: Replace simple display pipe with DRM atomic helpers")
Cc: <stable@vger.kernel.org> # 6.18.x
Signed-off-by: Sophie D <patches@scd31.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Acked-by: Ruben Wauters <rubenru09@aol.com>
Signed-off-by: Ruben Wauters <rubenru09@aol.com>
Link: https://patch.msgid.link/20260910014910.8564-1-patches@scd31.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/gud/gud_pipe.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/gpu/drm/gud/gud_pipe.c b/drivers/gpu/drm/gud/gud_pipe.c
index 5ef887d8485a..3388fdc8ea7b 100644
--- a/drivers/gpu/drm/gud/gud_pipe.c
+++ b/drivers/gpu/drm/gud/gud_pipe.c
@@ -482,6 +482,9 @@ int gud_plane_atomic_check(struct drm_plane *plane,
if (!new_plane_state->visible)
return 0;
+ if (gdrm->flags & GUD_DISPLAY_FLAG_FULL_UPDATE)
+ new_plane_state->ignore_damage_clips = true;
+
if (old_plane_state->rotation != new_plane_state->rotation)
crtc_state->mode_changed = true;
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 7.2 393/438] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (391 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 392/438] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 394/438] wifi: mwifiex: validate scan response extents Greg Kroah-Hartman
` (56 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Doruk Tan Ozturk, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Doruk Tan Ozturk <doruk@0sec.ai>
commit e667aee1c192d67d27c803007bfa9c6e0873e959 upstream.
mwifiex_search_oui_in_ie() reads a pairwise-cipher (PTK) count from a
beacon/probe-response RSN or WPA information element and then walks that
many 4-byte OUIs, comparing each with memcmp(). The count comes straight
from the (attacker-supplied) IE and is never checked against the
element's own length, and the callers admit the element on element_id
alone (has_ieee_hdr() / has_vendor_hdr(), no length check). A crafted
RSN/WPA IE with a large pairwise count therefore makes the walk read up
to 255 * 4 bytes past the element -- an out-of-bounds read of the
kmemdup()'d beacon buffer, reachable from any AP whose beacon/probe
response is processed during scan-result parsing.
Pass the number of IE bytes available at the OUI list and bound the walk
to the element. Keep the length signed and reject a negative value
before any unsigned arithmetic, so a small or zero IE length cannot
underflow to a large size_t and defeat the bound.
Found by 0sec automated security-research tooling (https://0sec.ai).
Fixes: 5e6e3a92b9a4 ("wireless: mwifiex: initial commit for Marvell mwifiex driver")
Cc: stable@vger.kernel.org
Assisted-by: 0sec:multi-model
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
Link: https://patch.msgid.link/20260814134704.85902-1-doruk@0sec.ai
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/scan.c | 25 ++++++++++++++++++++++---
1 file changed, 22 insertions(+), 3 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/scan.c
+++ b/drivers/net/wireless/marvell/mwifiex/scan.c
@@ -104,12 +104,24 @@ has_vendor_hdr(struct ieee_types_vendor_
* a given oui in PTK.
*/
static u8
-mwifiex_search_oui_in_ie(struct ie_body *iebody, u8 *oui)
+mwifiex_search_oui_in_ie(struct ie_body *iebody, u8 *oui, int ie_len)
{
+ const size_t ptk_body_offset = offsetof(struct ie_body, ptk_body);
u8 count;
+ /* ie_len is the number of bytes available at iebody. Keep it signed
+ * and reject a negative (underflowed) length before the unsigned
+ * comparisons below, so a small or zero IE length cannot wrap.
+ */
+ if (ie_len < 0 || (size_t)ie_len < ptk_body_offset)
+ return MWIFIEX_OUI_NOT_PRESENT;
+
count = iebody->ptk_cnt[0];
+ /* Reject an OUI count whose list would run past the element. */
+ if (ptk_body_offset + count * sizeof(iebody->ptk_body) > (size_t)ie_len)
+ return MWIFIEX_OUI_NOT_PRESENT;
+
/* There could be multiple OUIs for PTK hence
1) Take the length.
2) Check all the OUIs for AES.
@@ -143,11 +155,14 @@ mwifiex_is_rsn_oui_present(struct mwifie
u8 ret = MWIFIEX_OUI_NOT_PRESENT;
if (has_ieee_hdr(bss_desc->bcn_rsn_ie, WLAN_EID_RSN)) {
+ int ie_len = (int)bss_desc->bcn_rsn_ie->ieee_hdr.len -
+ RSN_GTK_OUI_OFFSET;
+
iebody = (struct ie_body *)
(((u8 *) bss_desc->bcn_rsn_ie->data) +
RSN_GTK_OUI_OFFSET);
oui = &mwifiex_rsn_oui[cipher][0];
- ret = mwifiex_search_oui_in_ie(iebody, oui);
+ ret = mwifiex_search_oui_in_ie(iebody, oui, ie_len);
if (ret)
return ret;
}
@@ -169,10 +184,14 @@ mwifiex_is_wpa_oui_present(struct mwifie
u8 ret = MWIFIEX_OUI_NOT_PRESENT;
if (has_vendor_hdr(bss_desc->bcn_wpa_ie, WLAN_EID_VENDOR_SPECIFIC)) {
+ int ie_len = (int)bss_desc->bcn_wpa_ie->vend_hdr.len -
+ (int)sizeof(bss_desc->bcn_wpa_ie->vend_hdr.oui) -
+ WPA_GTK_OUI_OFFSET;
+
iebody = (struct ie_body *)((u8 *)bss_desc->bcn_wpa_ie->data +
WPA_GTK_OUI_OFFSET);
oui = &mwifiex_wpa_oui[cipher][0];
- ret = mwifiex_search_oui_in_ie(iebody, oui);
+ ret = mwifiex_search_oui_in_ie(iebody, oui, ie_len);
if (ret)
return ret;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 340/398] drm/msm/adreno: fix autosuspend cleanup during teardown
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (336 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 339/398] drm/gud: Ignore damage clips in full update mode Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 341/398] drm/msm/dpu: clear pending peripheral flush state Greg Kroah-Hartman
` (64 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Dmitry Baryshkov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit 6fbbf1e152f34ad3913e4a6476680aba672c5068 upstream.
adreno_gpu_init() calls pm_runtime_use_autosuspend(), but
adreno_gpu_cleanup() does not call the matching
pm_runtime_dont_use_autosuspend() during teardown.
If the autosuspend delay is set to a negative value while autosuspend
is enabled, the runtime PM core increments usage_count to prevent
runtime suspend. Without calling pm_runtime_dont_use_autosuspend()
during teardown, this reference is not dropped and usage_count remains
unbalanced.
The documentation for pm_runtime_use_autosuspend() also notes that it
is important to undo it with pm_runtime_dont_use_autosuspend() at
driver exit time, unless runtime PM was initially enabled with
devm_pm_runtime_enable().
Add the missing pm_runtime_dont_use_autosuspend() call to
adreno_gpu_cleanup().
This issue was found by manual code inspection.
Fixes: eeb754746b14 ("drm/msm/gpu: use pm-runtime")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/745110/
Link: https://lore.kernel.org/r/20260808131624.2854412-1-lgs201920130244@gmail.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/msm/adreno/adreno_gpu.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/gpu/drm/msm/adreno/adreno_gpu.c
+++ b/drivers/gpu/drm/msm/adreno/adreno_gpu.c
@@ -1245,6 +1245,8 @@ void adreno_gpu_cleanup(struct adreno_gp
for (i = 0; i < ARRAY_SIZE(adreno_gpu->info->fw); i++)
release_firmware(adreno_gpu->fw[i]);
+ pm_runtime_dont_use_autosuspend(&gpu->pdev->dev);
+
if (priv && pm_runtime_enabled(&priv->gpu_pdev->dev))
pm_runtime_disable(&priv->gpu_pdev->dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 394/438] wifi: mwifiex: validate scan response extents
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (392 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 393/438] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 395/438] wifi: mwifiex: prevent authentication frame length truncation Greg Kroah-Hartman
` (55 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
commit 3687d7d48070838cc2953431b3a27717cab0aaf6 upstream.
mwifiex_ret_802_11_scan() subtracts the fixed response fields and the
firmware-provided BSS length from resp->size without first proving that
either extent fits. A short response or oversized BSS length can
therefore underflow tlv_buf_size and make the TLV parser walk beyond the
command response.
Compute the fixed extent from the selected normal or background scan
response. Validate that the fixed fields and BSS data fit before deriving
the TLV extent and entering the parser.
Fixes: 5e6e3a92b9a4 ("wireless: mwifiex: initial commit for Marvell mwifiex driver")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260815135227.50392-1-pengpeng@iscas.ac.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/scan.c | 29 ++++++++++++++++++----------
1 file changed, 19 insertions(+), 10 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/scan.c
+++ b/drivers/net/wireless/marvell/mwifiex/scan.c
@@ -2115,6 +2115,7 @@ int mwifiex_ret_802_11_scan(struct mwifi
u32 bytes_left;
u32 idx;
u32 tlv_buf_size;
+ size_t fixed_size;
struct mwifiex_ie_types_chan_band_list_param_set *chan_band_tlv;
struct chan_band_param_set *chan_band;
u8 is_bgscan_resp;
@@ -2130,6 +2131,14 @@ int mwifiex_ret_802_11_scan(struct mwifi
else
scan_rsp = &resp->params.scan_resp;
+ scan_resp_size = le16_to_cpu(resp->size);
+ fixed_size = scan_rsp->bss_desc_and_tlv_buffer - (u8 *)resp;
+ if (scan_resp_size < fixed_size) {
+ mwifiex_dbg(adapter, ERROR,
+ "SCAN_RESP: response is too short\n");
+ ret = -1;
+ goto check_next_scan;
+ }
if (scan_rsp->number_of_sets > MWIFIEX_MAX_AP) {
mwifiex_dbg(adapter, ERROR,
@@ -2147,8 +2156,6 @@ int mwifiex_ret_802_11_scan(struct mwifi
"info: SCAN_RESP: bss_descript_size %d\n",
bytes_left);
- scan_resp_size = le16_to_cpu(resp->size);
-
mwifiex_dbg(adapter, INFO,
"info: SCAN_RESP: returned %d APs before parsing\n",
scan_rsp->number_of_sets);
@@ -2156,15 +2163,17 @@ int mwifiex_ret_802_11_scan(struct mwifi
bss_info = scan_rsp->bss_desc_and_tlv_buffer;
/*
- * The size of the TLV buffer is equal to the entire command response
- * size (scan_resp_size) minus the fixed fields (sizeof()'s), the
- * BSS Descriptions (bss_descript_size as bytesLef) and the command
- * response header (S_DS_GEN)
+ * The TLV buffer follows the command-specific fixed fields and the BSS
+ * descriptions. Background-scan responses have an additional fixed
+ * field before scan_rsp, which is included in fixed_size.
*/
- tlv_buf_size = scan_resp_size - (bytes_left
- + sizeof(scan_rsp->bss_descript_size)
- + sizeof(scan_rsp->number_of_sets)
- + S_DS_GEN);
+ if (bytes_left > scan_resp_size - fixed_size) {
+ mwifiex_dbg(adapter, ERROR,
+ "SCAN_RESP: BSS data exceeds response\n");
+ ret = -1;
+ goto check_next_scan;
+ }
+ tlv_buf_size = scan_resp_size - fixed_size - bytes_left;
tlv_data = (struct mwifiex_ie_types_data *) (scan_rsp->
bss_desc_and_tlv_buffer +
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 341/398] drm/msm/dpu: clear pending peripheral flush state
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (337 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 340/398] drm/msm/adreno: fix autosuspend cleanup during teardown Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 342/398] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure Greg Kroah-Hartman
` (63 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Saim Shujah, Dmitry Baryshkov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Saim Shujah <saimzst@gmail.com>
commit a5b5cc909931572aec446e129c035b76b3f0c1fa upstream.
dpu_hw_ctl_clear_pending_flush() resets the cached per-block state after a
flush transaction, but misses pending_periph_flush_mask.
The peripheral flush updater accumulates interface bits in this mask. A
later transaction which sets the top-level peripheral flush bit can write
stale interface bits to CTL_PERIPH_FLUSH together with the current state.
Peripheral flush support was added after the helper started clearing every
individual pending flush mask. Clear the peripheral mask together with the
other cached child masks.
Fixes: 64f7b81f0358 ("drm/msm/dpu: add support of new peripheral flush mechanism")
Cc: stable@vger.kernel.org
Signed-off-by: Saim Shujah <saimzst@gmail.com>
Patchwork: https://patchwork.freedesktop.org/patch/748968/
Link: https://lore.kernel.org/r/20260828065440.140410-1-saimzst@gmail.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/msm/disp/dpu1/dpu_hw_ctl.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/gpu/drm/msm/disp/dpu1/dpu_hw_ctl.c
+++ b/drivers/gpu/drm/msm/disp/dpu1/dpu_hw_ctl.c
@@ -118,6 +118,7 @@ static inline void dpu_hw_ctl_clear_pend
ctx->pending_intf_flush_mask = 0;
ctx->pending_wb_flush_mask = 0;
ctx->pending_cwb_flush_mask = 0;
+ ctx->pending_periph_flush_mask = 0;
ctx->pending_merge_3d_flush_mask = 0;
ctx->pending_dsc_flush_mask = 0;
ctx->pending_cdm_flush_mask = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 395/438] wifi: mwifiex: prevent authentication frame length truncation
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (393 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 394/438] wifi: mwifiex: validate scan response extents Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 396/438] wifi: mwifiex: validate action frame fixed fields Greg Kroah-Hartman
` (54 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linmao Li, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linmao Li <lilinmao@kylinos.cn>
commit fa00193eb991f92b007aefe7afb6a7566976dacf upstream.
mwifiex_cfg80211_authenticate() derives the authentication frame length
from req->ie_len and req->auth_data_len, both of type size_t, but stores
it in a u16.
NL80211_ATTR_AUTH_DATA only has a minimum length policy. Since nla_len is
a u16, a single attribute can carry up to 65531 bytes of payload, so the
sum can exceed U16_MAX before it is assigned to pkt_len. The truncated
pkt_len determines the skb frame area, while the copy length remains
req->auth_data_len - 4, resulting in a heap buffer overflow.
For example, with auth_data_len equal to 65510 and no IEs, the sum is
65546. It is truncated to 10 and then reduced by four to 6. The driver
appends only six bytes to the skb with skb_put(), but then copies 65506
user-provided bytes into the authentication body.
Reaching this path requires CAP_NET_ADMIN in the user namespace owning
the network namespace, an up station netdev, and a suitable BSS/SAE
authentication request.
Compute the length in size_t, reject values that cannot be represented by
the firmware's u16 frame length field, and only then assign it to pkt_len.
Fixes: 36995892c271 ("wifi: mwifiex: add host mlme for client mode")
Cc: stable@vger.kernel.org # 6.12+
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Link: https://patch.msgid.link/20260820062155.3981976-1-lilinmao@kylinos.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/cfg80211.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/cfg80211.c
+++ b/drivers/net/wireless/marvell/mwifiex/cfg80211.c
@@ -4279,6 +4279,7 @@ mwifiex_cfg80211_authenticate(struct wip
struct mwifiex_adapter *adapter = priv->adapter;
struct sk_buff *skb;
u16 pkt_len, auth_alg;
+ size_t frame_len;
int ret;
struct mwifiex_ieee80211_mgmt *mgmt;
struct mwifiex_txinfo *tx_info;
@@ -4351,10 +4352,17 @@ mwifiex_cfg80211_authenticate(struct wip
mwifiex_cancel_scan(adapter);
- pkt_len = (u16)req->ie_len + req->auth_data_len +
+ frame_len = req->ie_len + req->auth_data_len +
MWIFIEX_MGMT_HEADER_LEN + MWIFIEX_AUTH_BODY_LEN;
if (req->auth_data_len >= 4)
- pkt_len -= 4;
+ frame_len -= 4;
+
+ if (frame_len > U16_MAX) {
+ mwifiex_dbg(priv->adapter, ERROR,
+ "auth frame too long: %zu bytes\n", frame_len);
+ return -EINVAL;
+ }
+ pkt_len = frame_len;
skb = dev_alloc_skb(MWIFIEX_MIN_DATA_HEADER_LEN +
MWIFIEX_MGMT_FRAME_HEADER_SIZE +
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 342/398] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (338 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 341/398] drm/msm/dpu: clear pending peripheral flush state Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 343/398] drm/msm: RCU-free the scheduler-containing ring and VM objects Greg Kroah-Hartman
` (62 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Krzysztof Kozlowski,
Dmitry Baryshkov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit f4fae975db08a9aeec0b15e145c7d4d0fe02a0ec upstream.
msm_hdmi_phy_probe() enables runtime PM before enabling the PHY
resources and initializing the PLL, but failures from either operation
return without calling the matching pm_runtime_disable().
The remove path disables runtime PM, but it is not called when probe
fails. As a result, runtime PM remains enabled after an unsuccessful
probe.
Route failures after pm_runtime_enable() through a common error path
and disable runtime PM before returning.
This issue was found by manual code inspection.
Fixes: 15b4a4523859 ("drm/msm/hdmi: Create a separate HDMI PHY driver")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/753043/
Link: https://lore.kernel.org/r/20260913085814.1509352-1-lgs201920130244@gmail.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/msm/hdmi/hdmi_phy.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/msm/hdmi/hdmi_phy.c
+++ b/drivers/gpu/drm/msm/hdmi/hdmi_phy.c
@@ -168,13 +168,13 @@ static int msm_hdmi_phy_probe(struct pla
ret = msm_hdmi_phy_resource_enable(phy);
if (ret)
- return ret;
+ goto err_pm_disable;
ret = msm_hdmi_phy_pll_init(pdev, phy->cfg->type);
if (ret) {
DRM_DEV_ERROR(dev, "couldn't init PLL\n");
msm_hdmi_phy_resource_disable(phy);
- return ret;
+ goto err_pm_disable;
}
msm_hdmi_phy_resource_disable(phy);
@@ -182,6 +182,10 @@ static int msm_hdmi_phy_probe(struct pla
platform_set_drvdata(pdev, phy);
return 0;
+
+err_pm_disable:
+ pm_runtime_disable(dev);
+ return ret;
}
static void msm_hdmi_phy_remove(struct platform_device *pdev)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 396/438] wifi: mwifiex: validate action frame fixed fields
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (394 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 395/438] wifi: mwifiex: prevent authentication frame length truncation Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 397/438] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver Greg Kroah-Hartman
` (53 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johannes Berg, Brian Norris, Zhao Li,
Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
commit 1c25bfad93e69ce13f744a2fb919f02ea396a985 upstream.
mwifiex_process_mgmt_packet() accepts an rx_pkt_length as small as a
four-address struct ieee80211_hdr plus the two-byte firmware length prefix.
After stripping the prefix, mwifiex_parse_mgmt_packet() can receive a
frame equal to sizeof(struct ieee80211_hdr).
For action frames, the parser reads the category byte immediately after
that header and, for a public action frame, reads the following action
code byte without verifying that either field is present. A truncated frame
can therefore make the parser consume up to two bytes past the
firmware-declared frame length. If those bytes look like a TDLS discovery
response, the malformed frame can spuriously update peer signal state.
Require the category and public action-code fields before reading them.
Use sizeof(*ieee_hdr) so the checks and field accesses directly match the
firmware four-address layout being parsed before address4 is removed.
Suggested-by: Johannes Berg <johannes@sipsolutions.net>
Suggested-by: Brian Norris <briannorris@chromium.org>
Fixes: 72e5aa8d2a6d ("mwifiex: support for parsing TDLS discovery frames")
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/all/66f148d83eb9f0970b9abbccc85d1b61244e54ad.camel@sipsolutions.net/
Link: https://lore.kernel.org/all/20260708195911.84365-8-enderaoelyther@gmail.com/
Link: https://lore.kernel.org/all/20260723011013.76968-1-enderaoelyther@gmail.com/
Link: https://lore.kernel.org/all/20260723202257.688-1-enderaoelyther@gmail.com/
Link: https://lore.kernel.org/all/anuWyiPQja6_5vly@google.com/
Assisted-by: Codex:gpt-5
Assisted-by: Kimi:K3
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260825112523.95774-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/marvell/mwifiex/util.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
--- a/drivers/net/wireless/marvell/mwifiex/util.c
+++ b/drivers/net/wireless/marvell/mwifiex/util.c
@@ -317,10 +317,16 @@ mwifiex_parse_mgmt_packet(struct mwifiex
switch (stype) {
case IEEE80211_STYPE_ACTION:
- category = *(payload + sizeof(struct ieee80211_hdr));
+ if (len < sizeof(*ieee_hdr) + 1)
+ return -1;
+
+ category = *(payload + sizeof(*ieee_hdr));
switch (category) {
case WLAN_CATEGORY_PUBLIC:
- action_code = *(payload + sizeof(struct ieee80211_hdr)
+ if (len < sizeof(*ieee_hdr) + 2)
+ return -1;
+
+ action_code = *(payload + sizeof(*ieee_hdr)
+ 1);
if (action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) {
addr2 = ieee_hdr->addr2;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 343/398] drm/msm: RCU-free the scheduler-containing ring and VM objects
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (339 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 342/398] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 344/398] drm/amdgpu: fix rmmio iounmap skipped on device removal Greg Kroah-Hartman
` (61 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jonghyuk Kim(MalHyuk), Rob Clark
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
commit 01c8d1f385f788f1bbbbb7687c4386d614281218 upstream.
Both struct msm_ringbuffer and struct msm_gem_vm embed a struct
drm_gpu_scheduler. msm_ringbuffer_destroy() and the VM free callback
msm_gem_vm_free() call drm_sched_fini() on the embedded scheduler and then
free the containing object with plain kfree().
drm_sched_fence_get_timeline_name() returns fence->sched->name, and the
scheduler fence keeps a .release callback so it is not ops-detached on
signalling. A finished fence exported to userspace (the submit out-fence, or
a VM_BIND fence, via sync_file / drm_syncobj) keeps pointing at the embedded
scheduler after the ring/VM is freed, so a later get_timeline_name() --
reachable unprivileged through SYNC_IOC_FILE_INFO -- dereferences freed slab
memory (KASAN slab-use-after-free read).
Per the dma-fence lifetime contract the exporter must keep the data backing a
signalled fence alive for an RCU grace period. Free the scheduler-containing
objects with kfree_rcu() instead of kfree().
Fixes: 1d8a5ca436ee ("drm/msm: Conversion to drm scheduler")
Fixes: 92395af63a99 ("drm/msm: Add VM_BIND submitqueue")
Cc: stable@vger.kernel.org
Signed-off-by: Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
Patchwork: https://patchwork.freedesktop.org/patch/750234/
Message-ID: <20260902012720.880783-1-malhyuk97@gmail.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/msm/msm_gem.h | 3 +++
drivers/gpu/drm/msm/msm_gem_vma.c | 2 +-
drivers/gpu/drm/msm/msm_ringbuffer.c | 2 +-
drivers/gpu/drm/msm/msm_ringbuffer.h | 1 +
4 files changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/msm/msm_gem.h
+++ b/drivers/gpu/drm/msm/msm_gem.h
@@ -68,6 +68,9 @@ struct msm_gem_vm {
/** @base: Inherit from drm_gpuvm. */
struct drm_gpuvm base;
+ /** @rcu: RCU-delayed free so an exported sched fence->sched stays valid. */
+ struct rcu_head rcu;
+
/**
* @sched: Scheduler used for asynchronous VM_BIND request.
*
--- a/drivers/gpu/drm/msm/msm_gem_vma.c
+++ b/drivers/gpu/drm/msm/msm_gem_vma.c
@@ -166,7 +166,7 @@ msm_gem_vm_free(struct drm_gpuvm *gpuvm)
dma_fence_put(vm->last_fence);
put_pid(vm->pid);
kfree(vm->log);
- kfree(vm);
+ kfree_rcu(vm, rcu);
}
/**
--- a/drivers/gpu/drm/msm/msm_ringbuffer.c
+++ b/drivers/gpu/drm/msm/msm_ringbuffer.c
@@ -140,5 +140,5 @@ void msm_ringbuffer_destroy(struct msm_r
msm_gem_kernel_put(ring->bo, ring->gpu->vm);
- kfree(ring);
+ kfree_rcu(ring, rcu);
}
--- a/drivers/gpu/drm/msm/msm_ringbuffer.h
+++ b/drivers/gpu/drm/msm/msm_ringbuffer.h
@@ -53,6 +53,7 @@ struct msm_ringbuffer {
/*
* The job scheduler for this ring.
*/
+ struct rcu_head rcu;
struct drm_gpu_scheduler sched;
bool sched_initialized;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 397/438] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (395 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 396/438] wifi: mwifiex: validate action frame fixed fields Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 398/438] wifi: mac80211: avoid out-of-bounds read for empty PREQ elements Greg Kroah-Hartman
` (52 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+af177aa139efdd13a9da,
Rik van Riel, syzbot+dcaca020ca8377e7ced0, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rik van Riel <riel@surriel.com>
commit da2ca406f45a6e21760243152ed8d2e8e72915c2 upstream.
ieee80211_set_bitrate_mask() checks if the interface is running via
ieee80211_sdata_running(), but it does not check if the interface is
still present in the driver.
When sdata is running but IEEE80211_SDATA_IN_DRIVER is not set, the
call reaches drv_set_bitrate_mask() in driver-ops.h which hits
wlan1: Failed check-sdata-in-driver check, flags: 0x0
WARNING: net/mac80211/driver-ops.h:884 at drv_set_bitrate_mask
Syzkaller triggers this via wext SIOCSIWRATE ioctl. The Call Trace shows
wext_ioctl_dispatch() in wext-core.c dispatching the ioctl, calling
ioctl_standard_call() for SIOCSIWRATE, which calls cfg80211_wext_siwrate()
in wext-compat.c. That builds a bitrate mask and calls
rdev_set_bitrate_mask() which ends up in ieee80211_set_bitrate_mask() in
cfg.c. The interface is marked running via SDATA_STATE_RUNNING but
flags is 0, so check_sdata_in_driver() fails.
When the interface is being torn down, or when wext ioctl is issued
during interface bringup before drv_add_interface() sets IN_DRIVER, the
running check passes while IN_DRIVER is clear.
Check IEEE80211_SDATA_IN_DRIVER in ieee80211_set_bitrate_mask() before
calling the driver, returning -ENETDOWN. This avoids the WARN_ONCE in
driver-ops.h and matches other cfg.c operations that bail early when not
in driver.
This change should be safe because wiphy mutex is held in
cfg80211_wext_siwrate() via guard(wiphy), and IN_DRIVER is set/cleared
under RTNL and wiphy paths in drv_add_interface() and
drv_remove_interface() in driver-ops.c, so the check is race-free
against driver add/remove. Returning -ENETDOWN is the same error other
not-running paths use and does not introduce new locking.
Reported-by: syzbot+af177aa139efdd13a9da@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=af177aa139efdd13a9da
Link: https://lore.kernel.org/all/6a75205c.59b6c763.2bba34.00c3.GAE@google.com/
Fixes: 554a43d5e77e ("mac80211: check sdata_running on ieee80211_set_bitrate_mask")
Cc: stable@vger.kernel.org
Assisted-by: Hermes:muse-spark-1.2 syzkaller
Signed-off-by: Rik van Riel <riel@surriel.com>
Link: https://patch.msgid.link/20260808104755.319c686e@fangorn
Reported-by: syzbot+dcaca020ca8377e7ced0@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dcaca020ca8377e7ced0
[also add second syzbot report]
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mac80211/cfg.c | 3 +++
1 file changed, 3 insertions(+)
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -4120,6 +4120,9 @@ static int ieee80211_set_bitrate_mask(st
if (!ieee80211_sdata_running(sdata))
return -ENETDOWN;
+ if (!(sdata->flags & IEEE80211_SDATA_IN_DRIVER))
+ return -ENETDOWN;
+
/*
* If active validate the setting and reject it if it doesn't leave
* at least one basic rate usable, since we really have to be able
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 344/398] drm/amdgpu: fix rmmio iounmap skipped on device removal
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (340 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 343/398] drm/msm: RCU-free the scheduler-containing ring and VM objects Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 345/398] smb: client: cancel reconnect work in clean_demultiplex_info() Greg Kroah-Hartman
` (60 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chengjun Yao, Asad Kamal,
Alex Deucher
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengjun Yao <Chengjun.Yao@amd.com>
commit 5155002b03b24ba3ef91c5c313b8cf0171b24904 upstream.
amdgpu_pci_remove() calls drm_dev_unplug() before fini_sw(), so
drm_dev_enter() is already false there and the iounmap() guarded by it
is skipped. This .remove path runs on both hot-unplug and plain rmmod,
so the register BAR ioremap mapping leaks one instance per unload.
Unmap rmmio unconditionally (guard only on non-NULL) and drop the now
unused idx.
Fixes: 62d5f9f7110a ("drm/amdgpu: Unmap MMIO mappings when device is not unplugged")
Signed-off-by: Chengjun Yao <Chengjun.Yao@amd.com>
Reviewed-by: Asad Kamal <asad.kamal@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit dd6f86a97260e5207d3329ad03aa89fdad61b1e6)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_device.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -5098,7 +5098,7 @@ void amdgpu_device_fini_hw(struct amdgpu
void amdgpu_device_fini_sw(struct amdgpu_device *adev)
{
- int i, idx;
+ int i;
bool px;
amdgpu_device_ip_fini(adev);
@@ -5140,11 +5140,9 @@ void amdgpu_device_fini_sw(struct amdgpu
if ((adev->pdev->class >> 8) == PCI_CLASS_DISPLAY_VGA)
vga_client_unregister(adev->pdev);
- if (drm_dev_enter(adev_to_drm(adev), &idx)) {
-
+ if (adev->rmmio) {
iounmap(adev->rmmio);
adev->rmmio = NULL;
- drm_dev_exit(idx);
}
if (IS_ENABLED(CONFIG_PERF_EVENTS))
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 398/438] wifi: mac80211: avoid out-of-bounds read for empty PREQ elements
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (396 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 397/438] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 399/438] wifi: mac80211: refuse to make a monitor active when it has no queue Greg Kroah-Hartman
` (51 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ivan Pustogarov, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ivan Pustogarov <ivan@ipust.net>
commit e6031f02269c0f51cf67886d177f02bc300b47cd upstream.
ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom
fields before checking whether the element contains even the fixed
header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to
account for the optional Address Extension field. Consequently, an
empty PREQ element causes a one-byte read beyond its declared payload.
Move the helper call after both size checks, so the bottom fields are
only accessed when they are present.
Fixes: 8b40b1d24a60 ("wifi: mac80211: Fix overread in PREQ frame processing")
Cc: stable@vger.kernel.org
Signed-off-by: Ivan Pustogarov <ivan@ipust.net>
Link: https://patch.msgid.link/20260903152616.1646637-1-ivan@ipust.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/ieee80211-mesh.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/include/linux/ieee80211-mesh.h b/include/linux/ieee80211-mesh.h
index 7eb15834531c..9e548b9173df 100644
--- a/include/linux/ieee80211-mesh.h
+++ b/include/linux/ieee80211-mesh.h
@@ -361,8 +361,7 @@ ieee80211_mesh_hwmp_perr_get_rcode(const u8 *ie, u8 dst_idx)
/* IEEE Std 802.11-2016 9.4.2.113 PREQ element */
static inline bool ieee80211_mesh_preq_size_ok(const u8 *pos, u8 elen)
{
- struct ieee80211_mesh_hwmp_preq_bottom *preq_elem_bottom =
- ieee80211_mesh_hwmp_preq_get_bottom(pos);
+ struct ieee80211_mesh_hwmp_preq_bottom *preq_elem_bottom;
u8 target_count;
int needed;
@@ -378,6 +377,7 @@ static inline bool ieee80211_mesh_preq_size_ok(const u8 *pos, u8 elen)
if (elen < needed)
return false;
+ preq_elem_bottom = ieee80211_mesh_hwmp_preq_get_bottom(pos);
target_count = preq_elem_bottom->target_count;
/* IEEE Std 802.11-2016 Table 14-10 to 14-16 */
if (target_count < 1)
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* [PATCH 6.18 345/398] smb: client: cancel reconnect work in clean_demultiplex_info()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (341 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 344/398] drm/amdgpu: fix rmmio iounmap skipped on device removal Greg Kroah-Hartman
@ 2026-09-23 14:06 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 346/398] smb: client: fix rlist race and missing initialization Greg Kroah-Hartman
` (59 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:06 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+5003556314abc915a71f,
Namjae Jeon, Paulo Alcantara, David Howells, Shyam Prasad N,
Ronnie Sahlberg, Tom Talpey, Bharath SM
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paulo Alcantara <pc@manguebit.org>
commit c65eae6f61d1778ff7a82e4aae4080e26f486af1 upstream.
clean_demultiplex_info() cancels server->echo delayed work but not
server->reconnect, which can cause a use-after-free when the
demultiplex thread exits while a reconnect work is still queued:
cifs_demultiplex_thread()
cifs_readv_from_socket()
cifs_reconnect()
__cifs_reconnect()
cifs_queue_server_reconn()
mod_delayed_work(cifsiod_wq, &server->reconnect, 0)
clean_demultiplex_info()
cancel_delayed_work_sync(&server->echo) // echo canceled
// reconnect NOT canceled
kfree_sensitive(server) // server freed
...later, on cifsiod_wq:
smb2_reconnect_server()
server->srv_count // UAF read of freed server
Fix this by canceling server->reconnect delayed work in
clean_demultiplex_info() before the server is freed, the same way
cifs_put_tcp_session() already does.
Reported-by: syzbot+5003556314abc915a71f@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/r/6aa4a12d.f81106d8.2ab401.0023.GAE@google.com
Fixes: 53e0e11efe92 ("CIFS: Fix a possible memory corruption during reconnect")
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: David Howells <dhowells@redhat.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/connect.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/smb/client/connect.c
+++ b/fs/smb/client/connect.c
@@ -1064,6 +1064,7 @@ clean_demultiplex_info(struct TCP_Server
spin_unlock(&server->srv_lock);
cancel_delayed_work_sync(&server->echo);
+ cancel_delayed_work_sync(&server->reconnect);
spin_lock(&server->srv_lock);
server->tcpStatus = CifsExiting;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 399/438] wifi: mac80211: refuse to make a monitor active when it has no queue
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (397 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 7.2 398/438] wifi: mac80211: avoid out-of-bounds read for empty PREQ elements Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 400/438] drm/gud: fix out-of-bounds write in gud_plane_atomic_check() Greg Kroah-Hartman
` (50 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Devin Wittmayer, Johannes Berg
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Devin Wittmayer <lucid_duck@justthetip.ca>
commit 2b04d6556964ae9f89819b86a0a7801e39c3aae5 upstream.
A monitor interface only gets a TXQ if it's created active, and one can't
be added later. Setting the flag on a down interface is still allowed, so
the driver is handed a monitor with no queue. ath9k dereferences it:
BUG: kernel NULL pointer dereference, address: 0000000000000066
RIP: 0010:ath_tx_node_init+0x49/0x170 [ath9k]
ath9k_add_interface+0x10c/0x140 [ath9k]
drv_add_interface+0x54/0x250 [mac80211]
ieee80211_do_open+0x32f/0x800 [mac80211]
Reached with CAP_NET_ADMIN by "iw dev X set monitor active" followed by
"ip link set X up". RTNL is held, so netlink operations block behind it.
Refuse the flag when there is no queue to give.
Fixes: 79af1f866193 ("mac80211: avoid allocating TXQs that won't be used")
Cc: stable@vger.kernel.org
Signed-off-by: Devin Wittmayer <lucid_duck@justthetip.ca>
Link: https://patch.msgid.link/20260904200338.10829-1-lucid_duck@justthetip.ca
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mac80211/cfg.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -115,6 +115,10 @@ static int ieee80211_set_mon_options(str
return -EBUSY;
}
+ /* TXQs are reserved in ieee80211_if_add() and cannot be added later */
+ if ((params->flags & MONITOR_FLAG_ACTIVE) && !sdata->vif.txq)
+ return -EOPNOTSUPP;
+
/* validate whether MU-MIMO can be configured */
if (!ieee80211_hw_check(&local->hw, WANT_MONITOR_VIF) &&
!ieee80211_hw_check(&local->hw, NO_VIRTUAL_MONITOR) &&
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 346/398] smb: client: fix rlist race and missing initialization
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (342 preceding siblings ...)
2026-09-23 14:06 ` [PATCH 6.18 345/398] smb: client: cancel reconnect work in clean_demultiplex_info() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 347/398] smb: client: fix use-after-free of iface in cifs_try_adding_channels() Greg Kroah-Hartman
` (58 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Paulo Alcantara,
David Howells, Shyam Prasad N, Ronnie Sahlberg, Tom Talpey,
Bharath SM
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paulo Alcantara <pc@manguebit.org>
commit 5f270f091256da1338c3631083e15d7f83cc05e1 upstream.
TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next
and ->prev to NULL instead of pointing to itself, making list_empty()
always return false and list_add() dereference a NULL ->prev pointer.
Also, cifs_signal_cifsd_for_reconnect() can be called concurrently
from multiple cifsd threads, allowing the same server's rlist node to
be added twice into the local list, corrupting it.
Closes: https://sashiko.dev/#/patchset/20260911204446.1719356-1-pc%40manguebit.org
Fixes: df0e03a4fb94 ("smb: client: fix potential deadlock when reconnecting channels")
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: David Howells <dhowells@redhat.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/connect.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/fs/smb/client/connect.c
+++ b/fs/smb/client/connect.c
@@ -171,6 +171,8 @@ cifs_signal_cifsd_for_reconnect(struct T
nserver = ses->chans[i].server;
if (!nserver)
continue;
+ if (!list_empty(&nserver->rlist))
+ continue;
nserver->srv_count++;
list_add(&nserver->rlist, &reco);
}
@@ -179,11 +181,15 @@ cifs_signal_cifsd_for_reconnect(struct T
}
}
+ spin_lock(&cifs_tcp_ses_lock);
list_for_each_entry_safe(server, nserver, &reco, rlist) {
list_del_init(&server->rlist);
set_need_reco(server);
+ spin_unlock(&cifs_tcp_ses_lock);
cifs_put_tcp_session(server, 0);
+ spin_lock(&cifs_tcp_ses_lock);
}
+ spin_unlock(&cifs_tcp_ses_lock);
}
/*
@@ -1823,6 +1829,7 @@ cifs_get_tcp_session(struct smb3_fs_cont
spin_lock_init(&tcp_ses->mid_counter_lock);
INIT_LIST_HEAD(&tcp_ses->tcp_ses_list);
INIT_LIST_HEAD(&tcp_ses->smb_ses_list);
+ INIT_LIST_HEAD(&tcp_ses->rlist);
INIT_DELAYED_WORK(&tcp_ses->echo, cifs_echo_request);
INIT_DELAYED_WORK(&tcp_ses->reconnect, smb2_reconnect_server);
mutex_init(&tcp_ses->reconnect_mutex);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 400/438] drm/gud: fix out-of-bounds write in gud_plane_atomic_check()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (398 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 399/438] wifi: mac80211: refuse to make a monitor active when it has no queue Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 401/438] drm/gud: Ignore damage clips in full update mode Greg Kroah-Hartman
` (49 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sajal Gupta, Ruben Wauters
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sajal Gupta <sajal2005gupta@gmail.com>
commit 59ced288fcba9e91bd38e61a972ad782c4edb7d0 upstream.
The plane property loop uses req->properties[num_properties + i] as write
index while simultaneously incrementing `num_properties` inside the loop.
At iteration i, num_properties has also incremented by i, so the write
is done at `initial_num_properties + 2*i`, skipping every other index and
advancing by 2 per iteration.
With just 2 connector and 32 plane properties the last write happens at
index 64, one slot past the end of the 64-slot (indices 0–63)
allocation. A USB device can trigger OOB by advertising the maximum
number of properties.
Fix by dropping the redundant `+ i`; num_properties is already the correct
running index, as gud_connector_fill_properties() fills the preceding
slots.
Fixes: 40e1a70b4aed ("drm: Add GUD USB Display driver")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260821071812.16500-1-sajal2005gupta%40gmail.com?part=1
Signed-off-by: Sajal Gupta <sajal2005gupta@gmail.com>
Cc: <stable@vger.kernel.org>
Acked-by: Ruben Wauters <rubenru09@aol.com>
Signed-off-by: Ruben Wauters <rubenru09@aol.com>
Link: https://patch.msgid.link/20260902123254.36987-1-sajal2005gupta@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/gud/gud_pipe.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/gud/gud_pipe.c
+++ b/drivers/gpu/drm/gud/gud_pipe.c
@@ -562,8 +562,8 @@ int gud_plane_atomic_check(struct drm_pl
goto out;
}
- req->properties[num_properties + i].prop = cpu_to_le16(prop);
- req->properties[num_properties + i].val = cpu_to_le64(val);
+ req->properties[num_properties].prop = cpu_to_le16(prop);
+ req->properties[num_properties].val = cpu_to_le64(val);
num_properties++;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 347/398] smb: client: fix use-after-free of iface in cifs_try_adding_channels()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (343 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 346/398] smb: client: fix rlist race and missing initialization Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 348/398] smb: client: reject short Next offsets in parse_server_interfaces() Greg Kroah-Hartman
` (57 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joseph Qi, Shyam Prasad N,
Paulo Alcantara
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joseph Qi <joseph.qi@linux.alibaba.com>
commit d034e836eefd7ce75e588f7031cffbeec594f5ac upstream.
cifs_try_adding_channels() iterates ses->iface_list with
list_for_each_entry_safe_from(), which captures the next entry
(niface) under iface_lock. The loop body then drops iface_lock for
the whole duration of cifs_ses_add_channel().
A concurrent interface refresh (SMB3_request_interfaces() ->
parse_server_interfaces()) marks all ifaces inactive and removes and
frees any that are not re-advertised via list_del() + kref_put(),
where release_iface() is a bare kfree(). Since niface typically has
no channel holding a reference, the list reference is its last and it
can be freed inside the unlocked window. On continue, the iterator
advance step then dereferences niface->iface_head.next, and the loop
body reads iface->rdma_capable/is_active, both on freed memory.
Fix this by never keeping an unreferenced list pointer across the
unlocked window. Each channel attempt now re-scans the list from the
head under iface_lock, takes a kref on the selected candidate, and
passes only that referenced candidate to cifs_ses_add_channel().
weight_fulfilled still tracks selection progress, so restarting the
scan preserves the original weighted distribution and the
weight_fulfilled-before-kref_put ordering on the failure path.
Add a per-pass attempts cap so a flapping interface refresh cannot
keep the inner loop spinning within a single tries increment.
Fixes: aa45dadd34e4 ("cifs: change iface_list from array to sorted linked list")
Cc: stable@vger.kernel.org
Assisted-by: Qoder:Qwen3.8-Max
Signed-off-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Acked-by: Shyam Prasad N <sprasad@microsoft.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/sess.c | 106 ++++++++++++++++++++++++++++++---------------------
1 file changed, 64 insertions(+), 42 deletions(-)
--- a/fs/smb/client/sess.c
+++ b/fs/smb/client/sess.c
@@ -150,9 +150,9 @@ int cifs_try_adding_channels(struct cifs
int old_chan_count, new_chan_count;
int left;
int rc = 0;
- int tries = 0;
+ int tries = 0, attempts;
size_t iface_weight = 0, iface_min_speed = 0;
- struct cifs_server_iface *iface = NULL, *niface = NULL;
+ struct cifs_server_iface *iface = NULL, *candidate = NULL;
struct cifs_server_iface *last_iface = NULL;
spin_lock(&ses->chan_lock);
@@ -198,67 +198,89 @@ int cifs_try_adding_channels(struct cifs
break;
}
- if (!iface)
- iface = list_first_entry(&ses->iface_list, struct cifs_server_iface,
- iface_head);
last_iface = list_last_entry(&ses->iface_list, struct cifs_server_iface,
iface_head);
iface_min_speed = last_iface->speed;
+ spin_unlock(&ses->iface_lock);
- list_for_each_entry_safe_from(iface, niface, &ses->iface_list,
- iface_head) {
- /* do not mix rdma and non-rdma interfaces */
- if (iface->rdma_capable != ses->server->rdma)
- continue;
-
- /* skip ifaces that are unusable */
- if (!iface->is_active ||
- (is_ses_using_iface(ses, iface) &&
- !iface->rss_capable))
- continue;
+ attempts = 0;
+ while (left > 0) {
+ spin_lock(&ses->iface_lock);
- /* check if we already allocated enough channels */
- iface_weight = iface->speed / iface_min_speed;
+ /*
+ * iface_lock must be dropped while opening a channel,
+ * and a concurrent interface refresh may remove and
+ * free entries during that window, so no list entry
+ * may be kept across it without a reference. Scan
+ * the list from the beginning each time and only pass
+ * a referenced candidate to cifs_ses_add_channel();
+ * weight_fulfilled tracks the progress so that no
+ * iface is selected beyond its weight.
+ */
+ candidate = NULL;
+ list_for_each_entry(iface, &ses->iface_list, iface_head) {
+ /* do not mix rdma and non-rdma interfaces */
+ if (iface->rdma_capable != ses->server->rdma)
+ continue;
+
+ /* skip ifaces that are unusable */
+ if (!iface->is_active ||
+ (is_ses_using_iface(ses, iface) &&
+ !iface->rss_capable))
+ continue;
+
+ /* check if we already allocated enough channels */
+ iface_weight = iface->speed / iface_min_speed;
+
+ if (iface->weight_fulfilled >= iface_weight)
+ continue;
+
+ /* take ref before unlock */
+ kref_get(&iface->refcount);
+ candidate = iface;
+ break;
+ }
- if (iface->weight_fulfilled >= iface_weight)
- continue;
+ if (!candidate) {
+ /* no usable iface. reset weight_fulfilled and start over */
+ list_for_each_entry(iface, &ses->iface_list, iface_head)
+ iface->weight_fulfilled = 0;
+ spin_unlock(&ses->iface_lock);
+ break;
+ }
- /* take ref before unlock */
- kref_get(&iface->refcount);
+ attempts++;
+ if (attempts > 3 * ses->chan_max) {
+ kref_put(&candidate->refcount, release_iface);
+ spin_unlock(&ses->iface_lock);
+ break;
+ }
spin_unlock(&ses->iface_lock);
- rc = cifs_ses_add_channel(ses, iface);
+ rc = cifs_ses_add_channel(ses, candidate);
spin_lock(&ses->iface_lock);
if (rc) {
cifs_dbg(VFS, "failed to open extra channel on iface:%pIS rc=%d\n",
- &iface->sockaddr,
+ &candidate->sockaddr,
rc);
/* failure to add chan should increase weight */
- iface->weight_fulfilled++;
- kref_put(&iface->refcount, release_iface);
+ candidate->weight_fulfilled++;
+ kref_put(&candidate->refcount, release_iface);
+ spin_unlock(&ses->iface_lock);
continue;
}
- iface->num_channels++;
- iface->weight_fulfilled++;
+ candidate->num_channels++;
+ candidate->weight_fulfilled++;
cifs_info("successfully opened new channel on iface:%pIS\n",
- &iface->sockaddr);
- break;
- }
-
- /* reached end of list. reset weight_fulfilled and start over */
- if (list_entry_is_head(iface, &ses->iface_list, iface_head)) {
- list_for_each_entry(iface, &ses->iface_list, iface_head)
- iface->weight_fulfilled = 0;
+ &candidate->sockaddr);
spin_unlock(&ses->iface_lock);
- iface = NULL;
- continue;
- }
- spin_unlock(&ses->iface_lock);
- left--;
- new_chan_count++;
+ left--;
+ new_chan_count++;
+ break;
+ }
}
return new_chan_count - old_chan_count;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 401/438] drm/gud: Ignore damage clips in full update mode
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (399 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 400/438] drm/gud: fix out-of-bounds write in gud_plane_atomic_check() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 402/438] drm/msm/adreno: fix autosuspend cleanup during teardown Greg Kroah-Hartman
` (48 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sophie D, Thomas Zimmermann,
Ruben Wauters
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sophie D <patches@scd31.com>
commit effce1cb87ee0d8b3a8cbe7722968f4ea7efd360 upstream.
When running in full update mode, previously small updates (such as
moving the mouse across the screen) would cause many full frames to be
generated. This would bog down the bus and lower the effective framerate
significantly - I was seeing a drop from 60 FPS to 2 FPS.
Set ignore_damage_clips in full update mode so the damage iterator
yields a single full-plane rectangle instead of one per clip.
Fixes: 73cfd166e045 ("drm/gud: Replace simple display pipe with DRM atomic helpers")
Cc: <stable@vger.kernel.org> # 6.18.x
Signed-off-by: Sophie D <patches@scd31.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Acked-by: Ruben Wauters <rubenru09@aol.com>
Signed-off-by: Ruben Wauters <rubenru09@aol.com>
Link: https://patch.msgid.link/20260910014910.8564-1-patches@scd31.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/gud/gud_pipe.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/gpu/drm/gud/gud_pipe.c
+++ b/drivers/gpu/drm/gud/gud_pipe.c
@@ -482,6 +482,9 @@ int gud_plane_atomic_check(struct drm_pl
if (!new_plane_state->visible)
return 0;
+ if (gdrm->flags & GUD_DISPLAY_FLAG_FULL_UPDATE)
+ new_plane_state->ignore_damage_clips = true;
+
if (old_plane_state->rotation != new_plane_state->rotation)
crtc_state->mode_changed = true;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 348/398] smb: client: reject short Next offsets in parse_server_interfaces()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (344 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 347/398] smb: client: fix use-after-free of iface in cifs_try_adding_channels() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 349/398] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error Greg Kroah-Hartman
` (56 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit 1b3221bb121079ad79a1f3c3aa360ba649832e7a upstream.
In parse_server_interfaces(), the server-supplied Next offset is
validated against bytes_left, but not against the size of the interface
structure itself.
A small, non-zero Next value can pass the bounds check but advance the
pointer by less than sizeof(*p). This causes the next iteration of the
loop to read misaligned, overlapping structure fields.
Fix this by ensuring the Next offset is at least sizeof(*p).
Fixes: 7d34ec36abb8 ("smb3: fix for slab out of bounds on mount to ksmbd")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -786,9 +786,9 @@ next_iface:
break;
}
/* Validate that Next doesn't point beyond the buffer */
- if (next > bytes_left) {
- cifs_dbg(VFS, "%s: invalid Next pointer %zu > %zd\n",
- __func__, next, bytes_left);
+ if (next < sizeof(*p) || next > bytes_left) {
+ cifs_dbg(VFS, "%s: invalid Next pointer %zu out of range [%zu, %zd]\n",
+ __func__, next, sizeof(*p), bytes_left);
rc = -EINVAL;
goto out;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 402/438] drm/msm/adreno: fix autosuspend cleanup during teardown
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (400 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 401/438] drm/gud: Ignore damage clips in full update mode Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 403/438] drm/msm/dpu: clear pending peripheral flush state Greg Kroah-Hartman
` (47 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Dmitry Baryshkov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit 6fbbf1e152f34ad3913e4a6476680aba672c5068 upstream.
adreno_gpu_init() calls pm_runtime_use_autosuspend(), but
adreno_gpu_cleanup() does not call the matching
pm_runtime_dont_use_autosuspend() during teardown.
If the autosuspend delay is set to a negative value while autosuspend
is enabled, the runtime PM core increments usage_count to prevent
runtime suspend. Without calling pm_runtime_dont_use_autosuspend()
during teardown, this reference is not dropped and usage_count remains
unbalanced.
The documentation for pm_runtime_use_autosuspend() also notes that it
is important to undo it with pm_runtime_dont_use_autosuspend() at
driver exit time, unless runtime PM was initially enabled with
devm_pm_runtime_enable().
Add the missing pm_runtime_dont_use_autosuspend() call to
adreno_gpu_cleanup().
This issue was found by manual code inspection.
Fixes: eeb754746b14 ("drm/msm/gpu: use pm-runtime")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/745110/
Link: https://lore.kernel.org/r/20260808131624.2854412-1-lgs201920130244@gmail.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/msm/adreno/adreno_gpu.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/gpu/drm/msm/adreno/adreno_gpu.c
+++ b/drivers/gpu/drm/msm/adreno/adreno_gpu.c
@@ -1252,6 +1252,8 @@ void adreno_gpu_cleanup(struct adreno_gp
for (i = 0; i < ARRAY_SIZE(adreno_gpu->info->fw); i++)
release_firmware(adreno_gpu->fw[i]);
+ pm_runtime_dont_use_autosuspend(&gpu->pdev->dev);
+
if (priv && pm_runtime_enabled(&priv->gpu_pdev->dev))
pm_runtime_disable(&priv->gpu_pdev->dev);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 349/398] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (345 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 348/398] smb: client: reject short Next offsets in parse_server_interfaces() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 350/398] smb: client: fix unaligned access in WSL reparse point parser Greg Kroah-Hartman
` (55 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Paulo Alcantara,
Tom Talpey, Stefan Metzmacher, Shyam Prasad N, Ronnie Sahlberg,
Bharath SM
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paulo Alcantara <pc@manguebit.org>
commit e75c96157d45e498970158c8f7373d90102e33b9 upstream.
When an RDMA connection is successfully established via
smbd_get_connection() but cifs_get_tcp_session() later fails (e.g.
kthread_create() returns an error), the error path frees tcp_ses
without first destroying the smbd_connection.
Fix this by calling smbd_destroy() in the out_err cleanup path before
kfree(tcp_ses). smbd_destroy() safely handles the case where
smbd_conn is NULL, so it can be called unconditionally.
Closes: https://sashiko.dev/#/patchset/20260912165503.521597-1-pc%40manguebit.org
Fixes: 2f8946464b11 ("CIFS: SMBD: Upper layer connects to SMBDirect session")
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: Tom Talpey <tom@talpey.com>
Cc: Stefan Metzmacher <metze@samba.org>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/connect.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/smb/client/connect.c
+++ b/fs/smb/client/connect.c
@@ -1933,6 +1933,7 @@ out_err:
kfree(tcp_ses->leaf_fullpath);
if (tcp_ses->ssocket)
sock_release(tcp_ses->ssocket);
+ smbd_destroy(tcp_ses);
kfree(tcp_ses);
}
return ERR_PTR(rc);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 403/438] drm/msm/dpu: clear pending peripheral flush state
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (401 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 402/438] drm/msm/adreno: fix autosuspend cleanup during teardown Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 404/438] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure Greg Kroah-Hartman
` (46 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Saim Shujah, Dmitry Baryshkov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Saim Shujah <saimzst@gmail.com>
commit a5b5cc909931572aec446e129c035b76b3f0c1fa upstream.
dpu_hw_ctl_clear_pending_flush() resets the cached per-block state after a
flush transaction, but misses pending_periph_flush_mask.
The peripheral flush updater accumulates interface bits in this mask. A
later transaction which sets the top-level peripheral flush bit can write
stale interface bits to CTL_PERIPH_FLUSH together with the current state.
Peripheral flush support was added after the helper started clearing every
individual pending flush mask. Clear the peripheral mask together with the
other cached child masks.
Fixes: 64f7b81f0358 ("drm/msm/dpu: add support of new peripheral flush mechanism")
Cc: stable@vger.kernel.org
Signed-off-by: Saim Shujah <saimzst@gmail.com>
Patchwork: https://patchwork.freedesktop.org/patch/748968/
Link: https://lore.kernel.org/r/20260828065440.140410-1-saimzst@gmail.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/msm/disp/dpu1/dpu_hw_ctl.c | 1 +
1 file changed, 1 insertion(+)
--- a/drivers/gpu/drm/msm/disp/dpu1/dpu_hw_ctl.c
+++ b/drivers/gpu/drm/msm/disp/dpu1/dpu_hw_ctl.c
@@ -118,6 +118,7 @@ static inline void dpu_hw_ctl_clear_pend
ctx->pending_intf_flush_mask = 0;
ctx->pending_wb_flush_mask = 0;
ctx->pending_cwb_flush_mask = 0;
+ ctx->pending_periph_flush_mask = 0;
ctx->pending_merge_3d_flush_mask = 0;
ctx->pending_dsc_flush_mask = 0;
ctx->pending_cdm_flush_mask = 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 350/398] smb: client: fix unaligned access in WSL reparse point parser
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (346 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 349/398] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 351/398] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Greg Kroah-Hartman
` (54 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Paulo Alcantara,
David Howells, Tom Talpey, Shyam Prasad N, Ronnie Sahlberg,
Bharath SM
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paulo Alcantara <pc@manguebit.org>
commit e1aeaf79dea51e6065da56924bc07e22d59012ac upstream.
When wsl_to_fattr() parses WSL extended attributes, it computes a
payload pointer from ea->ea_data + ea_name_length + 1. Since the
smb2_file_full_ea_info struct is __packed and all WSL xattr names are
6 bytes long, the value pointer always lands at an odd byte offset,
never satisfying __le32 or __le64 alignment requirements.
The code then casts this pointer to __le32 * or __le64 * and
dereferences it directly, which may cause alignment faults on some
architectures.
Replace all such casts with get_unaligned_le32() and
get_unaligned_le64() in reparse_mkdev(), wsl_make_kuid(),
wsl_make_kgid() and wsl_to_fattr().
Closes: https://sashiko.dev/#/patchset/20260906200517.725015-1-pc%40manguebit.org
Fixes: 78e26bec4d6d ("smb: client: parse uid, gid, mode and dev from WSL reparse points")
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: David Howells <dhowells@redhat.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/reparse.c | 4 ++--
fs/smb/client/reparse.h | 7 ++++---
2 files changed, 6 insertions(+), 5 deletions(-)
--- a/fs/smb/client/reparse.c
+++ b/fs/smb/client/reparse.c
@@ -1156,9 +1156,9 @@ static bool wsl_to_fattr(struct cifs_ope
fattr->cf_gid = wsl_make_kgid(cifs_sb, v);
else if (!strncmp(name, SMB2_WSL_XATTR_MODE, nlen)) {
/* File type in reparse point tag and in xattr mode must match. */
- if (S_DT(fattr->cf_mode) != S_DT(le32_to_cpu(*(__le32 *)v)))
+ if (S_DT(fattr->cf_mode) != S_DT(get_unaligned_le32(v)))
return false;
- fattr->cf_mode = (umode_t)le32_to_cpu(*(__le32 *)v);
+ fattr->cf_mode = (umode_t)get_unaligned_le32(v);
} else if (!strncmp(name, SMB2_WSL_XATTR_DEV, nlen)) {
fattr->cf_rdev = reparse_mkdev(v);
have_xattr_dev = true;
--- a/fs/smb/client/reparse.h
+++ b/fs/smb/client/reparse.h
@@ -9,6 +9,7 @@
#include <linux/fs.h>
#include <linux/stat.h>
#include <linux/uidgid.h>
+#include <linux/unaligned.h>
#include "fs_context.h"
#include "cifsglob.h"
@@ -22,7 +23,7 @@
static inline dev_t reparse_mkdev(void *ptr)
{
- u64 v = le64_to_cpu(*(__le64 *)ptr);
+ u64 v = get_unaligned_le64(ptr);
return MKDEV(v & 0xffffffff, v >> 32);
}
@@ -30,7 +31,7 @@ static inline dev_t reparse_mkdev(void *
static inline kuid_t wsl_make_kuid(struct cifs_sb_info *cifs_sb,
void *ptr)
{
- u32 uid = le32_to_cpu(*(__le32 *)ptr);
+ u32 uid = get_unaligned_le32(ptr);
if (cifs_sb_flags(cifs_sb) & CIFS_MOUNT_OVERR_UID)
return cifs_sb->ctx->linux_uid;
@@ -40,7 +41,7 @@ static inline kuid_t wsl_make_kuid(struc
static inline kgid_t wsl_make_kgid(struct cifs_sb_info *cifs_sb,
void *ptr)
{
- u32 gid = le32_to_cpu(*(__le32 *)ptr);
+ u32 gid = get_unaligned_le32(ptr);
if (cifs_sb_flags(cifs_sb) & CIFS_MOUNT_OVERR_GID)
return cifs_sb->ctx->linux_gid;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 404/438] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (402 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 403/438] drm/msm/dpu: clear pending peripheral flush state Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 405/438] drm/msm: RCU-free the scheduler-containing ring and VM objects Greg Kroah-Hartman
` (45 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Krzysztof Kozlowski,
Dmitry Baryshkov
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
commit f4fae975db08a9aeec0b15e145c7d4d0fe02a0ec upstream.
msm_hdmi_phy_probe() enables runtime PM before enabling the PHY
resources and initializing the PLL, but failures from either operation
return without calling the matching pm_runtime_disable().
The remove path disables runtime PM, but it is not called when probe
fails. As a result, runtime PM remains enabled after an unsuccessful
probe.
Route failures after pm_runtime_enable() through a common error path
and disable runtime PM before returning.
This issue was found by manual code inspection.
Fixes: 15b4a4523859 ("drm/msm/hdmi: Create a separate HDMI PHY driver")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/753043/
Link: https://lore.kernel.org/r/20260913085814.1509352-1-lgs201920130244@gmail.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/msm/hdmi/hdmi_phy.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/msm/hdmi/hdmi_phy.c
+++ b/drivers/gpu/drm/msm/hdmi/hdmi_phy.c
@@ -168,13 +168,13 @@ static int msm_hdmi_phy_probe(struct pla
ret = msm_hdmi_phy_resource_enable(phy);
if (ret)
- return ret;
+ goto err_pm_disable;
ret = msm_hdmi_phy_pll_init(pdev, phy->cfg->type);
if (ret) {
DRM_DEV_ERROR(dev, "couldn't init PLL\n");
msm_hdmi_phy_resource_disable(phy);
- return ret;
+ goto err_pm_disable;
}
msm_hdmi_phy_resource_disable(phy);
@@ -182,6 +182,10 @@ static int msm_hdmi_phy_probe(struct pla
platform_set_drvdata(pdev, phy);
return 0;
+
+err_pm_disable:
+ pm_runtime_disable(dev);
+ return ret;
}
static void msm_hdmi_phy_remove(struct platform_device *pdev)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 351/398] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (347 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 350/398] smb: client: fix unaligned access in WSL reparse point parser Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 352/398] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Greg Kroah-Hartman
` (53 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit 05762c5bc1cfdcac36747994fde2c04387a457f1 upstream.
Fix several related bounds checking and pointer lifecycle issues in
receive_encrypted_standard()'s handling of compound encrypted frames:
- Clear next_buffer after assigning it to server->bigbuf. A stale
next_buffer pointer can lead to a use-after-free on subsequent
error paths.
- Update pdu_length to the decrypted plaintext size (buf_size). Using
the pre-decryption length allows NextCommand to point into stale
ciphertext residue.
- Reject next_cmd values smaller than MID_HEADER_SIZE(server).
- Fix an integer overflow in the upper bound check by verifying
pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the
trailing slice is large enough for a header.
Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -5280,6 +5280,7 @@ receive_encrypted_standard(struct TCP_Se
length = decrypt_raw_data(server, buf, buf_size, NULL, false);
if (length)
return length;
+ pdu_length = buf_size;
next_is_large = server->large_buf;
one_more:
@@ -5292,8 +5293,15 @@ one_more:
}
if (next_cmd) {
- if (WARN_ON_ONCE(next_cmd > pdu_length))
+ if (next_cmd < MID_HEADER_SIZE(server) ||
+ next_cmd > pdu_length ||
+ pdu_length - next_cmd < MID_HEADER_SIZE(server)) {
+ unsigned int max_next = pdu_length > (unsigned int)MID_HEADER_SIZE(server) ?
+ pdu_length - (unsigned int)MID_HEADER_SIZE(server) : 0;
+ cifs_server_dbg(VFS, "invalid NextCommand offset %u out of range [%zu, %u]\n",
+ next_cmd, MID_HEADER_SIZE(server), max_next);
return -1;
+ }
if (next_is_large)
next_buffer = (char *)cifs_buf_get();
else
@@ -5329,6 +5337,7 @@ one_more:
server->bigbuf = buf = next_buffer;
else
server->smallbuf = buf = next_buffer;
+ next_buffer = NULL;
goto one_more;
} else if (ret != 0) {
/*
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 405/438] drm/msm: RCU-free the scheduler-containing ring and VM objects
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (403 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 404/438] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 406/438] drm/sched: Fix virtual runtime race Greg Kroah-Hartman
` (44 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jonghyuk Kim(MalHyuk), Rob Clark
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
commit 01c8d1f385f788f1bbbbb7687c4386d614281218 upstream.
Both struct msm_ringbuffer and struct msm_gem_vm embed a struct
drm_gpu_scheduler. msm_ringbuffer_destroy() and the VM free callback
msm_gem_vm_free() call drm_sched_fini() on the embedded scheduler and then
free the containing object with plain kfree().
drm_sched_fence_get_timeline_name() returns fence->sched->name, and the
scheduler fence keeps a .release callback so it is not ops-detached on
signalling. A finished fence exported to userspace (the submit out-fence, or
a VM_BIND fence, via sync_file / drm_syncobj) keeps pointing at the embedded
scheduler after the ring/VM is freed, so a later get_timeline_name() --
reachable unprivileged through SYNC_IOC_FILE_INFO -- dereferences freed slab
memory (KASAN slab-use-after-free read).
Per the dma-fence lifetime contract the exporter must keep the data backing a
signalled fence alive for an RCU grace period. Free the scheduler-containing
objects with kfree_rcu() instead of kfree().
Fixes: 1d8a5ca436ee ("drm/msm: Conversion to drm scheduler")
Fixes: 92395af63a99 ("drm/msm: Add VM_BIND submitqueue")
Cc: stable@vger.kernel.org
Signed-off-by: Jonghyuk Kim(MalHyuk) <malhyuk97@gmail.com>
Patchwork: https://patchwork.freedesktop.org/patch/750234/
Message-ID: <20260902012720.880783-1-malhyuk97@gmail.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/msm/msm_gem.h | 3 +++
drivers/gpu/drm/msm/msm_gem_vma.c | 2 +-
drivers/gpu/drm/msm/msm_ringbuffer.c | 2 +-
drivers/gpu/drm/msm/msm_ringbuffer.h | 1 +
4 files changed, 6 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/msm/msm_gem.h
+++ b/drivers/gpu/drm/msm/msm_gem.h
@@ -68,6 +68,9 @@ struct msm_gem_vm {
/** @base: Inherit from drm_gpuvm. */
struct drm_gpuvm base;
+ /** @rcu: RCU-delayed free so an exported sched fence->sched stays valid. */
+ struct rcu_head rcu;
+
/**
* @sched: Scheduler used for asynchronous VM_BIND request.
*
--- a/drivers/gpu/drm/msm/msm_gem_vma.c
+++ b/drivers/gpu/drm/msm/msm_gem_vma.c
@@ -166,7 +166,7 @@ msm_gem_vm_free(struct drm_gpuvm *gpuvm)
dma_fence_put(vm->last_fence);
put_pid(vm->pid);
kfree(vm->log);
- kfree(vm);
+ kfree_rcu(vm, rcu);
}
/**
--- a/drivers/gpu/drm/msm/msm_ringbuffer.c
+++ b/drivers/gpu/drm/msm/msm_ringbuffer.c
@@ -140,5 +140,5 @@ void msm_ringbuffer_destroy(struct msm_r
msm_gem_kernel_put(ring->bo, ring->gpu->vm);
- kfree(ring);
+ kfree_rcu(ring, rcu);
}
--- a/drivers/gpu/drm/msm/msm_ringbuffer.h
+++ b/drivers/gpu/drm/msm/msm_ringbuffer.h
@@ -55,6 +55,7 @@ struct msm_ringbuffer {
/*
* The job scheduler for this ring.
*/
+ struct rcu_head rcu;
struct drm_gpu_scheduler sched;
bool sched_initialized;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 352/398] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (348 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 351/398] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 353/398] smb: client: fix potential OOB read in smb3_enum_snapshots() Greg Kroah-Hartman
` (52 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit eeb5ef6083e1cefa2ef75041b5597ff228b8d7bb upstream.
In move_smb2_ea_to_cifs(), the while (src_size > 0) loop condition is
insufficient. It allows iteration to continue even if the remaining
src_size is too small to contain a complete smb2_ea_info structure.
Consequently, reads of ea_name_length and ea_value_length can occur
out-of-bounds.
Fix this by ensuring src_size >= sizeof(*src) before attempting to read
any structure fields. Additionally, reject any next_entry_offset that is
smaller than sizeof(*src) or that would advance the pointer beyond the
available buffer.
Note that for calls where the server returns a malformed EA list, the
error returned to userspace changes from -ENODATA (getxattr) or
-ERANGE (listxattr) to -EIO. This correctly signals a server protocol
error rather than misleadingly indicating "attribute not present" or
"output buffer too small".
Fixes: 95907fea4fd8 ("cifs: Add support for reading attributes on SMB2+")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 25 +++++++++++++++++--------
fs/smb/client/trace.h | 1 +
2 files changed, 18 insertions(+), 8 deletions(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -1054,8 +1054,9 @@ move_smb2_ea_to_cifs(char *dst, size_t d
char *name, *value;
size_t buf_size = dst_size;
size_t name_len, value_len, user_name_len;
+ u32 next_off;
- while (src_size > 0) {
+ while (src_size >= sizeof(*src)) {
name_len = (size_t)src->ea_name_length;
value_len = (size_t)le16_to_cpu(src->ea_value_length);
@@ -1110,14 +1111,22 @@ move_smb2_ea_to_cifs(char *dst, size_t d
if (!src->next_entry_offset)
break;
- if (src_size < le32_to_cpu(src->next_entry_offset)) {
- /* stop before overrun buffer */
- rc = -ERANGE;
- break;
+ next_off = le32_to_cpu(src->next_entry_offset);
+ if (next_off < sizeof(*src) || src_size < next_off) {
+ cifs_dbg(FYI, "EA next_entry_offset %u out of range [%zu, %zu]\n",
+ next_off, sizeof(*src), src_size);
+ rc = smb_EIO2(smb_eio_trace_ea_next_offset,
+ next_off, src_size);
+ goto out;
+ }
+ src_size -= next_off;
+ src = (void *)((char *)src + next_off);
+ if (src_size > 0 && src_size < sizeof(*src)) {
+ cifs_dbg(FYI, "EA next_entry_offset %u left truncated entry (%zu bytes)\n",
+ next_off, src_size);
+ rc = smb_EIO2(smb_eio_trace_ea_next_offset, next_off, src_size);
+ goto out;
}
- src_size -= le32_to_cpu(src->next_entry_offset);
- src = (void *)((char *)src +
- le32_to_cpu(src->next_entry_offset));
}
/* didn't find the named attribute */
--- a/fs/smb/client/trace.h
+++ b/fs/smb/client/trace.h
@@ -27,6 +27,7 @@
EM(smb_eio_trace_copychunk_overcopy_c, "copychunk_overcopy_c") \
EM(smb_eio_trace_create_rsp_too_small, "create_rsp_too_small") \
EM(smb_eio_trace_dfsref_no_rsp, "dfsref_no_rsp") \
+ EM(smb_eio_trace_ea_next_offset, "ea_next_offset") \
EM(smb_eio_trace_ea_overrun, "ea_overrun") \
EM(smb_eio_trace_extract_will_pin, "extract_will_pin") \
EM(smb_eio_trace_forced_shutdown, "forced_shutdown") \
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 406/438] drm/sched: Fix virtual runtime race
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (404 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 405/438] drm/msm: RCU-free the scheduler-containing ring and VM objects Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 407/438] drm/amdgpu: fix rmmio iounmap skipped on device removal Greg Kroah-Hartman
` (43 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tvrtko Ursulin, Luke.Wildhardt,
Christian König, Danilo Krummrich, Philipp Stanner,
Pierre-Eric Pelloux-Prayer, Matthew Brost, Vitaly Prosyak
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
commit 2ab510e63197360945f915dd5631a77c63ac6b27 upstream.
Prevent pushing a new job to an entity seeing it being the first in the
queue, and hence entering the drm_sched_rq_add_entity() path, if the pop
side in drm_sched_entity_pop_job() has just de-queued the job but not yet
updated the saved virtual time.
Restoring the unsaved virtual time, which is at this point not a delta but
still an absolute value, pushes the said entity to the rear of the run queue
for a potentially very long time.
We close this race by pulling the locked sections out to encompass both
the queue push/pop and corresponding rbtree management.
This is aligned with the future direction to replace the current lockless
job queue with one of the fully locked standard list primitives.
Signed-off-by: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
Fixes: 2fa4d8e2c109 ("drm/sched: Add fair scheduling policy")
Suggested-by: Luke.Wildhardt@proton.me # via Claude Opus
Tested-by: Luke.Wildhardt@proton.me
Cc: Christian König <christian.koenig@amd.com>
Cc: Danilo Krummrich <dakr@kernel.org>
Cc: Philipp Stanner <phasta@kernel.org>
Cc: Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Cc: Vitaly Prosyak <vitaly.prosyak@amd.com>
Cc: stable@vger.kernel.org # v7.2+
[phasta: commit title]
Signed-off-by: Philipp Stanner <phasta@kernel.org>
Link: https://patch.msgid.link/20260915150557.62847-1-tvrtko.ursulin@igalia.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/scheduler/sched_entity.c | 8 +++++++-
drivers/gpu/drm/scheduler/sched_rq.c | 20 +++++++++-----------
2 files changed, 16 insertions(+), 12 deletions(-)
--- a/drivers/gpu/drm/scheduler/sched_entity.c
+++ b/drivers/gpu/drm/scheduler/sched_entity.c
@@ -566,9 +566,10 @@ struct drm_sched_job *drm_sched_entity_p
*/
smp_wmb();
+ spin_lock(&entity->lock);
spsc_queue_pop(&entity->job_queue);
-
drm_sched_rq_pop_entity(entity);
+ spin_unlock(&entity->lock);
/* Jobs and entities might have different lifecycles. Since we're
* removing the job from the entities queue, set the jobs entity pointer
@@ -654,6 +655,9 @@ void drm_sched_entity_push_job(struct dr
* Make sure to set the submit_ts first, to avoid a race.
*/
sched_job->submit_ts = submit_ts = ktime_get();
+
+ spin_lock(&entity->lock);
+
first = spsc_queue_push(&entity->job_queue, &sched_job->queue_node);
/* first job wakes up scheduler */
@@ -664,5 +668,7 @@ void drm_sched_entity_push_job(struct dr
if (sched)
drm_sched_wakeup(sched);
}
+
+ spin_unlock(&entity->lock);
}
EXPORT_SYMBOL(drm_sched_entity_push_job);
--- a/drivers/gpu/drm/scheduler/sched_rq.c
+++ b/drivers/gpu/drm/scheduler/sched_rq.c
@@ -257,19 +257,17 @@ static ktime_t drm_sched_entity_get_job_
struct drm_gpu_scheduler *
drm_sched_rq_add_entity(struct drm_sched_entity *entity, ktime_t ts)
{
+ struct drm_sched_rq *rq = entity->rq;
struct drm_gpu_scheduler *sched;
- struct drm_sched_rq *rq;
/* Add the entity to the run queue */
- spin_lock(&entity->lock);
- if (entity->stopped) {
- spin_unlock(&entity->lock);
+ lockdep_assert_held(&entity->lock);
+ if (entity->stopped) {
DRM_ERROR("Trying to push to a killed entity\n");
return NULL;
}
- rq = entity->rq;
spin_lock(&rq->lock);
sched = rq->sched;
@@ -289,7 +287,6 @@ drm_sched_rq_add_entity(struct drm_sched
drm_sched_rq_update_fifo_locked(entity, rq, ts);
spin_unlock(&rq->lock);
- spin_unlock(&entity->lock);
return sched;
}
@@ -343,16 +340,17 @@ drm_sched_rq_next_rr_ts(struct drm_sched
*/
void drm_sched_rq_pop_entity(struct drm_sched_entity *entity)
{
+ struct drm_sched_rq *rq = entity->rq;
struct drm_sched_job *next_job;
- struct drm_sched_rq *rq;
+
+ lockdep_assert_held(&entity->lock);
+
+ spin_lock(&rq->lock);
/*
* Update the entity's location in the min heap according to
* the timestamp of the next job, if any.
*/
- spin_lock(&entity->lock);
- rq = entity->rq;
- spin_lock(&rq->lock);
next_job = drm_sched_entity_queue_peek(entity);
if (next_job) {
ktime_t ts;
@@ -375,8 +373,8 @@ void drm_sched_rq_pop_entity(struct drm_
drm_sched_entity_save_vruntime(entity, min_vruntime);
}
}
+
spin_unlock(&rq->lock);
- spin_unlock(&entity->lock);
}
/**
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 353/398] smb: client: fix potential OOB read in smb3_enum_snapshots()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (349 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 352/398] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 354/398] smb: client: fix server->total_read for compound encrypted PDUs Greg Kroah-Hartman
` (51 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit 4775c3b7a597907e0b97556c7986fda238a377ae upstream.
If snapshot_array_size is smaller than GMT_TOKEN_SIZE,
smb3_enum_snapshots() sets ret_data_len to
sizeof(struct smb_snapshot_array) without verifying the actual length
of the server's reply.
Because SMB2_ioctl() places no lower bound on the server-supplied
OutputCount and allocates retbuf to exactly that length, a short reply
results in ret_data_len exceeding the size of retbuf. The subsequent
copy_to_user() then reads past the end of retbuf, leaking adjacent slab
memory to userspace. The subsequent clamp check is ineffective as it
only reduces ret_data_len.
Fix this by rejecting replies shorter than
sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set
to the 12-byte struct size rather than the 16-byte
MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes
is exactly what copy_to_user() attempts to read.
Fixes: e02789a53d71 ("smb3: enumerating snapshots was leaving part of the data off end")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -2415,8 +2415,14 @@ smb3_enum_snapshots(const unsigned int x
* and retry the ioctl again with larger array size sufficient
* to hold all of the snapshot GMT tokens on the second try.
*/
- if (snapshot_in.snapshot_array_size < GMT_TOKEN_SIZE)
+ if (snapshot_in.snapshot_array_size < GMT_TOKEN_SIZE) {
+ if (ret_data_len < sizeof(struct smb_snapshot_array)) {
+ rc = -EIO;
+ kfree(retbuf);
+ return rc;
+ }
ret_data_len = sizeof(struct smb_snapshot_array);
+ }
/*
* We return struct SRV_SNAPSHOT_ARRAY, followed by
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 407/438] drm/amdgpu: fix rmmio iounmap skipped on device removal
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (405 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 406/438] drm/sched: Fix virtual runtime race Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 408/438] drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments Greg Kroah-Hartman
` (42 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chengjun Yao, Asad Kamal,
Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chengjun Yao <Chengjun.Yao@amd.com>
commit 5155002b03b24ba3ef91c5c313b8cf0171b24904 upstream.
amdgpu_pci_remove() calls drm_dev_unplug() before fini_sw(), so
drm_dev_enter() is already false there and the iounmap() guarded by it
is skipped. This .remove path runs on both hot-unplug and plain rmmod,
so the register BAR ioremap mapping leaks one instance per unload.
Unmap rmmio unconditionally (guard only on non-NULL) and drop the now
unused idx.
Fixes: 62d5f9f7110a ("drm/amdgpu: Unmap MMIO mappings when device is not unplugged")
Signed-off-by: Chengjun Yao <Chengjun.Yao@amd.com>
Reviewed-by: Asad Kamal <asad.kamal@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit dd6f86a97260e5207d3329ad03aa89fdad61b1e6)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_device.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -4344,7 +4344,7 @@ void amdgpu_device_fini_hw(struct amdgpu
void amdgpu_device_fini_sw(struct amdgpu_device *adev)
{
- int i, idx;
+ int i;
bool px;
amdgpu_device_ip_fini(adev);
@@ -4386,11 +4386,9 @@ void amdgpu_device_fini_sw(struct amdgpu
if ((adev->pdev->class >> 8) == PCI_CLASS_DISPLAY_VGA)
vga_client_unregister(adev->pdev);
- if (drm_dev_enter(adev_to_drm(adev), &idx)) {
-
+ if (adev->rmmio) {
iounmap(adev->rmmio);
adev->rmmio = NULL;
- drm_dev_exit(idx);
}
if (IS_ENABLED(CONFIG_PERF_EVENTS))
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 354/398] smb: client: fix server->total_read for compound encrypted PDUs
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (350 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 353/398] smb: client: fix potential OOB read in smb3_enum_snapshots() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 355/398] smb: client: fix missing lower-bound check on DFS referral string offsets Greg Kroah-Hartman
` (50 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit f73726b83e4756fdaa099e1bc1143293bd57ad79 upstream.
In receive_encrypted_standard(), server->total_read is left at the
full decrypted frame size when walking sub-PDUs of a compound encrypted
frame. As a result, cifs_handle_standard() passes this full size
to smb2_check_message(), causing the PDU length guards to incorrectly
validate the entire compound frame instead of the current sub-PDU.
This allows truncated non-last sub-PDUs to bypass length validation,
leading to out-of-bounds reads in smb2_get_data_area_len().
Fix this by setting server->total_read to the true length of the
current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining
pdu_length for the last one.
Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -5301,6 +5301,7 @@ receive_encrypted_standard(struct TCP_Se
one_more:
shdr = (struct smb2_hdr *)buf;
next_cmd = le32_to_cpu(shdr->NextCommand);
+ server->total_read = next_cmd ? next_cmd : pdu_length;
if (*num_mids >= MAX_COMPOUND) {
cifs_server_dbg(VFS, "too many PDUs in compound\n");
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 408/438] drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (406 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 407/438] drm/amdgpu: fix rmmio iounmap skipped on device removal Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 409/438] drm/amdgpu: Skip KFD mapping clear before initialization Greg Kroah-Hartman
` (41 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian König, Mike Lothian,
Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mike Lothian <mike@fireburn.co.uk>
commit 636139603b99d2e3a18a46cf3f8d39313ce8042e upstream.
amdgpu_dma_buf_map() adds VRAM to the allowed domains for a peer2peer
attachment. GTT is only a fallback placement when VRAM is preferred, so
ttm_bo_validate() migrates the buffer from GTT into VRAM. While the
exporting device is runtime suspended its SDMA rings are down and the
move fails:
amdgpu: Move buffer fallback to memcpy unavailable
An importer on a second GPU reaches this holding no runtime PM
reference on the exporter, e.g. a compositor on the APU submitting a
frame that references a buffer exported by an idle dGPU:
amdgpu_cs_ioctl -> amdgpu_cs_parser_bos -> amdgpu_cs_bo_validate
-> ttm_bo_validate -> amdgpu_bo_move -> dma_buf_map_attachment
-> amdgpu_dma_buf_map -> ttm_bo_validate -> amdgpu_bo_move
Pinning a dma-buf into VRAM has the same requirement, which
commit 030631e97b20 ("drm/amdgpu: revert "take runtime pm reference
when we attach a buffer" v2") called out as the one case that would
need the reference back.
Take it in attach and drop it in detach. pm_runtime_get_if_active()
never resumes the device, so it cannot deadlock against the reservation
taken during resume, which is why the old pm_runtime_get_sync() had to
go. If the device is not active, clear peer2peer instead: the buffer
then stays in GTT, which remains accessible while the GPU is powered
down. If runtime PM is disabled, take a plain reference so the put in
detach stays balanced.
Fixes: 030631e97b20 ("drm/amdgpu: revert "take runtime pm reference when we attach a buffer" v2")
Suggested-by: Christian König <christian.koenig@amd.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Mike Lothian <mike@fireburn.co.uk>
Assisted-by: Claude:Opus-5 [Claude Code]
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 062ff15e30a48d14fb7d7558eba84f8dc97197f0)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c | 43 +++++++++++++++++++++++++++-
1 file changed, 42 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c
@@ -43,6 +43,7 @@
#include <linux/dma-buf.h>
#include <linux/dma-fence-array.h>
#include <linux/pci-p2pdma.h>
+#include <linux/pm_runtime.h>
static const struct dma_buf_attach_ops amdgpu_dma_buf_attach_ops;
@@ -100,15 +101,54 @@ static int amdgpu_dma_buf_attach(struct
pci_p2pdma_distance(adev->pdev, attach->dev, false) < 0)
attach->peer2peer = false;
+ /*
+ * Only allow P2P while the exporter is active, and keep it active
+ * until detach. With runtime PM disabled take a plain reference so
+ * the put in detach stays balanced.
+ */
+ if (attach->peer2peer) {
+ struct device *dev = adev_to_drm(adev)->dev;
+ int ret = pm_runtime_get_if_active(dev);
+
+ if (!ret)
+ attach->peer2peer = false;
+ else if (ret < 0)
+ pm_runtime_get_noresume(dev);
+ }
+
r = dma_resv_lock(bo->tbo.base.resv, NULL);
if (r)
- return r;
+ goto err_pm_put;
amdgpu_vm_bo_update_shared(bo);
dma_resv_unlock(bo->tbo.base.resv);
return 0;
+
+err_pm_put:
+ if (attach->peer2peer)
+ pm_runtime_put_autosuspend(adev_to_drm(adev)->dev);
+ return r;
+}
+
+/**
+ * amdgpu_dma_buf_detach - &dma_buf_ops.detach implementation
+ *
+ * @dmabuf: DMA-buf where we remove the attachment from
+ * @attach: the attachment to remove
+ *
+ * Drop the runtime PM reference taken in amdgpu_dma_buf_attach().
+ */
+static void amdgpu_dma_buf_detach(struct dma_buf *dmabuf,
+ struct dma_buf_attachment *attach)
+{
+ struct drm_gem_object *obj = dmabuf->priv;
+ struct amdgpu_bo *bo = gem_to_amdgpu_bo(obj);
+ struct amdgpu_device *adev = amdgpu_ttm_adev(bo->tbo.bdev);
+
+ if (attach->peer2peer)
+ pm_runtime_put_autosuspend(adev_to_drm(adev)->dev);
}
/**
@@ -350,6 +390,7 @@ static void amdgpu_dma_buf_vunmap(struct
const struct dma_buf_ops amdgpu_dmabuf_ops = {
.attach = amdgpu_dma_buf_attach,
+ .detach = amdgpu_dma_buf_detach,
.pin = amdgpu_dma_buf_pin,
.unpin = amdgpu_dma_buf_unpin,
.map_dma_buf = amdgpu_dma_buf_map,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 355/398] smb: client: fix missing lower-bound check on DFS referral string offsets
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (351 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 354/398] smb: client: fix server->total_read for compound encrypted PDUs Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 356/398] smb: client: fix missing iov bounds check in parse_posix_sids() Greg Kroah-Hartman
` (49 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit e83330c55edc0c3ac08aa6c95e49e4694c65523b upstream.
parse_dfs_referrals() checks that DfsPathOffset and NetworkAddressOffset
do not exceed the buffer end, but fails to check that they don't point
inside the referral header itself.
If a server provides an offset smaller than
sizeof(struct dfs_referral_level_3), the derived string pointer overlaps
with the struct fields, causing cifs_strndup_from_utf16() to interpret
header data as UTF-16 strings.
Fix this by enforcing that string offsets are at least sizeof(*ref).
Fixes: 4ecce920e13a ("CIFS: move DFS response parsing out of SMB1 code")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/misc.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
--- a/fs/smb/client/misc.c
+++ b/fs/smb/client/misc.c
@@ -1050,7 +1050,11 @@ parse_dfs_referrals(struct get_dfs_refer
node->ref_flag = le16_to_cpu(ref->ReferralEntryFlags);
/* copy DfsPath */
- if (le16_to_cpu(ref->DfsPathOffset) > data_end - (char *)ref) {
+ if (le16_to_cpu(ref->DfsPathOffset) < sizeof(*ref) ||
+ le16_to_cpu(ref->DfsPathOffset) > data_end - (char *)ref) {
+ cifs_dbg(VFS, "%s: DfsPathOffset %u out of range [%zu, %td]\n",
+ __func__, le16_to_cpu(ref->DfsPathOffset),
+ sizeof(*ref), data_end - (char *)ref);
rc = -EINVAL;
goto parse_DFS_referrals_exit;
}
@@ -1064,7 +1068,11 @@ parse_dfs_referrals(struct get_dfs_refer
}
/* copy link target UNC */
- if (le16_to_cpu(ref->NetworkAddressOffset) > data_end - (char *)ref) {
+ if (le16_to_cpu(ref->NetworkAddressOffset) < sizeof(*ref) ||
+ le16_to_cpu(ref->NetworkAddressOffset) > data_end - (char *)ref) {
+ cifs_dbg(VFS, "%s: NetworkAddressOffset %u out of range [%zu, %td]\n",
+ __func__, le16_to_cpu(ref->NetworkAddressOffset),
+ sizeof(*ref), data_end - (char *)ref);
rc = -EINVAL;
goto parse_DFS_referrals_exit;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 409/438] drm/amdgpu: Skip KFD mapping clear before initialization
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (407 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 408/438] drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 410/438] drm/amdkfd: Avoid integer underflow in EOP ring size calculation Greg Kroah-Hartman
` (40 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Alex Deucher, Mario Limonciello
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello <mario.limonciello@amd.com>
commit 7f9caa70aef0950e06d395ca0035831214d88187 upstream.
amdgpu_amdkfd_clear_kfd_mapping() assumes that a non-NULL kfd_dev
has a fully populated node array. This is not true when KFD device
initialization fails after probe.
For example, kgd2kfd_device_init() sets num_nodes before checking
PCIe atomics support. On Polaris systems without the required atomics,
it returns before allocating nodes[0], but the kfd_dev remains attached
to the amdgpu device. A later GPU reset then dereferences nodes[0]->id.
Require the authoritative KFD initialization flag before walking the
node array, matching the existing KFD reset and teardown paths.
Fixes: 70cadefcc616 ("drm/amdgpu: unmap all user mappings of framebuffer and doorbell before mode1 reset")
Closes: https://gitlab.freedesktop.org/drm/amd/-/work_items/5833
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 4ac1835823c47903fbb278bbf474773c46f59edc)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd.c
@@ -329,7 +329,7 @@ void amdgpu_amdkfd_clear_kfd_mapping(str
struct kfd_dev *kfd = adev->kfd.dev;
unsigned int i;
- if (!kfd)
+ if (!kfd || !kfd->init_complete)
return;
for (i = 0; i < kfd->num_nodes; i++) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 356/398] smb: client: fix missing iov bounds check in parse_posix_sids()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (352 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 355/398] smb: client: fix missing lower-bound check on DFS referral string offsets Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 357/398] HID: asus: fortify keyboard handshake Greg Kroah-Hartman
` (48 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit b09d092eb24ad0110f16a9b7c1ed5d2a0c1733dc upstream.
In parse_posix_sids(), sidsbuf_end is calculated using the server-supplied
out_len without being validated against the actual length of the received
iov (iov_len).
If a server provides an inflated out_len, sidsbuf_end will point past the
end of the iov. This defeats the bounds guards in posix_info_sid_size(),
allowing out-of-bounds reads into adjacent kernel memory.
Fix this by rejecting responses where the calculated sidsbuf_end would
exceed the received iov boundaries or cause pointer wraparound.
Fixes: a90f37e3d7ac ("smb: client: parse owner/group when creating reparse points")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2inode.c | 11 +++++++++++
1 file changed, 11 insertions(+)
--- a/fs/smb/client/smb2inode.c
+++ b/fs/smb/client/smb2inode.c
@@ -70,6 +70,17 @@ static int parse_posix_sids(struct cifs_
sidsbuf = (u8 *)qi + le16_to_cpu(qi->OutputBufferOffset) + qi_len;
sidsbuf_end = sidsbuf + out_len - qi_len;
+ if (sidsbuf_end < sidsbuf) {
+ cifs_dbg(VFS, "%s: server-supplied out_len %u caused pointer wraparound\n",
+ __func__, out_len);
+ return -EINVAL;
+ }
+ if (sidsbuf_end > (u8 *)rsp_iov->iov_base + rsp_iov->iov_len) {
+ cifs_dbg(VFS, "%s: server-supplied out_len %u overruns iov by %td bytes\n",
+ __func__, out_len,
+ sidsbuf_end - ((u8 *)rsp_iov->iov_base + rsp_iov->iov_len));
+ return -EINVAL;
+ }
owner_len = posix_info_sid_size(sidsbuf, sidsbuf_end);
if (owner_len == -1)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 410/438] drm/amdkfd: Avoid integer underflow in EOP ring size calculation.
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (408 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 409/438] drm/amdgpu: Skip KFD mapping clear before initialization Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 411/438] drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc Greg Kroah-Hartman
` (39 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kent Russell, David Francis,
Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Francis <David.Francis@amd.com>
commit 8ee521b8b189799e361d4233c5180ba56656d4d4 upstream.
The low 6 bits of cp_hqd_eop_control store the base-2 logarithm
of the EOP ring size. This was calculated as
order_base_2(q->eop_ring_buffer_size / 4) - 1
But order_base_2 can in theory return 0, so this could underflow
(although in practice the ring buffer size cannot be less than 4096).
Change this to
order_base_2(q->eop_ring_buffer_size / 8)
using properties of logarithms.
Also add to the above comment to make the mathematics more clear.
Reviewed-by: Kent Russell <kent.russell@amd.com>
Signed-off-by: David Francis <David.Francis@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit f0f43fcf8b2b3a924cad9444340921c96ed5f634)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v9.c | 6 +++++-
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_vi.c | 5 ++++-
2 files changed, 9 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v9.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v9.c
@@ -299,6 +299,10 @@ static void update_mqd(struct mqd_manage
1 << CP_HQD_IB_CONTROL__IB_EXE_DISABLE__SHIFT;
/*
+ * The lowest 6 bits of eop_control store the EOP ring size. If
+ * their value is X, the ring size is 2^(X + 1) dwords, or
+ * 2^(X + 3) bytes.
+ *
* HW does not clamp this field correctly. Maximum EOP queue size
* is constrained by per-SE EOP done signal count, which is 8-bit.
* Limit is 0xFF EOP entries (= 0x7F8 dwords). CP will not submit
@@ -310,7 +314,7 @@ static void update_mqd(struct mqd_manage
*
*/
m->cp_hqd_eop_control = q->eop_ring_buffer_size ?
- min(0xA, order_base_2(q->eop_ring_buffer_size / 4) - 1) : 0;
+ min(0xA, order_base_2(q->eop_ring_buffer_size / 8)) : 0;
m->cp_hqd_eop_base_addr_lo =
lower_32_bits(q->eop_ring_buffer_address >> 8);
--- a/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_vi.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_vi.c
@@ -208,6 +208,9 @@ static void __update_mqd(struct mqd_mana
mtype << CP_HQD_IB_CONTROL__MTYPE__SHIFT;
/*
+ * The lowest 6 bits of eop_control store the EOP ring size. If
+ * their value is X, the ring size is 2^(X + 1) dwords, or
+ * 2^(X + 3) bytes.
* HW does not clamp this field correctly. Maximum EOP queue size
* is constrained by per-SE EOP done signal count, which is 8-bit.
* Limit is 0xFF EOP entries (= 0x7F8 dwords). CP will not submit
@@ -215,7 +218,7 @@ static void __update_mqd(struct mqd_mana
* is safe, giving a maximum field value of 0xA.
*/
m->cp_hqd_eop_control |= q->eop_ring_buffer_size ? min(0xA,
- order_base_2(q->eop_ring_buffer_size / 4) - 1) : 0;
+ order_base_2(q->eop_ring_buffer_size / 8)) : 0;
m->cp_hqd_eop_base_addr_lo =
lower_32_bits(q->eop_ring_buffer_address >> 8);
m->cp_hqd_eop_base_addr_hi =
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 357/398] HID: asus: fortify keyboard handshake
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (353 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 356/398] smb: client: fix missing iov bounds check in parse_posix_sids() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 358/398] ntsync: Honour callers time namespace for absolute MONOTONIC timeouts Greg Kroah-Hartman
` (47 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Benjamin Tissoires, Denis Benato,
Antheas Kapenekakis, Ilpo Järvinen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Antheas Kapenekakis <lkml@antheas.dev>
[ Upstream commit e82ae34af29e910c96d33c8b3a90c60e27f1625e ]
Handshaking with an Asus device involves sending it a feature report
with the string "ASUS Tech.Inc." and then reading it back to verify the
handshake was successful, under the feature ID the interaction will
take place.
Currently, the driver only does the first part. Add the readback to
verify the handshake was successful. As this could cause breakages,
allow the verification to fail with a dmesg error until we verify
all devices work with it (they seem to).
Since the response is more than 16 bytes, increase the buffer size
to 64 as well to avoid overflow errors. In addition, add the report
ID to prints, to help identify failed handshakes.
Reviewed-by: Benjamin Tissoires <bentiss@kernel.org>
Reviewed-by: Denis Benato <benato.denis96@gmail.com>
Acked-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Antheas Kapenekakis <lkml@antheas.dev>
Link: https://patch.msgid.link/20260122075044.5070-5-lkml@antheas.dev
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-asus.c | 34 ++++++++++++++++++++++++++++++----
1 file changed, 30 insertions(+), 4 deletions(-)
--- a/drivers/hid/hid-asus.c
+++ b/drivers/hid/hid-asus.c
@@ -48,7 +48,7 @@ MODULE_DESCRIPTION("Asus HID Keyboard an
#define FEATURE_REPORT_ID 0x0d
#define INPUT_REPORT_ID 0x5d
#define FEATURE_KBD_REPORT_ID 0x5a
-#define FEATURE_KBD_REPORT_SIZE 16
+#define FEATURE_KBD_REPORT_SIZE 64
#define FEATURE_KBD_LED_REPORT_ID1 0x5d
#define FEATURE_KBD_LED_REPORT_ID2 0x5e
@@ -393,15 +393,41 @@ static int asus_kbd_set_report(struct hi
static int asus_kbd_init(struct hid_device *hdev, u8 report_id)
{
+ /*
+ * The handshake is first sent as a set_report, then retrieved
+ * from a get_report. They should be equal.
+ */
const u8 buf[] = { report_id, 0x41, 0x53, 0x55, 0x53, 0x20, 0x54,
0x65, 0x63, 0x68, 0x2e, 0x49, 0x6e, 0x63, 0x2e, 0x00 };
int ret;
ret = asus_kbd_set_report(hdev, buf, sizeof(buf));
- if (ret < 0)
- hid_err(hdev, "Asus failed to send init command: %d\n", ret);
+ if (ret < 0) {
+ hid_err(hdev, "Asus handshake %02x failed to send: %d\n",
+ report_id, ret);
+ return ret;
+ }
- return ret;
+ u8 *readbuf __free(kfree) = kzalloc(FEATURE_KBD_REPORT_SIZE, GFP_KERNEL);
+ if (!readbuf)
+ return -ENOMEM;
+
+ ret = hid_hw_raw_request(hdev, report_id, readbuf,
+ FEATURE_KBD_REPORT_SIZE, HID_FEATURE_REPORT,
+ HID_REQ_GET_REPORT);
+ if (ret < 0) {
+ hid_warn(hdev, "Asus handshake %02x failed to receive ack: %d\n",
+ report_id, ret);
+ } else if (memcmp(readbuf, buf, sizeof(buf)) != 0) {
+ hid_warn(hdev, "Asus handshake %02x returned invalid response: %*ph\n",
+ report_id, FEATURE_KBD_REPORT_SIZE, readbuf);
+ }
+
+ /*
+ * Do not return error if handshake is wrong until this is
+ * verified to work for all devices.
+ */
+ return 0;
}
static int asus_kbd_get_functions(struct hid_device *hdev,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 411/438] drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (409 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 410/438] drm/amdkfd: Avoid integer underflow in EOP ring size calculation Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 412/438] drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1 Greg Kroah-Hartman
` (38 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kent Russell, David Francis,
Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Francis <David.Francis@amd.com>
commit c883d0a132d430ef7ebb23fd94323be94d0fbdb8 upstream.
The low 6 bits of cp_hqd_eop_control store the base-2 logarithm
of the EOP ring size. This was calculated as
ffs(q->eop_ring_buffer_size / sizeof(unsigned int)) - 1 - 1
But ffs can in theory return 1 or 0, so this could underflow
(although in practice the ring buffer size cannot be less than 4096).
Change this to
ffs(q->eop_ring_buffer_size / sizeof(unsigned int) / 4)
using properties of logarithms.
Reviewed-by: Kent Russell <kent.russell@amd.com>
Signed-off-by: David Francis <David.Francis@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 4f18c56630383c14bfc6b2d65f88f2f895d2121a)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v10.c | 2 +-
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v11.c | 2 +-
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12.c | 2 +-
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c | 2 +-
4 files changed, 4 insertions(+), 4 deletions(-)
--- a/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v10.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v10.c
@@ -204,7 +204,7 @@ static void update_mqd(struct mqd_manage
* is safe, giving a maximum field value of 0xA.
*/
m->cp_hqd_eop_control = q->eop_ring_buffer_size ? min(0xA,
- ffs(q->eop_ring_buffer_size / sizeof(unsigned int)) - 1 - 1) : 0;
+ ffs(q->eop_ring_buffer_size / sizeof(unsigned int) / 4)) : 0;
m->cp_hqd_eop_base_addr_lo =
lower_32_bits(q->eop_ring_buffer_address >> 8);
m->cp_hqd_eop_base_addr_hi =
--- a/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v11.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v11.c
@@ -242,7 +242,7 @@ static void update_mqd(struct mqd_manage
* is safe, giving a maximum field value of 0xA.
*/
m->cp_hqd_eop_control = q->eop_ring_buffer_size ? min(0xA,
- ffs(q->eop_ring_buffer_size / sizeof(unsigned int)) - 1 - 1) : 0;
+ ffs(q->eop_ring_buffer_size / sizeof(unsigned int) / 4)) : 0;
m->cp_hqd_eop_base_addr_lo =
lower_32_bits(q->eop_ring_buffer_address >> 8);
m->cp_hqd_eop_base_addr_hi =
--- a/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12.c
@@ -217,7 +217,7 @@ static void update_mqd(struct mqd_manage
* is safe, giving a maximum field value of 0xA.
*/
m->cp_hqd_eop_control = q->eop_ring_buffer_size ? min(0xA,
- ffs(q->eop_ring_buffer_size / sizeof(unsigned int)) - 1 - 1) : 0;
+ ffs(q->eop_ring_buffer_size / sizeof(unsigned int) / 4)) : 0;
m->cp_hqd_eop_base_addr_lo =
lower_32_bits(q->eop_ring_buffer_address >> 8);
m->cp_hqd_eop_base_addr_hi =
--- a/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c
@@ -295,7 +295,7 @@ static void update_mqd(struct mqd_manage
* is safe, giving a maximum field value of 0xA.
*/
m->cp_hqd_eop_control = q->eop_ring_buffer_size ? min(0xA,
- ffs(q->eop_ring_buffer_size / sizeof(unsigned int)) - 1 - 1) : 0;
+ ffs(q->eop_ring_buffer_size / sizeof(unsigned int) / 4)) : 0;
m->cp_hqd_eop_base_addr_lo =
lower_32_bits(q->eop_ring_buffer_address >> 8);
m->cp_hqd_eop_base_addr_hi =
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 358/398] ntsync: Honour callers time namespace for absolute MONOTONIC timeouts
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (354 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 357/398] HID: asus: fortify keyboard handshake Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 359/398] ntsync: reject wait ioctls with zero owner Greg Kroah-Hartman
` (46 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maoyi Xie, Thomas Gleixner,
Elizabeth Figura, Alice Ryhl
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
commit 180a232ea78003d1dc869b217b4e49106fd58e8f upstream.
ntsync_schedule() takes the absolute timeout from userspace and hands it to
schedule_hrtimeout_range_clock() with HRTIMER_MODE_ABS. For the default
CLOCK_MONOTONIC path, it does not call timens_ktime_to_host() first.
A process inside a CLOCK_MONOTONIC time namespace computes the absolute
timeout in its own clock view. The kernel reads the same value against the
host clock. The two differ by the namespace offset. The timeout then fires
too early or too late.
Other users of absolute timeouts run the ktime through
timens_ktime_to_host() before starting the hrtimer. ntsync was added later
and missed that step.
/dev/ntsync is mode 0666. Any user inside a time namespace that can
open it is affected. The visible effect is wrong timeout behaviour
for Wine in a container that sets a CLOCK_MONOTONIC offset.
Reproducer: unshare --user --time, set the monotonic offset to -10s,
issue NTSYNC_IOC_WAIT_ANY with a 100 ms absolute MONOTONIC timeout.
The baseline run elapses about 100 ms. The run inside the namespace
elapses about 0 ms.
Apply timens_ktime_to_host() to the parsed timeout when the caller
did not set NTSYNC_WAIT_REALTIME. The helper does nothing in the
initial time namespace, so the fast path is unchanged.
Fixes: b4a7b5fe3f51 ("ntsync: Introduce NTSYNC_IOC_WAIT_ANY.")
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Reviewed-by: Elizabeth Figura <zfigura@codeweavers.com>
Link: https://patch.msgid.link/20260528063311.3300393-3-maoyixie.tju@gmail.com
Cc: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/misc/ntsync.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/misc/ntsync.c
+++ b/drivers/misc/ntsync.c
@@ -19,6 +19,7 @@
#include <linux/sched/signal.h>
#include <linux/slab.h>
#include <linux/spinlock.h>
+#include <linux/time_namespace.h>
#include <uapi/linux/ntsync.h>
#define NTSYNC_NAME "ntsync"
@@ -845,6 +846,8 @@ static int ntsync_schedule(const struct
if (args->flags & NTSYNC_WAIT_REALTIME)
clock = CLOCK_REALTIME;
+ else
+ timeout = timens_ktime_to_host(clock, timeout);
do {
if (signal_pending(current)) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 412/438] drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (410 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 411/438] drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 413/438] smb: client: cancel reconnect work in clean_demultiplex_info() Greg Kroah-Hartman
` (37 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vladimir Marioukhine, Alex Deucher
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
commit 5f28bb1c2cd9dcdb76a20d61b3ea069b85893c59 upstream.
kfd_mqd_manager_v12.c (GFX 12.0) and kfd_mqd_manager_v12_1.c (GFX 12.1)
do not implement restore_mqd callbacks, leaving the function pointers
NULL and causing CRIU restore to return -EOPNOTSUPP on GFX12.
Implement restore_mqd for both compute and SDMA queues in
kfd_mqd_manager_v12.c and kfd_mqd_manager_v12_1.c, modeled after the
GFX 11 implementation with the following improvements:
- update cp_mqd_base_addr_lo/hi to the newly allocated MQD address,
fixing a pre-existing gap shared with v11 where the in-MQD copy
still pointed at the old checkpoint-time address after restore
- memset the full allocation before memcpy for compute queues to avoid
stale data in the GTT sub-allocator tail; SDMA MQDs use sizeof(*m)
since they are packed at mqd_size stride in a shared BO
checkpoint_mqd registration is deferred to a follow-up patch that also
implements get_checkpoint_info, so that checkpoint and restore are
enabled together as a complete and testable unit.
Note: GFX12.1 restore handles XCC0 only. Multi-XCC CRIU restore is
currently unreachable due to a separate validation issue in
kfd_criu_restore_queue(). A pr_warn_once() is emitted if a multi-XCC
device is encountered.
Signed-off-by: Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit b1f9601237d050f5df478464cf51bf1fff29a256)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c | 7 +
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12.c | 59 +++++++++++++++
drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c | 68 ++++++++++++++++++
3 files changed, 132 insertions(+), 2 deletions(-)
--- a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
@@ -797,10 +797,12 @@ static int create_queue_nocpsch(struct d
mqd_mgr = dqm->mqd_mgrs[get_mqd_type_from_queue_type(
q->properties.type)];
if (qd && !mqd_mgr->restore_mqd) {
- pr_debug("restore_mqd not implemented for this GPU\n");
+ pr_debug("restore_mqd not implemented for queue type %d\n",
+ q->properties.type);
retval = -EOPNOTSUPP;
goto deallocate_vmid;
}
+
if (q->properties.type == KFD_QUEUE_TYPE_COMPUTE) {
retval = allocate_hqd(dqm, q);
if (retval)
@@ -2168,7 +2170,8 @@ static int create_queue_cpsch(struct dev
mqd_mgr = dqm->mqd_mgrs[get_mqd_type_from_queue_type(
q->properties.type)];
if (qd && !mqd_mgr->restore_mqd) {
- pr_debug("restore_mqd not implemented for this GPU\n");
+ pr_debug("restore_mqd not implemented for queue type %d\n",
+ q->properties.type);
retval = -EOPNOTSUPP;
goto out_deallocate_doorbell;
}
--- a/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12.c
@@ -380,6 +380,63 @@ static int debugfs_show_mqd_sdma(struct
#endif
+static void restore_mqd(struct mqd_manager *mm, void **mqd,
+ struct kfd_mem_obj *mqd_mem_obj, uint64_t *gart_addr,
+ struct queue_properties *qp, const void *mqd_src,
+ const void *ctl_stack_src, const u32 ctl_stack_size)
+{
+ u64 addr;
+ struct v12_compute_mqd *m;
+
+ m = (struct v12_compute_mqd *)mqd_mem_obj->cpu_ptr;
+ addr = mqd_mem_obj->gpu_addr;
+
+ memset(m, 0, AMDGPU_MQD_SIZE_ALIGN(mm->mqd_size));
+ memcpy(m, mqd_src, sizeof(*m));
+
+ /* Update MQD base address to the newly allocated location */
+ m->cp_mqd_base_addr_lo = lower_32_bits(addr);
+ m->cp_mqd_base_addr_hi = upper_32_bits(addr);
+
+ m->cp_hqd_pq_doorbell_control &=
+ ~CP_HQD_PQ_DOORBELL_CONTROL__DOORBELL_OFFSET_MASK;
+ m->cp_hqd_pq_doorbell_control |=
+ qp->doorbell_off << CP_HQD_PQ_DOORBELL_CONTROL__DOORBELL_OFFSET__SHIFT;
+ pr_debug("cp_hqd_pq_doorbell_control 0x%x\n", m->cp_hqd_pq_doorbell_control);
+
+ *mqd = m;
+ if (gart_addr)
+ *gart_addr = addr;
+
+ qp->is_active = 0;
+}
+
+static void restore_mqd_sdma(struct mqd_manager *mm, void **mqd,
+ struct kfd_mem_obj *mqd_mem_obj, uint64_t *gart_addr,
+ struct queue_properties *qp,
+ const void *mqd_src,
+ const void *ctl_stack_src,
+ const u32 ctl_stack_size)
+{
+ u64 addr;
+ struct v12_sdma_mqd *m;
+
+ m = (struct v12_sdma_mqd *)mqd_mem_obj->cpu_ptr;
+ addr = mqd_mem_obj->gpu_addr;
+
+ memset(m, 0, AMDGPU_MQD_SIZE_ALIGN(mm->mqd_size));
+ memcpy(m, mqd_src, sizeof(*m));
+
+ m->sdmax_rlcx_doorbell_offset =
+ qp->doorbell_off << SDMA0_QUEUE0_DOORBELL_OFFSET__OFFSET__SHIFT;
+
+ *mqd = m;
+ if (gart_addr)
+ *gart_addr = addr;
+
+ qp->is_active = 0;
+}
+
struct mqd_manager *mqd_manager_init_v12(enum KFD_MQD_TYPE type,
struct kfd_node *dev)
{
@@ -407,6 +464,7 @@ struct mqd_manager *mqd_manager_init_v12
mqd->mqd_size = sizeof(struct v12_compute_mqd);
mqd->get_wave_state = get_wave_state;
mqd->mqd_stride = kfd_mqd_stride;
+ mqd->restore_mqd = restore_mqd;
#if defined(CONFIG_DEBUG_FS)
mqd->debugfs_show_mqd = debugfs_show_mqd;
#endif
@@ -453,6 +511,7 @@ struct mqd_manager *mqd_manager_init_v12
mqd->is_occupied = kfd_is_occupied_sdma;
mqd->mqd_size = sizeof(struct v12_sdma_mqd);
mqd->mqd_stride = kfd_mqd_stride;
+ mqd->restore_mqd = restore_mqd_sdma;
#if defined(CONFIG_DEBUG_FS)
mqd->debugfs_show_mqd = debugfs_show_mqd_sdma;
#endif
--- a/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_mqd_manager_v12_1.c
@@ -641,6 +641,72 @@ static int debugfs_show_mqd_sdma(struct
#endif
+static void restore_mqd_v12_1(struct mqd_manager *mm, void **mqd,
+ struct kfd_mem_obj *mqd_mem_obj, uint64_t *gart_addr,
+ struct queue_properties *qp, const void *mqd_src,
+ const void *ctl_stack_src, const u32 ctl_stack_size)
+{
+ u64 addr;
+ struct v12_1_compute_mqd *m;
+
+ /*
+ * GFX12.1 is multi-XCC capable but this restore handles XCC0 only.
+ * Multi-XCC CRIU restore is currently unreachable because
+ * kfd_criu_restore_queue() validates against unscaled mqd_size.
+ */
+ if (NUM_XCC(mm->dev->xcc_mask) > 1)
+ pr_warn_once("GFX12.1 multi-XCC CRIU restore not fully supported\n");
+
+ m = (struct v12_1_compute_mqd *)mqd_mem_obj->cpu_ptr;
+ addr = mqd_mem_obj->gpu_addr;
+
+ memset(m, 0, AMDGPU_MQD_SIZE_ALIGN(mm->mqd_size) *
+ NUM_XCC(mm->dev->xcc_mask));
+ memcpy(m, mqd_src, sizeof(*m));
+
+ /* Update MQD base address to the newly allocated location */
+ m->cp_mqd_base_addr_lo = lower_32_bits(addr);
+ m->cp_mqd_base_addr_hi = upper_32_bits(addr);
+
+ m->cp_hqd_pq_doorbell_control &=
+ ~CP_HQD_PQ_DOORBELL_CONTROL__DOORBELL_OFFSET_MASK;
+ m->cp_hqd_pq_doorbell_control |=
+ qp->doorbell_off << CP_HQD_PQ_DOORBELL_CONTROL__DOORBELL_OFFSET__SHIFT;
+ pr_debug("cp_hqd_pq_doorbell_control 0x%x\n", m->cp_hqd_pq_doorbell_control);
+
+ *mqd = m;
+ if (gart_addr)
+ *gart_addr = addr;
+
+ qp->is_active = 0;
+}
+
+static void restore_mqd_sdma_v12_1(struct mqd_manager *mm, void **mqd,
+ struct kfd_mem_obj *mqd_mem_obj, uint64_t *gart_addr,
+ struct queue_properties *qp,
+ const void *mqd_src,
+ const void *ctl_stack_src,
+ const u32 ctl_stack_size)
+{
+ u64 addr;
+ struct v12_sdma_mqd *m;
+
+ m = (struct v12_sdma_mqd *)mqd_mem_obj->cpu_ptr;
+ addr = mqd_mem_obj->gpu_addr;
+
+ memset(m, 0, AMDGPU_MQD_SIZE_ALIGN(mm->mqd_size));
+ memcpy(m, mqd_src, sizeof(*m));
+
+ m->sdmax_rlcx_doorbell_offset =
+ qp->doorbell_off << SDMA0_SDMA_QUEUE0_DOORBELL_OFFSET__OFFSET__SHIFT;
+
+ *mqd = m;
+ if (gart_addr)
+ *gart_addr = addr;
+
+ qp->is_active = 0;
+}
+
struct mqd_manager *mqd_manager_init_v12_1(enum KFD_MQD_TYPE type,
struct kfd_node *dev)
{
@@ -668,6 +734,7 @@ struct mqd_manager *mqd_manager_init_v12
mqd->mqd_size = sizeof(struct v12_1_compute_mqd);
mqd->get_wave_state = get_wave_state_v12_1;
mqd->mqd_stride = kfd_mqd_stride;
+ mqd->restore_mqd = restore_mqd_v12_1;
#if defined(CONFIG_DEBUG_FS)
mqd->debugfs_show_mqd = debugfs_show_mqd;
#endif
@@ -714,6 +781,7 @@ struct mqd_manager *mqd_manager_init_v12
mqd->is_occupied = kfd_is_occupied_sdma;
mqd->mqd_size = sizeof(struct v12_sdma_mqd);
mqd->mqd_stride = kfd_mqd_stride;
+ mqd->restore_mqd = restore_mqd_sdma_v12_1;
#if defined(CONFIG_DEBUG_FS)
mqd->debugfs_show_mqd = debugfs_show_mqd_sdma;
#endif
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 359/398] ntsync: reject wait ioctls with zero owner
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (355 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 358/398] ntsync: Honour callers time namespace for absolute MONOTONIC timeouts Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 360/398] smb: client: fix busy dentry warning on unmount after DIO Greg Kroah-Hartman
` (45 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Iván Ezequiel Rodriguez,
Griffin Kroah-Hartman, Elizabeth Figura, Alice Ryhl
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
commit 61611481f7b599e0526a3782c626b1a9deeb48bd upstream.
setup_wait() already validates pad and flags but not owner, while
Documentation/userspace-api/ntsync.rst requires EINVAL when owner is
zero. Reject early before queueing waiters.
Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Signed-off-by: Griffin Kroah-Hartman <griffin@kroah.com>
Reviewed-by: Elizabeth Figura <zfigura@codeweavers.com>
Signed-off-by: Elizabeth Figura <zfigura@codeweavers.com>
Link: https://patch.msgid.link/20260723201301.11826-4-zfigura@codeweavers.com
Cc: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/misc/ntsync.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/misc/ntsync.c
+++ b/drivers/misc/ntsync.c
@@ -884,6 +884,9 @@ static int setup_wait(struct ntsync_devi
if (args->pad || (args->flags & ~NTSYNC_WAIT_REALTIME))
return -EINVAL;
+ if (!args->owner)
+ return -EINVAL;
+
if (size >= sizeof(fds))
return -EINVAL;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 413/438] smb: client: cancel reconnect work in clean_demultiplex_info()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (411 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 412/438] drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1 Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 414/438] smb/client: send lease break ACKs thru correct session for multiuser mounts Greg Kroah-Hartman
` (36 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+5003556314abc915a71f,
Namjae Jeon, Paulo Alcantara, David Howells, Shyam Prasad N,
Ronnie Sahlberg, Tom Talpey, Bharath SM
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paulo Alcantara <pc@manguebit.org>
commit c65eae6f61d1778ff7a82e4aae4080e26f486af1 upstream.
clean_demultiplex_info() cancels server->echo delayed work but not
server->reconnect, which can cause a use-after-free when the
demultiplex thread exits while a reconnect work is still queued:
cifs_demultiplex_thread()
cifs_readv_from_socket()
cifs_reconnect()
__cifs_reconnect()
cifs_queue_server_reconn()
mod_delayed_work(cifsiod_wq, &server->reconnect, 0)
clean_demultiplex_info()
cancel_delayed_work_sync(&server->echo) // echo canceled
// reconnect NOT canceled
kfree_sensitive(server) // server freed
...later, on cifsiod_wq:
smb2_reconnect_server()
server->srv_count // UAF read of freed server
Fix this by canceling server->reconnect delayed work in
clean_demultiplex_info() before the server is freed, the same way
cifs_put_tcp_session() already does.
Reported-by: syzbot+5003556314abc915a71f@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/r/6aa4a12d.f81106d8.2ab401.0023.GAE@google.com
Fixes: 53e0e11efe92 ("CIFS: Fix a possible memory corruption during reconnect")
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: David Howells <dhowells@redhat.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/connect.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/smb/client/connect.c
+++ b/fs/smb/client/connect.c
@@ -1067,6 +1067,7 @@ clean_demultiplex_info(struct TCP_Server
spin_unlock(&server->srv_lock);
cancel_delayed_work_sync(&server->echo);
+ cancel_delayed_work_sync(&server->reconnect);
spin_lock(&server->srv_lock);
server->tcpStatus = CifsExiting;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 360/398] smb: client: fix busy dentry warning on unmount after DIO
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (356 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 359/398] ntsync: reject wait ioctls with zero owner Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 361/398] ALSA: usb-audio: Optimize the copy of packet sizes for implicit fb handling Greg Kroah-Hartman
` (44 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zizhi Wo, Steve French,
Hamza Mahfooz
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zizhi Wo <wozizhi@huawei.com>
commit 75f5c412fa867efa0bf9b646bffe0d912109e84a upstream.
Commit c68337442f03 ("cifs: Fix busy dentry used after unmounting") fixed
the issue in cifs where deferred close of a file led to a dentry reference
count not being released in umount, by flushing deferredclose_wq in
cifs_kill_sb() to solve it.
However, the cifs DIO path suffers from the same busy-dentry problem caused
by a delayed dentry reference-count release:
[dio] [cifsd] [close + umount]
netfs_unbuffered_write_iter_locked
...
cifs_demultiplex_thread
netfs_unbuffered_write
cifs_issue_write
netfs_wait_for_in_progress_stream [1]
...
netfs_write_subrequest_terminated
netfs_subreq_clear_in_progress
netfs_wake_collector // wake [1]
netfs_put_subrequest
netfs_put_request
queue_work(system_dfl_wq, xxx) [2]
// dio write return cifs_close
_cifsFileInfo_put
// cfile->count 2->1
--cfile->count [3]
// umount
cifs_kill_sb
kill_anon_super
// warning triggered!
shrink_dcache_for_umount [4]
[system_dfl_wq] [5]
netfs_free_request
...
_cifsFileInfo_put
// cfile->count 1->0
--cfile->count
queue_work(fileinfo_put_wq, xxx)
[fileinfo_put_wq] [6]
cifsFileInfo_put_work
cifsFileInfo_put_final
dput
If the umount path is triggered before [5], it results warning:
BUG: Dentry 00000000eab1f070{i=9a917b66ae404fec,n=test} still in use (1)
[unmount of cifs cifs]
The existing per-inode ictx->io_count wait in cifs_evict_inode() does not
help: it lives in the inode eviction path, which runs after
shrink_dcache_for_umount() has already warned about the busy dentries.
Fix it by adding a per-superblock outstanding-rreq counter that is
incremented in cifs_init_request() and decremented in cifs_free_request().
In cifs_kill_sb(), before kill_anon_super(), wait for this counter to reach
0 - which guarantees that all cleanup_work for this sb have run and thus
all relevant cfile puts are queued on fileinfo_put_wq or serverclose_wq.
Then drain the workqueue so the dentry refs are dropped.
This is a targeted wait, not a flush of the system-wide system_dfl_wq.
Fixes: 340cea84f691c ("cifs: open files should not hold ref on superblock")
Signed-off-by: Zizhi Wo <wozizhi@huawei.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
Signed-off-by: Hamza Mahfooz <hamzamahfooz@linux.microsoft.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/cifs_fs_sb.h | 1 +
fs/smb/client/cifsfs.c | 12 ++++++++++++
fs/smb/client/connect.c | 1 +
fs/smb/client/file.c | 5 +++++
4 files changed, 19 insertions(+)
--- a/fs/smb/client/cifs_fs_sb.h
+++ b/fs/smb/client/cifs_fs_sb.h
@@ -57,6 +57,7 @@ struct cifs_sb_info {
struct smb3_fs_context *ctx;
atomic_t active;
atomic_t mnt_cifs_flags;
+ atomic_t outstanding_rreq; /* nr of rreqs not yet fully deinitialized */
struct delayed_work prune_tlinks;
struct rcu_head rcu;
--- a/fs/smb/client/cifsfs.c
+++ b/fs/smb/client/cifsfs.c
@@ -342,6 +342,18 @@ static void cifs_kill_sb(struct super_bl
/* Wait for all opened files to release */
flush_workqueue(deferredclose_wq);
+ /*
+ * Wait for all in-flight netfs I/O requests to finish their
+ * cleanup_work so that any cifsFileInfo final puts they queue
+ * to fileinfo_put_wq/serverclose_wq have been queued, then
+ * drain the workqueue so the cfile dentry refs are dropped to
+ * avoid the busy dentry warning.
+ */
+ wait_var_event(&cifs_sb->outstanding_rreq,
+ !atomic_read(&cifs_sb->outstanding_rreq));
+ flush_workqueue(serverclose_wq);
+ flush_workqueue(fileinfo_put_wq);
+
/* finally release root dentry */
dput(cifs_sb->root);
cifs_sb->root = NULL;
--- a/fs/smb/client/connect.c
+++ b/fs/smb/client/connect.c
@@ -3597,6 +3597,7 @@ int cifs_setup_cifs_sb(struct cifs_sb_in
spin_lock_init(&cifs_sb->tlink_tree_lock);
cifs_sb->tlink_tree = RB_ROOT;
+ atomic_set(&cifs_sb->outstanding_rreq, 0);
cifs_dbg(FYI, "file mode: %04ho dir mode: %04ho\n",
ctx->file_mode, ctx->dir_mode);
--- a/fs/smb/client/file.c
+++ b/fs/smb/client/file.c
@@ -289,6 +289,7 @@ static int cifs_init_request(struct netf
return -EIO;
}
+ atomic_inc(&cifs_sb->outstanding_rreq);
return 0;
}
@@ -310,9 +311,13 @@ static void cifs_rreq_done(struct netfs_
static void cifs_free_request(struct netfs_io_request *rreq)
{
struct cifs_io_request *req = container_of(rreq, struct cifs_io_request, rreq);
+ struct cifs_sb_info *cifs_sb = CIFS_SB(rreq->inode->i_sb);
if (req->cfile)
cifsFileInfo_put(req->cfile);
+
+ if (atomic_dec_and_test(&cifs_sb->outstanding_rreq))
+ wake_up_var(&cifs_sb->outstanding_rreq);
}
static void cifs_free_subrequest(struct netfs_io_subrequest *subreq)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 414/438] smb/client: send lease break ACKs thru correct session for multiuser mounts
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (412 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 413/438] smb: client: cancel reconnect work in clean_demultiplex_info() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 415/438] smb: client: fix rlist race and missing initialization Greg Kroah-Hartman
` (35 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, April Cardenas, Namjae Jeon,
Bharath S M, Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: April Cardenas <april.cardenas@canonical.com>
commit ebc5660132ddd244b57f03ed324922013a3d7363 upstream.
Currently, when cifs_oplock_break handles a break request from the server
it searches for the appropriate tlink to handle the request
but incorrectly uses the current fsuid as the search key, eventually
causing read errors for users with multiuser mounts on NetApp.
Fix this by using the tlink from the cfile struct instead to respond
through the correct session.
As breaks are handled in a worker thread, the current fsuid
isn't guaranteed to match the session that the break is intended for.
This means that cifs_sb_tlink may search the rbtree using the wrong fsuid,
and return a tlink with an incorrect session than
the lease break was intended for. As a result, the breaks
may be ACKed through an incorrect session.
While it seems that Samba/Windows Servers 2016-2025 ignore this as long as
the lease key is correct, we ran into a case where if you're using
NetApp ONTAP or Azure NetApp Files they will reject the ACK
and return `STATUS_LOCK_NOT_GRANTED` errors on any future read requests
a user may initiate through their still held open file handle,
and the server will eventually close the file.
In the dmesg logs, the user may see errors like these:
CIFS: Status code returned 0xc0000128 STATUS_FILE_CLOSED
CIFS: VFS: Send error in read = -9
With a multiuser mount using NetApp, this issue is really easy
for users to hit on a wide variety of kernel versions
by attempting to copy a file from the share
to the local machine through GNOME Files/Nautilus.
This copy will always result in Nautilus throwing
a `Bad File Descriptor` error to the user and fail.
With this fix, you can copy files through Nautilus without issue.
>From looking at the traces, it seems that glib will
open the file first, and call listxattr before actually attempting
to copy the file data. The listxattr call always triggers a break,
causing the copy to fail.
The proposed fix returns to the way the client grabbed the tlink before
commit e8f5f849ffce2 ("cifs: fix potential oops in cifs_oplock_break").
The bulk of that commit (checking for list empty) remains untouched, and
I think the change to using cifs_sb_tlink was intended to avoid a
NULL/ERR deference on the tlink as well as update the reference count.
I believe this fix should preserve those safety properties, but of course
I'd appreciate any corrections here.
Fixes: e8f5f849ffce2 ("cifs: fix potential oops in cifs_oplock_break")
Cc: stable@vger.kernel.org
Signed-off-by: April Cardenas <april.cardenas@canonical.com>
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Reviewed-by: Bharath S M <bharathsm@microsoft.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/file.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/fs/smb/client/file.c
+++ b/fs/smb/client/file.c
@@ -3330,8 +3330,8 @@ void cifs_oplock_break(struct work_struc
wait_on_bit(&cinode->flags, CIFS_INODE_PENDING_WRITERS,
TASK_UNINTERRUPTIBLE);
- tlink = cifs_sb_tlink(cifs_sb);
- if (IS_ERR(tlink)) {
+ tlink = cifs_get_tlink(cfile->tlink);
+ if (IS_ERR_OR_NULL(tlink)) {
/* drop the reference taken when the break was queued */
_cifsFileInfo_put(cfile, false /* do not wait for ourself */, false);
goto out;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 361/398] ALSA: usb-audio: Optimize the copy of packet sizes for implicit fb handling
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (357 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 360/398] smb: client: fix busy dentry warning on unmount after DIO Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 362/398] ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity Greg Kroah-Hartman
` (43 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 36adb51ac0b19edb32ffeea3fe66b174bad25ead ]
We did manual copies over loop for the packet data update of the
implicit feedback, but this can be optimized with a simple memcpy().
Along with it, change the data type of snd_usb_packet_info struct to
align with other (from uint32_t to int).
No functional changes but only code optimizations.
Link: https://patch.msgid.link/20260216141209.1849200-3-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Stable-dep-of: 76a986c980bb ("ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/card.h | 2 +-
sound/usb/endpoint.c | 6 +++---
2 files changed, 4 insertions(+), 4 deletions(-)
--- a/sound/usb/card.h
+++ b/sound/usb/card.h
@@ -90,7 +90,7 @@ struct snd_usb_endpoint {
struct snd_urb_ctx urb[MAX_URBS];
struct snd_usb_packet_info {
- uint32_t packet_size[MAX_PACKS_HS];
+ int packet_size[MAX_PACKS_HS];
int packets;
} next_packet[MAX_URBS];
unsigned int next_packet_head; /* ring buffer offset to read */
--- a/sound/usb/endpoint.c
+++ b/sound/usb/endpoint.c
@@ -470,7 +470,7 @@ int snd_usb_queue_pending_output_urbs(st
while (ep_state_running(ep)) {
struct snd_usb_packet_info *packet;
struct snd_urb_ctx *ctx = NULL;
- int err, i;
+ int err;
scoped_guard(spinlock_irqsave, &ep->lock) {
if ((!implicit_fb || ep->next_packet_queued > 0) &&
@@ -490,8 +490,8 @@ int snd_usb_queue_pending_output_urbs(st
/* copy over the length information */
if (implicit_fb) {
ctx->packets = packet->packets;
- for (i = 0; i < packet->packets; i++)
- ctx->packet_size[i] = packet->packet_size[i];
+ memcpy(ctx->packet_size, packet->packet_size,
+ packet->packets * sizeof(packet->packet_size[0]));
}
/* call the data handler to fill in playback data */
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 415/438] smb: client: fix rlist race and missing initialization
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (413 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 414/438] smb/client: send lease break ACKs thru correct session for multiuser mounts Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 416/438] smb: client: fix use-after-free of iface in cifs_try_adding_channels() Greg Kroah-Hartman
` (34 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Paulo Alcantara,
David Howells, Shyam Prasad N, Ronnie Sahlberg, Tom Talpey,
Bharath SM
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paulo Alcantara <pc@manguebit.org>
commit 5f270f091256da1338c3631083e15d7f83cc05e1 upstream.
TCP_Server_Info.rlist is allocated via kzalloc which zeros both ->next
and ->prev to NULL instead of pointing to itself, making list_empty()
always return false and list_add() dereference a NULL ->prev pointer.
Also, cifs_signal_cifsd_for_reconnect() can be called concurrently
from multiple cifsd threads, allowing the same server's rlist node to
be added twice into the local list, corrupting it.
Closes: https://sashiko.dev/#/patchset/20260911204446.1719356-1-pc%40manguebit.org
Fixes: df0e03a4fb94 ("smb: client: fix potential deadlock when reconnecting channels")
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: David Howells <dhowells@redhat.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/connect.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/fs/smb/client/connect.c
+++ b/fs/smb/client/connect.c
@@ -174,6 +174,8 @@ cifs_signal_cifsd_for_reconnect(struct T
nserver = ses->chans[i].server;
if (!nserver)
continue;
+ if (!list_empty(&nserver->rlist))
+ continue;
nserver->srv_count++;
list_add(&nserver->rlist, &reco);
}
@@ -182,11 +184,15 @@ cifs_signal_cifsd_for_reconnect(struct T
}
}
+ spin_lock(&cifs_tcp_ses_lock);
list_for_each_entry_safe(server, nserver, &reco, rlist) {
list_del_init(&server->rlist);
set_need_reco(server);
+ spin_unlock(&cifs_tcp_ses_lock);
cifs_put_tcp_session(server, 0);
+ spin_lock(&cifs_tcp_ses_lock);
}
+ spin_unlock(&cifs_tcp_ses_lock);
}
/*
@@ -1824,6 +1830,7 @@ cifs_get_tcp_session(struct smb3_fs_cont
spin_lock_init(&tcp_ses->mid_counter_lock);
INIT_LIST_HEAD(&tcp_ses->tcp_ses_list);
INIT_LIST_HEAD(&tcp_ses->smb_ses_list);
+ INIT_LIST_HEAD(&tcp_ses->rlist);
INIT_DELAYED_WORK(&tcp_ses->echo, cifs_echo_request);
INIT_DELAYED_WORK(&tcp_ses->reconnect, smb2_reconnect_server);
mutex_init(&tcp_ses->reconnect_mutex);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 362/398] ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (358 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 361/398] ALSA: usb-audio: Optimize the copy of packet sizes for implicit fb handling Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 363/398] signal: Move MMCID exit out of sighand lock Greg Kroah-Hartman
` (42 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, co+8eacd4fa193b1b28, Xiang Mei,
Takashi Iwai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit 76a986c980bb502c7688d605ac7a67fd257a9a1b ]
data_ep_set_params() allocates each data URB for exactly u->packets
isochronous frames, so urb->iso_frame_desc[] has u->packets slots and
ctx->packets is the driver's only record of that limit. For an implicit
feedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the
sync source's packet count, which is calculated independently from the
capture endpoint's parameters. When that count is larger,
prepare_playback_urb() and prepare_silent_urb() can write
iso_frame_desc[] past the allocation; their existing bounds limit payload
bytes, not the descriptor index.
The reproducer uses a high-speed UAC2 device declaring bInterval 1 for
implicit feedback capture (8 packets) and bInterval 4 for playback
(1 packet). On the first capture completion after the stream starts, it
accesses seven descriptors spanning 112 bytes beyond the one-packet URB:
BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560)
Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178
prepare_playback_urb (sound/usb/pcm.c:1560)
prepare_outbound_urb (sound/usb/endpoint.c:340)
snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501)
snd_complete_urb (sound/usb/endpoint.c:1834)
__usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107)
kthread (kernel/kthread.c:436)
The buggy address belongs to the object at ffff88801e696a00
which belongs to the cache kmalloc-256 of size 256
The buggy address is located 0 bytes to the right of
allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0)
Record the allocated packet count per endpoint and clamp both the adopted
count and the packet-size copy to it. Fold the Format Type II delimiter
into urb_packs before the allocation loop so the recorded limit matches
every URB.
Fixes: cf044e441902 ("ALSA: usb-audio: Update the number of packets properly at receiving")
Reported-by: co+8eacd4fa193b1b28@bugs.sh
Closes: https://lore.kernel.org/all/22xPn8drvIUtYgVeQnBiNqXuevOTpBAjepLz%40bugs.sh/
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Link: https://patch.msgid.link/20260912200530.1955491-1-xmei5@asu.edu
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/card.h | 1 +
sound/usb/endpoint.c | 12 +++++++-----
2 files changed, 8 insertions(+), 5 deletions(-)
--- a/sound/usb/card.h
+++ b/sound/usb/card.h
@@ -116,6 +116,7 @@ struct snd_usb_endpoint {
unsigned int phase; /* phase accumulator */
unsigned int maxpacksize; /* max packet size in bytes */
unsigned int maxframesize; /* max packet size in frames */
+ unsigned int max_urb_packs; /* packets allocated per data URB */
unsigned int max_urb_frames; /* max URB size in frames */
unsigned int curpacksize; /* current packet size in bytes (for capture) */
unsigned int curframesize; /* current packet size in frames (for capture) */
--- a/sound/usb/endpoint.c
+++ b/sound/usb/endpoint.c
@@ -489,9 +489,10 @@ int snd_usb_queue_pending_output_urbs(st
/* copy over the length information */
if (implicit_fb) {
- ctx->packets = packet->packets;
+ ctx->packets = min_t(int, packet->packets,
+ ep->max_urb_packs);
memcpy(ctx->packet_size, packet->packet_size,
- packet->packets * sizeof(packet->packet_size[0]));
+ ctx->packets * sizeof(packet->packet_size[0]));
}
/* call the data handler to fill in playback data */
@@ -1235,15 +1236,16 @@ static int data_ep_set_params(struct snd
ep->nurbs = min(max_urbs, urbs_per_period * ep->cur_buffer_periods);
}
+ if (fmt->fmt_type == UAC_FORMAT_TYPE_II)
+ urb_packs++; /* for transfer delimiter */
+ ep->max_urb_packs = urb_packs;
+
/* allocate and initialize data urbs */
for (i = 0; i < ep->nurbs; i++) {
struct snd_urb_ctx *u = &ep->urb[i];
u->index = i;
u->ep = ep;
u->packets = urb_packs;
-
- if (fmt->fmt_type == UAC_FORMAT_TYPE_II)
- u->packets++; /* for transfer delimiter */
u->buffer_size = maxsize * u->packets;
u->urb = usb_alloc_urb(u->packets, GFP_KERNEL);
if (!u->urb)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 416/438] smb: client: fix use-after-free of iface in cifs_try_adding_channels()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (414 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 415/438] smb: client: fix rlist race and missing initialization Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 417/438] smb: client: reject short Next offsets in parse_server_interfaces() Greg Kroah-Hartman
` (33 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joseph Qi, Shyam Prasad N,
Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joseph Qi <joseph.qi@linux.alibaba.com>
commit d034e836eefd7ce75e588f7031cffbeec594f5ac upstream.
cifs_try_adding_channels() iterates ses->iface_list with
list_for_each_entry_safe_from(), which captures the next entry
(niface) under iface_lock. The loop body then drops iface_lock for
the whole duration of cifs_ses_add_channel().
A concurrent interface refresh (SMB3_request_interfaces() ->
parse_server_interfaces()) marks all ifaces inactive and removes and
frees any that are not re-advertised via list_del() + kref_put(),
where release_iface() is a bare kfree(). Since niface typically has
no channel holding a reference, the list reference is its last and it
can be freed inside the unlocked window. On continue, the iterator
advance step then dereferences niface->iface_head.next, and the loop
body reads iface->rdma_capable/is_active, both on freed memory.
Fix this by never keeping an unreferenced list pointer across the
unlocked window. Each channel attempt now re-scans the list from the
head under iface_lock, takes a kref on the selected candidate, and
passes only that referenced candidate to cifs_ses_add_channel().
weight_fulfilled still tracks selection progress, so restarting the
scan preserves the original weighted distribution and the
weight_fulfilled-before-kref_put ordering on the failure path.
Add a per-pass attempts cap so a flapping interface refresh cannot
keep the inner loop spinning within a single tries increment.
Fixes: aa45dadd34e4 ("cifs: change iface_list from array to sorted linked list")
Cc: stable@vger.kernel.org
Assisted-by: Qoder:Qwen3.8-Max
Signed-off-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Acked-by: Shyam Prasad N <sprasad@microsoft.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/sess.c | 106 ++++++++++++++++++++++++++++++---------------------
1 file changed, 64 insertions(+), 42 deletions(-)
--- a/fs/smb/client/sess.c
+++ b/fs/smb/client/sess.c
@@ -149,9 +149,9 @@ int cifs_try_adding_channels(struct cifs
int old_chan_count, new_chan_count;
int left;
int rc = 0;
- int tries = 0;
+ int tries = 0, attempts;
size_t iface_weight = 0, iface_min_speed = 0;
- struct cifs_server_iface *iface = NULL, *niface = NULL;
+ struct cifs_server_iface *iface = NULL, *candidate = NULL;
struct cifs_server_iface *last_iface = NULL;
spin_lock(&ses->chan_lock);
@@ -197,67 +197,89 @@ int cifs_try_adding_channels(struct cifs
break;
}
- if (!iface)
- iface = list_first_entry(&ses->iface_list, struct cifs_server_iface,
- iface_head);
last_iface = list_last_entry(&ses->iface_list, struct cifs_server_iface,
iface_head);
iface_min_speed = last_iface->speed;
+ spin_unlock(&ses->iface_lock);
- list_for_each_entry_safe_from(iface, niface, &ses->iface_list,
- iface_head) {
- /* do not mix rdma and non-rdma interfaces */
- if (iface->rdma_capable != ses->server->rdma)
- continue;
-
- /* skip ifaces that are unusable */
- if (!iface->is_active ||
- (is_ses_using_iface(ses, iface) &&
- !iface->rss_capable))
- continue;
+ attempts = 0;
+ while (left > 0) {
+ spin_lock(&ses->iface_lock);
- /* check if we already allocated enough channels */
- iface_weight = iface->speed / iface_min_speed;
+ /*
+ * iface_lock must be dropped while opening a channel,
+ * and a concurrent interface refresh may remove and
+ * free entries during that window, so no list entry
+ * may be kept across it without a reference. Scan
+ * the list from the beginning each time and only pass
+ * a referenced candidate to cifs_ses_add_channel();
+ * weight_fulfilled tracks the progress so that no
+ * iface is selected beyond its weight.
+ */
+ candidate = NULL;
+ list_for_each_entry(iface, &ses->iface_list, iface_head) {
+ /* do not mix rdma and non-rdma interfaces */
+ if (iface->rdma_capable != ses->server->rdma)
+ continue;
+
+ /* skip ifaces that are unusable */
+ if (!iface->is_active ||
+ (is_ses_using_iface(ses, iface) &&
+ !iface->rss_capable))
+ continue;
+
+ /* check if we already allocated enough channels */
+ iface_weight = iface->speed / iface_min_speed;
+
+ if (iface->weight_fulfilled >= iface_weight)
+ continue;
+
+ /* take ref before unlock */
+ kref_get(&iface->refcount);
+ candidate = iface;
+ break;
+ }
- if (iface->weight_fulfilled >= iface_weight)
- continue;
+ if (!candidate) {
+ /* no usable iface. reset weight_fulfilled and start over */
+ list_for_each_entry(iface, &ses->iface_list, iface_head)
+ iface->weight_fulfilled = 0;
+ spin_unlock(&ses->iface_lock);
+ break;
+ }
- /* take ref before unlock */
- kref_get(&iface->refcount);
+ attempts++;
+ if (attempts > 3 * ses->chan_max) {
+ kref_put(&candidate->refcount, release_iface);
+ spin_unlock(&ses->iface_lock);
+ break;
+ }
spin_unlock(&ses->iface_lock);
- rc = cifs_ses_add_channel(ses, iface);
+ rc = cifs_ses_add_channel(ses, candidate);
spin_lock(&ses->iface_lock);
if (rc) {
cifs_dbg(VFS, "failed to open extra channel on iface:%pIS rc=%d\n",
- &iface->sockaddr,
+ &candidate->sockaddr,
rc);
/* failure to add chan should increase weight */
- iface->weight_fulfilled++;
- kref_put(&iface->refcount, release_iface);
+ candidate->weight_fulfilled++;
+ kref_put(&candidate->refcount, release_iface);
+ spin_unlock(&ses->iface_lock);
continue;
}
- iface->num_channels++;
- iface->weight_fulfilled++;
+ candidate->num_channels++;
+ candidate->weight_fulfilled++;
cifs_info("successfully opened new channel on iface:%pIS\n",
- &iface->sockaddr);
- break;
- }
-
- /* reached end of list. reset weight_fulfilled and start over */
- if (list_entry_is_head(iface, &ses->iface_list, iface_head)) {
- list_for_each_entry(iface, &ses->iface_list, iface_head)
- iface->weight_fulfilled = 0;
+ &candidate->sockaddr);
spin_unlock(&ses->iface_lock);
- iface = NULL;
- continue;
- }
- spin_unlock(&ses->iface_lock);
- left--;
- new_chan_count++;
+ left--;
+ new_chan_count++;
+ break;
+ }
}
return new_chan_count - old_chan_count;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 363/398] signal: Move MMCID exit out of sighand lock
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (359 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 362/398] ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 364/398] signal: Prevent exec() race Greg Kroah-Hartman
` (41 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Gleixner,
Peter Zijlstra (Intel), Mathieu Desnoyers, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Gleixner <tglx@linutronix.de>
[ Upstream commit 2b1642b881088bbf73fcb1147c474a198ec46729 ]
There is no need anymore to keep this under sighand lock as the current
code and the upcoming replacement are not depending on the exit state of a
task anymore.
That allows to use a mutex in the exit path.
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Reviewed-by: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Link: https://patch.msgid.link/20251119172549.706439391@linutronix.de
[Backport to 6.18: Keep the MMCID declarations and CONFIG_SCHED_MM_CID
stub in include/linux/mm.h, where they live in this tree, and rename the
existing exit helper and its barrier-comment references there and in
kernel/sched/core.c. Preserve the stable helper's runqueue locking,
mm_cid_active store, memory barrier and per-CPU CID release, as well as
the separate sched_mm_cid_before_execve() implementation. This tree does
not have the upstream MMCID refactoring that moved the declarations to
sched.h and made the exec helper call the exit helper.
Move the existing exit cleanup before exit_signals() in do_exit(), as
upstream does. This removes the MMCID calls from the exit_signals() code
rewritten by d2710c8d938ae ("signal: Prevent exec() race"), allowing that
fix to apply without importing unrelated MMCID changes. No functions are
added.]
[ sashal: Reduced backport -- upstream 2b1642b881088 touches 4 file(s), this
backport carries 4. Not backported here:
include/linux/sched.h
This note is generated from the file lists only; see the resolution record
for the reasoning. ]
Stable-dep-of: d2710c8d938a ("signal: Prevent exec() race")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/mm.h | 4 ++--
kernel/exit.c | 1 +
kernel/sched/core.c | 6 +++---
kernel/signal.c | 2 --
4 files changed, 6 insertions(+), 7 deletions(-)
--- a/include/linux/mm.h
+++ b/include/linux/mm.h
@@ -2516,7 +2516,7 @@ struct zap_details {
void sched_mm_cid_before_execve(struct task_struct *t);
void sched_mm_cid_after_execve(struct task_struct *t);
void sched_mm_cid_fork(struct task_struct *t);
-void sched_mm_cid_exit_signals(struct task_struct *t);
+void sched_mm_cid_exit(struct task_struct *t);
static inline int task_mm_cid(struct task_struct *t)
{
return t->mm_cid;
@@ -2525,7 +2525,7 @@ static inline int task_mm_cid(struct tas
static inline void sched_mm_cid_before_execve(struct task_struct *t) { }
static inline void sched_mm_cid_after_execve(struct task_struct *t) { }
static inline void sched_mm_cid_fork(struct task_struct *t) { }
-static inline void sched_mm_cid_exit_signals(struct task_struct *t) { }
+static inline void sched_mm_cid_exit(struct task_struct *t) { }
static inline int task_mm_cid(struct task_struct *t)
{
/*
--- a/kernel/exit.c
+++ b/kernel/exit.c
@@ -924,6 +924,7 @@ void __noreturn do_exit(long code)
user_events_exit(tsk);
io_uring_files_cancel();
+ sched_mm_cid_exit(tsk);
exit_signals(tsk); /* sets PF_EXITING */
seccomp_filter_release(tsk);
--- a/kernel/sched/core.c
+++ b/kernel/sched/core.c
@@ -10545,7 +10545,7 @@ int __sched_mm_cid_migrate_from_try_stea
*
* The implicit barrier after cmpxchg per-mm/cpu cid before loading
* rq->curr->mm_cid_active matches the barrier in
- * sched_mm_cid_exit_signals(), sched_mm_cid_before_execve(), and
+ * sched_mm_cid_exit(), sched_mm_cid_before_execve(), and
* sched_mm_cid_after_execve() between store to t->mm_cid_active and
* load of per-mm/cpu cid.
*/
@@ -10665,7 +10665,7 @@ static void sched_mm_cid_remote_clear(st
*
* The implicit barrier after cmpxchg per-mm/cpu cid before loading
* rq->curr->mm_cid_active matches the barrier in
- * sched_mm_cid_exit_signals(), sched_mm_cid_before_execve(), and
+ * sched_mm_cid_exit(), sched_mm_cid_before_execve(), and
* sched_mm_cid_after_execve() between store to t->mm_cid_active and
* load of per-mm/cpu cid.
*/
@@ -10810,7 +10810,7 @@ void task_tick_mm_cid(struct rq *rq, str
task_work_add(curr, work, TWA_RESUME);
}
-void sched_mm_cid_exit_signals(struct task_struct *t)
+void sched_mm_cid_exit(struct task_struct *t)
{
struct mm_struct *mm = t->mm;
struct rq *rq;
--- a/kernel/signal.c
+++ b/kernel/signal.c
@@ -3150,7 +3150,6 @@ void exit_signals(struct task_struct *ts
cgroup_threadgroup_change_begin(tsk);
if (thread_group_empty(tsk) || (tsk->signal->flags & SIGNAL_GROUP_EXIT)) {
- sched_mm_cid_exit_signals(tsk);
tsk->flags |= PF_EXITING;
cgroup_threadgroup_change_end(tsk);
return;
@@ -3161,7 +3160,6 @@ void exit_signals(struct task_struct *ts
* From now this task is not visible for group-wide signals,
* see wants_signal(), do_signal_stop().
*/
- sched_mm_cid_exit_signals(tsk);
tsk->flags |= PF_EXITING;
cgroup_threadgroup_change_end(tsk);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 417/438] smb: client: reject short Next offsets in parse_server_interfaces()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (415 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 416/438] smb: client: fix use-after-free of iface in cifs_try_adding_channels() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 418/438] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error Greg Kroah-Hartman
` (32 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit 1b3221bb121079ad79a1f3c3aa360ba649832e7a upstream.
In parse_server_interfaces(), the server-supplied Next offset is
validated against bytes_left, but not against the size of the interface
structure itself.
A small, non-zero Next value can pass the bounds check but advance the
pointer by less than sizeof(*p). This causes the next iteration of the
loop to read misaligned, overlapping structure fields.
Fix this by ensuring the Next offset is at least sizeof(*p).
Fixes: 7d34ec36abb8 ("smb3: fix for slab out of bounds on mount to ksmbd")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -785,9 +785,9 @@ next_iface:
break;
}
/* Validate that Next doesn't point beyond the buffer */
- if (next > bytes_left) {
- cifs_dbg(VFS, "%s: invalid Next pointer %zu > %zd\n",
- __func__, next, bytes_left);
+ if (next < sizeof(*p) || next > bytes_left) {
+ cifs_dbg(VFS, "%s: invalid Next pointer %zu out of range [%zu, %zd]\n",
+ __func__, next, sizeof(*p), bytes_left);
rc = -EINVAL;
goto out;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 364/398] signal: Prevent exec() race
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (360 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 363/398] signal: Move MMCID exit out of sighand lock Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 365/398] xfrm: Refactor xfrm_input lock to reduce contention with RSS Greg Kroah-Hartman
` (40 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hyunwoo Kim, Eric W. Biederman,
Thomas Gleixner, Kijo Park, Oleg Nesterov, Frederic Weisbecker,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Gleixner <tglx@kernel.org>
[ Upstream commit d2710c8d938ae6a825a6463158e6e6f31eac792a ]
Hyunwoo debugged the following KASAN UAF splat:
BUG: KASAN: slab-use-after-free in __send_signal_locked+0xb27/0xba0
Write of size 8 at addr ffff888007ed80c8 by task poc/79
...
Call Trace:
__send_signal_locked+0xb27/0xba0
do_send_sig_info+0xa7/0x160
do_send_specific+0x76/0xa0
__x64_sys_tgkill+0x193/0x270
...
Allocated by task 80:
do_timer_create+0x1a4/0x1030
__x64_sys_timer_create+0x145/0x190
...
Freed by task 12:
kmem_cache_free_bulk+0x1f8/0x4a0
kvfree_rcu_bulk+0x14f/0x1c0
kfree_rcu_work+0x128/0x1a0
...
Last potentially related work creation:
kvfree_call_rcu+0x39/0x390
__flush_itimer_signals+0x211/0x320
flush_itimer_signals+0x47/0x90
begin_new_exec+0xa6b/0x28c0
It turned out that this happens with a non-leader exec() as Hyunwoo
explained:
de_thread() calls exchange_tids() before release_task(leader), so the
struct pid held by a SIGEV_THREAD_ID timer created against the leader's tid
now points to the thread which called execve(). pid_task() returns that
thread and lock_task_sighand() on it succeeds.
If the timer signal is blocked, its sigqueue stays queued on the leader's
task::pending. The next expiry of that timer can then run while
release_task() flushes the queue.
posixtimer_send_sigqueue() checks whether the sigqueue is already queued
with a plain list_empty(), which only reads list_head::next.
list_del_init() is not atomic and INIT_LIST_HEAD() stores list_head::next
before list_head::prev, so the check can pass in between. list_add_tail()
queues the entry on the task::pending of the live thread, and the
list_head::prev store from the flush then overwrites the list_head::prev
link that list_add_tail() has just set.
__flush_itimer_signals() does not undo that either. With list_head::prev
pointing at the entry itself, its list_del_init() only stores the same
values again, so the entry is not removed from the list. It is still there
after the last reference is dropped and the timer is freed by RCU, and the
list_add_tail() of a later tgkill() follows that list_head::prev into the
freed timer.
This problem surfaced with the recent commit which moved the sigqueue flush
out of the sighand lock held region.
Hyonwoo proposed to fix this by using list_del_init_careful(), but that
just papers over the problem. After some disucssions and various attempts
to solve it, Eric pointed out that there is no reason to flush
task::pending late in release_task() and it should be done in
exit_signals() already.
As nothing can collect and deliver signals which are queued in a dying
task's pending queue, there is no reason to delay it further.
But it has to be ensured that no signals can be queued into it after that
point. exit_signals() sets PF_EXITING in task::flags, which can be used as
an indicator for this.
Cure it by:
- Preventing signal queueing for task private signals (PIDTYPE_PID) when
the task has PF_EXITING set in __send_signal_locked() and in
posixtimer_send_sigqueue().
- Protecting the unlocked setting of PF_EXITING in exit_signals() for the
task group empty and the group exit case with sighand lock
- Flushing task::pending signals right there.
Optimize that by moving the whole pending list to an on-stack list head
under sighand lock and free the signals without the lock held.
There has been quite some discussion about the lockless flush and the
non-leader exec case on weakly ordered systems. The problem is that a third
party which tries to send a posix timer signal relies on the PID lookup to
find the target task and that lookup might result in the new leader when
the signal was originaly directed to the old leader. In case that the
signal was queued on the old leader then the lockless flush raised a
concern over the following situation:
old_leader new_leader third party
A: flush_list() // list_del_init() stores to sigqueue
LOCK (tasklist)
old_leader->exit_state = EXIT_ZOMBIE;
B: UNLOCK (tasklist)
C: LOCK (tasklist)
if (old_leader->exit_state)
transfer_tids()
D: store PID
posix_timer_send_sigqueue()
// Observes #D so t = new_leader
E: t = get_target()
F: LOCK (sighand)
G: if (list_empty(sigqueue))
list_add(sigqueue)
The concern was that the third party might observe #D but not observe #A
and therefore would proceed to #G while the list_del() stores (#A) in
flush_list() are not visible yet, which could result in list corruption.
That would be possible if looking at it solely from a RELEASE+ACQUIRE
ordering point of view, but B-C is a UNLOCK+LOCK hand-over, which is not
the same as RELEASE+ACQUIRE:
RELEASE+ACQUIRE: RCpc, only the CPUs involved agree on the ordering
UNLOCK+LOCK: RCtso, the hand-over is store-ordering
As B-C is UNLOCK+LOCK, which is RCtso and that does impose store order,
A stores must happen before the D store.
Combine with E-F, which has a data dependency from the LOAD to the LOCK and
thereby constraints later LOADs, those sigqueue loads in G that come after
F must in fact observe the A stores.
Fixes: fb3bbcfe344e ("exit: change the release_task() paths to call flush_sigqueue() lockless")
Reported-by: Hyunwoo Kim <imv4bel@gmail.com>
Debugged-by: Hyunwoo Kim <imv4bel@gmail.com>
Suggested-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Tested-by: Kijo Park <red993688@gmail.com>
Reviewed-by: Oleg Nesterov <oleg@redhat.com>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260911090541.572536604@kernel.org
Closes: https://patch.msgid.link/aok1rdkBgZsynHZB@v4bel
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/exit.c | 11 ++---
kernel/signal.c | 117 +++++++++++++++++++++++++++++++++++++++++---------------
2 files changed, 92 insertions(+), 36 deletions(-)
--- a/kernel/exit.c
+++ b/kernel/exit.c
@@ -304,12 +304,13 @@ repeat:
free_pids(post.pids);
release_thread(p);
/*
- * This task was already removed from the process/thread/pid lists
- * and lock_task_sighand(p) can't succeed. Nobody else can touch
- * ->pending or, if group dead, signal->shared_pending. We can call
- * flush_sigqueue() lockless.
+ * This task was already removed from the process/thread/pid lists and
+ * lock_task_sighand(p) can't succeed. If it's the group leader then
+ * flush tsk->signal->shared_pending. tsk->pending has been flushed
+ * already in exit_signals(). Nothing else can touch
+ * signal->shared_pending anymore, so flush_sigqueue() can be invoked
+ * lockless.
*/
- flush_sigqueue(&p->pending);
if (thread_group_leader(p))
flush_sigqueue(&p->signal->shared_pending);
--- a/kernel/signal.c
+++ b/kernel/signal.c
@@ -475,18 +475,42 @@ static void __sigqueue_free(struct sigqu
kmem_cache_free(sigqueue_cachep, q);
}
-void flush_sigqueue(struct sigpending *queue)
+/*
+ * flush_sigqueue_list() can only be invoked without holding sighand::siglock in
+ * the following cases:
+ *
+ * 1) When flushing task::pending _after_ setting task::flags PF_EXITING
+ *
+ * All functions which try to send a signal to @task will observe PF_EXITING
+ * and drop the signal.
+ *
+ * 2) When flushing task::signal::shared_pending _after_ the last task in a
+ * thread group was unhashed and task::sighand is NULL.
+ *
+ * Nothing can queue a signal anymore because sighand is NULL.
+ */
+static void flush_sigqueue_list(struct list_head *head)
{
- struct sigqueue *q;
+ struct sigqueue *q, *tmp;
- sigemptyset(&queue->signal);
- while (!list_empty(&queue->list)) {
- q = list_entry(queue->list.next, struct sigqueue , list);
+ list_for_each_entry_safe(q, tmp, head, list) {
list_del_init(&q->list);
__sigqueue_free(q);
}
}
+void flush_sigqueue(struct sigpending *queue)
+{
+ sigemptyset(&queue->signal);
+ flush_sigqueue_list(&queue->list);
+}
+
+static void sigqueue_dequeue_pending(struct sigpending *queue, struct list_head *head)
+{
+ sigemptyset(&queue->signal);
+ list_splice_init(&queue->list, head);
+}
+
/*
* Flush all pending signals for this kthread.
*/
@@ -1039,6 +1063,21 @@ static inline bool legacy_queue(struct s
return (sig < SIGRTMIN) && sigismember(&signals->signal, sig);
}
+/*
+ * When PF_EXITING is set the task is on the way out and has t::pending
+ * flushed already. Prevent queueing of PIDTYPE_PID signals as they would
+ * be leaked.
+ */
+static inline bool task_can_queue_signal(struct task_struct *t, enum pid_type type)
+{
+ lockdep_assert_held(&t->sighand->siglock);
+
+ if (!(t->flags & PF_EXITING))
+ return true;
+
+ return type != PIDTYPE_PID;
+}
+
static int __send_signal_locked(int sig, struct kernel_siginfo *info,
struct task_struct *t, enum pid_type type, bool force)
{
@@ -1050,6 +1089,10 @@ static int __send_signal_locked(int sig,
lockdep_assert_held(&t->sighand->siglock);
result = TRACE_SIGNAL_IGNORED;
+
+ if (!task_can_queue_signal(t, type))
+ goto ret;
+
if (!prepare_signal(sig, t, force))
goto ret;
@@ -1993,11 +2036,25 @@ static inline struct task_struct *posixt
struct task_struct *t = pid_task(tmr->it_pid, tmr->it_pid_type);
if (t && tmr->it_pid_type != PIDTYPE_PID &&
- same_thread_group(t, current) && !current->exit_state)
+ same_thread_group(t, current) && !(current->flags & PF_EXITING))
t = current;
return t;
}
+/*
+ * Find the target task for the POSIX timer signal and prevent that a
+ * PIDTYPE_PID signal is queued on a task which has PF_EXITING set.
+ */
+static inline struct task_struct *posixtimer_get_unignore_target(struct k_itimer *tmr)
+{
+ struct task_struct *t = posixtimer_get_target(tmr);
+
+ if (t && task_can_queue_signal(t, tmr->it_pid_type))
+ return t;
+
+ return NULL;
+}
+
void posixtimer_send_sigqueue(struct k_itimer *tmr)
{
struct sigqueue *q = &tmr->sigq;
@@ -2015,6 +2072,9 @@ void posixtimer_send_sigqueue(struct k_i
if (!likely(lock_task_sighand(t, &flags)))
return;
+ if (!task_can_queue_signal(t, tmr->it_pid_type))
+ goto unlock;
+
/*
* Update @tmr::sigqueue_seq for posix timer signals with sighand
* locked to prevent a race against dequeue_signal().
@@ -2106,6 +2166,7 @@ void posixtimer_send_sigqueue(struct k_i
result = TRACE_SIGNAL_DELIVERED;
out:
trace_signal_generate(sig, &q->info, t, tmr->it_pid_type != PIDTYPE_PID, result);
+unlock:
unlock_task_sighand(t, &flags);
}
@@ -2161,7 +2222,7 @@ static void posixtimer_sig_unignore(stru
* has exited by now, drop the reference count.
*/
guard(rcu)();
- target = posixtimer_get_target(tmr);
+ target = posixtimer_get_unignore_target(tmr);
if (target)
posixtimer_queue_sigqueue(&tmr->sigq, target, tmr->it_pid_type);
else
@@ -3140,42 +3201,36 @@ static void retarget_shared_pending(stru
void exit_signals(struct task_struct *tsk)
{
+ LIST_HEAD(sigq_list);
int group_stop = 0;
- sigset_t unblocked;
/*
* @tsk is about to have PF_EXITING set - lock out users which
- * expect stable threadgroup.
+ * expect a stable threadgroup.
*/
cgroup_threadgroup_change_begin(tsk);
- if (thread_group_empty(tsk) || (tsk->signal->flags & SIGNAL_GROUP_EXIT)) {
+ scoped_guard(spinlock_irq, &tsk->sighand->siglock) {
tsk->flags |= PF_EXITING;
- cgroup_threadgroup_change_end(tsk);
- return;
- }
- spin_lock_irq(&tsk->sighand->siglock);
- /*
- * From now this task is not visible for group-wide signals,
- * see wants_signal(), do_signal_stop().
- */
- tsk->flags |= PF_EXITING;
+ sigqueue_dequeue_pending(&tsk->pending, &sigq_list);
- cgroup_threadgroup_change_end(tsk);
+ if (task_sigpending(tsk) && !thread_group_empty(tsk) &&
+ !(tsk->signal->flags & SIGNAL_GROUP_EXIT)) {
+ sigset_t unblocked = tsk->blocked;
+
+ signotset(&unblocked);
+ retarget_shared_pending(tsk, &unblocked);
+
+ if (unlikely(tsk->jobctl & JOBCTL_STOP_PENDING) &&
+ task_participate_group_stop(tsk))
+ group_stop = CLD_STOPPED;
+ }
+ }
- if (!task_sigpending(tsk))
- goto out;
+ cgroup_threadgroup_change_end(tsk);
- unblocked = tsk->blocked;
- signotset(&unblocked);
- retarget_shared_pending(tsk, &unblocked);
-
- if (unlikely(tsk->jobctl & JOBCTL_STOP_PENDING) &&
- task_participate_group_stop(tsk))
- group_stop = CLD_STOPPED;
-out:
- spin_unlock_irq(&tsk->sighand->siglock);
+ flush_sigqueue_list(&sigq_list);
/*
* If group stop has completed, deliver the notification. This
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 418/438] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (416 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 417/438] smb: client: reject short Next offsets in parse_server_interfaces() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 419/438] smb: client: fix unaligned access in WSL reparse point parser Greg Kroah-Hartman
` (31 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Paulo Alcantara,
Tom Talpey, Stefan Metzmacher, Shyam Prasad N, Ronnie Sahlberg,
Bharath SM
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paulo Alcantara <pc@manguebit.org>
commit e75c96157d45e498970158c8f7373d90102e33b9 upstream.
When an RDMA connection is successfully established via
smbd_get_connection() but cifs_get_tcp_session() later fails (e.g.
kthread_create() returns an error), the error path frees tcp_ses
without first destroying the smbd_connection.
Fix this by calling smbd_destroy() in the out_err cleanup path before
kfree(tcp_ses). smbd_destroy() safely handles the case where
smbd_conn is NULL, so it can be called unconditionally.
Closes: https://sashiko.dev/#/patchset/20260912165503.521597-1-pc%40manguebit.org
Fixes: 2f8946464b11 ("CIFS: SMBD: Upper layer connects to SMBDirect session")
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: Tom Talpey <tom@talpey.com>
Cc: Stefan Metzmacher <metze@samba.org>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/connect.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/smb/client/connect.c
+++ b/fs/smb/client/connect.c
@@ -1934,6 +1934,7 @@ out_err:
kfree(tcp_ses->leaf_fullpath);
if (tcp_ses->ssocket)
sock_release(tcp_ses->ssocket);
+ smbd_destroy(tcp_ses);
kfree(tcp_ses);
}
return ERR_PTR(rc);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 365/398] xfrm: Refactor xfrm_input lock to reduce contention with RSS
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (361 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 364/398] signal: Prevent exec() race Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 366/398] xfrm: Fix dev use-after-free in xfrm async resumption Greg Kroah-Hartman
` (39 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jianbo Liu, Cosmin Ratiu,
Steffen Klassert, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jianbo Liu <jianbol@nvidia.com>
[ Upstream commit 10a11861943902fda74f37f456b45183b2bca270 ]
With newer NICs like mlx5 supporting RSS for IPsec crypto offload,
packets for a single Security Association (SA) are scattered across
multiple CPU cores for parallel processing. The xfrm_state spinlock
(x->lock) is held for each packet during xfrm processing.
When multiple connections or flows share the same SA, this parallelism
causes high lock contention on x->lock, creating a performance
bottleneck and limiting scalability.
The original xfrm_input() function exacerbated this issue by releasing
and immediately re-acquiring x->lock. For hardware crypto offload
paths, this unlock/relock sequence is unnecessary and introduces
significant overhead. This patch refactors the function to relocate
the type_offload->input_tail call for the offload path, performing all
necessary work while continuously holding the lock. This reordering is
safe, since packets which don't pass the checks below will still fail
them with the new code.
Performance testing with iperf using multiple parallel streams over a
single IPsec SA shows significant improvement in throughput as the
number of queues (and thus CPU cores) increases:
+-----------+---------------+--------------+-----------------+
| RX queues | Before (Gbps) | After (Gbps) | Improvement (%) |
+-----------+---------------+--------------+-----------------+
| 2 | 32.3 | 34.4 | 6.5 |
| 4 | 34.4 | 40.0 | 16.3 |
| 6 | 24.5 | 38.3 | 56.3 |
| 8 | 23.1 | 38.3 | 65.8 |
| 12 | 18.1 | 29.9 | 65.2 |
| 16 | 16.0 | 25.2 | 57.5 |
+-----------+---------------+--------------+-----------------+
Signed-off-by: Jianbo Liu <jianbol@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Stable-dep-of: 3cf5cdecd99c ("xfrm: save input state data before secpath resets")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/xfrm_input.c | 14 +++++++-------
1 file changed, 7 insertions(+), 7 deletions(-)
--- a/net/xfrm/xfrm_input.c
+++ b/net/xfrm/xfrm_input.c
@@ -504,6 +504,7 @@ int xfrm_input(struct sk_buff *skb, int
if (encap_type == -1) {
async = 1;
seq = XFRM_SKB_CB(skb)->seq.input.low;
+ spin_lock(&x->lock);
goto resume;
}
/* GRO call */
@@ -540,6 +541,8 @@ int xfrm_input(struct sk_buff *skb, int
XFRM_INC_STATS(net, LINUX_MIB_XFRMINHDRERROR);
goto drop;
}
+
+ nexthdr = x->type_offload->input_tail(x, skb);
}
goto lock;
@@ -637,11 +640,9 @@ lock:
goto drop_unlock;
}
- spin_unlock(&x->lock);
-
if (xfrm_tunnel_check(skb, x, family)) {
XFRM_INC_STATS(net, LINUX_MIB_XFRMINSTATEMODEERROR);
- goto drop;
+ goto drop_unlock;
}
seq_hi = htonl(xfrm_replay_seqhi(x, seq));
@@ -649,9 +650,8 @@ lock:
XFRM_SKB_CB(skb)->seq.input.low = seq;
XFRM_SKB_CB(skb)->seq.input.hi = seq_hi;
- if (crypto_done) {
- nexthdr = x->type_offload->input_tail(x, skb);
- } else {
+ if (!crypto_done) {
+ spin_unlock(&x->lock);
dev_hold(skb->dev);
nexthdr = x->type->input(x, skb);
@@ -662,9 +662,9 @@ lock:
}
dev_put(skb->dev);
+ spin_lock(&x->lock);
}
resume:
- spin_lock(&x->lock);
if (nexthdr < 0) {
if (nexthdr == -EBADMSG) {
xfrm_audit_state_icvfail(x, skb,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 419/438] smb: client: fix unaligned access in WSL reparse point parser
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (417 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 418/438] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 420/438] smb: client: fix fattr leaking on wsl_to_fattr() failure Greg Kroah-Hartman
` (30 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Paulo Alcantara,
David Howells, Tom Talpey, Shyam Prasad N, Ronnie Sahlberg,
Bharath SM
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paulo Alcantara <pc@manguebit.org>
commit e1aeaf79dea51e6065da56924bc07e22d59012ac upstream.
When wsl_to_fattr() parses WSL extended attributes, it computes a
payload pointer from ea->ea_data + ea_name_length + 1. Since the
smb2_file_full_ea_info struct is __packed and all WSL xattr names are
6 bytes long, the value pointer always lands at an odd byte offset,
never satisfying __le32 or __le64 alignment requirements.
The code then casts this pointer to __le32 * or __le64 * and
dereferences it directly, which may cause alignment faults on some
architectures.
Replace all such casts with get_unaligned_le32() and
get_unaligned_le64() in reparse_mkdev(), wsl_make_kuid(),
wsl_make_kgid() and wsl_to_fattr().
Closes: https://sashiko.dev/#/patchset/20260906200517.725015-1-pc%40manguebit.org
Fixes: 78e26bec4d6d ("smb: client: parse uid, gid, mode and dev from WSL reparse points")
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: David Howells <dhowells@redhat.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/reparse.c | 4 ++--
fs/smb/client/reparse.h | 7 ++++---
2 files changed, 6 insertions(+), 5 deletions(-)
--- a/fs/smb/client/reparse.c
+++ b/fs/smb/client/reparse.c
@@ -1201,9 +1201,9 @@ static bool wsl_to_fattr(struct cifs_ope
fattr->cf_gid = wsl_make_kgid(cifs_sb, v);
} else if (!strncmp(name, SMB2_WSL_XATTR_MODE, nlen)) {
/* File type in reparse point tag and in xattr mode must match. */
- if (S_DT(fattr->cf_mode) != S_DT(le32_to_cpu(*(__le32 *)v)))
+ if (S_DT(fattr->cf_mode) != S_DT(get_unaligned_le32(v)))
return false;
- fattr->cf_mode = (umode_t)le32_to_cpu(*(__le32 *)v);
+ fattr->cf_mode = (umode_t)get_unaligned_le32(v);
} else if (!strncmp(name, SMB2_WSL_XATTR_DEV, nlen)) {
fattr->cf_rdev = reparse_mkdev(v);
have_xattr_dev = true;
--- a/fs/smb/client/reparse.h
+++ b/fs/smb/client/reparse.h
@@ -9,6 +9,7 @@
#include <linux/fs.h>
#include <linux/stat.h>
#include <linux/uidgid.h>
+#include <linux/unaligned.h>
#include "fs_context.h"
#include "cifsglob.h"
#include "../common/smbfsctl.h"
@@ -23,7 +24,7 @@
static inline dev_t reparse_mkdev(void *ptr)
{
- u64 v = le64_to_cpu(*(__le64 *)ptr);
+ u64 v = get_unaligned_le64(ptr);
return MKDEV(v & 0xffffffff, v >> 32);
}
@@ -31,7 +32,7 @@ static inline dev_t reparse_mkdev(void *
static inline kuid_t wsl_make_kuid(struct cifs_sb_info *cifs_sb,
void *ptr)
{
- u32 uid = le32_to_cpu(*(__le32 *)ptr);
+ u32 uid = get_unaligned_le32(ptr);
if (cifs_sb_flags(cifs_sb) & CIFS_MOUNT_OVERR_UID)
return cifs_sb->ctx->linux_uid;
@@ -41,7 +42,7 @@ static inline kuid_t wsl_make_kuid(struc
static inline kgid_t wsl_make_kgid(struct cifs_sb_info *cifs_sb,
void *ptr)
{
- u32 gid = le32_to_cpu(*(__le32 *)ptr);
+ u32 gid = get_unaligned_le32(ptr);
if (cifs_sb_flags(cifs_sb) & CIFS_MOUNT_OVERR_GID)
return cifs_sb->ctx->linux_gid;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 366/398] xfrm: Fix dev use-after-free in xfrm async resumption
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (362 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 365/398] xfrm: Refactor xfrm_input lock to reduce contention with RSS Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 367/398] xfrm: save input state data before secpath resets Greg Kroah-Hartman
` (38 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xu Chunxiao, Dong Chenchen,
Steffen Klassert, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dong Chenchen <dongchenchen2@huawei.com>
[ Upstream commit 8045c0df98d4f14c54e5cb875f1c9c0ce89fe4ff ]
xfrm async resumption hold skb->dev refcnt until after transport_finish.
However, xfrm_rcv_cb may modify skb->dev to tunnel dev without taking
device reference, such as vti_rcv_cb. The subsequent async resumption
will decrement the tunnel device's reference count, which lead to uaf
of tunnel dev and refcnt leak of orig dev as below:
unregister_netdevice: waiting for vti1 to become free. Usage count = -2
Stash the original skb->dev to fix refcnt imbalance. The new skb->dev set
by xfrm_rcv_cb can race with device teardown. Extend rcu protection over
xfrm_rcv_cb and transport_finish to prevent races.
Fixes: 1c428b038400 ("xfrm: hold dev ref until after transport_finish NF_HOOK")
Reported-by: Xu Chunxiao <xuchunxiao3@huawei.com>
Signed-off-by: Dong Chenchen <dongchenchen2@huawei.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Stable-dep-of: 3cf5cdecd99c ("xfrm: save input state data before secpath resets")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/ipv4/xfrm4_input.c | 2 --
net/ipv6/xfrm6_input.c | 2 --
net/xfrm/xfrm_input.c | 29 ++++++++++++++++-------------
3 files changed, 16 insertions(+), 17 deletions(-)
--- a/net/ipv4/xfrm4_input.c
+++ b/net/ipv4/xfrm4_input.c
@@ -76,8 +76,6 @@ int xfrm4_transport_finish(struct sk_buf
NF_HOOK(NFPROTO_IPV4, NF_INET_PRE_ROUTING,
dev_net(dev), NULL, skb, dev, NULL,
xfrm4_rcv_encap_finish);
- if (async)
- dev_put(dev);
return 0;
}
--- a/net/ipv6/xfrm6_input.c
+++ b/net/ipv6/xfrm6_input.c
@@ -71,8 +71,6 @@ int xfrm6_transport_finish(struct sk_buf
NF_HOOK(NFPROTO_IPV6, NF_INET_PRE_ROUTING,
dev_net(dev), NULL, skb, dev, NULL,
xfrm6_transport_finish2);
- if (async)
- dev_put(dev);
return 0;
}
--- a/net/xfrm/xfrm_input.c
+++ b/net/xfrm/xfrm_input.c
@@ -464,6 +464,7 @@ int xfrm_input(struct sk_buff *skb, int
{
const struct xfrm_state_afinfo *afinfo;
struct net *net = dev_net(skb->dev);
+ struct net_device *dev = skb->dev;
int err;
__be32 seq;
__be32 seq_hi;
@@ -490,7 +491,7 @@ int xfrm_input(struct sk_buff *skb, int
LINUX_MIB_XFRMINSTATEINVALID);
if (encap_type == -1)
- dev_put(skb->dev);
+ dev_put(dev);
goto drop;
}
@@ -652,16 +653,16 @@ lock:
if (!crypto_done) {
spin_unlock(&x->lock);
- dev_hold(skb->dev);
+ dev_hold(dev);
nexthdr = x->type->input(x, skb);
if (nexthdr == -EINPROGRESS) {
if (async)
- dev_put(skb->dev);
+ dev_put(dev);
return 0;
}
- dev_put(skb->dev);
+ dev_put(dev);
spin_lock(&x->lock);
}
resume:
@@ -696,7 +697,7 @@ resume:
err = xfrm_inner_mode_input(x, skb);
if (err == -EINPROGRESS) {
if (async)
- dev_put(skb->dev);
+ dev_put(dev);
return 0;
} else if (err) {
XFRM_INC_STATS(net, LINUX_MIB_XFRMINSTATEMODEERROR);
@@ -723,9 +724,12 @@ resume_decapped:
crypto_done = false;
} while (!err);
+ rcu_read_lock();
err = xfrm_rcv_cb(skb, family, x->type->proto, 0);
- if (err)
+ if (err) {
+ rcu_read_unlock();
goto drop;
+ }
nf_reset_ct(skb);
@@ -736,8 +740,9 @@ resume_decapped:
if (skb_valid_dst(skb))
skb_dst_drop(skb);
if (async)
- dev_put(skb->dev);
+ dev_put(dev);
gro_cells_receive(&gro_cells, skb);
+ rcu_read_unlock();
return 0;
} else {
xo = xfrm_offload(skb);
@@ -745,23 +750,21 @@ resume_decapped:
xfrm_gro = xo->flags & XFRM_GRO;
err = -EAFNOSUPPORT;
- rcu_read_lock();
afinfo = xfrm_state_afinfo_get_rcu(x->props.family);
if (likely(afinfo))
err = afinfo->transport_finish(skb, xfrm_gro || async);
- rcu_read_unlock();
if (xfrm_gro) {
sp = skb_sec_path(skb);
if (sp)
sp->olen = 0;
if (skb_valid_dst(skb))
skb_dst_drop(skb);
- if (async)
- dev_put(skb->dev);
gro_cells_receive(&gro_cells, skb);
- return err;
}
+ if (async)
+ dev_put(dev);
+ rcu_read_unlock();
return err;
}
@@ -769,7 +772,7 @@ drop_unlock:
spin_unlock(&x->lock);
drop:
if (async)
- dev_put(skb->dev);
+ dev_put(dev);
xfrm_rcv_cb(skb, family, x && x->type ? x->type->proto : nexthdr, -1);
kfree_skb(skb);
return 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 420/438] smb: client: fix fattr leaking on wsl_to_fattr() failure
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (418 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 419/438] smb: client: fix unaligned access in WSL reparse point parser Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 421/438] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Greg Kroah-Hartman
` (29 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namjae Jeon, Paulo Alcantara,
David Howells, Tom Talpey, Shyam Prasad N, Ronnie Sahlberg,
Bharath SM
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paulo Alcantara <pc@manguebit.org>
commit e1253a82bb4c0fed6706a5839fc8b6e01be1abe2 upstream.
wsl_to_fattr() mutates fattr fields as it parses each WSL EA. If
validation later fails, the function returns false with partially
mutated fattr fields that callers do not reset.
Fix this by parsing into local variables and only committing them to
fattr on success.
Closes: https://sashiko.dev/#/patchset/20260906200517.725015-1-pc%40manguebit.org
Fixes: 78e26bec4d6d ("smb: client: parse uid, gid, mode and dev from WSL reparse points")
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Cc: David Howells <dhowells@redhat.com>
Cc: Tom Talpey <tom@talpey.com>
Cc: Shyam Prasad N <sprasad@microsoft.com>
Cc: Ronnie Sahlberg <ronniesahlberg@gmail.com>
Cc: Bharath SM <bharathsm@microsoft.com>
Cc: Namjae Jeon <linkinjeon@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/reparse.c | 34 +++++++++++++++++++---------------
1 file changed, 19 insertions(+), 15 deletions(-)
--- a/fs/smb/client/reparse.c
+++ b/fs/smb/client/reparse.c
@@ -1149,29 +1149,30 @@ static bool wsl_to_fattr(struct cifs_ope
u32 tag, struct cifs_fattr *fattr)
{
unsigned int sbflags = cifs_sb_flags(cifs_sb);
+ kuid_t uid = cifs_sb->ctx->linux_uid;
+ kgid_t gid = cifs_sb->ctx->linux_gid;
struct smb2_file_full_ea_info *ea;
bool have_xattr_dev = false;
+ dev_t rdev = 0;
+ umode_t mode;
u32 next = 0;
- fattr->cf_uid = cifs_sb->ctx->linux_uid;
- fattr->cf_gid = cifs_sb->ctx->linux_gid;
-
- fattr->cf_mode &= ~S_IFMT;
+ mode = fattr->cf_mode & ~S_IFMT;
switch (tag) {
case IO_REPARSE_TAG_LX_SYMLINK:
- fattr->cf_mode |= S_IFLNK;
+ mode |= S_IFLNK;
break;
case IO_REPARSE_TAG_LX_FIFO:
- fattr->cf_mode |= S_IFIFO;
+ mode |= S_IFIFO;
break;
case IO_REPARSE_TAG_AF_UNIX:
- fattr->cf_mode |= S_IFSOCK;
+ mode |= S_IFSOCK;
break;
case IO_REPARSE_TAG_LX_CHR:
- fattr->cf_mode |= S_IFCHR;
+ mode |= S_IFCHR;
break;
case IO_REPARSE_TAG_LX_BLK:
- fattr->cf_mode |= S_IFBLK;
+ mode |= S_IFBLK;
break;
}
@@ -1195,26 +1196,29 @@ static bool wsl_to_fattr(struct cifs_ope
if (!strncmp(name, SMB2_WSL_XATTR_UID, nlen)) {
if (!(sbflags & CIFS_MOUNT_OVERR_UID))
- fattr->cf_uid = wsl_make_kuid(cifs_sb, v);
+ uid = wsl_make_kuid(cifs_sb, v);
} else if (!strncmp(name, SMB2_WSL_XATTR_GID, nlen)) {
if (!(sbflags & CIFS_MOUNT_OVERR_GID))
- fattr->cf_gid = wsl_make_kgid(cifs_sb, v);
+ gid = wsl_make_kgid(cifs_sb, v);
} else if (!strncmp(name, SMB2_WSL_XATTR_MODE, nlen)) {
/* File type in reparse point tag and in xattr mode must match. */
- if (S_DT(fattr->cf_mode) != S_DT(get_unaligned_le32(v)))
+ if (S_DT(mode) != S_DT(get_unaligned_le32(v)))
return false;
- fattr->cf_mode = (umode_t)get_unaligned_le32(v);
+ mode = get_unaligned_le32(v);
} else if (!strncmp(name, SMB2_WSL_XATTR_DEV, nlen)) {
- fattr->cf_rdev = reparse_mkdev(v);
+ rdev = reparse_mkdev(v);
have_xattr_dev = true;
}
} while (next);
out:
-
/* Major and minor numbers for char and block devices are mandatory. */
if (!have_xattr_dev && (tag == IO_REPARSE_TAG_LX_CHR || tag == IO_REPARSE_TAG_LX_BLK))
return false;
+ fattr->cf_uid = uid;
+ fattr->cf_gid = gid;
+ fattr->cf_mode = mode;
+ fattr->cf_rdev = rdev;
return true;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 367/398] xfrm: save input state data before secpath resets
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (363 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 366/398] xfrm: Fix dev use-after-free in xfrm async resumption Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 368/398] mm: move vma_kernel_pagesize() from hugetlb to mm.h Greg Kroah-Hartman
` (37 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Steffen Klassert,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhiling Zou <zhilinz@nebusec.ai>
[ Upstream commit 3cf5cdecd99c9c186a5ea518d93bbf3045b6e3aa ]
xfrm_input() stores the current xfrm_state in the skb secpath while it
continues receive-side processing. Some input paths can reset that secpath
before xfrm_input() has finished dereferencing the state.
Receive callback users such as VTI and XFRM interfaces can reset the
secpath. The VTI receive path does so before checking whether the packet
crosses network namespaces, while the XFRM interface path does so only for
cross-network-namespace packets. The XFRM_MAX_DEPTH error path can also
reset the secpath before the final drop callback reports the current
state's protocol.
If secpath_reset() drops the last state reference while the state is
concurrently deleted, xfrm_input() can still dereference the freed state
when selecting transport_finish() or reporting the drop callback protocol.
Save the state protocol on the stack while the state is still valid,
and use the already saved address family for transport_finish(). A larval
XFRM_STATE_ACQ state has no type, so retain nexthdr as its protocol. This
preserves the existing drop-path fallback while avoiding the post-reset
state dereferences without adding an extra state reference to every
received packet.
Fixes: df3893c176e9 ("vti: Update the ipv4 side to use it's own receive hook.")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/xfrm/xfrm_input.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
--- a/net/xfrm/xfrm_input.c
+++ b/net/xfrm/xfrm_input.c
@@ -471,6 +471,7 @@ int xfrm_input(struct sk_buff *skb, int
struct xfrm_state *x = NULL;
xfrm_address_t *daddr;
u32 mark = skb->mark;
+ u8 xfrm_proto = nexthdr;
unsigned int family = AF_UNSPEC;
int decaps = 0;
int async = 0;
@@ -482,6 +483,7 @@ int xfrm_input(struct sk_buff *skb, int
if (encap_type < 0 || (xo && (xo->flags & XFRM_GRO || encap_type == 0 ||
encap_type == UDP_ENCAP_ESPINUDP))) {
x = xfrm_input_state(skb);
+ xfrm_proto = x->type ? x->type->proto : nexthdr;
if (unlikely(x->km.state != XFRM_STATE_VALID)) {
if (x->km.state == XFRM_STATE_ACQ)
@@ -589,11 +591,13 @@ int xfrm_input(struct sk_buff *skb, int
x = xfrm_input_state_lookup(net, mark, daddr, spi, nexthdr, family);
if (x == NULL) {
+ xfrm_proto = nexthdr;
secpath_reset(skb);
XFRM_INC_STATS(net, LINUX_MIB_XFRMINNOSTATES);
xfrm_audit_state_notfound(skb, family, spi, seq);
goto drop;
}
+ xfrm_proto = x->type ? x->type->proto : nexthdr;
if (unlikely(x->dir && x->dir != XFRM_SA_DIR_IN)) {
secpath_reset(skb);
@@ -601,6 +605,7 @@ int xfrm_input(struct sk_buff *skb, int
xfrm_audit_state_notfound(skb, family, spi, seq);
xfrm_state_put(x);
x = NULL;
+ xfrm_proto = nexthdr;
goto drop;
}
@@ -725,7 +730,7 @@ resume_decapped:
} while (!err);
rcu_read_lock();
- err = xfrm_rcv_cb(skb, family, x->type->proto, 0);
+ err = xfrm_rcv_cb(skb, family, xfrm_proto, 0);
if (err) {
rcu_read_unlock();
goto drop;
@@ -750,7 +755,7 @@ resume_decapped:
xfrm_gro = xo->flags & XFRM_GRO;
err = -EAFNOSUPPORT;
- afinfo = xfrm_state_afinfo_get_rcu(x->props.family);
+ afinfo = xfrm_state_afinfo_get_rcu(family);
if (likely(afinfo))
err = afinfo->transport_finish(skb, xfrm_gro || async);
if (xfrm_gro) {
@@ -773,7 +778,7 @@ drop_unlock:
drop:
if (async)
dev_put(dev);
- xfrm_rcv_cb(skb, family, x && x->type ? x->type->proto : nexthdr, -1);
+ xfrm_rcv_cb(skb, family, xfrm_proto, -1);
kfree_skb(skb);
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 421/438] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (419 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 420/438] smb: client: fix fattr leaking on wsl_to_fattr() failure Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 422/438] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Greg Kroah-Hartman
` (28 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit 05762c5bc1cfdcac36747994fde2c04387a457f1 upstream.
Fix several related bounds checking and pointer lifecycle issues in
receive_encrypted_standard()'s handling of compound encrypted frames:
- Clear next_buffer after assigning it to server->bigbuf. A stale
next_buffer pointer can lead to a use-after-free on subsequent
error paths.
- Update pdu_length to the decrypted plaintext size (buf_size). Using
the pre-decryption length allows NextCommand to point into stale
ciphertext residue.
- Reject next_cmd values smaller than MID_HEADER_SIZE(server).
- Fix an integer overflow in the upper bound check by verifying
pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the
trailing slice is large enough for a header.
Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -5362,6 +5362,7 @@ receive_encrypted_standard(struct TCP_Se
length = decrypt_raw_data(server, buf, buf_size, NULL, false);
if (length)
return length;
+ pdu_length = buf_size;
next_is_large = server->large_buf;
one_more:
@@ -5374,8 +5375,15 @@ one_more:
}
if (next_cmd) {
- if (WARN_ON_ONCE(next_cmd > pdu_length))
+ if (next_cmd < MID_HEADER_SIZE(server) ||
+ next_cmd > pdu_length ||
+ pdu_length - next_cmd < MID_HEADER_SIZE(server)) {
+ unsigned int max_next = pdu_length > (unsigned int)MID_HEADER_SIZE(server) ?
+ pdu_length - (unsigned int)MID_HEADER_SIZE(server) : 0;
+ cifs_server_dbg(VFS, "invalid NextCommand offset %u out of range [%zu, %u]\n",
+ next_cmd, MID_HEADER_SIZE(server), max_next);
return -1;
+ }
if (next_is_large)
next_buffer = (char *)cifs_buf_get();
else
@@ -5411,6 +5419,7 @@ one_more:
server->bigbuf = buf = next_buffer;
else
server->smallbuf = buf = next_buffer;
+ next_buffer = NULL;
goto one_more;
} else if (ret != 0) {
/*
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 368/398] mm: move vma_kernel_pagesize() from hugetlb to mm.h
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (364 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 367/398] xfrm: save input state data before secpath resets Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 369/398] mm/huge_memory: bypass THP tuneables for huge pfnmap mappings Greg Kroah-Hartman
` (36 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Hildenbrand (Arm),
Lorenzo Stoakes (Oracle), Mike Rapoport (Microsoft), Dan Williams,
Christophe Leroy (CS GROUP), Jann Horn, Liam Howlett,
Madhavan Srinivasan, Michael Ellerman, Michal Hocko, Muchun Song,
Nicholas Piggin, Oscar Salvador, Paolo Bonzini, Pedro Falcato,
Suren Baghdasaryan, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "David Hildenbrand (Arm)" <david@kernel.org>
[ Upstream commit 341ffe82a7a3a1e0756b58999405b6df0c2b3e8d ]
Patch series "mm: move vma_(kernel|mmu)_pagesize() out of hugetlb.c", v2.
Looking into vma_(kernel|mmu)_pagesize(), I realized that there is one
scenario where DAX would not do the right thing when the kernel is not
compiled with hugetlb support.
Without hugetlb support, vma_(kernel|mmu)_pagesize() will always return
PAGE_SIZE instead of using the ->pagesize() result provided by dax-device
code.
Fix that by moving vma_kernel_pagesize() to core MM code, where it
belongs. I don't think this is stable material, but am not 100% sure.
Also, move vma_mmu_pagesize() while at it. Remove the unnecessary
hugetlb.h inclusion from KVM code.
This patch (of 4):
In the past, only hugetlb had special "vma_kernel_pagesize()"
requirements, so it provided its own implementation.
In commit 05ea88608d4e ("mm, hugetlbfs: introduce ->pagesize() to
vm_operations_struct") we generalized that approach by providing a
vm_ops->pagesize() callback to be used by device-dax.
Once device-dax started using that callback in commit c1d53b92b95c
("device-dax: implement ->pagesize() for smaps to report MMUPageSize") it
was missed that CONFIG_DEV_DAX does not depend on hugetlb support.
So building a kernel with CONFIG_DEV_DAX but without CONFIG_HUGETLBFS
would not pick up that value.
Fix it by moving vma_kernel_pagesize() to mm.h, providing only a single
implementation. While at it, improve the kerneldoc a bit.
Ideally, we'd move vma_mmu_pagesize() as well to the header. However, its
__weak symbol might be overwritten by a PPC variant in hugetlb code. So
let's leave it in there for now, as it really only matters for some
hugetlb oddities.
This was found by code inspection.
Link: https://lkml.kernel.org/r/20260309151901.123947-1-david@kernel.org
Link: https://lkml.kernel.org/r/20260309151901.123947-2-david@kernel.org
Fixes: c1d53b92b95c ("device-dax: implement ->pagesize() for smaps to report MMUPageSize")
Signed-off-by: David Hildenbrand (Arm) <david@kernel.org>
Reviewed-by: Lorenzo Stoakes (Oracle) <ljs@kernel.org>
Acked-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Cc: Dan Williams <dan.j.williams@intel.com>
Cc: "Christophe Leroy (CS GROUP)" <chleroy@kernel.org>
Cc: Jann Horn <jannh@google.com>
Cc: Liam Howlett <liam.howlett@oracle.com>
Cc: Madhavan Srinivasan <maddy@linux.ibm.com>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: Paolo Bonzini <pbonzini@redhat.com>
Cc: Pedro Falcato <pfalcato@suse.de>
Cc: Suren Baghdasaryan <surenb@google.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Stable-dep-of: e384abeb559d ("mm/huge_memory: bypass THP tuneables for huge pfnmap mappings")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/hugetlb.h | 7 -------
include/linux/mm.h | 20 ++++++++++++++++++++
mm/hugetlb.c | 17 -----------------
3 files changed, 20 insertions(+), 24 deletions(-)
--- a/include/linux/hugetlb.h
+++ b/include/linux/hugetlb.h
@@ -767,8 +767,6 @@ static inline unsigned long huge_page_si
return (unsigned long)PAGE_SIZE << h->order;
}
-extern unsigned long vma_kernel_pagesize(struct vm_area_struct *vma);
-
extern unsigned long vma_mmu_pagesize(struct vm_area_struct *vma);
static inline unsigned long huge_page_mask(struct hstate *h)
@@ -1184,11 +1182,6 @@ static inline unsigned long huge_page_ma
return PAGE_MASK;
}
-static inline unsigned long vma_kernel_pagesize(struct vm_area_struct *vma)
-{
- return PAGE_SIZE;
-}
-
static inline unsigned long vma_mmu_pagesize(struct vm_area_struct *vma)
{
return PAGE_SIZE;
--- a/include/linux/mm.h
+++ b/include/linux/mm.h
@@ -1020,6 +1020,26 @@ static inline bool vma_is_shared_maywrit
return is_shared_maywrite(vma->vm_flags);
}
+/**
+ * vma_kernel_pagesize - Default page size granularity for this VMA.
+ * @vma: The user mapping.
+ *
+ * The kernel page size specifies in which granularity VMA modifications
+ * can be performed. Folios in this VMA will be aligned to, and at least
+ * the size of the number of bytes returned by this function.
+ *
+ * The default kernel page size is not affected by Transparent Huge Pages
+ * being in effect.
+ *
+ * Return: The default page size granularity for this VMA.
+ */
+static inline unsigned long vma_kernel_pagesize(struct vm_area_struct *vma)
+{
+ if (unlikely(vma->vm_ops && vma->vm_ops->pagesize))
+ return vma->vm_ops->pagesize(vma);
+ return PAGE_SIZE;
+}
+
static inline
struct vm_area_struct *vma_find(struct vma_iterator *vmi, unsigned long max)
{
--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -1027,23 +1027,6 @@ static pgoff_t vma_hugecache_offset(stru
(vma->vm_pgoff >> huge_page_order(h));
}
-/**
- * vma_kernel_pagesize - Page size granularity for this VMA.
- * @vma: The user mapping.
- *
- * Folios in this VMA will be aligned to, and at least the size of the
- * number of bytes returned by this function.
- *
- * Return: The default size of the folios allocated when backing a VMA.
- */
-unsigned long vma_kernel_pagesize(struct vm_area_struct *vma)
-{
- if (vma->vm_ops && vma->vm_ops->pagesize)
- return vma->vm_ops->pagesize(vma);
- return PAGE_SIZE;
-}
-EXPORT_SYMBOL_GPL(vma_kernel_pagesize);
-
/*
* Return the page size being used by the MMU to back a VMA. In the majority
* of cases, the page size used by the kernel matches the MMU size. On
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 422/438] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (420 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 421/438] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 423/438] smb: client: fix potential OOB read in smb3_enum_snapshots() Greg Kroah-Hartman
` (27 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit eeb5ef6083e1cefa2ef75041b5597ff228b8d7bb upstream.
In move_smb2_ea_to_cifs(), the while (src_size > 0) loop condition is
insufficient. It allows iteration to continue even if the remaining
src_size is too small to contain a complete smb2_ea_info structure.
Consequently, reads of ea_name_length and ea_value_length can occur
out-of-bounds.
Fix this by ensuring src_size >= sizeof(*src) before attempting to read
any structure fields. Additionally, reject any next_entry_offset that is
smaller than sizeof(*src) or that would advance the pointer beyond the
available buffer.
Note that for calls where the server returns a malformed EA list, the
error returned to userspace changes from -ENODATA (getxattr) or
-ERANGE (listxattr) to -EIO. This correctly signals a server protocol
error rather than misleadingly indicating "attribute not present" or
"output buffer too small".
Fixes: 95907fea4fd8 ("cifs: Add support for reading attributes on SMB2+")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 25 +++++++++++++++++--------
fs/smb/client/trace.h | 1 +
2 files changed, 18 insertions(+), 8 deletions(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -1053,8 +1053,9 @@ move_smb2_ea_to_cifs(char *dst, size_t d
char *name, *value;
size_t buf_size = dst_size;
size_t name_len, value_len, user_name_len;
+ u32 next_off;
- while (src_size > 0) {
+ while (src_size >= sizeof(*src)) {
name_len = (size_t)src->ea_name_length;
value_len = (size_t)le16_to_cpu(src->ea_value_length);
@@ -1110,14 +1111,22 @@ move_smb2_ea_to_cifs(char *dst, size_t d
if (!src->next_entry_offset)
break;
- if (src_size < le32_to_cpu(src->next_entry_offset)) {
- /* stop before overrun buffer */
- rc = -ERANGE;
- break;
+ next_off = le32_to_cpu(src->next_entry_offset);
+ if (next_off < sizeof(*src) || src_size < next_off) {
+ cifs_dbg(FYI, "EA next_entry_offset %u out of range [%zu, %zu]\n",
+ next_off, sizeof(*src), src_size);
+ rc = smb_EIO2(smb_eio_trace_ea_next_offset,
+ next_off, src_size);
+ goto out;
+ }
+ src_size -= next_off;
+ src = (void *)((char *)src + next_off);
+ if (src_size > 0 && src_size < sizeof(*src)) {
+ cifs_dbg(FYI, "EA next_entry_offset %u left truncated entry (%zu bytes)\n",
+ next_off, src_size);
+ rc = smb_EIO2(smb_eio_trace_ea_next_offset, next_off, src_size);
+ goto out;
}
- src_size -= le32_to_cpu(src->next_entry_offset);
- src = (void *)((char *)src +
- le32_to_cpu(src->next_entry_offset));
}
/* didn't find the named attribute */
--- a/fs/smb/client/trace.h
+++ b/fs/smb/client/trace.h
@@ -27,6 +27,7 @@
EM(smb_eio_trace_copychunk_overcopy_c, "copychunk_overcopy_c") \
EM(smb_eio_trace_create_rsp_too_small, "create_rsp_too_small") \
EM(smb_eio_trace_dfsref_no_rsp, "dfsref_no_rsp") \
+ EM(smb_eio_trace_ea_next_offset, "ea_next_offset") \
EM(smb_eio_trace_ea_overrun, "ea_overrun") \
EM(smb_eio_trace_extract_will_pin, "extract_will_pin") \
EM(smb_eio_trace_forced_shutdown, "forced_shutdown") \
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 369/398] mm/huge_memory: bypass THP tuneables for huge pfnmap mappings
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (365 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 368/398] mm: move vma_kernel_pagesize() from hugetlb to mm.h Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 370/398] cifs: Fix specification of function pointers Greg Kroah-Hartman
` (35 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM), Zi Yan,
Cedric Le Goater, Saravanan D, Lance Yang, SJ Park, Baolin Wang,
Barry Song, David Hildenbrand, Dev Jain, Jason Gunthorpe,
Liam R. Howlett, Peter Xu, Ryan Roberts, Andrew Morton,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
[ Upstream commit e384abeb559d10d6505aec053ede9368d81d4c71 ]
The sysfs THP tuneables at /sys/kernel/mm/transparent_huge_pages/ rather
confusingly only control the behaviour of THP in some instances.
They are not applicable to MADV_COLLAPSE operations, nor to DAX mappings.
Long-term, THP is predicated upon compaction being able to obtain large
folios to populate THP ranges.
However, vm_normal_folio() returns NULL for PFN map mappings, thus their
reference count is maintained by the driver, not core mm.
As a consequence, the folios are not subject to reclaim nor compaction, so
are not truly part of the THP mechanism at all.
However, since commit 5dd40721f147 ("mm: allow THP orders for PFNMAPs")
introduced the ability to establish huge PFN maps, they have been subject
to THP tuneables.
This is incorrect - if a huge PFN map is available (defined by
vma->vm_ops->huge_fault being non-NULL for a VMA_PFNMAP_BIT VMA), then it
should be mapped huge upon fault-in.
Correct this by explicitly checking for this while ensuring that smaps
continues to accurately report THPeligible statistics.
While here, abstract the entire file-backed THP check in
vma_can_map_huge_file(), with sensible separation of logic into helper
functions.
Note that drm_gem_shmem_mmap() and panthor_gem_mmap() establish huge PFN
maps of shmem folios, however they are marked unevictable in
drm_gem_get_pages(), and in any case would fail the reference check in
__remove_mapping() even if they weren't.
Failing to map huge PFN maps has resulted in significant real-world
performance degradation, see links for details.
[ziy@nvidia.com: rename some functions]
Link: https://lore.kernel.org/DL1HIHWYJ7TB.1CY76SJS0V03L@nvidia.com
Link: https://lore.kernel.org/20260827-hugepfn-allowable-orders-v1-1-94819c8807c8@kernel.org
Fixes: 5dd40721f147 ("mm: allow THP orders for PFNMAPs")
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Signed-off-by: Zi Yan <ziy@nvidia.com>
Reported-by: Cedric Le Goater <clg@redhat.com>
Closes: https://lore.kernel.org/linux-mm/20260805055544.1568534-1-clg@redhat.com/
Reported-by: Saravanan D <saravanand@crusoe.ai>
Closes: https://lore.kernel.org/linux-mm/20260821070520.25759-1-saravanand@crusoe.ai/
Reviewed-by: Zi Yan <ziy@nvidia.com>
Tested-by: Saravanan D <saravanand@crusoe.ai>
Tested-by: Lance Yang <lance.yang@linux.dev>
Reviewed-by: SJ Park <sj@kernel.org>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Barry Song <baohua@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Jason Gunthorpe <jgg@ziepe.ca>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Peter Xu <peterx@redhat.com>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
[ replaced vma_test(vma, VMA_PFNMAP_BIT) with (vma->vm_flags & VM_PFNMAP) ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/huge_memory.c | 86 ++++++++++++++++++++++++++++++++++++++++---------------
1 file changed, 64 insertions(+), 22 deletions(-)
--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -84,7 +84,7 @@ unsigned long huge_anon_orders_madvise _
unsigned long huge_anon_orders_inherit __read_mostly;
static bool anon_orders_configured __initdata;
-static inline bool file_thp_enabled(struct vm_area_struct *vma)
+static inline bool file_thp_enabled(const struct vm_area_struct *vma)
{
struct inode *inode;
@@ -102,6 +102,67 @@ static inline bool file_thp_enabled(stru
return !inode_is_open_for_write(inode) && S_ISREG(inode->i_mode);
}
+static bool vma_file_bypass_thp_tuneables(const struct vm_area_struct *vma,
+ enum tva_type type)
+{
+ const bool has_huge_fault = vma->vm_ops->huge_fault;
+
+ /* MADV_COLLAPSE ignores tuneables. */
+ if (type == TVA_FORCED_COLLAPSE)
+ return true;
+ /* Huge PFN mappings are uncompactable so the policy doesn't apply. */
+ if ((vma->vm_flags & VM_PFNMAP) && has_huge_fault)
+ return true;
+ return false;
+}
+
+static bool vma_file_allow_thp_tuneables(vm_flags_t vm_flags)
+{
+ /* THP=always? */
+ if (hugepage_global_always())
+ return true;
+ /* THP=madvise and marked MADV_HUGEPAGE? */
+ if (hugepage_global_enabled() && (vm_flags & VM_HUGEPAGE))
+ return true;
+ return false;
+}
+
+static bool vma_file_check_thp_tuneables(const struct vm_area_struct *vma,
+ vm_flags_t vm_flags, enum tva_type type)
+{
+ return vma_file_bypass_thp_tuneables(vma, type) ||
+ vma_file_allow_thp_tuneables(vm_flags);
+}
+
+static bool vma_can_map_huge_file(const struct vm_area_struct *vma,
+ vm_flags_t vm_flags, enum tva_type type)
+{
+ const bool has_huge_fault = vma->vm_ops->huge_fault;
+
+ /*
+ * Enforce THP collapse requirements as necessary. Anonymous vmas
+ * were already handled in thp_vma_allowable_orders().
+ */
+ if (!vma_file_check_thp_tuneables(vma, vm_flags, type))
+ return false;
+
+ switch (type) {
+ case TVA_PAGEFAULT:
+ /*
+ * Trust that ->huge_fault() handlers know what they are doing
+ * in fault path.
+ */
+ return has_huge_fault;
+ case TVA_SMAPS:
+ if (has_huge_fault)
+ return true;
+ fallthrough;
+ default:
+ /* Only regular file is valid in collapse path. */
+ return file_thp_enabled(vma);
+ }
+}
+
unsigned long __thp_vma_allowable_orders(struct vm_area_struct *vma,
vm_flags_t vm_flags,
enum tva_type type,
@@ -174,27 +235,8 @@ unsigned long __thp_vma_allowable_orders
vma, vma->vm_pgoff, 0,
forced_collapse);
- if (!vma_is_anonymous(vma)) {
- /*
- * Enforce THP collapse requirements as necessary. Anonymous vmas
- * were already handled in thp_vma_allowable_orders().
- */
- if (!forced_collapse &&
- (!hugepage_global_enabled() || (!(vm_flags & VM_HUGEPAGE) &&
- !hugepage_global_always())))
- return 0;
-
- /*
- * Trust that ->huge_fault() handlers know what they are doing
- * in fault path.
- */
- if (((in_pf || smaps)) && vma->vm_ops->huge_fault)
- return orders;
- /* Only regular file is valid in collapse path */
- if (((!in_pf || smaps)) && file_thp_enabled(vma))
- return orders;
- return 0;
- }
+ if (!vma_is_anonymous(vma))
+ return vma_can_map_huge_file(vma, vm_flags, type) ? orders : 0;
if (vma_is_temporary_stack(vma))
return 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 423/438] smb: client: fix potential OOB read in smb3_enum_snapshots()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (421 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 422/438] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 424/438] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Greg Kroah-Hartman
` (26 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit 4775c3b7a597907e0b97556c7986fda238a377ae upstream.
If snapshot_array_size is smaller than GMT_TOKEN_SIZE,
smb3_enum_snapshots() sets ret_data_len to
sizeof(struct smb_snapshot_array) without verifying the actual length
of the server's reply.
Because SMB2_ioctl() places no lower bound on the server-supplied
OutputCount and allocates retbuf to exactly that length, a short reply
results in ret_data_len exceeding the size of retbuf. The subsequent
copy_to_user() then reads past the end of retbuf, leaking adjacent slab
memory to userspace. The subsequent clamp check is ineffective as it
only reduces ret_data_len.
Fix this by rejecting replies shorter than
sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set
to the 12-byte struct size rather than the 16-byte
MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes
is exactly what copy_to_user() attempts to read.
Fixes: e02789a53d71 ("smb3: enumerating snapshots was leaving part of the data off end")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -2460,8 +2460,14 @@ smb3_enum_snapshots(const unsigned int x
* and retry the ioctl again with larger array size sufficient
* to hold all of the snapshot GMT tokens on the second try.
*/
- if (snapshot_in.snapshot_array_size < GMT_TOKEN_SIZE)
+ if (snapshot_in.snapshot_array_size < GMT_TOKEN_SIZE) {
+ if (ret_data_len < sizeof(struct smb_snapshot_array)) {
+ rc = -EIO;
+ kfree(retbuf);
+ return rc;
+ }
ret_data_len = sizeof(struct smb_snapshot_array);
+ }
/*
* We return struct SRV_SNAPSHOT_ARRAY, followed by
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 370/398] cifs: Fix specification of function pointers
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (366 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 369/398] mm/huge_memory: bypass THP tuneables for huge pfnmap mappings Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 371/398] 9p: Fix v9fs_issue_write() to update i_size and remote_i_size Greg Kroah-Hartman
` (34 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Howells,
Paulo Alcantara (Red Hat), linux-cifs, Steve French, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
[ Upstream commit 6a86a4cc281a5cfceda7af60ea6fa506b3db7430 ]
Change the mid_receive_t, mid_callback_t and mid_handle_t function pointers
to have the pointer marker in the typedef.
Signed-off-by: David Howells <dhowells@redhat.com>
Reviewed-by: Paulo Alcantara (Red Hat) <pc@manguebit.org>
cc: linux-cifs@vger.kernel.org
Signed-off-by: Steve French <stfrench@microsoft.com>
Stable-dep-of: c60ae98c5aa6 ("9p: Fix v9fs_issue_write() to update i_size and remote_i_size")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/cifsglob.h | 12 ++++++------
fs/smb/client/cifsproto.h | 8 ++++----
fs/smb/client/transport.c | 4 ++--
3 files changed, 12 insertions(+), 12 deletions(-)
--- a/fs/smb/client/cifsglob.h
+++ b/fs/smb/client/cifsglob.h
@@ -1663,7 +1663,7 @@ static inline void cifs_stats_bytes_read
* Returns zero on a successful receive, or an error. The receive state in
* the TCP_Server_Info will also be updated.
*/
-typedef int (mid_receive_t)(struct TCP_Server_Info *server,
+typedef int (*mid_receive_t)(struct TCP_Server_Info *server,
struct mid_q_entry *mid);
/*
@@ -1674,13 +1674,13 @@ typedef int (mid_receive_t)(struct TCP_S
* - it will be called by cifsd, with no locks held
* - the mid will be removed from any lists
*/
-typedef void (mid_callback_t)(struct mid_q_entry *mid);
+typedef void (*mid_callback_t)(struct mid_q_entry *mid);
/*
* This is the protopyte for mid handle function. This is called once the mid
* has been recognized after decryption of the message.
*/
-typedef int (mid_handle_t)(struct TCP_Server_Info *server,
+typedef int (*mid_handle_t)(struct TCP_Server_Info *server,
struct mid_q_entry *mid);
/* one of these for every pending CIFS request to the server */
@@ -1698,9 +1698,9 @@ struct mid_q_entry {
unsigned long when_sent; /* time when smb send finished */
unsigned long when_received; /* when demux complete (taken off wire) */
#endif
- mid_receive_t *receive; /* call receive callback */
- mid_callback_t *callback; /* call completion callback */
- mid_handle_t *handle; /* call handle mid callback */
+ mid_receive_t receive; /* call receive callback */
+ mid_callback_t callback; /* call completion callback */
+ mid_handle_t handle; /* call handle mid callback */
void *callback_data; /* general purpose pointer for callback */
struct task_struct *creator;
void *resp_buf; /* pointer to received SMB header */
--- a/fs/smb/client/cifsproto.h
+++ b/fs/smb/client/cifsproto.h
@@ -97,10 +97,10 @@ extern int cifs_ipaddr_cmp(struct sockad
extern bool cifs_match_ipaddr(struct sockaddr *srcaddr, struct sockaddr *rhs);
extern int cifs_discard_remaining_data(struct TCP_Server_Info *server);
extern int cifs_call_async(struct TCP_Server_Info *server,
- struct smb_rqst *rqst,
- mid_receive_t *receive, mid_callback_t *callback,
- mid_handle_t *handle, void *cbdata, const int flags,
- const struct cifs_credits *exist_credits);
+ struct smb_rqst *rqst,
+ mid_receive_t receive, mid_callback_t callback,
+ mid_handle_t handle, void *cbdata, const int flags,
+ const struct cifs_credits *exist_credits);
extern struct TCP_Server_Info *cifs_pick_channel(struct cifs_ses *ses);
extern int cifs_send_recv(const unsigned int xid, struct cifs_ses *ses,
struct TCP_Server_Info *server,
--- a/fs/smb/client/transport.c
+++ b/fs/smb/client/transport.c
@@ -659,8 +659,8 @@ int wait_for_response(struct TCP_Server_
*/
int
cifs_call_async(struct TCP_Server_Info *server, struct smb_rqst *rqst,
- mid_receive_t *receive, mid_callback_t *callback,
- mid_handle_t *handle, void *cbdata, const int flags,
+ mid_receive_t receive, mid_callback_t callback,
+ mid_handle_t handle, void *cbdata, const int flags,
const struct cifs_credits *exist_credits)
{
int rc;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 424/438] smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (422 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 423/438] smb: client: fix potential OOB read in smb3_enum_snapshots() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 425/438] smb: client: fix server->total_read for compound encrypted PDUs Greg Kroah-Hartman
` (25 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit 5f0306e731e2f46e91419eae57eee3a241c055e0 upstream.
In cifs_query_reparse_point(), the start >= end check before casting to
struct reparse_data_buffer * only ensures the start pointer is within the
response. It fails to verify that there is enough space remaining for the
fixed 8-byte header of the structure.
If a server provides a DataOffset that leaves less than 8 bytes remaining,
the check passes, but subsequent reads of ReparseTag and ReparseDataLength
will occur out-of-bounds.
Fix this by ensuring the remaining space is at least the size of the
reparse_data_buffer structure before accessing its fields.
Fixes: 56e84c64fc25 ("cifs: Fix validation of SMB1 query reparse point response")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/cifssmb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/smb/client/cifssmb.c
+++ b/fs/smb/client/cifssmb.c
@@ -3080,7 +3080,7 @@ int cifs_query_reparse_point(const unsig
end = 2 + get_bcc(&io_rsp->hdr) + (__u8 *)&io_rsp->ByteCount;
start = (__u8 *)&io_rsp->hdr.Protocol + data_offset;
- if (start >= end) {
+ if (start >= end || (size_t)(end - start) < sizeof(*buf)) {
rc = smb_EIO2(smb_eio_trace_qreparse_data_area,
(unsigned long)start - (unsigned long)io_rsp,
(unsigned long)end - (unsigned long)io_rsp);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 371/398] 9p: Fix v9fs_issue_write() to update i_size and remote_i_size
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (367 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 370/398] cifs: Fix specification of function pointers Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 372/398] mm/vma: correctly unaccount on mmap_prepare() failure Greg Kroah-Hartman
` (33 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Mulqueen, David Howells,
Dominique Martinet, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Howells <dhowells@redhat.com>
[ Upstream commit c60ae98c5aa64021751b38ab1313b19d620bf640 ]
Fix v9fs_issue_write() to update i_size and remote_i_size to the new size
of the server file if we made it larger, using the start fpos and the count
returned by p9_client_write() to calculate the new minimum file size.
This assumes that if the 9P server makes a short write (say it hits
ENOSPC), a reduced count is returned.
Fixes: 5fb70e7275a6 ("netfs, 9p: Implement helpers for new write code")
Reported-by: Michael Mulqueen <mike@method-b.uk>
Closes: https://lore.kernel.org/r/fbb9e395-1e07-4212-8f70-23f3cd498074@method-b.uk/
Cc: stable@vger.kernel.org
Signed-off-by: David Howells <dhowells@redhat.com>
Message-ID: <2226525.1789118704@warthog.procyon.org.uk>
Signed-off-by: Dominique Martinet <asmadeus@codewreck.org>
[ replaced unavailable netfs_write_sizes() with i_size_write() and direct remote_i_size assignment. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/9p/vfs_addr.c | 29 ++++++++++++++++++++++++++++-
1 file changed, 28 insertions(+), 1 deletion(-)
--- a/fs/9p/vfs_addr.c
+++ b/fs/9p/vfs_addr.c
@@ -54,11 +54,38 @@ static void v9fs_begin_writeback(struct
static void v9fs_issue_write(struct netfs_io_subrequest *subreq)
{
struct p9_fid *fid = subreq->rreq->netfs_priv;
+ struct inode *inode = subreq->rreq->inode;
+ struct netfs_inode *ictx = netfs_inode(inode);
int err, len;
len = p9_client_write(fid, subreq->start, &subreq->io_iter, &err);
- if (len > 0)
+ if (len > 0) {
+ unsigned long long end = subreq->start + len, i_size, remote;
+ bool set = false;
+
+ spin_lock(&inode->i_lock);
+
+ /* We can read the sizes directly as we hold i_lock. */
+ i_size = inode->i_size;
+ remote = ictx->remote_i_size;
+
+ if (end > i_size) {
+ i_size = end;
+ set = true;
+ }
+ if (end > remote) {
+ remote = end;
+ set = true;
+ }
+
+ if (set) {
+ i_size_write(inode, i_size);
+ ictx->remote_i_size = remote;
+ }
+ spin_unlock(&inode->i_lock);
+
__set_bit(NETFS_SREQ_MADE_PROGRESS, &subreq->flags);
+ }
netfs_write_subrequest_terminated(subreq, len ?: err);
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 425/438] smb: client: fix server->total_read for compound encrypted PDUs
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (423 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 424/438] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 426/438] smb: client: fix missing lower-bound check on DFS referral string offsets Greg Kroah-Hartman
` (24 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit f73726b83e4756fdaa099e1bc1143293bd57ad79 upstream.
In receive_encrypted_standard(), server->total_read is left at the
full decrypted frame size when walking sub-PDUs of a compound encrypted
frame. As a result, cifs_handle_standard() passes this full size
to smb2_check_message(), causing the PDU length guards to incorrectly
validate the entire compound frame instead of the current sub-PDU.
This allows truncated non-last sub-PDUs to bypass length validation,
leading to out-of-bounds reads in smb2_get_data_area_len().
Fix this by setting server->total_read to the true length of the
current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining
pdu_length for the last one.
Fixes: b24df3e30cbf ("cifs: update receive_encrypted_standard to handle compounded responses")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2ops.c | 1 +
1 file changed, 1 insertion(+)
--- a/fs/smb/client/smb2ops.c
+++ b/fs/smb/client/smb2ops.c
@@ -5383,6 +5383,7 @@ receive_encrypted_standard(struct TCP_Se
one_more:
shdr = (struct smb2_hdr *)buf;
next_cmd = le32_to_cpu(shdr->NextCommand);
+ server->total_read = next_cmd ? next_cmd : pdu_length;
if (*num_mids >= MAX_COMPOUND) {
cifs_server_dbg(VFS, "too many PDUs in compound\n");
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 372/398] mm/vma: correctly unaccount on mmap_prepare() failure
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (368 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 371/398] 9p: Fix v9fs_issue_write() to update i_size and remote_i_size Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 373/398] wifi: mac80211: track MU-MIMO configuration on disabled interfaces Greg Kroah-Hartman
` (32 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM), Jann Horn,
Liam R. Howlett, Pedro Falcato, Vlastimil Babka, Andrew Morton,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
[ Upstream commit 6cc27d82196385fe06853319f74312a7d8019726 ]
__mmap_setup() accounts memory for relevant mappings via:
security_vm_enough_memory_mm()
-> __vm_enough_memory()
-> vm_acct_memory()
If __mmap_setup() fails, this indicates that this accounting did not take
place, and thus it's appropriate for __mmap_region() to jump to
abort_munmap.
However if call_mmap_prepare() fails, it also jumps there and any accounted
memory is not correctly unaccounted.
Fix this by handling each error separately.
Link: https://lore.kernel.org/20260902-fix-unaccount-mmap_prepare-v1-1-ea070189fdfb@kernel.org
Fixes: c84bf6dd2b83 ("mm: introduce new .mmap_prepare() file callback")
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Cc: Jann Horn <jannh@google.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Pedro Falcato <pfalcato@suse.de>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/vma.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
--- a/mm/vma.c
+++ b/mm/vma.c
@@ -2693,10 +2693,12 @@ static unsigned long __mmap_region(struc
map.check_ksm_early = can_set_ksm_flags_early(&map);
error = __mmap_prepare(&map, uf);
- if (!error && have_mmap_prepare)
- error = call_mmap_prepare(&map);
if (error)
goto abort_munmap;
+ if (have_mmap_prepare)
+ error = call_mmap_prepare(&map);
+ if (error)
+ goto unacct_error;
if (map.check_ksm_early)
update_ksm_flags(&map);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 426/438] smb: client: fix missing lower-bound check on DFS referral string offsets
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (424 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 425/438] smb: client: fix server->total_read for compound encrypted PDUs Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 427/438] smb: client: fix missing iov bounds check in parse_posix_sids() Greg Kroah-Hartman
` (23 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit e83330c55edc0c3ac08aa6c95e49e4694c65523b upstream.
parse_dfs_referrals() checks that DfsPathOffset and NetworkAddressOffset
do not exceed the buffer end, but fails to check that they don't point
inside the referral header itself.
If a server provides an offset smaller than
sizeof(struct dfs_referral_level_3), the derived string pointer overlaps
with the struct fields, causing cifs_strndup_from_utf16() to interpret
header data as UTF-16 strings.
Fix this by enforcing that string offsets are at least sizeof(*ref).
Fixes: 4ecce920e13a ("CIFS: move DFS response parsing out of SMB1 code")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/misc.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
--- a/fs/smb/client/misc.c
+++ b/fs/smb/client/misc.c
@@ -788,7 +788,11 @@ parse_dfs_referrals(struct get_dfs_refer
node->ref_flag = le16_to_cpu(ref->ReferralEntryFlags);
/* copy DfsPath */
- if (le16_to_cpu(ref->DfsPathOffset) > data_end - (char *)ref) {
+ if (le16_to_cpu(ref->DfsPathOffset) < sizeof(*ref) ||
+ le16_to_cpu(ref->DfsPathOffset) > data_end - (char *)ref) {
+ cifs_dbg(VFS, "%s: DfsPathOffset %u out of range [%zu, %td]\n",
+ __func__, le16_to_cpu(ref->DfsPathOffset),
+ sizeof(*ref), data_end - (char *)ref);
rc = -EINVAL;
goto parse_DFS_referrals_exit;
}
@@ -802,7 +806,11 @@ parse_dfs_referrals(struct get_dfs_refer
}
/* copy link target UNC */
- if (le16_to_cpu(ref->NetworkAddressOffset) > data_end - (char *)ref) {
+ if (le16_to_cpu(ref->NetworkAddressOffset) < sizeof(*ref) ||
+ le16_to_cpu(ref->NetworkAddressOffset) > data_end - (char *)ref) {
+ cifs_dbg(VFS, "%s: NetworkAddressOffset %u out of range [%zu, %td]\n",
+ __func__, le16_to_cpu(ref->NetworkAddressOffset),
+ sizeof(*ref), data_end - (char *)ref);
rc = -EINVAL;
goto parse_DFS_referrals_exit;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 373/398] wifi: mac80211: track MU-MIMO configuration on disabled interfaces
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (369 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 372/398] mm/vma: correctly unaccount on mmap_prepare() failure Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 374/398] wifi: mac80211: refuse to make a monitor active when it has no queue Greg Kroah-Hartman
` (31 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Benjamin Berg, Johannes Berg,
Miri Korenblit, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Benjamin Berg <benjamin.berg@intel.com>
[ Upstream commit a5aa46f1ac4f53e03b9b75cbf55634131f2f8cac ]
For monitoring, userspace will try to configure the VIF sdata, while the
driver may see the monitor_sdata that is created when only monitor
interfaces are up. This causes the odd situation that it may not be
possible to store the MU-MIMO configuration on monitor_sdata.
Fix this by storing that information on the VIF sdata and updating the
monitor_sdata when available and the interface is up. Also, adjust the
code that adds monitor_sdata so that it will configure MU-MIMO based on
the newly added interface or one of the existing ones.
This should give a mostly consistent behaviour when configuring MU-MIMO
on sniffer interfaces. Should the user configure MU-MIMO on multiple
sniffer interfaces, then mac80211 will simply select one of the
configurations. This behaviour should be good enough and avoids breaking
user expectations in the common scenarios.
Signed-off-by: Benjamin Berg <benjamin.berg@intel.com>
Reviewed-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20251110141514.677915f8f6bb.If4e04a57052f9ca763562a67248b06fd80d0c2c1@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 2b04d6556964 ("wifi: mac80211: refuse to make a monitor active when it has no queue")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mac80211/cfg.c | 47 ++++++++++++++++++++++++++++++---------------
net/mac80211/ieee80211_i.h | 3 +-
net/mac80211/iface.c | 46 ++++++++++++++++++++++++++++++++++++++------
net/mac80211/util.c | 3 +-
4 files changed, 76 insertions(+), 23 deletions(-)
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -63,12 +63,14 @@ static void ieee80211_set_mu_mimo_follow
memcpy(sdata->vif.bss_conf.mu_group.position,
params->vht_mumimo_groups + WLAN_MEMBERSHIP_LEN,
WLAN_USER_POSITION_LEN);
- ieee80211_link_info_change_notify(sdata, &sdata->deflink,
- BSS_CHANGED_MU_GROUPS);
+
/* don't care about endianness - just check for 0 */
memcpy(&membership, params->vht_mumimo_groups,
WLAN_MEMBERSHIP_LEN);
mu_mimo_groups = membership != 0;
+
+ /* Unset following if configured explicitly */
+ eth_broadcast_addr(sdata->u.mntr.mu_follow_addr);
}
if (params->vht_mumimo_follow_addr) {
@@ -76,16 +78,26 @@ static void ieee80211_set_mu_mimo_follow
is_valid_ether_addr(params->vht_mumimo_follow_addr);
ether_addr_copy(sdata->u.mntr.mu_follow_addr,
params->vht_mumimo_follow_addr);
+
+ /* Unset current membership until a management frame is RXed */
+ memset(sdata->vif.bss_conf.mu_group.membership, 0,
+ WLAN_MEMBERSHIP_LEN);
}
sdata->vif.bss_conf.mu_mimo_owner = mu_mimo_groups || mu_mimo_follow;
+
+ /* Notify only after setting mu_mimo_owner */
+ if (sdata->vif.bss_conf.mu_mimo_owner &&
+ sdata->flags & IEEE80211_SDATA_IN_DRIVER)
+ ieee80211_link_info_change_notify(sdata, &sdata->deflink,
+ BSS_CHANGED_MU_GROUPS);
}
static int ieee80211_set_mon_options(struct ieee80211_sub_if_data *sdata,
struct vif_params *params)
{
struct ieee80211_local *local = sdata->local;
- struct ieee80211_sub_if_data *monitor_sdata;
+ struct ieee80211_sub_if_data *monitor_sdata = NULL;
/* check flags first */
if (params->flags && ieee80211_sdata_running(sdata)) {
@@ -103,23 +115,28 @@ static int ieee80211_set_mon_options(str
return -EBUSY;
}
- /* also validate MU-MIMO change */
- if (ieee80211_hw_check(&local->hw, NO_VIRTUAL_MONITOR))
- monitor_sdata = sdata;
- else
- monitor_sdata = wiphy_dereference(local->hw.wiphy,
- local->monitor_sdata);
-
- if (!monitor_sdata &&
+ /* validate whether MU-MIMO can be configured */
+ if (!ieee80211_hw_check(&local->hw, WANT_MONITOR_VIF) &&
+ !ieee80211_hw_check(&local->hw, NO_VIRTUAL_MONITOR) &&
(params->vht_mumimo_groups || params->vht_mumimo_follow_addr))
return -EOPNOTSUPP;
+ /* Also update dependent monitor_sdata if required */
+ if (test_bit(SDATA_STATE_RUNNING, &sdata->state) &&
+ !ieee80211_hw_check(&local->hw, NO_VIRTUAL_MONITOR))
+ monitor_sdata = wiphy_dereference(local->hw.wiphy,
+ local->monitor_sdata);
+
/* apply all changes now - no failures allowed */
- if (monitor_sdata &&
- (ieee80211_hw_check(&local->hw, WANT_MONITOR_VIF) ||
- ieee80211_hw_check(&local->hw, NO_VIRTUAL_MONITOR)))
- ieee80211_set_mu_mimo_follow(monitor_sdata, params);
+ if (ieee80211_hw_check(&local->hw, WANT_MONITOR_VIF) ||
+ ieee80211_hw_check(&local->hw, NO_VIRTUAL_MONITOR)) {
+ /* This is copied in when the VIF is activated */
+ ieee80211_set_mu_mimo_follow(sdata, params);
+
+ if (monitor_sdata)
+ ieee80211_set_mu_mimo_follow(monitor_sdata, params);
+ }
if (params->flags) {
if (ieee80211_sdata_running(sdata)) {
--- a/net/mac80211/ieee80211_i.h
+++ b/net/mac80211/ieee80211_i.h
@@ -2114,7 +2114,8 @@ void ieee80211_adjust_monitor_flags(stru
const int offset);
int ieee80211_do_open(struct wireless_dev *wdev, bool coming_up);
void ieee80211_sdata_stop(struct ieee80211_sub_if_data *sdata);
-int ieee80211_add_virtual_monitor(struct ieee80211_local *local);
+int ieee80211_add_virtual_monitor(struct ieee80211_local *local,
+ struct ieee80211_sub_if_data *creator_sdata);
void ieee80211_del_virtual_monitor(struct ieee80211_local *local);
bool __ieee80211_recalc_txpower(struct ieee80211_link_data *link);
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -753,8 +753,9 @@ static void ieee80211_do_stop(struct iee
ieee80211_configure_filter(local);
ieee80211_hw_config(local, -1, hw_reconf_flags);
+ /* Passing NULL means an interface is picked for configuration */
if (local->virt_monitors == local->open_count)
- ieee80211_add_virtual_monitor(local);
+ ieee80211_add_virtual_monitor(local, NULL);
}
void ieee80211_stop_mbssid(struct ieee80211_sub_if_data *sdata)
@@ -1215,7 +1216,8 @@ static void ieee80211_sdata_init(struct
ieee80211_link_init(sdata, -1, &sdata->deflink, &sdata->vif.bss_conf);
}
-int ieee80211_add_virtual_monitor(struct ieee80211_local *local)
+int ieee80211_add_virtual_monitor(struct ieee80211_local *local,
+ struct ieee80211_sub_if_data *creator_sdata)
{
struct ieee80211_sub_if_data *sdata;
int ret;
@@ -1223,10 +1225,14 @@ int ieee80211_add_virtual_monitor(struct
ASSERT_RTNL();
lockdep_assert_wiphy(local->hw.wiphy);
- if (local->monitor_sdata ||
- ieee80211_hw_check(&local->hw, NO_VIRTUAL_MONITOR))
+ if (ieee80211_hw_check(&local->hw, NO_VIRTUAL_MONITOR))
return 0;
+ /* Already have a monitor set up, configure it */
+ sdata = wiphy_dereference(local->hw.wiphy, local->monitor_sdata);
+ if (sdata)
+ goto configure_monitor;
+
sdata = kzalloc(sizeof(*sdata) + local->hw.vif_data_size, GFP_KERNEL);
if (!sdata)
return -ENOMEM;
@@ -1279,6 +1285,32 @@ int ieee80211_add_virtual_monitor(struct
skb_queue_head_init(&sdata->status_queue);
wiphy_work_init(&sdata->work, ieee80211_iface_work);
+configure_monitor:
+ /* Copy in the MU-MIMO configuration if set */
+ if (!creator_sdata) {
+ struct ieee80211_sub_if_data *other;
+
+ list_for_each_entry(other, &local->mon_list, list) {
+ if (!other->vif.bss_conf.mu_mimo_owner)
+ continue;
+
+ creator_sdata = other;
+ break;
+ }
+ }
+
+ if (creator_sdata && creator_sdata->vif.bss_conf.mu_mimo_owner) {
+ sdata->vif.bss_conf.mu_mimo_owner = true;
+ memcpy(&sdata->vif.bss_conf.mu_group,
+ &creator_sdata->vif.bss_conf.mu_group,
+ sizeof(sdata->vif.bss_conf.mu_group));
+ memcpy(&sdata->u.mntr.mu_follow_addr,
+ creator_sdata->u.mntr.mu_follow_addr, ETH_ALEN);
+
+ ieee80211_link_info_change_notify(sdata, &sdata->deflink,
+ BSS_CHANGED_MU_GROUPS);
+ }
+
return 0;
}
@@ -1435,11 +1467,13 @@ int ieee80211_do_open(struct wireless_de
if (res)
goto err_stop;
} else {
- if (local->virt_monitors == 0 && local->open_count == 0) {
- res = ieee80211_add_virtual_monitor(local);
+ /* add/configure if there is no non-monitor interface */
+ if (local->virt_monitors == local->open_count) {
+ res = ieee80211_add_virtual_monitor(local, sdata);
if (res)
goto err_stop;
}
+
local->virt_monitors++;
/* must be before the call to ieee80211_configure_filter */
--- a/net/mac80211/util.c
+++ b/net/mac80211/util.c
@@ -2202,9 +2202,10 @@ int ieee80211_reconfig(struct ieee80211_
}
}
+ /* Passing NULL means an interface is picked for configuration */
if (local->virt_monitors > 0 &&
local->virt_monitors == local->open_count)
- ieee80211_add_virtual_monitor(local);
+ ieee80211_add_virtual_monitor(local, NULL);
if (!suspended)
return 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 427/438] smb: client: fix missing iov bounds check in parse_posix_sids()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (425 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 426/438] smb: client: fix missing lower-bound check on DFS referral string offsets Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 428/438] fs/super: skip non-memcg-aware nr_cached_objects in memcg slab shrink Greg Kroah-Hartman
` (22 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
commit b09d092eb24ad0110f16a9b7c1ed5d2a0c1733dc upstream.
In parse_posix_sids(), sidsbuf_end is calculated using the server-supplied
out_len without being validated against the actual length of the received
iov (iov_len).
If a server provides an inflated out_len, sidsbuf_end will point past the
end of the iov. This defeats the bounds guards in posix_info_sid_size(),
allowing out-of-bounds reads into adjacent kernel memory.
Fix this by rejecting responses where the calculated sidsbuf_end would
exceed the received iov boundaries or cause pointer wraparound.
Fixes: a90f37e3d7ac ("smb: client: parse owner/group when creating reparse points")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/smb2inode.c | 11 +++++++++++
1 file changed, 11 insertions(+)
--- a/fs/smb/client/smb2inode.c
+++ b/fs/smb/client/smb2inode.c
@@ -76,6 +76,17 @@ static int parse_posix_sids(struct cifs_
sidsbuf = (u8 *)qi + le16_to_cpu(qi->OutputBufferOffset) + qi_len;
sidsbuf_end = sidsbuf + out_len - qi_len;
+ if (sidsbuf_end < sidsbuf) {
+ cifs_dbg(VFS, "%s: server-supplied out_len %u caused pointer wraparound\n",
+ __func__, out_len);
+ return -EINVAL;
+ }
+ if (sidsbuf_end > (u8 *)rsp_iov->iov_base + rsp_iov->iov_len) {
+ cifs_dbg(VFS, "%s: server-supplied out_len %u overruns iov by %td bytes\n",
+ __func__, out_len,
+ sidsbuf_end - ((u8 *)rsp_iov->iov_base + rsp_iov->iov_len));
+ return -EINVAL;
+ }
owner_len = posix_info_sid_size(sidsbuf, sidsbuf_end);
if (owner_len == -1)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 374/398] wifi: mac80211: refuse to make a monitor active when it has no queue
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (370 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 373/398] wifi: mac80211: track MU-MIMO configuration on disabled interfaces Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 375/398] scsi: fnic: Rename fnic_scsi_fcpio_reset() Greg Kroah-Hartman
` (30 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Devin Wittmayer, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Devin Wittmayer <lucid_duck@justthetip.ca>
[ Upstream commit 2b04d6556964ae9f89819b86a0a7801e39c3aae5 ]
A monitor interface only gets a TXQ if it's created active, and one can't
be added later. Setting the flag on a down interface is still allowed, so
the driver is handed a monitor with no queue. ath9k dereferences it:
BUG: kernel NULL pointer dereference, address: 0000000000000066
RIP: 0010:ath_tx_node_init+0x49/0x170 [ath9k]
ath9k_add_interface+0x10c/0x140 [ath9k]
drv_add_interface+0x54/0x250 [mac80211]
ieee80211_do_open+0x32f/0x800 [mac80211]
Reached with CAP_NET_ADMIN by "iw dev X set monitor active" followed by
"ip link set X up". RTNL is held, so netlink operations block behind it.
Refuse the flag when there is no queue to give.
Fixes: 79af1f866193 ("mac80211: avoid allocating TXQs that won't be used")
Cc: stable@vger.kernel.org
Signed-off-by: Devin Wittmayer <lucid_duck@justthetip.ca>
Link: https://patch.msgid.link/20260904200338.10829-1-lucid_duck@justthetip.ca
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mac80211/cfg.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/net/mac80211/cfg.c
+++ b/net/mac80211/cfg.c
@@ -115,6 +115,10 @@ static int ieee80211_set_mon_options(str
return -EBUSY;
}
+ /* TXQs are reserved in ieee80211_if_add() and cannot be added later */
+ if ((params->flags & MONITOR_FLAG_ACTIVE) && !sdata->vif.txq)
+ return -EOPNOTSUPP;
+
/* validate whether MU-MIMO can be configured */
if (!ieee80211_hw_check(&local->hw, WANT_MONITOR_VIF) &&
!ieee80211_hw_check(&local->hw, NO_VIRTUAL_MONITOR) &&
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 428/438] fs/super: skip non-memcg-aware nr_cached_objects in memcg slab shrink
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (426 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 427/438] smb: client: fix missing iov bounds check in parse_posix_sids() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 429/438] fs: fix missed removal of super_fs_objects_eligible() Greg Kroah-Hartman
` (21 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Usama Arif,
Christian Brauner (Amutable), Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Usama Arif <usama.arif@linux.dev>
[ Upstream commit 0baad6f9b9970c6e3f1d33dbfd17d1a77702771d ]
The super_block shrinker is registered with SHRINKER_MEMCG_AWARE because its
dentry and inode LRUs are memcg-aware (via list_lru). But the optional
->nr_cached_objects() hooks that the shrinker also drives are not memcg-aware:
btrfs extent maps and xfs inode reclaim operate on filesystem-global
state, and shmem's unused-huge shrinker walks a per-superblock shrinklist.
None of them filter by sc->memcg.
The mismatch shows up under memcg-heavy slab reclaim. shrink_slab_memcg()
calls do_shrink_slab() once per (memcg, NUMA node) pair for every memcg
whose bit is set in the per-superblock shrinker bitmap, which on a busy
host means hundreds of calls per reclaim pass. Each scan queues the same
global shrinker work item that's already kicked from the root path.
Because btrfs/xfs global count is typically non-zero on any in-use filesystem,
the returned total stays positive even if a memcg's own dentry/inode LRUs
are empty. shrink_slab_memcg() therefore never clears the SB shrinker bit
in the memcg bitmap, so subsequent reclaim passes from the same memcg
re-enter super_cache_count() and pay for the global counter walk again.
Restrict ->nr_cached_objects() to the global shrink path (sc->memcg NULL
or root). The memcg-aware dentry/inode LRUs keep being counted and
scanned per memcg as before; only the global fs-specific hooks are skipped.
The root/global shrink path still drives those hooks; only their
invocation from non-root memcg slab reclaim is removed.
Signed-off-by: Usama Arif <usama.arif@linux.dev>
Link: https://patch.msgid.link/20260609123047.1948242-1-usama.arif@linux.dev
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Stable-dep-of: 641aade99f06 ("fs: fix missed removal of super_fs_objects_eligible()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/super.c | 19 +++++++++++++++++--
1 file changed, 17 insertions(+), 2 deletions(-)
--- a/fs/super.c
+++ b/fs/super.c
@@ -24,6 +24,7 @@
#include <linux/export.h>
#include <linux/slab.h>
#include <linux/blkdev.h>
+#include <linux/memcontrol.h>
#include <linux/mount.h>
#include <linux/security.h>
#include <linux/writeback.h> /* for the emergency remount stuff */
@@ -170,6 +171,19 @@ static void super_wake(struct super_bloc
}
/*
+ * The s_op->nr_cached_objects hooks (used for example by btrfs and xfs)
+ * operate on filesystem-global state and ignore sc->memcg. Driving them
+ * from per-memcg shrink_slab_memcg() invocations only burns CPU walking
+ * per-cpu counters and queueing duplicate work: the actual reclaim happens on
+ * the global path (kswapd or root direct reclaim) regardless. Restrict them
+ * to that path.
+ */
+static inline bool super_fs_objects_eligible(struct shrink_control *sc)
+{
+ return !sc->memcg || mem_cgroup_is_root(sc->memcg);
+}
+
+/*
* One thing we have to be careful of with a per-sb shrinker is that we don't
* drop the last active reference to the superblock from within the shrinker.
* If that happens we could trigger unregistering the shrinker from within the
@@ -198,7 +212,7 @@ static unsigned long super_cache_scan(st
if (!super_trylock_shared(sb))
return SHRINK_STOP;
- if (sb->s_op->nr_cached_objects)
+ if (sb->s_op->nr_cached_objects && super_fs_objects_eligible(sc))
fs_objects = sb->s_op->nr_cached_objects(sb, sc);
inodes = list_lru_shrink_count(&sb->s_inode_lru, sc);
@@ -259,7 +273,8 @@ static unsigned long super_cache_count(s
return 0;
smp_rmb();
- if (sb->s_op && sb->s_op->nr_cached_objects)
+ if (sb->s_op && sb->s_op->nr_cached_objects &&
+ super_fs_objects_eligible(sc))
total_objects = sb->s_op->nr_cached_objects(sb, sc);
total_objects += list_lru_shrink_count(&sb->s_dentry_lru, sc);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 375/398] scsi: fnic: Rename fnic_scsi_fcpio_reset()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (371 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 374/398] wifi: mac80211: refuse to make a monitor active when it has no queue Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 376/398] scsi: fnic: Bump up version number Greg Kroah-Hartman
` (29 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karan Tilak Kumar, Sesidhar Baddela,
Arulprabhu Ponnusamy, Gian Carlo Boffa, Arun Easi,
Hannes Reinecke, Lee Duncan, Martin K. Petersen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karan Tilak Kumar <kartilak@cisco.com>
[ Upstream commit 31eda39bfd468a0fbabc0179e913c0755377e3b5 ]
The function has no dependency on SCSI/FCP, so rename it to
fnic_fcpio_reset() and move it to fnic_fcs.c
Tested-by: Karan Tilak Kumar <kartilak@cisco.com>
Reviewed-by: Sesidhar Baddela <sebaddel@cisco.com>
Reviewed-by: Arulprabhu Ponnusamy <arulponn@cisco.com>
Reviewed-by: Gian Carlo Boffa <gcboffa@cisco.com>
Reviewed-by: Arun Easi <aeasi@cisco.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Reviewed-by: Lee Duncan <lduncan@suse.com>
Signed-off-by: Karan Tilak Kumar <kartilak@cisco.com>
Co-developed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260217223943.7938-3-kartilak@cisco.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: 0cb1fd924126 ("scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/fnic/fdls_disc.c | 4 +--
drivers/scsi/fnic/fip.c | 2 -
drivers/scsi/fnic/fnic.h | 1
drivers/scsi/fnic/fnic_fcs.c | 50 ++++++++++++++++++++++++++++++++++++++
drivers/scsi/fnic/fnic_fdls.h | 2 -
drivers/scsi/fnic/fnic_scsi.c | 54 ------------------------------------------
6 files changed, 55 insertions(+), 58 deletions(-)
--- a/drivers/scsi/fnic/fdls_disc.c
+++ b/drivers/scsi/fnic/fdls_disc.c
@@ -4613,7 +4613,7 @@ void fnic_fdls_disc_start(struct fnic_ip
if (!iport->usefip) {
if (iport->flags & FNIC_FIRST_LINK_UP) {
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- fnic_scsi_fcpio_reset(iport->fnic);
+ fnic_fcpio_reset(iport->fnic);
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
iport->flags &= ~FNIC_FIRST_LINK_UP;
@@ -5072,7 +5072,7 @@ void fnic_fdls_link_down(struct fnic_ipo
iport->fabric.flags = 0;
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- fnic_scsi_fcpio_reset(iport->fnic);
+ fnic_fcpio_reset(iport->fnic);
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
list_for_each_entry_safe(tport, next, &iport->tport_list, links) {
FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
--- a/drivers/scsi/fnic/fip.c
+++ b/drivers/scsi/fnic/fip.c
@@ -737,7 +737,7 @@ void fnic_work_on_fip_timer(struct work_
if (memcmp(iport->selected_fcf.fcf_mac, zmac, ETH_ALEN) != 0) {
if (iport->flags & FNIC_FIRST_LINK_UP) {
- fnic_scsi_fcpio_reset(iport->fnic);
+ fnic_fcpio_reset(iport->fnic);
iport->flags &= ~FNIC_FIRST_LINK_UP;
}
--- a/drivers/scsi/fnic/fnic.h
+++ b/drivers/scsi/fnic/fnic.h
@@ -511,7 +511,6 @@ int fnic_host_reset(struct Scsi_Host *sh
void fnic_reset(struct Scsi_Host *shost);
int fnic_issue_fc_host_lip(struct Scsi_Host *shost);
void fnic_get_host_port_state(struct Scsi_Host *shost);
-void fnic_scsi_fcpio_reset(struct fnic *fnic);
int fnic_wq_copy_cmpl_handler(struct fnic *fnic, int copy_work_to_do, unsigned int cq_index);
int fnic_wq_cmpl_handler(struct fnic *fnic, int);
int fnic_flogi_reg_handler(struct fnic *fnic, u32);
--- a/drivers/scsi/fnic/fnic_fcs.c
+++ b/drivers/scsi/fnic/fnic_fcs.c
@@ -1108,3 +1108,53 @@ void fnic_reset_work_handler(struct work
spin_unlock_irqrestore(&reset_fnic_list_lock,
reset_fnic_list_lock_flags);
}
+
+void fnic_fcpio_reset(struct fnic *fnic)
+{
+ unsigned long flags;
+ enum fnic_state old_state;
+ struct fnic_iport_s *iport = &fnic->iport;
+ DECLARE_COMPLETION_ONSTACK(fw_reset_done);
+ int time_remain;
+
+ /* issue fw reset */
+ spin_lock_irqsave(&fnic->fnic_lock, flags);
+ if (unlikely(fnic->state == FNIC_IN_FC_TRANS_ETH_MODE)) {
+ /* fw reset is in progress, poll for its completion */
+ spin_unlock_irqrestore(&fnic->fnic_lock, flags);
+ FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ "fnic is in unexpected state: %d for fw_reset\n",
+ fnic->state);
+ return;
+ }
+
+ old_state = fnic->state;
+ fnic->state = FNIC_IN_FC_TRANS_ETH_MODE;
+
+ fnic_update_mac_locked(fnic, iport->hwmac);
+ fnic->fw_reset_done = &fw_reset_done;
+ spin_unlock_irqrestore(&fnic->fnic_lock, flags);
+
+ FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ "Issuing fw reset\n");
+ if (fnic_fw_reset_handler(fnic)) {
+ spin_lock_irqsave(&fnic->fnic_lock, flags);
+ if (fnic->state == FNIC_IN_FC_TRANS_ETH_MODE)
+ fnic->state = old_state;
+ spin_unlock_irqrestore(&fnic->fnic_lock, flags);
+ } else {
+ FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ "Waiting for fw completion\n");
+ time_remain = wait_for_completion_timeout(&fw_reset_done,
+ msecs_to_jiffies(FNIC_FW_RESET_TIMEOUT));
+ FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ "Woken up after fw completion timeout\n");
+ if (time_remain == 0) {
+ FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ "FW reset completion timed out after %d ms\n",
+ FNIC_FW_RESET_TIMEOUT);
+ }
+ atomic64_inc(&fnic->fnic_stats.reset_stats.fw_reset_timeouts);
+ }
+ fnic->fw_reset_done = NULL;
+}
--- a/drivers/scsi/fnic/fnic_fdls.h
+++ b/drivers/scsi/fnic/fnic_fdls.h
@@ -410,6 +410,7 @@ void fnic_fdls_add_tport(struct fnic_ipo
void fnic_fdls_remove_tport(struct fnic_iport_s *iport,
struct fnic_tport_s *tport,
unsigned long flags);
+void fnic_fcpio_reset(struct fnic *fnic);
/* fip.c */
void fnic_fcoe_send_vlan_req(struct fnic *fnic);
@@ -422,7 +423,6 @@ void fnic_handle_fip_timer(struct timer_
extern void fdls_fabric_timer_callback(struct timer_list *t);
/* fnic_scsi.c */
-void fnic_scsi_fcpio_reset(struct fnic *fnic);
extern void fdls_fabric_timer_callback(struct timer_list *t);
void fnic_rport_exch_reset(struct fnic *fnic, u32 fcid);
int fnic_fdls_register_portid(struct fnic_iport_s *iport, u32 port_id,
--- a/drivers/scsi/fnic/fnic_scsi.c
+++ b/drivers/scsi/fnic/fnic_scsi.c
@@ -1974,8 +1974,7 @@ void fnic_scsi_unload(struct fnic *fnic)
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
if (fdls_get_state(&fnic->iport.fabric) != FDLS_STATE_INIT)
- fnic_scsi_fcpio_reset(fnic);
-
+ fnic_fcpio_reset(fnic);
spin_lock_irqsave(&fnic->fnic_lock, flags);
fnic->in_remove = 1;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
@@ -3039,54 +3038,3 @@ int fnic_eh_host_reset_handler(struct sc
ret = fnic_host_reset(shost);
return ret;
}
-
-
-void fnic_scsi_fcpio_reset(struct fnic *fnic)
-{
- unsigned long flags;
- enum fnic_state old_state;
- struct fnic_iport_s *iport = &fnic->iport;
- DECLARE_COMPLETION_ONSTACK(fw_reset_done);
- int time_remain;
-
- /* issue fw reset */
- spin_lock_irqsave(&fnic->fnic_lock, flags);
- if (unlikely(fnic->state == FNIC_IN_FC_TRANS_ETH_MODE)) {
- /* fw reset is in progress, poll for its completion */
- spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "fnic is in unexpected state: %d for fw_reset\n",
- fnic->state);
- return;
- }
-
- old_state = fnic->state;
- fnic->state = FNIC_IN_FC_TRANS_ETH_MODE;
-
- fnic_update_mac_locked(fnic, iport->hwmac);
- fnic->fw_reset_done = &fw_reset_done;
- spin_unlock_irqrestore(&fnic->fnic_lock, flags);
-
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "Issuing fw reset\n");
- if (fnic_fw_reset_handler(fnic)) {
- spin_lock_irqsave(&fnic->fnic_lock, flags);
- if (fnic->state == FNIC_IN_FC_TRANS_ETH_MODE)
- fnic->state = old_state;
- spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- } else {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "Waiting for fw completion\n");
- time_remain = wait_for_completion_timeout(&fw_reset_done,
- msecs_to_jiffies(FNIC_FW_RESET_TIMEOUT));
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "Woken up after fw completion timeout\n");
- if (time_remain == 0) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "FW reset completion timed out after %d ms)\n",
- FNIC_FW_RESET_TIMEOUT);
- }
- atomic64_inc(&fnic->fnic_stats.reset_stats.fw_reset_timeouts);
- }
- fnic->fw_reset_done = NULL;
-}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 429/438] fs: fix missed removal of super_fs_objects_eligible()
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (427 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 428/438] fs/super: skip non-memcg-aware nr_cached_objects in memcg slab shrink Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 430/438] scsi: fnic: Make debug logging protocol independent Greg Kroah-Hartman
` (20 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qi Zheng, Usama Arif, Baolin Wang,
Christian Brauner, David Hildenbrand, Hugh Dickins,
Johannes Weiner, Michal Hocko, Muchun Song, Roman Gushchin,
Shakeel Butt, Andrew Morton, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qi Zheng <zhengqi.arch@bytedance.com>
[ Upstream commit 641aade99f06df0037e52b5c81645461b7132947 ]
Commit 0ef8faff490be ("fs: push nr_cached_objects memcg gating into
individual filesystems") was meant to drop the blanket memcg gate in
fs/super.c and let each ->nr_cached_objects() implementation decide for
itself whether it is meaningful in per-memcg reclaim. However, when
that patch was applied the removal of super_fs_objects_eligible() and
its two call sites in super_cache_scan() / super_cache_count() was
lost, so the helper is still gating every ->nr_cached_objects() hook
and 0ef8faff490be is effectively a no-op.
Consequences of the leftover gate:
- XFS's inode-reclaim hook, which is intentionally driven from
per-memcg contexts to free memcg-charged slab, is still
short-circuited in fs/super.c exactly the regression from
commit 0baad6f9b997 ("fs/super: skip non-memcg-aware
nr_cached_objects in memcg slab shrink") that 0ef8faff490be was
written to undo. Memcg-charged XFS inode slab therefore keeps
piling up under per-memcg pressure until global reclaim kicks in.
- Any future ->nr_cached_objects()/->free_cached_objects() that
grows memcg awareness is likewise blocked before it can run, so
filesystems cannot opt in to per-memcg reclaim on their own
defeating the whole point of pushing the gating decision down
into the callbacks.
Drop the leftover helper and its call sites so the intent of
0ef8faff490be actually takes effect.
Link: https://lore.kernel.org/cover.1786955972.git.zhengqi.arch@bytedance.com
Link: https://lore.kernel.org/3b038d373c70ebac7cdabfb0035bb91d1d6e6cfe.1786955972.git.zhengqi.arch@bytedance.com
Link: https://lore.kernel.org/all/20260715103516.2410175-1-usama.arif@linux.dev/ [0]
Fixes: 0ef8faff490b ("fs: push nr_cached_objects memcg gating into individual filesystems")
Signed-off-by: Qi Zheng <zhengqi.arch@bytedance.com>
Acked-by: Usama Arif <usama.arif@linux.dev>
Cc: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Christian Brauner <brauner@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Hugh Dickins <hughd@google.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/super.c | 18 ++----------------
1 file changed, 2 insertions(+), 16 deletions(-)
--- a/fs/super.c
+++ b/fs/super.c
@@ -171,19 +171,6 @@ static void super_wake(struct super_bloc
}
/*
- * The s_op->nr_cached_objects hooks (used for example by btrfs and xfs)
- * operate on filesystem-global state and ignore sc->memcg. Driving them
- * from per-memcg shrink_slab_memcg() invocations only burns CPU walking
- * per-cpu counters and queueing duplicate work: the actual reclaim happens on
- * the global path (kswapd or root direct reclaim) regardless. Restrict them
- * to that path.
- */
-static inline bool super_fs_objects_eligible(struct shrink_control *sc)
-{
- return !sc->memcg || mem_cgroup_is_root(sc->memcg);
-}
-
-/*
* One thing we have to be careful of with a per-sb shrinker is that we don't
* drop the last active reference to the superblock from within the shrinker.
* If that happens we could trigger unregistering the shrinker from within the
@@ -212,7 +199,7 @@ static unsigned long super_cache_scan(st
if (!super_trylock_shared(sb))
return SHRINK_STOP;
- if (sb->s_op->nr_cached_objects && super_fs_objects_eligible(sc))
+ if (sb->s_op->nr_cached_objects)
fs_objects = sb->s_op->nr_cached_objects(sb, sc);
inodes = list_lru_shrink_count(&sb->s_inode_lru, sc);
@@ -273,8 +260,7 @@ static unsigned long super_cache_count(s
return 0;
smp_rmb();
- if (sb->s_op && sb->s_op->nr_cached_objects &&
- super_fs_objects_eligible(sc))
+ if (sb->s_op && sb->s_op->nr_cached_objects)
total_objects = sb->s_op->nr_cached_objects(sb, sc);
total_objects += list_lru_shrink_count(&sb->s_dentry_lru, sc);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 376/398] scsi: fnic: Bump up version number
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (372 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 375/398] scsi: fnic: Rename fnic_scsi_fcpio_reset() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 377/398] scsi: fnic: Make debug logging protocol independent Greg Kroah-Hartman
` (28 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karan Tilak Kumar, Sesidhar Baddela,
Arulprabhu Ponnusamy, Gian Carlo Boffa, Arun Easi,
Hannes Reinecke, Martin K. Petersen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karan Tilak Kumar <kartilak@cisco.com>
[ Upstream commit 47e088c9d1a06e0f762ac7ea62ae48c9e16c4def ]
Bump up version number.
Tested-by: Karan Tilak Kumar <kartilak@cisco.com>
Reviewed-by: Sesidhar Baddela <sebaddel@cisco.com>
Reviewed-by: Arulprabhu Ponnusamy <arulponn@cisco.com>
Reviewed-by: Gian Carlo Boffa <gcboffa@cisco.com>
Reviewed-by: Arun Easi <aeasi@cisco.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Signed-off-by: Karan Tilak Kumar <kartilak@cisco.com>
Link: https://patch.msgid.link/20260217223943.7938-5-kartilak@cisco.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: 0cb1fd924126 ("scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/fnic/fnic.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/scsi/fnic/fnic.h
+++ b/drivers/scsi/fnic/fnic.h
@@ -30,7 +30,7 @@
#define DRV_NAME "fnic"
#define DRV_DESCRIPTION "Cisco FCoE HBA Driver"
-#define DRV_VERSION "1.8.0.2"
+#define DRV_VERSION "1.8.0.3"
#define PFX DRV_NAME ": "
#define DFX DRV_NAME "%d: "
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 430/438] scsi: fnic: Make debug logging protocol independent
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (428 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 429/438] fs: fix missed removal of super_fs_objects_eligible() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 431/438] scsi: fnic: Bump up version number Greg Kroah-Hartman
` (19 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sesidhar Baddela,
Arulprabhu Ponnusamy, Gian Carlo Boffa, Arun Easi,
Hannes Reinecke, Lee Duncan, Karan Tilak Kumar,
Martin K. Petersen, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karan Tilak Kumar <kartilak@cisco.com>
[ Upstream commit b93c38a9f2ce5441c90de55776f8df97679cf8a2 ]
Make the fnic debug macros take struct fnic instead of struct Scsi_Host so
FCP and NVMe initiator roles can share the same logging interface.
Add fnic_printk() to route FCP initiator messages through shost_printk()
and non-SCSI role messages through printk(). Add role and non-SCSI role
messages through printk(). Add role predicates and separate FDLS, FIP, and
NVMe logging masks.
Convert FCS, FIP, SCSI, ISR, and main debug call sites to pass the fnic
instance directly, and keep FIP VLAN MAC descriptors skipped while
reporting unexpected descriptor types.
Reviewed-by: Sesidhar Baddela <sebaddel@cisco.com>
Reviewed-by: Arulprabhu Ponnusamy <arulponn@cisco.com>
Reviewed-by: Gian Carlo Boffa <gcboffa@cisco.com>
Reviewed-by: Arun Easi <aeasi@cisco.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Reviewed-by: Lee Duncan <lduncan@suse.com>
Signed-off-by: Karan Tilak Kumar <kartilak@cisco.com>
Co-developed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260724174811.5118-2-kartilak@cisco.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: 0cb1fd924126 ("scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/fnic/fdls_disc.c | 726 +++++++++++++++++++++---------------------
drivers/scsi/fnic/fip.c | 117 +++---
drivers/scsi/fnic/fip.h | 2
drivers/scsi/fnic/fnic.h | 74 ++--
drivers/scsi/fnic/fnic_fcs.c | 126 +++----
drivers/scsi/fnic/fnic_isr.c | 28 -
drivers/scsi/fnic/fnic_main.c | 56 +--
drivers/scsi/fnic/fnic_scsi.c | 210 ++++++------
8 files changed, 675 insertions(+), 664 deletions(-)
--- a/drivers/scsi/fnic/fdls_disc.c
+++ b/drivers/scsi/fnic/fdls_disc.c
@@ -104,7 +104,7 @@ uint8_t *fdls_alloc_frame(struct fnic_ip
frame = mempool_alloc(fnic->frame_pool, GFP_ATOMIC);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame");
return NULL;
}
@@ -136,7 +136,7 @@ uint16_t fdls_alloc_oxid(struct fnic_ipo
*/
idx = find_next_zero_bit(oxid_pool->bitmap, FNIC_OXID_POOL_SZ, oxid_pool->next_idx);
if (idx == FNIC_OXID_POOL_SZ) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Alloc oxid: all oxid slots are busy iport state:%d\n",
iport->state);
return FNIC_UNASSIGNED_OXID;
@@ -148,7 +148,7 @@ uint16_t fdls_alloc_oxid(struct fnic_ipo
oxid = FNIC_OXID_ENCODE(idx, oxid_frame_type);
*active_oxid = oxid;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"alloc oxid: 0x%x, iport state: %d\n",
oxid, iport->state);
return oxid;
@@ -169,7 +169,7 @@ static void fdls_free_oxid_idx(struct fn
lockdep_assert_held(&fnic->fnic_lock);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"free oxid idx: 0x%x\n", oxid_idx);
WARN_ON(!test_and_clear_bit(oxid_idx, oxid_pool->bitmap));
@@ -194,7 +194,7 @@ void fdls_reclaim_oxid_handler(struct wo
struct reclaim_entry_s *reclaim_entry, *next;
unsigned long delay_j, cur_jiffies;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Reclaim oxid callback\n");
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
@@ -223,7 +223,7 @@ void fdls_reclaim_oxid_handler(struct wo
delay_j = reclaim_entry->expires - cur_jiffies;
schedule_delayed_work(&oxid_pool->oxid_reclaim_work, delay_j);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Scheduling next callback at:%ld jiffies\n", delay_j);
}
@@ -266,7 +266,7 @@ void fdls_schedule_oxid_free(struct fnic
lockdep_assert_held(&fnic->fnic_lock);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Schedule oxid free. oxid: 0x%x\n", *active_oxid);
*active_oxid = FNIC_UNASSIGNED_OXID;
@@ -275,7 +275,7 @@ void fdls_schedule_oxid_free(struct fnic
kzalloc_obj(struct reclaim_entry_s, GFP_ATOMIC);
if (!reclaim_entry) {
- FNIC_FCS_DBG(KERN_WARNING, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_WARNING, fnic,
"Failed to allocate memory for reclaim struct for oxid idx: %d\n",
oxid_idx);
@@ -313,7 +313,7 @@ void fdls_schedule_oxid_free_retry_work(
for_each_set_bit(idx, oxid_pool->pending_schedule_free, FNIC_OXID_POOL_SZ) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Schedule oxid free. oxid idx: %d\n", idx);
reclaim_entry = kzalloc_obj(*reclaim_entry);
@@ -416,7 +416,7 @@ fdls_start_fabric_timer(struct fnic_ipor
struct fnic *fnic = iport->fnic;
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x: Canceling fabric disc timer\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -429,7 +429,7 @@ fdls_start_fabric_timer(struct fnic_ipor
fabric_tov = jiffies + msecs_to_jiffies(timeout);
mod_timer(&iport->fabric.retry_timer, round_jiffies(fabric_tov));
iport->fabric.timer_pending = 1;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fabric timer is %d ", timeout);
}
@@ -441,7 +441,7 @@ fdls_start_tport_timer(struct fnic_iport
struct fnic *fnic = iport->fnic;
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid 0x%x: Canceling disc timer\n",
tport->fcid);
fnic_del_tport_timer_sync(fnic, tport);
@@ -575,7 +575,7 @@ fdls_send_rscn_resp(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send RSCN response");
return;
}
@@ -588,7 +588,7 @@ fdls_send_rscn_resp(struct fnic_iport_s
oxid = FNIC_STD_GET_OX_ID(rscn_fchdr);
FNIC_STD_SET_OX_ID(pels_acc->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send RSCN response with oxid: 0x%x",
iport->fcid, oxid);
@@ -608,7 +608,7 @@ fdls_send_logo_resp(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send LOGO response");
return;
}
@@ -621,7 +621,7 @@ fdls_send_logo_resp(struct fnic_iport_s
oxid = FNIC_STD_GET_OX_ID(req_fchdr);
FNIC_STD_SET_OX_ID(plogo_resp->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send LOGO response with oxid: 0x%x",
iport->fcid, oxid);
@@ -642,7 +642,7 @@ fdls_send_tport_abts(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send tport ABTS");
return;
}
@@ -665,7 +665,7 @@ fdls_send_tport_abts(struct fnic_iport_s
FNIC_STD_SET_OX_ID(*ptport_abts, tport->active_oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send tport abts: tport->state: %d ",
iport->fcid, tport->state);
@@ -687,7 +687,7 @@ static void fdls_send_fabric_abts(struct
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send fabric ABTS");
return;
}
@@ -750,7 +750,7 @@ static void fdls_send_fabric_abts(struct
oxid = iport->active_oxid_fabric_req;
FNIC_STD_SET_OX_ID(*pfabric_abts, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send fabric abts. iport->fabric.state: %d oxid: 0x%x",
iport->fcid, iport->fabric.state, oxid);
@@ -773,7 +773,7 @@ static uint8_t *fdls_alloc_init_fdmi_abt
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send FDMI ABTS");
return NULL;
}
@@ -802,7 +802,7 @@ static void fdls_send_fdmi_abts(struct f
if (frame == NULL)
return;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI PLOGI abts. iport->fabric.state: %d oxid: 0x%x",
iport->fcid, iport->fabric.state, iport->active_oxid_fdmi_plogi);
fnic_send_fcoe_frame(iport, frame, frame_size);
@@ -813,7 +813,7 @@ static void fdls_send_fdmi_abts(struct f
if (frame == NULL)
return;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI RHBA abts. iport->fabric.state: %d oxid: 0x%x",
iport->fcid, iport->fabric.state, iport->active_oxid_fdmi_rhba);
fnic_send_fcoe_frame(iport, frame, frame_size);
@@ -828,7 +828,7 @@ static void fdls_send_fdmi_abts(struct f
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI RPA abts. iport->fabric.state: %d oxid: 0x%x",
iport->fcid, iport->fabric.state, iport->active_oxid_fdmi_rpa);
fnic_send_fcoe_frame(iport, frame, frame_size);
@@ -840,7 +840,7 @@ arm_timer:
mod_timer(&iport->fabric.fdmi_timer, round_jiffies(fdmi_tov));
iport->fabric.fdmi_pending |= FDLS_FDMI_ABORT_PENDING;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
}
@@ -856,7 +856,7 @@ static void fdls_send_fabric_flogi(struc
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send FLOGI");
iport->fabric.flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -885,7 +885,7 @@ static void fdls_send_fabric_flogi(struc
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send FLOGI",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -894,7 +894,7 @@ static void fdls_send_fabric_flogi(struc
}
FNIC_STD_SET_OX_ID(pflogi->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send fabric FLOGI with oxid: 0x%x", iport->fcid,
oxid);
@@ -916,7 +916,7 @@ static void fdls_send_fabric_plogi(struc
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send PLOGI");
iport->fabric.flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -928,7 +928,7 @@ static void fdls_send_fabric_plogi(struc
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_FABRIC_PLOGI,
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send fabric PLOGI",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -937,7 +937,7 @@ static void fdls_send_fabric_plogi(struc
}
FNIC_STD_SET_OX_ID(pplogi->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send fabric PLOGI with oxid: 0x%x", iport->fcid,
oxid);
@@ -962,7 +962,7 @@ static void fdls_send_fdmi_plogi(struct
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send FDMI PLOGI");
goto err_out;
}
@@ -974,7 +974,7 @@ static void fdls_send_fdmi_plogi(struct
&iport->active_oxid_fdmi_plogi);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send FDMI PLOGI",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -985,7 +985,7 @@ static void fdls_send_fdmi_plogi(struct
hton24(d_id, FC_FID_MGMT_SERV);
FNIC_STD_SET_D_ID(pplogi->fchdr, d_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI PLOGI with oxid: 0x%x",
iport->fcid, oxid);
@@ -1009,7 +1009,7 @@ static void fdls_send_rpn_id(struct fnic
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send RPN_ID");
iport->fabric.flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1036,7 +1036,7 @@ static void fdls_send_rpn_id(struct fnic
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send RPN_ID",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1045,7 +1045,7 @@ static void fdls_send_rpn_id(struct fnic
}
FNIC_STD_SET_OX_ID(prpn_id->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send RPN ID with oxid: 0x%x", iport->fcid,
oxid);
@@ -1068,7 +1068,7 @@ static void fdls_send_scr(struct fnic_ip
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send SCR");
iport->fabric.flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1090,7 +1090,7 @@ static void fdls_send_scr(struct fnic_ip
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_FABRIC_SCR,
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send SCR",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1099,7 +1099,7 @@ static void fdls_send_scr(struct fnic_ip
}
FNIC_STD_SET_OX_ID(pscr->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send SCR with oxid: 0x%x", iport->fcid,
oxid);
@@ -1123,7 +1123,7 @@ static void fdls_send_gpn_ft(struct fnic
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send GPN FT");
iport->fabric.flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1148,7 +1148,7 @@ static void fdls_send_gpn_ft(struct fnic
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send GPN FT",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1157,7 +1157,7 @@ static void fdls_send_gpn_ft(struct fnic
}
FNIC_STD_SET_OX_ID(pgpn_ft->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send GPN FT with oxid: 0x%x", iport->fcid,
oxid);
@@ -1183,7 +1183,7 @@ fdls_send_tgt_adisc(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send TGT ADISC");
tport->flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1203,7 +1203,7 @@ fdls_send_tgt_adisc(struct fnic_iport_s
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_TGT_ADISC, &tport->active_oxid);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send TGT ADISC",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1222,7 +1222,7 @@ fdls_send_tgt_adisc(struct fnic_iport_s
padisc->els.adisc_cmd = ELS_ADISC;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send ADISC to tgt fcid: 0x%x",
iport->fcid, tport->fcid);
@@ -1242,7 +1242,7 @@ bool fdls_delete_tport(struct fnic_iport
if ((tport->state == FDLS_TGT_STATE_OFFLINING)
|| (tport->state == FDLS_TGT_STATE_OFFLINE)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid 0x%x: tport state is offlining/offline\n",
tport->fcid);
return false;
@@ -1257,7 +1257,7 @@ bool fdls_delete_tport(struct fnic_iport
tport->flags |= FNIC_FDLS_TPORT_TERMINATING;
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid 0x%x: Canceling disc timer\n",
tport->fcid);
fnic_del_tport_timer_sync(fnic, tport);
@@ -1272,9 +1272,9 @@ bool fdls_delete_tport(struct fnic_iport
tport_del_evt =
kzalloc_obj(struct fnic_tport_event_s, GFP_ATOMIC);
if (!tport_del_evt) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "Failed to allocate memory for tport fcid: 0x%0x\n",
- tport->fcid);
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "iport: 0x%x tport 0x%x: Failed to allocate memory\n",
+ iport->fcid, tport->fcid);
return false;
}
tport_del_evt->event = TGT_EV_RPORT_DEL;
@@ -1282,9 +1282,9 @@ bool fdls_delete_tport(struct fnic_iport
list_add_tail(&tport_del_evt->links, &fnic->tport_event_list);
queue_work(fnic_event_queue, &fnic->tport_work);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "tport 0x%x not reg with scsi_transport. Freeing locally",
- tport->fcid);
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "tport 0x%x not registered, freeing locally\n",
+ tport->fcid);
list_del(&tport->links);
kfree(tport);
}
@@ -1305,7 +1305,7 @@ fdls_send_tgt_plogi(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send TGT PLOGI");
tport->flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1316,7 +1316,7 @@ fdls_send_tgt_plogi(struct fnic_iport_s
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_TGT_PLOGI, &tport->active_oxid);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate oxid to send PLOGI to fcid: 0x%x",
iport->fcid, tport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1330,7 +1330,7 @@ fdls_send_tgt_plogi(struct fnic_iport_s
hton24(d_id, tport->fcid);
FNIC_STD_SET_D_ID(pplogi->fchdr, d_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send tgt PLOGI to tgt: 0x%x with oxid: 0x%x",
iport->fcid, tport->fcid, oxid);
@@ -1353,7 +1353,7 @@ fnic_fc_plogi_rsp_rdf(struct fnic_iport_
be16_to_cpu(plogi_rsp->els.fl_cssp[2].cp_rdfs) & FNIC_FC_C3_RDF;
struct fnic *fnic = iport->fnic;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MFS: b2b_rdf_size: 0x%x spc3_rdf_size: 0x%x",
b2b_rdf_size, spc3_rdf_size);
@@ -1372,7 +1372,7 @@ static void fdls_send_register_fc4_types
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send RFT");
return;
}
@@ -1396,7 +1396,7 @@ static void fdls_send_register_fc4_types
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send RFT",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1404,15 +1404,18 @@ static void fdls_send_register_fc4_types
}
FNIC_STD_SET_OX_ID(prft_id->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "0x%x: FDLS send RFT with oxid: 0x%x", iport->fcid,
- oxid);
prft_id->rft_id.fr_fts.ff_type_map[0] =
cpu_to_be32(1 << FC_TYPE_FCP);
prft_id->rft_id.fr_fts.ff_type_map[1] =
cpu_to_be32(1 << (FC_TYPE_CT % FC_NS_BPW));
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "0x%x: FDLS send RFT 0x%08x 0x%08x 0x%08x with oxid: 0x%x",
+ iport->fcid, prft_id->rft_id.fr_fts.ff_type_map[0],
+ prft_id->rft_id.fr_fts.ff_type_map[1],
+ prft_id->rft_id.fr_fts.ff_type_map[2],
+ oxid);
fnic_send_fcoe_frame(iport, frame, frame_size);
@@ -1432,7 +1435,7 @@ static void fdls_send_register_fc4_featu
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send RFF");
return;
}
@@ -1458,7 +1461,7 @@ static void fdls_send_register_fc4_featu
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send RFF",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1466,12 +1469,13 @@ static void fdls_send_register_fc4_featu
}
FNIC_STD_SET_OX_ID(prff_id->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "0x%x: FDLS send RFF with oxid: 0x%x", iport->fcid,
- oxid);
-
prff_id->rff_id.fr_type = FC_TYPE_FCP;
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "0x%x: FDLS send RFF with oxid: 0x%x type 0%x feat 0%x",
+ iport->fcid, oxid, prff_id->rff_id.fr_type,
+ prff_id->rff_id.fr_feat);
+
fnic_send_fcoe_frame(iport, frame, frame_size);
/* Even if fnic_send_fcoe_frame() fails we want to retry after timeout */
@@ -1493,7 +1497,7 @@ fdls_send_tgt_prli(struct fnic_iport_s *
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send TGT PRLI");
tport->flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1513,7 +1517,7 @@ fdls_send_tgt_prli(struct fnic_iport_s *
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_TGT_PRLI, &tport->active_oxid);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"0x%x: Failed to allocate OXID to send TGT PRLI to 0x%x",
iport->fcid, tport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1530,7 +1534,7 @@ fdls_send_tgt_prli(struct fnic_iport_s *
FNIC_STD_SET_S_ID(pprli->fchdr, s_id);
FNIC_STD_SET_D_ID(pprli->fchdr, d_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send PRLI to tgt: 0x%x with oxid: 0x%x",
iport->fcid, tport->fcid, oxid);
@@ -1564,7 +1568,7 @@ void fdls_send_fabric_logo(struct fnic_i
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send fabric LOGO");
return;
}
@@ -1576,7 +1580,7 @@ void fdls_send_fabric_logo(struct fnic_i
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send fabric LOGO",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1589,7 +1593,7 @@ void fdls_send_fabric_logo(struct fnic_i
iport->fabric.flags &= ~FNIC_FDLS_FABRIC_ABORT_ISSUED;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send fabric LOGO with oxid: 0x%x",
iport->fcid, oxid);
@@ -1621,7 +1625,7 @@ void fdls_tgt_logout(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send fabric LOGO");
return;
}
@@ -1631,7 +1635,7 @@ void fdls_tgt_logout(struct fnic_iport_s
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_TGT_LOGO, &tport->active_oxid);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send tgt LOGO",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1642,7 +1646,7 @@ void fdls_tgt_logout(struct fnic_iport_s
hton24(d_id, tport->fcid);
FNIC_STD_SET_D_ID(plogo->fchdr, d_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send tgt LOGO with oxid: 0x%x",
iport->fcid, oxid);
@@ -1657,7 +1661,7 @@ static void fdls_tgt_discovery_start(str
u32 old_link_down_cnt = iport->fnic->link_down_cnt;
struct fnic *fnic = iport->fnic;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Starting FDLS target discovery", iport->fcid);
list_for_each_entry_safe(tport, next, &iport->tport_list, links) {
@@ -1711,7 +1715,7 @@ static void fdls_target_restart_nexus(st
struct fnic *fnic = iport->fnic;
bool retval = true;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid: 0x%x state: %d restart_count: %d",
tport->fcid, tport->state, tport->nexus_restart_count);
@@ -1721,13 +1725,13 @@ static void fdls_target_restart_nexus(st
retval = fdls_delete_tport(iport, tport);
if (retval != true) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Error deleting tport: 0x%x", fcid);
return;
}
if (nexus_restart_count >= FNIC_TPORT_MAX_NEXUS_RESTART) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Exceeded nexus restart retries tport: 0x%x",
fcid);
return;
@@ -1744,7 +1748,7 @@ static void fdls_target_restart_nexus(st
*/
new_tport = fdls_create_tport(iport, fcid, wwpn);
if (!new_tport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Error creating new tport: 0x%x", fcid);
return;
}
@@ -1773,12 +1777,12 @@ static struct fnic_tport_s *fdls_create_
struct fnic_tport_s *tport;
struct fnic *fnic = iport->fnic;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS create tport: fcid: 0x%x wwpn: 0x%llx", fcid, wwpn);
tport = kzalloc_obj(struct fnic_tport_s, GFP_ATOMIC);
if (!tport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Memory allocation failure while creating tport: 0x%x\n",
fcid);
return NULL;
@@ -1791,12 +1795,12 @@ static struct fnic_tport_s *fdls_create_
tport->wwpn = wwpn;
tport->iport = iport;
- FNIC_FCS_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_DEBUG, fnic,
"Need to setup tport timer callback");
timer_setup(&tport->retry_timer, fdls_tport_timer_callback, 0);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Added tport 0x%x", tport->fcid);
fdls_set_tport_state(tport, FDLS_TGT_STATE_INIT);
list_add_tail(&tport->links, &iport->tport_list);
@@ -1847,7 +1851,7 @@ static void fdls_fdmi_register_hba(struc
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send FDMI RHBA");
return;
}
@@ -1875,7 +1879,7 @@ static void fdls_fdmi_register_hba(struc
&iport->active_oxid_fdmi_rhba);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send FDMI RHBA",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1896,14 +1900,14 @@ static void fdls_fdmi_register_hba(struc
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_NODE_NAME,
FNIC_FDMI_NN_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"NN set, off=%d", attr_off_bytes);
strscpy_pad(data, FNIC_FDMI_MANUFACTURER, FNIC_FDMI_MANU_LEN);
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_MANUFACTURER,
FNIC_FDMI_MANU_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MFG set <%s>, off=%d", data, attr_off_bytes);
err = vnic_dev_fw_info(fnic->vdev, &fw_info);
@@ -1912,7 +1916,7 @@ static void fdls_fdmi_register_hba(struc
FNIC_FDMI_SERIAL_LEN);
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_SERIAL_NUMBER,
FNIC_FDMI_SERIAL_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"SERIAL set <%s>, off=%d", data, attr_off_bytes);
}
@@ -1923,21 +1927,21 @@ static void fdls_fdmi_register_hba(struc
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_MODEL, FNIC_FDMI_MODEL_LEN,
data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MODEL set <%s>, off=%d", data, attr_off_bytes);
strscpy_pad(data, FNIC_FDMI_MODEL_DESCRIPTION, FNIC_FDMI_MODEL_DES_LEN);
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_MODEL_DES,
FNIC_FDMI_MODEL_DES_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MODEL_DESC set <%s>, off=%d", data, attr_off_bytes);
if (!err) {
strscpy_pad(data, fw_info->hw_version, FNIC_FDMI_HW_VER_LEN);
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_HARDWARE_VERSION,
FNIC_FDMI_HW_VER_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"HW_VER set <%s>, off=%d", data, attr_off_bytes);
}
@@ -1946,14 +1950,14 @@ static void fdls_fdmi_register_hba(struc
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_DRIVER_VERSION,
FNIC_FDMI_DR_VER_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"DRV_VER set <%s>, off=%d", data, attr_off_bytes);
strscpy_pad(data, "N/A", FNIC_FDMI_ROM_VER_LEN);
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_ROM_VERSION,
FNIC_FDMI_ROM_VER_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ROM_VER set <%s>, off=%d", data, attr_off_bytes);
if (!err) {
@@ -1961,14 +1965,14 @@ static void fdls_fdmi_register_hba(struc
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_FIRMWARE_VERSION,
FNIC_FDMI_FW_VER_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FW_VER set <%s>, off=%d", data, attr_off_bytes);
}
len = sizeof(struct fc_std_fdmi_rhba) + attr_off_bytes;
frame_size += len;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI RHBA with oxid: 0x%x fs: %d", iport->fcid,
oxid, frame_size);
@@ -1992,7 +1996,7 @@ static void fdls_fdmi_register_pa(struct
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send FDMI RPA");
return;
}
@@ -2020,7 +2024,7 @@ static void fdls_fdmi_register_pa(struct
&iport->active_oxid_fdmi_rpa);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send FDMI RPA",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -2085,7 +2089,7 @@ static void fdls_fdmi_register_pa(struct
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_OS_NAME,
FNIC_FDMI_OS_NAME_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"OS name set <%s>, off=%d", data, attr_off_bytes);
sprintf(fc_host_system_hostname(fnic->host), "%s", utsname()->nodename);
@@ -2094,13 +2098,13 @@ static void fdls_fdmi_register_pa(struct
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_HOST_NAME,
FNIC_FDMI_HN_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Host name set <%s>, off=%d", data, attr_off_bytes);
len = sizeof(struct fc_std_fdmi_rpa) + attr_off_bytes;
frame_size += len;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI RPA with oxid: 0x%x fs: %d", iport->fcid,
oxid, frame_size);
@@ -2117,7 +2121,7 @@ void fdls_fabric_timer_callback(struct t
struct fnic *fnic = iport->fnic;
unsigned long flags;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tp: %d fab state: %d fab retry counter: %d max_flogi_retries: %d",
iport->fabric.timer_pending, iport->fabric.state,
iport->fabric.retry_counter, iport->max_flogi_retries);
@@ -2132,7 +2136,7 @@ void fdls_fabric_timer_callback(struct t
if (iport->fabric.del_timer_inprogress) {
iport->fabric.del_timer_inprogress = 0;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fabric_del_timer inprogress(%d). Skip timer cb",
iport->fabric.del_timer_inprogress);
return;
@@ -2160,7 +2164,7 @@ void fdls_fabric_timer_callback(struct t
iport->fabric.flags &= ~FNIC_FDLS_FABRIC_ABORT_ISSUED;
fdls_send_fabric_flogi(iport);
} else
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Exceeded max FLOGI retries");
}
break;
@@ -2182,7 +2186,7 @@ void fdls_fabric_timer_callback(struct t
iport->fabric.flags &= ~FNIC_FDLS_FABRIC_ABORT_ISSUED;
fdls_send_fabric_plogi(iport);
} else
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Exceeded max PLOGI retries");
}
break;
@@ -2213,7 +2217,7 @@ void fdls_fabric_timer_callback(struct t
else {
/* ABTS has timed out */
fdls_schedule_oxid_free(iport, &iport->active_oxid_fabric_req);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ABTS timed out. Starting PLOGI: %p", iport);
fnic_fdls_start_plogi(iport);
}
@@ -2230,7 +2234,7 @@ void fdls_fabric_timer_callback(struct t
} else {
/* ABTS has timed out */
fdls_schedule_oxid_free(iport, &iport->active_oxid_fabric_req);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ABTS timed out. Starting PLOGI: %p", iport);
fnic_fdls_start_plogi(iport); /* go back to fabric Plogi */
}
@@ -2247,7 +2251,7 @@ void fdls_fabric_timer_callback(struct t
else {
/* ABTS has timed out */
fdls_schedule_oxid_free(iport, &iport->active_oxid_fabric_req);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ABTS timed out. Starting PLOGI %p", iport);
fnic_fdls_start_plogi(iport); /* go back to fabric Plogi */
}
@@ -2269,7 +2273,7 @@ void fdls_fabric_timer_callback(struct t
if (iport->fabric.retry_counter < FDLS_RETRY_COUNT) {
fdls_send_gpn_ft(iport, iport->fabric.state);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ABTS timeout for fabric GPN_FT. Check name server: %p",
iport);
}
@@ -2289,7 +2293,7 @@ void fdls_fdmi_retry_plogi(struct fnic_i
/* If max retries not exhausted, start over from fdmi plogi */
if (iport->fabric.fdmi_retry < FDLS_FDMI_MAX_RETRY) {
iport->fabric.fdmi_retry++;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Retry FDMI PLOGI. FDMI retry: %d",
iport->fabric.fdmi_retry);
fdls_send_fdmi_plogi(iport);
@@ -2307,7 +2311,7 @@ void fdls_fdmi_timer_callback(struct tim
spin_lock_irqsave(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->fabric.fdmi_pending: 0x%x\n", iport->fabric.fdmi_pending);
if (!iport->fabric.fdmi_pending) {
@@ -2315,7 +2319,7 @@ void fdls_fdmi_timer_callback(struct tim
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->fabric.fdmi_pending: 0x%x\n", iport->fabric.fdmi_pending);
/* if not abort pending, send an abort */
@@ -2324,7 +2328,7 @@ void fdls_fdmi_timer_callback(struct tim
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->fabric.fdmi_pending: 0x%x\n", iport->fabric.fdmi_pending);
/* ABTS pending for an active fdmi request that is pending.
@@ -2332,29 +2336,36 @@ void fdls_fdmi_timer_callback(struct tim
* Schedule to free the OXID after 2*r_a_tov and proceed
*/
if (iport->fabric.fdmi_pending & FDLS_FDMI_PLOGI_PENDING) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDMI PLOGI ABTS timed out. Schedule oxid free: 0x%x\n",
iport->active_oxid_fdmi_plogi);
fdls_schedule_oxid_free(iport, &iport->active_oxid_fdmi_plogi);
} else {
if (iport->fabric.fdmi_pending & FDLS_FDMI_REG_HBA_PENDING) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDMI RHBA ABTS timed out. Schedule oxid free: 0x%x\n",
iport->active_oxid_fdmi_rhba);
fdls_schedule_oxid_free(iport, &iport->active_oxid_fdmi_rhba);
}
if (iport->fabric.fdmi_pending & FDLS_FDMI_RPA_PENDING) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDMI RPA ABTS timed out. Schedule oxid free: 0x%x\n",
iport->active_oxid_fdmi_rpa);
fdls_schedule_oxid_free(iport, &iport->active_oxid_fdmi_rpa);
}
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->fabric.fdmi_pending: 0x%x\n", iport->fabric.fdmi_pending);
- fdls_fdmi_retry_plogi(iport);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ iport->fabric.fdmi_pending = 0;
+ /* If max retries not exhaused, start over from fdmi plogi */
+ if (iport->fabric.fdmi_retry < FDLS_FDMI_MAX_RETRY) {
+ iport->fabric.fdmi_retry++;
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "retry fdmi timer %d", iport->fabric.fdmi_retry);
+ fdls_send_fdmi_plogi(iport);
+ }
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->fabric.fdmi_pending: 0x%x\n", iport->fabric.fdmi_pending);
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
}
@@ -2367,7 +2378,7 @@ static void fdls_send_delete_tport_msg(s
tport_del_evt = kzalloc_obj(struct fnic_tport_event_s, GFP_ATOMIC);
if (!tport_del_evt) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Failed to allocate memory for tport event fcid: 0x%x",
tport->fcid);
return;
@@ -2400,13 +2411,13 @@ static void fdls_tport_timer_callback(st
if (tport->del_timer_inprogress) {
tport->del_timer_inprogress = 0;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport_del_timer inprogress. Skip timer cb tport fcid: 0x%x\n",
tport->fcid);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid: 0x%x timer pending: %d state: %d retry counter: %d",
tport->fcid, tport->timer_pending, tport->state,
tport->retry_counter);
@@ -2467,15 +2478,16 @@ static void fdls_tport_timer_callback(st
} else {
/* exceeded retry count */
fdls_schedule_oxid_free(iport, &tport->active_oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ADISC not responding. Deleting target port: 0x%x",
tport->fcid);
fdls_send_delete_tport_msg(tport);
}
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "oxid: 0x%x Unknown tport state: 0x%x", oxid, tport->state);
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "0x%x timeout tport 0x%x oxid 0x%x state %d\n",
+ iport->fcid, tport->fcid, oxid, tport->state);
break;
}
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
@@ -2524,26 +2536,26 @@ fdls_process_tgt_adisc_rsp(struct fnic_i
tport = fnic_find_tport_by_fcid(iport, tgt_fcid);
if (!tport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Tgt ADISC response tport not found: 0x%x", tgt_fcid);
return;
}
if ((iport->state != FNIC_IPORT_STATE_READY)
|| (tport->state != FDLS_TGT_STATE_ADISC)
|| (tport->flags & FNIC_FDLS_TGT_ABORT_ISSUED)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping this ADISC response");
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport state: %d tport state: %d Is abort issued on PRLI? %d",
iport->state, tport->state,
(tport->flags & FNIC_FDLS_TGT_ABORT_ISSUED));
return;
}
if (FNIC_STD_GET_OX_ID(fchdr) != tport->active_oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping frame from target: 0x%x",
tgt_fcid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Reason: Stale ADISC/Aborted ADISC/OOO frame delivery");
return;
}
@@ -2555,7 +2567,7 @@ fdls_process_tgt_adisc_rsp(struct fnic_i
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.tport_adisc_ls_accepts);
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport 0x%p Canceling fabric disc timer\n",
tport);
fnic_del_tport_timer_sync(fnic, tport);
@@ -2565,12 +2577,12 @@ fdls_process_tgt_adisc_rsp(struct fnic_i
frame_wwnn = get_unaligned_be64(&adisc_rsp->els.adisc_wwnn);
frame_wwpn = get_unaligned_be64(&adisc_rsp->els.adisc_wwpn);
if ((frame_wwnn == tport->wwnn) && (frame_wwpn == tport->wwpn)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ADISC accepted from target: 0x%x. Target logged in",
tgt_fcid);
fdls_set_tport_state(tport, FDLS_TGT_STATE_READY);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Error mismatch frame: ADISC");
}
break;
@@ -2580,14 +2592,14 @@ fdls_process_tgt_adisc_rsp(struct fnic_i
if (((els_rjt->rej.er_reason == ELS_RJT_BUSY)
|| (els_rjt->rej.er_reason == ELS_RJT_UNAB))
&& (tport->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ADISC ret ELS_LS_RJT BUSY. Retry from timer routine: 0x%x",
tgt_fcid);
/* Retry ADISC again from the timer routine. */
tport->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ADISC returned ELS_LS_RJT from target: 0x%x",
tgt_fcid);
fdls_delete_tport(iport, tport);
@@ -2611,33 +2623,33 @@ fdls_process_tgt_plogi_rsp(struct fnic_i
fcid = FNIC_STD_GET_S_ID(fchdr);
tgt_fcid = ntoh24(fcid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS processing target PLOGI response: tgt_fcid: 0x%x",
tgt_fcid);
tport = fnic_find_tport_by_fcid(iport, tgt_fcid);
if (!tport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport not found: 0x%x", tgt_fcid);
return;
}
if ((iport->state != FNIC_IPORT_STATE_READY)
|| (tport->flags & FNIC_FDLS_TGT_ABORT_ISSUED)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping frame! iport state: %d tport state: %d",
iport->state, tport->state);
return;
}
if (tport->state != FDLS_TGT_STATE_PLOGI) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI rsp recvd in wrong state. Drop the frame and restart nexus");
fdls_target_restart_nexus(tport);
return;
}
if (FNIC_STD_GET_OX_ID(fchdr) != tport->active_oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI response from target: 0x%x. Dropping frame",
tgt_fcid);
return;
@@ -2649,7 +2661,7 @@ fdls_process_tgt_plogi_rsp(struct fnic_i
switch (plogi_rsp->els.fl_cmd) {
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.tport_plogi_ls_accepts);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI accepted by target: 0x%x", tgt_fcid);
break;
@@ -2658,14 +2670,14 @@ fdls_process_tgt_plogi_rsp(struct fnic_i
if (((els_rjt->rej.er_reason == ELS_RJT_BUSY)
|| (els_rjt->rej.er_reason == ELS_RJT_UNAB))
&& (tport->retry_counter < iport->max_plogi_retries)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI ret ELS_LS_RJT BUSY. Retry from timer routine: 0x%x",
tgt_fcid);
/* Retry plogi again from the timer routine. */
tport->flags |= FNIC_FDLS_RETRY_FRAME;
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI returned ELS_LS_RJT from target: 0x%x",
tgt_fcid);
fdls_delete_tport(iport, tport);
@@ -2673,18 +2685,18 @@ fdls_process_tgt_plogi_rsp(struct fnic_i
default:
atomic64_inc(&iport->iport_stats.tport_plogi_misc_rejects);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI not accepted from target fcid: 0x%x",
tgt_fcid);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Found the PLOGI target: 0x%x and state: %d",
(unsigned int) tgt_fcid, tport->state);
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid 0x%x: Canceling disc timer\n",
tport->fcid);
fnic_del_tport_timer_sync(fnic, tport);
@@ -2702,13 +2714,13 @@ fdls_process_tgt_plogi_rsp(struct fnic_i
min(max_payload_size, iport->max_payload_size);
if (tport->max_payload_size < FNIC_MIN_DATA_FIELD_SIZE) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MFS: tport max frame size below spec bounds: %d",
tport->max_payload_size);
tport->max_payload_size = FNIC_MIN_DATA_FIELD_SIZE;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MAX frame size: %u iport max_payload_size: %d tport mfs: %d",
max_payload_size, iport->max_payload_size,
tport->max_payload_size);
@@ -2736,12 +2748,12 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
fcid = FNIC_STD_GET_S_ID(fchdr);
tgt_fcid = ntoh24(fcid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process tgt PRLI response: 0x%x", tgt_fcid);
tport = fnic_find_tport_by_fcid(iport, tgt_fcid);
if (!tport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport not found: 0x%x", tgt_fcid);
/* Handle or just drop? */
return;
@@ -2749,24 +2761,24 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
if ((iport->state != FNIC_IPORT_STATE_READY)
|| (tport->flags & FNIC_FDLS_TGT_ABORT_ISSUED)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping frame! iport st: %d tport st: %d tport fcid: 0x%x",
iport->state, tport->state, tport->fcid);
return;
}
if (tport->state != FDLS_TGT_STATE_PRLI) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI rsp recvd in wrong state. Drop frame. Restarting nexus");
fdls_target_restart_nexus(tport);
return;
}
if (FNIC_STD_GET_OX_ID(fchdr) != tport->active_oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping PRLI response from target: 0x%x ",
tgt_fcid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Reason: Stale PRLI response/Aborted PDISC/OOO frame delivery");
return;
}
@@ -2777,11 +2789,11 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
switch (prli_rsp->els_prli.prli_cmd) {
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.tport_prli_ls_accepts);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI accepted from target: 0x%x", tgt_fcid);
if (prli_rsp->sp.spp_type != FC_FC4_TYPE_SCSI) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"mismatched target zoned with FC SCSI initiator: 0x%x",
tgt_fcid);
mismatched_tgt = true;
@@ -2798,7 +2810,7 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
|| (els_rjt->rej.er_reason == ELS_RJT_UNAB))
&& (tport->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI ret ELS_LS_RJT BUSY. Retry from timer routine: 0x%x",
tgt_fcid);
@@ -2806,7 +2818,7 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
tport->flags |= FNIC_FDLS_RETRY_FRAME;
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI returned ELS_LS_RJT from target: 0x%x",
tgt_fcid);
@@ -2815,17 +2827,17 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
return;
default:
atomic64_inc(&iport->iport_stats.tport_prli_misc_rejects);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI not accepted from target: 0x%x", tgt_fcid);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Found the PRLI target: 0x%x and state: %d",
(unsigned int) tgt_fcid, tport->state);
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid 0x%x: Canceling disc timer\n",
tport->fcid);
fnic_del_tport_timer_sync(fnic, tport);
@@ -2841,7 +2853,7 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
/* Check if the device plays Target Mode Function */
if (!(tport->fcp_csp & FCP_PRLI_FUNC_TARGET)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Remote port(0x%x): no target support. Deleting it\n",
tgt_fcid);
fdls_tgt_logout(iport, tport);
@@ -2854,16 +2866,16 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
/* Inform the driver about new target added */
tport_add_evt = kzalloc_obj(struct fnic_tport_event_s, GFP_ATOMIC);
if (!tport_add_evt) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "tport event memory allocation failure: 0x%0x\n",
- tport->fcid);
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "iport fcid: 0x%x tport event memory allocation failure: 0x%0x\n",
+ iport->fcid, tport->fcid);
return;
}
tport_add_evt->event = TGT_EV_RPORT_ADD;
tport_add_evt->arg1 = (void *) tport;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "iport fcid: 0x%x add tport event fcid: 0x%x\n",
- tport->fcid, iport->fcid);
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "iport fcid: 0x%x add tport event fcid: 0x%x\n",
+ tport->fcid, iport->fcid);
list_add_tail(&tport_add_evt->links, &fnic->tport_event_list);
queue_work(fnic_event_queue, &fnic->tport_work);
}
@@ -2881,21 +2893,21 @@ fdls_process_rff_id_rsp(struct fnic_ipor
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (fdls_get_state(fdls) != FDLS_STATE_REGISTER_FC4_FEATURES) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFF_ID resp recvd in state(%d). Dropping.",
fdls_get_state(fdls));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
return;
}
rsp = FNIC_STD_GET_FC_CT_CMD((&rff_rsp->fc_std_ct_hdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS process RFF ID response: 0x%04x", iport->fcid,
(uint32_t) rsp);
@@ -2904,7 +2916,7 @@ fdls_process_rff_id_rsp(struct fnic_ipor
switch (rsp) {
case FC_FS_ACC:
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -2918,18 +2930,18 @@ fdls_process_rff_id_rsp(struct fnic_ipor
if (((reason_code == FC_FS_RJT_BSY)
|| (reason_code == FC_FS_RJT_UNABL))
&& (fdls->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFF_ID ret ELS_LS_RJT BUSY. Retry from timer routine %p",
iport);
/* Retry again from the timer routine */
fdls->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFF_ID returned ELS_LS_RJT. Halting discovery %p",
iport);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -2954,14 +2966,14 @@ fdls_process_rft_id_rsp(struct fnic_ipor
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (fdls_get_state(fdls) != FDLS_STATE_REGISTER_FC4_TYPES) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFT_ID resp recvd in state(%d). Dropping.",
fdls_get_state(fdls));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
return;
@@ -2969,7 +2981,7 @@ fdls_process_rft_id_rsp(struct fnic_ipor
rsp = FNIC_STD_GET_FC_CT_CMD((&rft_rsp->fc_std_ct_hdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS process RFT ID response: 0x%04x", iport->fcid,
(uint32_t) rsp);
@@ -2978,7 +2990,7 @@ fdls_process_rft_id_rsp(struct fnic_ipor
switch (rsp) {
case FC_FS_ACC:
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -2992,19 +3004,19 @@ fdls_process_rft_id_rsp(struct fnic_ipor
if (((reason_code == FC_FS_RJT_BSY)
|| (reason_code == FC_FS_RJT_UNABL))
&& (fdls->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: RFT_ID ret ELS_LS_RJT BUSY. Retry from timer routine",
iport->fcid);
/* Retry again from the timer routine */
fdls->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: RFT_ID REJ. Halting discovery reason %d expl %d",
iport->fcid, reason_code,
rft_rsp->fc_std_ct_hdr.ct_explan);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -3029,20 +3041,20 @@ fdls_process_rpn_id_rsp(struct fnic_ipor
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (fdls_get_state(fdls) != FDLS_STATE_RPN_ID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RPN_ID resp recvd in state(%d). Dropping.",
fdls_get_state(fdls));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
return;
}
rsp = FNIC_STD_GET_FC_CT_CMD((&rpn_rsp->fc_std_ct_hdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS process RPN ID response: 0x%04x", iport->fcid,
(uint32_t) rsp);
fdls_free_oxid(iport, oxid, &iport->active_oxid_fabric_req);
@@ -3050,7 +3062,7 @@ fdls_process_rpn_id_rsp(struct fnic_ipor
switch (rsp) {
case FC_FS_ACC:
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -3064,17 +3076,17 @@ fdls_process_rpn_id_rsp(struct fnic_ipor
if (((reason_code == FC_FS_RJT_BSY)
|| (reason_code == FC_FS_RJT_UNABL))
&& (fdls->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RPN_ID returned REJ BUSY. Retry from timer routine %p",
iport);
/* Retry again from the timer routine */
fdls->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RPN_ID ELS_LS_RJT. Halting discovery %p", iport);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -3097,18 +3109,18 @@ fdls_process_scr_rsp(struct fnic_iport_s
struct fnic *fnic = iport->fnic;
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process SCR response: 0x%04x",
(uint32_t) scr_rsp->scr.scr_cmd);
if (fdls_get_state(fdls) != FDLS_STATE_SCR) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"SCR resp recvd in state(%d). Dropping.",
fdls_get_state(fdls));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
}
@@ -3119,7 +3131,7 @@ fdls_process_scr_rsp(struct fnic_iport_s
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.fabric_scr_ls_accepts);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -3133,17 +3145,17 @@ fdls_process_scr_rsp(struct fnic_iport_s
if (((els_rjt->rej.er_reason == ELS_RJT_BUSY)
|| (els_rjt->rej.er_reason == ELS_RJT_UNAB))
&& (fdls->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"SCR ELS_LS_RJT BUSY. Retry from timer routine %p",
iport);
/* Retry again from the timer routine */
fdls->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"SCR returned ELS_LS_RJT. Halting discovery %p",
iport);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n",
iport);
fnic_del_fabric_timer_sync(fnic);
@@ -3171,7 +3183,7 @@ fdls_process_gpn_ft_tgt_list(struct fnic
u32 old_link_down_cnt = iport->fnic->link_down_cnt;
struct fnic *fnic = iport->fnic;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS process GPN_FT tgt list", iport->fcid);
gpn_ft_tgt =
@@ -3185,7 +3197,7 @@ fdls_process_gpn_ft_tgt_list(struct fnic
fcid = ntoh24(gpn_ft_tgt->fcid);
wwpn = be64_to_cpu(gpn_ft_tgt->wwpn);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport: 0x%x: ctrl:0x%x", fcid, gpn_ft_tgt->ctrl);
if (fcid == iport->fcid) {
@@ -3232,7 +3244,7 @@ fdls_process_gpn_ft_tgt_list(struct fnic
rem_len -= sizeof(struct fc_gpn_ft_rsp_iu);
}
if (rem_len <= 0) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"GPN_FT response: malformed/corrupt frame rxlen: %d remlen: %d",
len, rem_len);
}
@@ -3242,7 +3254,7 @@ fdls_process_gpn_ft_tgt_list(struct fnic
list_for_each_entry_safe(tport, next, &iport->tport_list, links) {
if (!(tport->flags & FNIC_FDLS_TPORT_IN_GPN_FT_LIST)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Remove port: 0x%x not found in GPN_FT list",
tport->fcid);
fdls_delete_tport(iport, tport);
@@ -3271,7 +3283,7 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
struct fnic *fnic = iport->fnic;
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process GPN_FT response: iport state: %d len: %d",
iport->state, len);
@@ -3291,14 +3303,14 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
&& ((fdls_get_state(fdls) == FDLS_STATE_RSCN_GPN_FT)
|| (fdls_get_state(fdls) == FDLS_STATE_SEND_GPNFT)
|| (fdls_get_state(fdls) == FDLS_STATE_TGT_DISCOVERY))))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"GPNFT resp recvd in fab state(%d) iport_state(%d). Dropping.",
fdls_get_state(fdls), iport->state);
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
}
@@ -3311,10 +3323,10 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
switch (rsp) {
case FC_FS_ACC:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: GPNFT_RSP accept", iport->fcid);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Canceling fabric disc timer\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -3329,7 +3341,7 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
* that will be taken care in next link up event
*/
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Halting target discovery: fab st: %d iport st: %d ",
fdls_get_state(fdls), iport->state);
break;
@@ -3339,22 +3351,22 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
case FC_FS_RJT:
reason_code = gpn_ft_rsp->fc_std_ct_hdr.ct_reason;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: GPNFT_RSP Reject reason: %d", iport->fcid, reason_code);
if (((reason_code == FC_FS_RJT_BSY)
|| (reason_code == FC_FS_RJT_UNABL))
&& (fdls->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: GPNFT_RSP ret REJ/BSY. Retry from timer routine",
iport->fcid);
/* Retry again from the timer routine */
fdls->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: GPNFT_RSP reject", iport->fcid);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Canceling fabric disc timer\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -3368,7 +3380,7 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
count = 0;
list_for_each_entry_safe(tport, next, &iport->tport_list,
links) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"GPN_FT_REJECT: Remove port: 0x%x",
tport->fcid);
fdls_delete_tport(iport, tport);
@@ -3378,7 +3390,7 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
}
count++;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"GPN_FT_REJECT: Removed (0x%x) ports", count);
}
break;
@@ -3403,7 +3415,7 @@ fdls_process_fabric_logo_rsp(struct fnic
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
}
@@ -3412,7 +3424,7 @@ fdls_process_fabric_logo_rsp(struct fnic
switch (flogo_rsp->els.fl_cmd) {
case ELS_LS_ACC:
if (iport->fabric.state != FDLS_STATE_FABRIC_LOGO) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Flogo response. Fabric not in LOGO state. Dropping! %p",
iport);
return;
@@ -3422,25 +3434,25 @@ fdls_process_fabric_logo_rsp(struct fnic
iport->state = FNIC_IPORT_STATE_LINK_WAIT;
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport 0x%p Canceling fabric disc timer\n",
iport);
fnic_del_fabric_timer_sync(fnic);
}
iport->fabric.timer_pending = 0;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Flogo response from Fabric for did: 0x%x",
ntoh24(fchdr->fh_d_id));
return;
case ELS_LS_RJT:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Flogo response from Fabric for did: 0x%x returned ELS_LS_RJT",
ntoh24(fchdr->fh_d_id));
return;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGO response not accepted or rejected: 0x%x",
flogo_rsp->els.fl_cmd);
}
@@ -3458,17 +3470,17 @@ fdls_process_flogi_rsp(struct fnic_iport
struct fnic *fnic = iport->fnic;
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS processing FLOGI response", iport->fcid);
if (fdls_get_state(fabric) != FDLS_STATE_FABRIC_FLOGI) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI response received in state (%d). Dropping frame",
fdls_get_state(fabric));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fabric), oxid, iport->active_oxid_fabric_req);
return;
@@ -3480,7 +3492,7 @@ fdls_process_flogi_rsp(struct fnic_iport
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.fabric_flogi_ls_accepts);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x Canceling fabric disc timer\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -3490,7 +3502,7 @@ fdls_process_flogi_rsp(struct fnic_iport
iport->fabric.retry_counter = 0;
fcid = FNIC_STD_GET_D_ID(fchdr);
iport->fcid = ntoh24(fcid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FLOGI response accepted", iport->fcid);
/* Learn the Service Params */
@@ -3500,7 +3512,7 @@ fdls_process_flogi_rsp(struct fnic_iport
iport->max_payload_size = min(rdf_size,
iport->max_payload_size);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"max_payload_size from fabric: %u set: %d", rdf_size,
iport->max_payload_size);
@@ -3510,7 +3522,7 @@ fdls_process_flogi_rsp(struct fnic_iport
if (FNIC_LOGI_FEATURES(flogi_rsp->els) & FNIC_FC_EDTOV_NSEC)
iport->e_d_tov = iport->e_d_tov / FNIC_NSEC_TO_MSEC;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"From fabric: R_A_TOV: %d E_D_TOV: %d",
iport->r_a_tov, iport->e_d_tov);
@@ -3521,13 +3533,13 @@ fdls_process_flogi_rsp(struct fnic_iport
fnic_fdls_learn_fcoe_macs(iport, rx_frame, fcid);
if (fnic_fdls_register_portid(iport, iport->fcid, rx_frame) != 0) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FLOGI registration failed", iport->fcid);
break;
}
memcpy(&fcmac[3], fcid, 3);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Adding vNIC device MAC addr: %02x:%02x:%02x:%02x:%02x:%02x",
fcmac[0], fcmac[1], fcmac[2], fcmac[3], fcmac[4],
fcmac[5]);
@@ -3535,7 +3547,7 @@ fdls_process_flogi_rsp(struct fnic_iport
if (fdls_get_state(fabric) == FDLS_STATE_FABRIC_FLOGI) {
fnic_fdls_start_plogi(iport);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI response received. Starting PLOGI");
} else {
/* From FDLS_STATE_FABRIC_FLOGI state fabric can only go to
@@ -3543,7 +3555,7 @@ fdls_process_flogi_rsp(struct fnic_iport
* state, hence we don't have to worry about undoing:
* the fnic_fdls_register_portid and vnic_dev_add_addr
*/
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI response received in state (%d). Dropping frame",
fdls_get_state(fabric));
}
@@ -3552,7 +3564,7 @@ fdls_process_flogi_rsp(struct fnic_iport
case ELS_LS_RJT:
atomic64_inc(&iport->iport_stats.fabric_flogi_ls_rejects);
if (fabric->retry_counter < iport->max_flogi_retries) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI returned ELS_LS_RJT BUSY. Retry from timer routine %p",
iport);
@@ -3560,11 +3572,11 @@ fdls_process_flogi_rsp(struct fnic_iport
fabric->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI returned ELS_LS_RJT. Halting discovery %p",
iport);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport 0x%p Canceling fabric disc timer\n",
iport);
fnic_del_fabric_timer_sync(fnic);
@@ -3575,7 +3587,7 @@ fdls_process_flogi_rsp(struct fnic_iport
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI response not accepted: 0x%x",
flogi_rsp->els.fl_cmd);
atomic64_inc(&iport->iport_stats.fabric_flogi_misc_rejects);
@@ -3594,13 +3606,13 @@ fdls_process_fabric_plogi_rsp(struct fni
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (fdls_get_state((&iport->fabric)) != FDLS_STATE_FABRIC_PLOGI) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Fabric PLOGI response received in state (%d). Dropping frame",
fdls_get_state(&iport->fabric));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
return;
@@ -3611,7 +3623,7 @@ fdls_process_fabric_plogi_rsp(struct fni
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.fabric_plogi_ls_accepts);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x fabric PLOGI response: Accepted\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -3626,15 +3638,15 @@ fdls_process_fabric_plogi_rsp(struct fni
if (((els_rjt->rej.er_reason == ELS_RJT_BUSY)
|| (els_rjt->rej.er_reason == ELS_RJT_UNAB))
&& (iport->fabric.retry_counter < iport->max_plogi_retries)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Fabric PLOGI ELS_LS_RJT BUSY. Retry from timer routine",
iport->fcid);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Fabric PLOGI ELS_LS_RJT. Halting discovery",
iport->fcid);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x Canceling fabric disc timer\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -3645,7 +3657,7 @@ fdls_process_fabric_plogi_rsp(struct fni
}
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI response not accepted: 0x%x",
plogi_rsp->els.fl_cmd);
atomic64_inc(&iport->iport_stats.fabric_plogi_misc_rejects);
@@ -3664,7 +3676,7 @@ static void fdls_process_fdmi_plogi_rsp(
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (iport->active_oxid_fdmi_plogi != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fdmi_plogi);
return;
@@ -3678,9 +3690,9 @@ static void fdls_process_fdmi_plogi_rsp(
iport->fabric.fdmi_pending = 0;
switch (plogi_rsp->els.fl_cmd) {
case ELS_LS_ACC:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process fdmi PLOGI response status: ELS_LS_ACC\n");
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Sending fdmi registration for port 0x%x\n",
iport->fcid);
@@ -3691,7 +3703,7 @@ static void fdls_process_fdmi_plogi_rsp(
round_jiffies(fdmi_tov));
break;
case ELS_LS_RJT:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Fabric FDMI PLOGI returned ELS_LS_RJT reason: 0x%x",
els_rjt->rej.er_reason);
@@ -3715,7 +3727,7 @@ static void fdls_process_fdmi_reg_ack(st
uint16_t oxid;
if (!iport->fabric.fdmi_pending) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received FDMI ack while not waiting: 0x%x\n",
FNIC_STD_GET_OX_ID(fchdr));
return;
@@ -3725,7 +3737,7 @@ static void fdls_process_fdmi_reg_ack(st
if ((iport->active_oxid_fdmi_rhba != oxid) &&
(iport->active_oxid_fdmi_rpa != oxid)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. oxid recvd: 0x%x, active oxids(rhba,rpa): 0x%x, 0x%x\n",
oxid, iport->active_oxid_fdmi_rhba, iport->active_oxid_fdmi_rpa);
return;
@@ -3738,13 +3750,13 @@ static void fdls_process_fdmi_reg_ack(st
fdls_free_oxid(iport, oxid, &iport->active_oxid_fdmi_rpa);
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x: Received FDMI registration ack\n",
iport->fcid);
if (!iport->fabric.fdmi_pending) {
timer_delete_sync(&iport->fabric.fdmi_timer);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x: Canceling FDMI timer\n",
iport->fcid);
}
@@ -3760,7 +3772,7 @@ static void fdls_process_fdmi_abts_rsp(s
s_id = ntoh24(FNIC_STD_GET_S_ID(fchdr));
if (!(s_id != FC_FID_MGMT_SERV)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abts rsp with invalid SID: 0x%x. Dropping frame",
s_id);
return;
@@ -3770,23 +3782,23 @@ static void fdls_process_fdmi_abts_rsp(s
switch (FNIC_FRAME_TYPE(oxid)) {
case FNIC_FRAME_TYPE_FDMI_PLOGI:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received FDMI PLOGI ABTS rsp with oxid: 0x%x", oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
fdls_free_oxid(iport, oxid, &iport->active_oxid_fdmi_plogi);
iport->fabric.fdmi_pending &= ~FDLS_FDMI_PLOGI_PENDING;
iport->fabric.fdmi_pending &= ~FDLS_FDMI_ABORT_PENDING;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
break;
case FNIC_FRAME_TYPE_FDMI_RHBA:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received FDMI RHBA ABTS rsp with oxid: 0x%x", oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
@@ -3800,14 +3812,14 @@ static void fdls_process_fdmi_abts_rsp(s
iport->fabric.fdmi_pending &= ~FDLS_FDMI_ABORT_PENDING;
fdls_free_oxid(iport, oxid, &iport->active_oxid_fdmi_rhba);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
break;
case FNIC_FRAME_TYPE_FDMI_RPA:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received FDMI RPA ABTS rsp with oxid: 0x%x", oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
@@ -3821,12 +3833,12 @@ static void fdls_process_fdmi_abts_rsp(s
iport->fabric.fdmi_pending &= ~FDLS_FDMI_ABORT_PENDING;
fdls_free_oxid(iport, oxid, &iport->active_oxid_fdmi_rpa);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abts rsp with invalid oxid: 0x%x. Dropping frame",
oxid);
break;
@@ -3861,7 +3873,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (!((s_id == FC_FID_DIR_SERV) || (s_id == FC_FID_FLOGI)
|| (s_id == FC_FID_FCTRL))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abts rsp with invalid SID: 0x%x. Dropping frame",
s_id);
return;
@@ -3869,14 +3881,14 @@ fdls_process_fabric_abts_rsp(struct fnic
oxid = FNIC_STD_GET_OX_ID(fchdr);
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abts rsp with invalid oxid: 0x%x. Dropping frame",
oxid);
return;
}
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -3884,11 +3896,11 @@ fdls_process_fabric_abts_rsp(struct fnic
iport->fabric.flags &= ~FNIC_FDLS_FABRIC_ABORT_ISSUED;
if (fchdr->fh_r_ctl == FC_RCTL_BA_ACC) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abts rsp BA_ACC for fabric_state: %d OX_ID: 0x%x",
fabric_state, be16_to_cpu(ba_acc->acc.ba_ox_id));
} else if (fchdr->fh_r_ctl == FC_RCTL_BA_RJT) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"BA_RJT fs: %d OX_ID: 0x%x rc: 0x%x rce: 0x%x",
fabric_state, FNIC_STD_GET_OX_ID(&ba_rjt->fchdr),
ba_rjt->rjt.br_reason, ba_rjt->rjt.br_explan);
@@ -3903,7 +3915,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter < iport->max_flogi_retries)
fdls_send_fabric_flogi(iport);
else
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Exceeded max FLOGI retries");
break;
case FNIC_FRAME_TYPE_FABRIC_LOGO:
@@ -3914,7 +3926,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter < iport->max_plogi_retries)
fdls_send_fabric_plogi(iport);
else
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Exceeded max PLOGI retries");
break;
case FNIC_FRAME_TYPE_FABRIC_RPN:
@@ -3928,7 +3940,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter < FDLS_RETRY_COUNT)
fdls_send_scr(iport);
else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"SCR exhausted retries. Start fabric PLOGI %p",
iport);
fnic_fdls_start_plogi(iport); /* go back to fabric Plogi */
@@ -3938,7 +3950,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter < FDLS_RETRY_COUNT)
fdls_send_register_fc4_types(iport);
else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFT exhausted retries. Start fabric PLOGI %p",
iport);
fnic_fdls_start_plogi(iport); /* go back to fabric Plogi */
@@ -3948,7 +3960,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter < FDLS_RETRY_COUNT)
fdls_send_register_fc4_features(iport);
else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFF exhausted retries. Start fabric PLOGI %p",
iport);
fnic_fdls_start_plogi(iport); /* go back to fabric Plogi */
@@ -3958,7 +3970,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter <= FDLS_RETRY_COUNT)
fdls_send_gpn_ft(iport, fabric_state);
else
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"GPN FT exhausted retries. Start fabric PLOGI %p",
iport);
break;
@@ -3967,7 +3979,7 @@ fdls_process_fabric_abts_rsp(struct fnic
* We should not be here since we already validated rx oxid with
* our active_oxid_fabric_req
*/
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Invalid OXID/active oxid 0x%x\n", oxid);
WARN_ON(true);
return;
@@ -3987,7 +3999,7 @@ fdls_process_abts_req(struct fnic_iport_
sizeof(struct fc_std_abts_ba_acc);
nport_id = ntoh24(fchdr->fh_s_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abort from SID 0x%8x", nport_id);
tport = fnic_find_tport_by_fcid(iport, nport_id);
@@ -4000,7 +4012,7 @@ fdls_process_abts_req(struct fnic_iport_
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"0x%x: Failed to allocate frame to send response for ABTS req",
iport->fcid);
return;
@@ -4021,7 +4033,7 @@ fdls_process_abts_req(struct fnic_iport_
pba_acc->acc.ba_rx_id = cpu_to_be16(FNIC_STD_GET_RX_ID(fchdr));
pba_acc->acc.ba_ox_id = cpu_to_be16(FNIC_STD_GET_OX_ID(fchdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send BA ACC with oxid: 0x%x",
iport->fcid, oxid);
@@ -4041,7 +4053,7 @@ fdls_process_unsupported_els_req(struct
sizeof(struct fc_std_els_rjt_rsp);
if (iport->fcid != d_id) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping unsupported ELS with illegal frame bits 0x%x\n",
d_id);
atomic64_inc(&iport->iport_stats.unsupported_frames_dropped);
@@ -4050,7 +4062,7 @@ fdls_process_unsupported_els_req(struct
if ((iport->state != FNIC_IPORT_STATE_READY)
&& (iport->state != FNIC_IPORT_STATE_FABRIC_DISC)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping unsupported ELS request in iport state: %d",
iport->state);
atomic64_inc(&iport->iport_stats.unsupported_frames_dropped);
@@ -4059,7 +4071,7 @@ fdls_process_unsupported_els_req(struct
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send response to unsupported ELS request");
return;
}
@@ -4067,7 +4079,7 @@ fdls_process_unsupported_els_req(struct
pls_rsp = (struct fc_std_els_rjt_rsp *) (frame + FNIC_ETH_FCOE_HDRS_OFFSET);
fdls_init_els_rjt_frame(frame, iport);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Process unsupported ELS request from SID: 0x%x",
iport->fcid, ntoh24(fchdr->fh_s_id));
@@ -4094,12 +4106,12 @@ fdls_process_rls_req(struct fnic_iport_s
uint16_t frame_size = FNIC_ETH_FCOE_HDRS_OFFSET +
sizeof(struct fc_std_rls_acc);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Process RLS request %d", iport->fnic->fnic_num);
if ((iport->state != FNIC_IPORT_STATE_READY)
&& (iport->state != FNIC_IPORT_STATE_FABRIC_DISC)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received RLS req in iport state: %d. Dropping the frame.",
iport->state);
return;
@@ -4107,7 +4119,7 @@ fdls_process_rls_req(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send RLS accept");
return;
}
@@ -4148,33 +4160,33 @@ fdls_process_els_req(struct fnic_iport_s
if ((iport->state != FNIC_IPORT_STATE_READY)
&& (iport->state != FNIC_IPORT_STATE_FABRIC_DISC)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping ELS frame type: 0x%x in iport state: %d",
type, iport->state);
return;
}
switch (type) {
case ELS_ECHO:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"sending LS_ACC for ECHO request %d\n",
iport->fnic->fnic_num);
break;
case ELS_RRQ:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"sending LS_ACC for RRQ request %d\n",
iport->fnic->fnic_num);
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"sending LS_ACC for 0x%x ELS frame\n", type);
break;
}
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send ELS response for 0x%x",
type);
return;
@@ -4220,17 +4232,17 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
tport = fnic_find_tport_by_fcid(iport, s_id);
if (!tport) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received tgt abts rsp with invalid SID: 0x%x", s_id);
return;
}
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"tport 0x%p Canceling fabric disc timer\n", tport);
fnic_del_tport_timer_sync(fnic, tport);
}
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received tgt abts rsp in iport state(%d). Dropping.",
iport->state);
return;
@@ -4245,15 +4257,15 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
switch (frame_type) {
case FNIC_FRAME_TYPE_TGT_ADISC:
if (fchdr->fh_r_ctl == FC_RCTL_BA_ACC) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"OX_ID: 0x%x tgt_fcid: 0x%x rcvd tgt adisc abts resp BA_ACC",
be16_to_cpu(ba_acc->acc.ba_ox_id),
tport->fcid);
} else if (fchdr->fh_r_ctl == FC_RCTL_BA_RJT) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"ADISC BA_RJT rcvd tport_fcid: 0x%x tport_state: %d ",
tport->fcid, tport_state);
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"reason code: 0x%x reason code explanation:0x%x ",
ba_rjt->rjt.br_reason,
ba_rjt->rjt.br_explan);
@@ -4265,7 +4277,7 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
return;
}
fdls_free_oxid(iport, oxid, &tport->active_oxid);
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"ADISC not responding. Deleting target port: 0x%x",
tport->fcid);
fdls_delete_tport(iport, tport);
@@ -4278,14 +4290,14 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
break;
case FNIC_FRAME_TYPE_TGT_PLOGI:
if (fchdr->fh_r_ctl == FC_RCTL_BA_ACC) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received tgt PLOGI abts response BA_ACC tgt_fcid: 0x%x",
tport->fcid);
} else if (fchdr->fh_r_ctl == FC_RCTL_BA_RJT) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI BA_RJT received for tport_fcid: 0x%x OX_ID: 0x%x",
tport->fcid, FNIC_STD_GET_OX_ID(fchdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"reason code: 0x%x reason code explanation: 0x%x",
ba_rjt->rjt.br_reason,
ba_rjt->rjt.br_explan);
@@ -4308,14 +4320,14 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
break;
case FNIC_FRAME_TYPE_TGT_PRLI:
if (fchdr->fh_r_ctl == FC_RCTL_BA_ACC) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Received tgt PRLI abts response BA_ACC",
tport->fcid);
} else if (fchdr->fh_r_ctl == FC_RCTL_BA_RJT) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI BA_RJT received for tport_fcid: 0x%x OX_ID: 0x%x ",
tport->fcid, FNIC_STD_GET_OX_ID(fchdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"reason code: 0x%x reason code explanation: 0x%x",
ba_rjt->rjt.br_reason,
ba_rjt->rjt.br_explan);
@@ -4331,7 +4343,7 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
fdls_set_tport_state(tport, FDLS_TGT_STATE_PLOGI);
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received ABTS response for unknown frame %p", iport);
break;
}
@@ -4351,14 +4363,14 @@ fdls_process_plogi_req(struct fnic_iport
sizeof(struct fc_std_els_rjt_rsp);
if (iport->fcid != d_id) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received PLOGI with illegal frame bits. Dropping frame from 0x%x",
d_id);
return;
}
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received PLOGI request in iport state: %d Dropping frame",
iport->state);
return;
@@ -4366,7 +4378,7 @@ fdls_process_plogi_req(struct fnic_iport
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send response to PLOGI request");
return;
}
@@ -4374,7 +4386,7 @@ fdls_process_plogi_req(struct fnic_iport
pplogi_rsp = (struct fc_std_els_rjt_rsp *) (frame + FNIC_ETH_FCOE_HDRS_OFFSET);
fdls_init_els_rjt_frame(frame, iport);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Process PLOGI request from SID: 0x%x",
iport->fcid, ntoh24(fchdr->fh_s_id));
@@ -4404,11 +4416,11 @@ fdls_process_logo_req(struct fnic_iport_
nport_id = ntoh24(logo->els.fl_n_port_id);
nport_name = be64_to_cpu(logo->els.fl_n_port_wwn);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Process LOGO request from fcid: 0x%x", nport_id);
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Dropping LOGO req from 0x%x in iport state: %d",
nport_id, iport->state);
return;
@@ -4418,19 +4430,19 @@ fdls_process_logo_req(struct fnic_iport_
if (!tport) {
/* We are not logged in with the nport, log and drop... */
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received LOGO from an nport not logged in: 0x%x(0x%llx)",
nport_id, nport_name);
return;
}
if (tport->fcid != nport_id) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received LOGO with invalid target port fcid: 0x%x(0x%llx)",
nport_id, nport_name);
return;
}
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"tport fcid 0x%x: Canceling disc timer\n",
tport->fcid);
fnic_del_tport_timer_sync(fnic, tport);
@@ -4447,7 +4459,7 @@ fdls_process_logo_req(struct fnic_iport_
if ((iport->state == FNIC_IPORT_STATE_READY)
&& (fdls_get_state(&iport->fabric) != FDLS_STATE_SEND_GPNFT)
&& (fdls_get_state(&iport->fabric) != FDLS_STATE_RSCN_GPN_FT)) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Sending GPNFT in response to LOGO from Target:0x%x",
nport_id);
fdls_send_gpn_ft(iport, FDLS_STATE_SEND_GPNFT);
@@ -4460,7 +4472,7 @@ fdls_process_logo_req(struct fnic_iport_
fdls_send_logo_resp(iport, &logo->fchdr);
if ((fdls_get_state(&iport->fabric) != FDLS_STATE_SEND_GPNFT) &&
(fdls_get_state(&iport->fabric) != FDLS_STATE_RSCN_GPN_FT)) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Sending GPNFT in response to LOGO from Target:0x%x",
nport_id);
fdls_send_gpn_ft(iport, FDLS_STATE_SEND_GPNFT);
@@ -4487,11 +4499,11 @@ fdls_process_rscn(struct fnic_iport_s *i
atomic64_inc(&iport->iport_stats.num_rscns);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process RSCN %p", iport);
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS RSCN received in state(%d). Dropping",
fdls_get_state(fdls));
return;
@@ -4508,18 +4520,18 @@ fdls_process_rscn(struct fnic_iport_s *i
if ((rscn_payload_len == 0xFFFF)
&& (sid == FC_FID_FCTRL)) {
rscn_type = PC_RSCN;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"pcrscn: PCRSCN received. sid: 0x%x payload len: 0x%x",
sid, rscn_payload_len);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RSCN payload_len: 0x%x page_len: 0x%x",
rscn_payload_len, rscn->els.rscn_page_len);
/* if this happens then we need to send ADISC to all the tports. */
list_for_each_entry_safe(tport, next, &iport->tport_list, links) {
if (tport->state == FDLS_TGT_STATE_READY)
tport->flags |= FNIC_FDLS_TPORT_SEND_ADISC;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RSCN for port id: 0x%x", tport->fcid);
}
} /* end else */
@@ -4527,7 +4539,7 @@ fdls_process_rscn(struct fnic_iport_s *i
num_ports = (rscn_payload_len - 4) / rscn->els.rscn_page_len;
rscn_port = (struct fc_els_rscn_page *)(rscn + 1);
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RSCN received for num_ports: %d payload_len: %d page_len: %d ",
num_ports, rscn_payload_len, rscn->els.rscn_page_len);
@@ -4551,14 +4563,14 @@ fdls_process_rscn(struct fnic_iport_s *i
if (tport->state == FDLS_TGT_STATE_READY)
tport->flags |= FNIC_FDLS_TPORT_SEND_ADISC;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RSCN for port id: 0x%x", tport->fcid);
}
break;
}
tport = fnic_find_tport_by_fcid(iport, nport_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RSCN port id list: 0x%x", nport_id);
if (!tport) {
@@ -4573,13 +4585,13 @@ fdls_process_rscn(struct fnic_iport_s *i
rscn_type == PC_RSCN && fnic->role == FNIC_ROLE_FCP_INITIATOR) {
if (fnic->pc_rscn_handling_status == PC_RSCN_HANDLING_IN_PROGRESS) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PCRSCN handling already in progress. Skip host reset: %d",
iport->fnic->fnic_num);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Processing PCRSCN. Queuing fnic for host reset: %d",
iport->fnic->fnic_num);
fnic->pc_rscn_handling_status = PC_RSCN_HANDLING_IN_PROGRESS;
@@ -4595,7 +4607,7 @@ fdls_process_rscn(struct fnic_iport_s *i
queue_work(reset_fnic_work_queue, &reset_fnic_work);
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process RSCN sending GPN_FT: newports: %d", newports);
fdls_send_gpn_ft(iport, FDLS_STATE_RSCN_GPN_FT);
fdls_send_rscn_resp(iport, fchdr);
@@ -4644,20 +4656,20 @@ fdls_process_adisc_req(struct fnic_iport
uint16_t acc_frame_size = FNIC_ETH_FCOE_HDRS_OFFSET +
sizeof(struct fc_std_els_adisc);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Process ADISC request %d", iport->fnic->fnic_num);
fcid = FNIC_STD_GET_S_ID(fchdr);
tgt_fcid = ntoh24(fcid);
tport = fnic_find_tport_by_fcid(iport, tgt_fcid);
if (!tport) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"tport for fcid: 0x%x not found. Dropping ADISC req.",
tgt_fcid);
return;
}
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Dropping ADISC req from fcid: 0x%x in iport state: %d",
tgt_fcid, iport->state);
return;
@@ -4668,16 +4680,16 @@ fdls_process_adisc_req(struct fnic_iport
if ((frame_wwnn != tport->wwnn) || (frame_wwpn != tport->wwpn)) {
/* send reject */
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"ADISC req from fcid: 0x%x mismatch wwpn: 0x%llx wwnn: 0x%llx",
tgt_fcid, frame_wwpn, frame_wwnn);
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"local tport wwpn: 0x%llx wwnn: 0x%llx. Sending RJT",
tport->wwpn, tport->wwnn);
rjt_frame = fdls_alloc_frame(iport);
if (rjt_frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate rjt_frame to send response to ADISC request");
return;
}
@@ -4700,7 +4712,7 @@ fdls_process_adisc_req(struct fnic_iport
acc_frame = fdls_alloc_frame(iport);
if (acc_frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send ADISC accept");
return;
}
@@ -4754,7 +4766,7 @@ fnic_fdls_validate_and_get_frame_type(st
/* some common validation */
if (fdls_get_state(fabric) > FDLS_STATE_FABRIC_FLOGI) {
if (iport->fcid != d_id || (!FNIC_FC_FRAME_CS_CTL(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"invalid frame received. Dropping frame");
return -1;
}
@@ -4764,14 +4776,14 @@ fnic_fdls_validate_and_get_frame_type(st
if ((fchdr->fh_r_ctl == FC_RCTL_BA_ACC)
|| (fchdr->fh_r_ctl == FC_RCTL_BA_RJT)) {
if (!(FNIC_FC_FRAME_TYPE_BLS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received ABTS invalid frame. Dropping frame");
return -1;
}
if (fdls_is_oxid_fabric_req(oxid)) {
if (!(iport->fabric.flags & FNIC_FDLS_FABRIC_ABORT_ISSUED)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unexpected ABTS RSP(oxid:0x%x) from 0x%x. Dropping frame",
oxid, s_id);
return -1;
@@ -4782,7 +4794,7 @@ fnic_fdls_validate_and_get_frame_type(st
} else if (fdls_is_oxid_tgt_req(oxid)) {
return FNIC_TPORT_BLS_ABTS_RSP;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received ABTS rsp with unknown oxid(0x%x) from 0x%x. Dropping frame",
oxid, s_id);
return -1;
@@ -4791,7 +4803,7 @@ fnic_fdls_validate_and_get_frame_type(st
/* BLS ABTS Req */
if ((fchdr->fh_r_ctl == FC_RCTL_BA_ABTS)
&& (FNIC_FC_FRAME_TYPE_BLS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Receiving Abort Request from s_id: 0x%x", s_id);
return FNIC_BLS_ABTS_REQ;
}
@@ -4803,7 +4815,7 @@ fnic_fdls_validate_and_get_frame_type(st
if ((!FNIC_FC_FRAME_FCTL_FIRST_LAST_SEQINIT(fchdr))
|| (!FNIC_FC_FRAME_UNSOLICITED(fchdr))
|| (!FNIC_FC_FRAME_TYPE_ELS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received LOGO invalid frame. Dropping frame");
return -1;
}
@@ -4812,12 +4824,12 @@ fnic_fdls_validate_and_get_frame_type(st
if ((!FNIC_FC_FRAME_FCTL_FIRST_LAST_SEQINIT(fchdr))
|| (!FNIC_FC_FRAME_TYPE_ELS(fchdr))
|| (!FNIC_FC_FRAME_UNSOLICITED(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received RSCN invalid FCTL. Dropping frame");
return -1;
}
if (s_id != FC_FID_FCTRL)
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received RSCN from target FCTL: 0x%x type: 0x%x s_id: 0x%x.",
fchdr->fh_f_ctl[0], fchdr->fh_type, s_id);
return FNIC_ELS_RSCN_REQ;
@@ -4832,7 +4844,7 @@ fnic_fdls_validate_and_get_frame_type(st
case ELS_RRQ:
return FNIC_ELS_RRQ;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Unsupported frame (type:0x%02x) from fcid: 0x%x",
type, s_id);
return FNIC_ELS_UNSUPPORTED_REQ;
@@ -4841,14 +4853,14 @@ fnic_fdls_validate_and_get_frame_type(st
/* solicited response from fabric or target */
oxid_frame_type = FNIC_FRAME_TYPE(oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"oxid frame code: 0x%x, oxid: 0x%x\n", oxid_frame_type, oxid);
switch (oxid_frame_type) {
case FNIC_FRAME_TYPE_FABRIC_FLOGI:
if (type == ELS_LS_ACC) {
if ((s_id != FC_FID_FLOGI)
|| (!FNIC_FC_FRAME_TYPE_ELS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4859,7 +4871,7 @@ fnic_fdls_validate_and_get_frame_type(st
if (type == ELS_LS_ACC) {
if ((s_id != FC_FID_DIR_SERV)
|| (!FNIC_FC_FRAME_TYPE_ELS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4870,7 +4882,7 @@ fnic_fdls_validate_and_get_frame_type(st
if (type == ELS_LS_ACC) {
if ((s_id != FC_FID_FCTRL)
|| (!FNIC_FC_FRAME_TYPE_ELS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4879,7 +4891,7 @@ fnic_fdls_validate_and_get_frame_type(st
case FNIC_FRAME_TYPE_FABRIC_RPN:
if ((s_id != FC_FID_DIR_SERV) || (!FNIC_FC_FRAME_TYPE_FC_GS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4887,7 +4899,7 @@ fnic_fdls_validate_and_get_frame_type(st
case FNIC_FRAME_TYPE_FABRIC_RFT:
if ((s_id != FC_FID_DIR_SERV) || (!FNIC_FC_FRAME_TYPE_FC_GS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4895,7 +4907,7 @@ fnic_fdls_validate_and_get_frame_type(st
case FNIC_FRAME_TYPE_FABRIC_RFF:
if ((s_id != FC_FID_DIR_SERV) || (!FNIC_FC_FRAME_TYPE_FC_GS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4903,7 +4915,7 @@ fnic_fdls_validate_and_get_frame_type(st
case FNIC_FRAME_TYPE_FABRIC_GPN_FT:
if ((s_id != FC_FID_DIR_SERV) || (!FNIC_FC_FRAME_TYPE_FC_GS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4925,7 +4937,7 @@ fnic_fdls_validate_and_get_frame_type(st
return FNIC_TPORT_ADISC_RSP;
case FNIC_FRAME_TYPE_TGT_LOGO:
if (!FNIC_FC_FRAME_TYPE_ELS(fchdr)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping Unknown frame in tport solicited exchange range type: 0x%x.",
fchdr->fh_type);
return -1;
@@ -4933,7 +4945,7 @@ fnic_fdls_validate_and_get_frame_type(st
return FNIC_TPORT_LOGO_RSP;
default:
/* Drop the Rx frame and log/stats it */
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Solicited response: unknown OXID: 0x%x", oxid);
return -1;
}
@@ -5003,7 +5015,7 @@ void fnic_fdls_recv_frame(struct fnic_ip
break;
case FNIC_TPORT_LOGO_RSP:
/* Logo response from tgt which we have deleted */
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Logo response from tgt: 0x%x",
ntoh24(fchdr->fh_s_id));
break;
@@ -5046,9 +5058,9 @@ void fnic_fdls_recv_frame(struct fnic_ip
fdls_process_fdmi_reg_ack(iport, fchdr, frame_type);
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"s_id: 0x%x d_did: 0x%x", s_id, d_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown FCoE frame of len: %d. Dropping frame", len);
break;
}
@@ -5065,7 +5077,7 @@ void fnic_fdls_link_down(struct fnic_ipo
struct fnic_tport_s *tport, *next;
struct fnic *fnic = iport->fnic;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS processing link down", iport->fcid);
fdls_set_state((&iport->fabric), FDLS_STATE_LINKDOWN);
@@ -5075,7 +5087,7 @@ void fnic_fdls_link_down(struct fnic_ipo
fnic_fcpio_reset(iport->fnic);
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
list_for_each_entry_safe(tport, next, &iport->tport_list, links) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"removing rport: 0x%x", tport->fcid);
fdls_delete_tport(iport, tport);
}
@@ -5088,6 +5100,6 @@ void fnic_fdls_link_down(struct fnic_ipo
iport->flags &= ~FNIC_FDMI_ACTIVE;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS finish processing link down", iport->fcid);
}
--- a/drivers/scsi/fnic/fip.c
+++ b/drivers/scsi/fnic/fip.c
@@ -27,7 +27,7 @@ void fnic_fcoe_reset_vlans(struct fnic *
}
spin_unlock_irqrestore(&fnic->vlans_lock, flags);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Reset vlan complete\n");
}
@@ -46,7 +46,7 @@ void fnic_fcoe_send_vlan_req(struct fnic
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FIP_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send VLAN req");
return;
}
@@ -54,10 +54,10 @@ void fnic_fcoe_send_vlan_req(struct fnic
fnic_fcoe_reset_vlans(fnic);
fnic->set_vlan(fnic, 0);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"set vlan done\n");
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"got MAC 0x%x:%x:%x:%x:%x:%x\n", iport->hwmac[0],
iport->hwmac[1], iport->hwmac[2], iport->hwmac[3],
iport->hwmac[4], iport->hwmac[5]);
@@ -81,13 +81,13 @@ void fnic_fcoe_send_vlan_req(struct fnic
iport->fip.state = FDLS_FIP_VLAN_DISCOVERY_STARTED;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Send VLAN req\n");
fnic_send_fip_frame(iport, frame, frame_size);
vlan_tov = jiffies + msecs_to_jiffies(FCOE_CTLR_FIPVLAN_TOV);
mod_timer(&fnic->retry_fip_timer, round_jiffies(vlan_tov));
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fip timer set\n");
}
@@ -111,11 +111,11 @@ void fnic_fcoe_process_vlan_resp(struct
struct fip_vlan_desc *vlan_desc;
unsigned long flags;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p got vlan resp\n", fnic);
desc_len = be16_to_cpu(vlan_notif->fip.fip_dl_len);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"desc_len %d\n", desc_len);
spin_lock_irqsave(&fnic->vlans_lock, flags);
@@ -128,23 +128,20 @@ void fnic_fcoe_process_vlan_resp(struct
if (vlan_desc->fd_desc.fip_dtype == FIP_DT_VLAN) {
if (vlan_desc->fd_desc.fip_dlen != 1) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Invalid descriptor length(%x) in VLan response\n",
vlan_desc->fd_desc.fip_dlen);
}
num_vlan++;
vid = be16_to_cpu(vlan_desc->fd_vlan);
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"process_vlan_resp: FIP VLAN %d\n", vid);
vlan = kzalloc_obj(*vlan, GFP_ATOMIC);
if (!vlan) {
/* retry from timer */
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Mem Alloc failure\n");
spin_unlock_irqrestore(&fnic->vlans_lock,
flags);
@@ -155,14 +152,14 @@ void fnic_fcoe_process_vlan_resp(struct
list_add_tail(&vlan->list, &fnic->vlan_list);
break;
}
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
- "Invalid descriptor type(%x) in VLan response\n",
- vlan_desc->fd_desc.fip_dtype);
/*
- * Note : received a type=2 descriptor here i.e. FIP
- * MAC Address Descriptor
+ * Note : skip any type=2 descriptor here
+ * (i.e. FIP MAC Address Descriptor)
*/
+ if (vlan_desc->fd_desc.fip_dtype != FIP_DT_MAC)
+ FNIC_FIP_DBG(KERN_INFO, fnic,
+ "Invalid descriptor type(0x%x) in vlan response\n",
+ vlan_desc->fd_desc.fip_dtype);
cur_desc += vlan_desc->fd_desc.fip_dlen;
desc_len -= vlan_desc->fd_desc.fip_dlen;
}
@@ -170,7 +167,7 @@ void fnic_fcoe_process_vlan_resp(struct
/* any VLAN descriptors present ? */
if (num_vlan == 0) {
atomic64_inc(&fnic_stats->vlan_stats.resp_withno_vlanID);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p No VLAN descriptors in FIP VLAN response\n",
fnic);
}
@@ -195,7 +192,7 @@ void fnic_fcoe_start_fcf_discovery(struc
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FIP_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_ERR, fnic,
"Failed to allocate frame to start FCF discovery");
return;
}
@@ -222,7 +219,7 @@ void fnic_fcoe_start_fcf_discovery(struc
FNIC_STD_SET_NODE_NAME(&pdisc_sol->name_desc.fd_wwn, iport->wwnn);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Start FCF discovery\n");
fnic_send_fip_frame(iport, frame, frame_size);
@@ -257,16 +254,14 @@ void fnic_fcoe_fip_discovery_resp(struct
switch (iport->fip.state) {
case FDLS_FIP_FCF_DISCOVERY_STARTED:
if (be16_to_cpu(disc_adv->fip.fip_flags) & FIP_FL_SOL) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p Solicited adv\n", fnic);
if ((disc_adv->prio_desc.fd_pri <
iport->selected_fcf.fcf_priority)
&& (be16_to_cpu(disc_adv->fip.fip_flags) & FIP_FL_AVAIL)) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p FCF Available\n", fnic);
memcpy(iport->selected_fcf.fcf_mac,
disc_adv->mac_desc.fd_mac, ETH_ALEN);
@@ -274,8 +269,8 @@ void fnic_fcoe_fip_discovery_resp(struct
disc_adv->prio_desc.fd_pri;
iport->selected_fcf.fka_adv_period =
be32_to_cpu(disc_adv->fka_adv_desc.fd_fka_period);
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num, "adv time %d",
+ FNIC_FIP_DBG(KERN_INFO, fnic,
+ "adv time %d",
iport->selected_fcf.fka_adv_period);
iport->selected_fcf.ka_disabled =
(disc_adv->fka_adv_desc.fd_flags & 1);
@@ -294,8 +289,7 @@ void fnic_fcoe_fip_discovery_resp(struct
iport->selected_fcf.fka_adv_period =
be32_to_cpu(disc_adv->fka_adv_desc.fd_fka_period);
FNIC_FIP_DBG(KERN_INFO,
- fnic->host,
- fnic->fnic_num,
+ fnic,
"change fka to %d",
iport->selected_fcf.fka_adv_period);
}
@@ -362,7 +356,7 @@ void fnic_fcoe_start_flogi(struct fnic *
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FIP_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_ERR, fnic,
"Failed to allocate frame to start FIP FLOGI");
return;
}
@@ -415,7 +409,7 @@ void fnic_fcoe_start_flogi(struct fnic *
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_FABRIC_FLOGI,
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Failed to allocate OXID to send FIP FLOGI");
mempool_free(frame, fnic->frame_pool);
return;
@@ -427,7 +421,7 @@ void fnic_fcoe_start_flogi(struct fnic *
FNIC_STD_SET_NODE_NAME(&pflogi_req->flogi_desc.flogi.els.fl_wwnn,
iport->wwnn);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"FIP start FLOGI\n");
fnic_send_fip_frame(iport, frame, frame_size);
iport->fip.flogi_retry++;
@@ -457,11 +451,11 @@ void fnic_fcoe_process_flogi_resp(struct
struct fnic_stats *fnic_stats = &fnic->fnic_stats;
struct fc_frame_header *fchdr = &flogi_rsp->rsp_desc.flogi.fchdr;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p FIP FLOGI rsp\n", fnic);
desc_len = be16_to_cpu(flogi_rsp->fip.fip_dl_len);
if (desc_len != 38) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Invalid Descriptor List len (%x). Dropping frame\n",
desc_len);
return;
@@ -471,7 +465,7 @@ void fnic_fcoe_process_flogi_resp(struct
&& (flogi_rsp->rsp_desc.fd_desc.fip_dlen == 36))
|| !((flogi_rsp->mac_desc.fd_desc.fip_dtype == 2)
&& (flogi_rsp->mac_desc.fd_desc.fip_dlen == 2))) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Dropping frame invalid type and len mix\n");
return;
}
@@ -484,7 +478,7 @@ void fnic_fcoe_process_flogi_resp(struct
|| (s_id != FC_FID_FLOGI)
|| (frame_type != FNIC_FABRIC_FLOGI_RSP)
|| (fchdr->fh_type != 0x01)) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Dropping invalid frame: s_id %x F %x R %x t %x OX_ID %x\n",
s_id, fchdr->fh_f_ctl[0], fchdr->fh_r_ctl,
fchdr->fh_type, FNIC_STD_GET_OX_ID(fchdr));
@@ -492,7 +486,7 @@ void fnic_fcoe_process_flogi_resp(struct
}
if (iport->fip.state == FDLS_FIP_FLOGI_STARTED) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p rsp for pending FLOGI\n", fnic);
oxid = FNIC_STD_GET_OX_ID(fchdr);
@@ -502,8 +496,7 @@ void fnic_fcoe_process_flogi_resp(struct
if ((be16_to_cpu(flogi_rsp->fip.fip_dl_len) == FIP_FLOGI_LEN)
&& (flogi_rsp->rsp_desc.flogi.els.fl_cmd == ELS_LS_ACC)) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p FLOGI success\n", fnic);
memcpy(iport->fpma, flogi_rsp->mac_desc.fd_mac, ETH_ALEN);
iport->fcid =
@@ -519,8 +512,7 @@ void fnic_fcoe_process_flogi_resp(struct
if (fnic_fdls_register_portid(iport, iport->fcid, NULL)
!= 0) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p flogi registration failed\n",
fnic);
return;
@@ -528,8 +520,8 @@ void fnic_fcoe_process_flogi_resp(struct
iport->fip.state = FDLS_FIP_FLOGI_COMPLETE;
iport->state = FNIC_IPORT_STATE_FABRIC_DISC;
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num, "iport->state:%d\n",
+ FNIC_FIP_DBG(KERN_INFO, fnic,
+ "iport->state:%d\n",
iport->state);
fnic_fdls_disc_start(iport);
if (!((iport->selected_fcf.ka_disabled)
@@ -575,7 +567,7 @@ void fnic_common_fip_cleanup(struct fnic
if (!iport->usefip)
return;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p fip cleanup\n", fnic);
iport->fip.state = FDLS_FIP_INIT;
@@ -617,7 +609,7 @@ void fnic_fcoe_process_cvl(struct fnic *
int found = false;
int max_count = 0;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p clear virtual link handler\n", fnic);
if (!((cvl_msg->fcf_mac_desc.fd_desc.fip_dtype == 2)
@@ -625,7 +617,7 @@ void fnic_fcoe_process_cvl(struct fnic *
|| !((cvl_msg->name_desc.fd_desc.fip_dtype == 4)
&& (cvl_msg->name_desc.fd_desc.fip_dlen == 3))) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"invalid mix: ft %x fl %x ndt %x ndl %x",
cvl_msg->fcf_mac_desc.fd_desc.fip_dtype,
cvl_msg->fcf_mac_desc.fd_desc.fip_dlen,
@@ -640,8 +632,7 @@ void fnic_fcoe_process_cvl(struct fnic *
if (!((cvl_msg->vn_ports_desc[i].fd_desc.fip_dtype == 11)
&& (cvl_msg->vn_ports_desc[i].fd_desc.fip_dlen == 5))) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Invalid type and len mix type: %d len: %d\n",
cvl_msg->vn_ports_desc[i].fd_desc.fip_dtype,
cvl_msg->vn_ports_desc[i].fd_desc.fip_dlen);
@@ -664,12 +655,12 @@ void fnic_fcoe_process_cvl(struct fnic *
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
max_count++;
if (max_count >= FIP_FNIC_RESET_WAIT_COUNT) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Rthr waited too long. Skipping handle link event %p\n",
fnic);
return;
}
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic reset in progress. Link event needs to wait %p",
fnic);
}
@@ -714,7 +705,7 @@ int fdls_fip_recv_frame(struct fnic *fni
return true;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Not a FIP Frame");
return false;
}
@@ -724,7 +715,7 @@ void fnic_work_on_fip_timer(struct work_
struct fnic *fnic = container_of(work, struct fnic, fip_timer_work);
struct fnic_iport_s *iport = &fnic->iport;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"FIP timeout\n");
if (iport->fip.state == FDLS_FIP_VLAN_DISCOVERY_STARTED) {
@@ -732,7 +723,7 @@ void fnic_work_on_fip_timer(struct work_
} else if (iport->fip.state == FDLS_FIP_FCF_DISCOVERY_STARTED) {
u8 zmac[ETH_ALEN] = { 0, 0, 0, 0, 0, 0 };
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"FCF Discovery timeout\n");
if (memcmp(iport->selected_fcf.fcf_mac, zmac, ETH_ALEN) != 0) {
@@ -754,13 +745,13 @@ void fnic_work_on_fip_timer(struct work_
round_jiffies(fcf_tov));
}
} else {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num, "FCF Discovery timeout\n");
+ FNIC_FIP_DBG(KERN_INFO, fnic,
+ "FCF Discovery timeout\n");
fnic_vlan_discovery_timeout(fnic);
}
} else if (iport->fip.state == FDLS_FIP_FLOGI_STARTED) {
fdls_schedule_oxid_free(iport, &iport->active_oxid_fabric_req);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"FLOGI timeout\n");
if (iport->fip.flogi_retry < fnic->config.flogi_retries)
fnic_fcoe_start_flogi(fnic);
@@ -807,7 +798,7 @@ void fnic_handle_enode_ka_timer(struct t
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FIP_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send enode ka");
return;
}
@@ -828,7 +819,7 @@ void fnic_handle_enode_ka_timer(struct t
memcpy(penode_ka->eth.h_dest, iport->selected_fcf.fcf_mac, ETH_ALEN);
memcpy(penode_ka->mac_desc.fd_mac, iport->hwmac, ETH_ALEN);
- FNIC_FIP_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_DEBUG, fnic,
"Handle enode KA timer\n");
fnic_send_fip_frame(iport, frame, frame_size);
enode_ka_tov = jiffies
@@ -861,7 +852,7 @@ void fnic_handle_vn_ka_timer(struct time
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FIP_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send vn ka");
return;
}
@@ -887,7 +878,7 @@ void fnic_handle_vn_ka_timer(struct time
memcpy(pvn_port_ka->vn_port_desc.fd_fc_id, fcid, 3);
FNIC_STD_SET_NPORT_NAME(&pvn_port_ka->vn_port_desc.fd_wwpn, iport->wwpn);
- FNIC_FIP_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_DEBUG, fnic,
"Handle vnport KA timer\n");
fnic_send_fip_frame(iport, frame, frame_size);
vn_ka_tov = jiffies + msecs_to_jiffies(FIP_VN_KA_PERIOD);
@@ -977,7 +968,7 @@ void fnic_work_on_fcs_ka_timer(struct wo
*fnic = container_of(work, struct fnic, fip_timer_work);
struct fnic_iport_s *iport = &fnic->iport;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p fcs ka timeout\n", fnic);
fnic_common_fip_cleanup(fnic);
--- a/drivers/scsi/fnic/fip.h
+++ b/drivers/scsi/fnic/fip.h
@@ -142,7 +142,7 @@ fnic_debug_dump_fip_frame(struct fnic *f
u16 op = be16_to_cpu(fiph->fip_op);
u8 sub = fiph->fip_subcode;
- FNIC_FCS_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_DEBUG, fnic,
"FIP %s packet contents: op: 0x%x sub: 0x%x (len = %d)",
pfx, op, sub, len);
--- a/drivers/scsi/fnic/fnic.h
+++ b/drivers/scsi/fnic/fnic.h
@@ -144,6 +144,9 @@
#define PCI_SUBDEVICE_ID_CISCO_HELSINKI 0x02e4 /* VIC 15235 */
#define PCI_SUBDEVICE_ID_CISCO_GOTHENBURG 0x02f2 /* VIC 15425 */
+#define IS_FNIC_FCP_INITIATOR(fnic) (fnic->role == FNIC_ROLE_FCP_INITIATOR)
+#define IS_FNIC_NVME_INITIATOR(fnic) (fnic->role == FNIC_ROLE_NVME_INITIATOR)
+
struct fnic_pcie_device {
u32 device;
u8 *desc;
@@ -240,6 +243,9 @@ extern struct work_struct reset_fnic_wor
#define FNIC_FCS_LOGGING 0x02
#define FNIC_SCSI_LOGGING 0x04
#define FNIC_ISR_LOGGING 0x08
+#define FNIC_FDLS_LOGGING 0x10
+#define FNIC_NVME_LOGGING 0x20
+#define FNIC_FIP_LOGGING 0x40
#define FNIC_CHECK_LOGGING(LEVEL, CMD) \
do { \
@@ -249,38 +255,39 @@ do { \
} while (0); \
} while (0)
-#define FNIC_MAIN_DBG(kern_level, host, fnic_num, fmt, args...) \
- FNIC_CHECK_LOGGING(FNIC_MAIN_LOGGING, \
- shost_printk(kern_level, host, \
- "fnic<%d>: %s: %d: " fmt, fnic_num,\
- __func__, __LINE__, ##args);)
-
-#define FNIC_FCS_DBG(kern_level, host, fnic_num, fmt, args...) \
- FNIC_CHECK_LOGGING(FNIC_FCS_LOGGING, \
- shost_printk(kern_level, host, \
- "fnic<%d>: %s: %d: " fmt, fnic_num,\
- __func__, __LINE__, ##args);)
-
-#define FNIC_FIP_DBG(kern_level, host, fnic_num, fmt, args...) \
- FNIC_CHECK_LOGGING(FNIC_FCS_LOGGING, \
- shost_printk(kern_level, host, \
- "fnic<%d>: %s: %d: " fmt, fnic_num,\
- __func__, __LINE__, ##args);)
-
-#define FNIC_SCSI_DBG(kern_level, host, fnic_num, fmt, args...) \
- FNIC_CHECK_LOGGING(FNIC_SCSI_LOGGING, \
- shost_printk(kern_level, host, \
- "fnic<%d>: %s: %d: " fmt, fnic_num,\
- __func__, __LINE__, ##args);)
-
-#define FNIC_ISR_DBG(kern_level, host, fnic_num, fmt, args...) \
- FNIC_CHECK_LOGGING(FNIC_ISR_LOGGING, \
- shost_printk(kern_level, host, \
- "fnic<%d>: %s: %d: " fmt, fnic_num,\
- __func__, __LINE__, ##args);)
+#define fnic_printk(kern_level, fnic, fmt, ...) \
+ (IS_FNIC_FCP_INITIATOR(fnic) ? \
+ shost_printk(kern_level, fnic->host, "fnic<%d>: %s: %d: " fmt, \
+ fnic->fnic_num, __func__, __LINE__, ##__VA_ARGS__) : \
+ printk(kern_level "fnic<%d>: %s: %d: " fmt, fnic->fnic_num, \
+ __func__, __LINE__, ##__VA_ARGS__))
+
+#define FNIC_MAIN_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_MAIN_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
+
+#define FNIC_FCS_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_FCS_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
+
+#define FNIC_FIP_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_FIP_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
+
+#define FNIC_SCSI_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_SCSI_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
+
+#define FNIC_ISR_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_ISR_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
+
+#define FNIC_NVME_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_NVME_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
-#define FNIC_MAIN_NOTE(kern_level, host, fmt, args...) \
- shost_printk(kern_level, host, fmt, ##args)
+#define FNIC_MAIN_NOTE(kern_level, fnic, fmt, args...) \
+ fnic_printk(kern_level, fnic, fmt, ##args)
#define FNIC_WQ_COPY_MAX 64
#define FNIC_WQ_MAX 1
@@ -325,6 +332,7 @@ enum fnic_state {
enum fnic_role_e {
FNIC_ROLE_FCP_INITIATOR = 0,
+ FNIC_ROLE_NVME_INITIATOR,
};
enum fnic_evt {
@@ -598,7 +606,7 @@ fnic_debug_dump(struct fnic *fnic, uint8
int i;
for (i = 0; i < len; i = i+8) {
- FNIC_FCS_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"%d: %02x %02x %02x %02x %02x %02x %02x %02x", i / 8,
u8arr[i + 0], u8arr[i + 1], u8arr[i + 2], u8arr[i + 3],
u8arr[i + 4], u8arr[i + 5], u8arr[i + 6], u8arr[i + 7]);
@@ -613,7 +621,7 @@ fnic_debug_dump_fc_frame(struct fnic *fn
s_id = ntoh24(fchdr->fh_s_id);
d_id = ntoh24(fchdr->fh_d_id);
- FNIC_FCS_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"%s packet contents: sid/did/type/oxid = 0x%x/0x%x/0x%x/0x%x (len = %d)\n",
pfx, s_id, d_id, fchdr->fh_type,
FNIC_STD_GET_OX_ID(fchdr), len);
--- a/drivers/scsi/fnic/fnic_fcs.c
+++ b/drivers/scsi/fnic/fnic_fcs.c
@@ -39,7 +39,7 @@ static uint8_t FCOE_ALL_FCF_MAC[6] = FC_
static inline void fnic_fdls_set_fcoe_srcmac(struct fnic *fnic,
uint8_t *src_mac)
{
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Setting src mac: %02x:%02x:%02x:%02x:%02x:%02x",
src_mac[0], src_mac[1], src_mac[2], src_mac[3],
src_mac[4], src_mac[5]);
@@ -54,7 +54,7 @@ static inline void fnic_fdls_set_fcoe_sr
static inline void fnic_fdls_set_fcoe_dstmac(struct fnic *fnic,
uint8_t *dst_mac)
{
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Setting dst mac: %02x:%02x:%02x:%02x:%02x:%02x",
dst_mac[0], dst_mac[1], dst_mac[2], dst_mac[3],
dst_mac[4], dst_mac[5]);
@@ -82,7 +82,7 @@ void fnic_fdls_link_status_change(struct
{
struct fnic_iport_s *iport = &fnic->iport;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"link up: %d, usefip: %d", linkup, iport->usefip);
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
@@ -90,12 +90,12 @@ void fnic_fdls_link_status_change(struct
if (linkup) {
if (iport->usefip) {
iport->state = FNIC_IPORT_STATE_FIP;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"link up: %d, usefip: %d", linkup, iport->usefip);
fnic_fcoe_send_vlan_req(fnic);
} else {
iport->state = FNIC_IPORT_STATE_FABRIC_DISC;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->state: %d", iport->state);
fnic_fdls_disc_start(iport);
}
@@ -125,13 +125,13 @@ void fnic_fdls_learn_fcoe_macs(struct fn
memcpy(&fcmac[3], fcid, 3);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"learn fcoe: dst_mac: %02x:%02x:%02x:%02x:%02x:%02x",
ethhdr->h_dest[0], ethhdr->h_dest[1],
ethhdr->h_dest[2], ethhdr->h_dest[3],
ethhdr->h_dest[4], ethhdr->h_dest[5]);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"learn fcoe: fc_mac: %02x:%02x:%02x:%02x:%02x:%02x",
fcmac[0], fcmac[1], fcmac[2], fcmac[3], fcmac[4],
fcmac[5]);
@@ -149,7 +149,7 @@ void fnic_fdls_init(struct fnic *fnic, i
iport->fnic = fnic;
iport->usefip = usefip;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iportsrcmac: %02x:%02x:%02x:%02x:%02x:%02x",
iport->hwmac[0], iport->hwmac[1], iport->hwmac[2],
iport->hwmac[3], iport->hwmac[4], iport->hwmac[5]);
@@ -168,14 +168,14 @@ void fnic_handle_link(struct work_struct
int max_count = 0;
if (vnic_dev_get_intr_mode(fnic->vdev) != VNIC_DEV_INTR_MODE_MSI)
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Interrupt mode is not MSI\n");
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
if (fnic->stop_rx_link_events) {
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Stop link rx events\n");
return;
}
@@ -184,10 +184,10 @@ void fnic_handle_link(struct work_struct
if ((fnic->state != FNIC_IN_ETH_MODE)
&& (fnic->state != FNIC_IN_FC_MODE)) {
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic in transitional state: %d. link up: %d ignored",
fnic->state, vnic_dev_link_status(fnic->vdev));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Current link status: %d iport state: %d\n",
fnic->link_status, fnic->iport.state);
return;
@@ -199,36 +199,36 @@ void fnic_handle_link(struct work_struct
fnic->link_down_cnt = vnic_dev_link_down_cnt(fnic->vdev);
while (fnic->reset_in_progress == IN_PROGRESS) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic reset in progress. Link event needs to wait\n");
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"waiting for reset completion\n");
wait_for_completion_timeout(&fnic->reset_completion_wait,
msecs_to_jiffies(5000));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"woken up from reset completion wait\n");
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
max_count++;
if (max_count >= MAX_RESET_WAIT_COUNT) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Rstth waited for too long. Skipping handle link event\n");
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
return;
}
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Marking fnic reset in progress\n");
fnic->reset_in_progress = IN_PROGRESS;
if ((vnic_dev_get_intr_mode(fnic->vdev) != VNIC_DEV_INTR_MODE_MSI) ||
(fnic->link_status != old_link_status)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"old link status: %d link status: %d\n",
old_link_status, (int) fnic->link_status);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"old down count %d down count: %d\n",
old_link_down_cnt, (int) fnic->link_down_cnt);
}
@@ -237,36 +237,36 @@ void fnic_handle_link(struct work_struct
if (!fnic->link_status) {
/* DOWN -> DOWN */
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"down->down\n");
} else {
if (old_link_down_cnt != fnic->link_down_cnt) {
/* UP -> DOWN -> UP */
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"up->down. Link down\n");
fnic_fdls_link_status_change(fnic, 0);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"down->up. Link up\n");
fnic_fdls_link_status_change(fnic, 1);
} else {
/* UP -> UP */
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"up->up\n");
}
}
} else if (fnic->link_status) {
/* DOWN -> UP */
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"down->up. Link up\n");
fnic_fdls_link_status_change(fnic, 1);
} else {
/* UP -> DOWN */
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"up->down. Link down\n");
fnic_fdls_link_status_change(fnic, 0);
}
@@ -275,7 +275,7 @@ void fnic_handle_link(struct work_struct
fnic->reset_in_progress = NOT_IN_PROGRESS;
complete(&fnic->reset_completion_wait);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Marking fnic reset completion\n");
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
}
@@ -302,7 +302,7 @@ void fnic_handle_frame(struct work_struc
*/
if (fnic->state != FNIC_IN_FC_MODE &&
fnic->state != FNIC_IN_ETH_MODE) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Cannot process frame in transitional state\n");
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
return;
@@ -328,7 +328,7 @@ void fnic_handle_fip_frame(struct work_s
struct fnic_frame_list *cur_frame, *next;
struct fnic *fnic = container_of(work, struct fnic, fip_frame_work);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Processing FIP frame\n");
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
@@ -407,7 +407,7 @@ void fnic_update_mac_locked(struct fnic
if (ether_addr_equal(data, new))
return;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Update MAC: %u\n", *new);
if (!is_zero_ether_addr(data) && !ether_addr_equal(data, ctl))
@@ -477,7 +477,7 @@ static void fnic_rq_cmpl_frame_recv(stru
if (!fcs_ok) {
atomic64_inc(&fnic_stats->misc_stats.frame_errors);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic 0x%p fcs error. Dropping packet.\n", fnic);
goto drop;
}
@@ -487,21 +487,21 @@ static void fnic_rq_cmpl_frame_recv(stru
if (fnic_import_rq_eth_pkt(fnic, fp))
return;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping h_proto 0x%x",
be16_to_cpu(eh->h_proto));
goto drop;
}
} else {
/* wrong CQ type */
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic rq_cmpl wrong cq type x%x\n", type);
goto drop;
}
if (!fcs_ok || packet_error || !fcoe_fnic_crc_ok || fcoe_enc_error) {
atomic64_inc(&fnic_stats->misc_stats.frame_errors);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fcoe %x fcsok %x pkterr %x ffco %x fee %x\n",
fcoe, fcs_ok, packet_error,
fcoe_fnic_crc_ok, fcoe_enc_error);
@@ -511,7 +511,7 @@ static void fnic_rq_cmpl_frame_recv(stru
spin_lock_irqsave(&fnic->fnic_lock, flags);
if (fnic->stop_rx_link_events) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic->stop_rx_link_events: %d\n",
fnic->stop_rx_link_events);
goto drop;
@@ -521,7 +521,7 @@ static void fnic_rq_cmpl_frame_recv(stru
frame_elem = mempool_alloc(fnic->frame_elem_pool, GFP_ATOMIC);
if (!frame_elem) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Failed to allocate memory for frame elem");
goto drop;
}
@@ -567,7 +567,7 @@ int fnic_rq_cmpl_handler(struct fnic *fn
if (cur_work_done && fnic->stop_rx_link_events != 1) {
err = vnic_rq_fill(&fnic->rq[i], fnic_alloc_rq_frame);
if (err)
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"fnic_alloc_rq_frame can't alloc"
" frame\n");
}
@@ -593,7 +593,7 @@ int fnic_alloc_rq_frame(struct vnic_rq *
len = FNIC_FRAME_HT_ROOM;
buf = mempool_alloc(fnic->frame_recv_pool, GFP_ATOMIC);
if (!buf) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Unable to allocate RQ buffer of size: %d\n", len);
return -ENOMEM;
}
@@ -601,7 +601,7 @@ int fnic_alloc_rq_frame(struct vnic_rq *
pa = dma_map_single(&fnic->pdev->dev, buf, len, DMA_FROM_DEVICE);
if (dma_mapping_error(&fnic->pdev->dev, pa)) {
ret = -ENOMEM;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PCI mapping failed with error %d\n", ret);
goto free_buf;
}
@@ -642,7 +642,7 @@ static int fnic_send_frame(struct fnic *
if ((fnic_fc_trace_set_data(fnic->fnic_num,
FNIC_FC_SEND | 0x80, (char *) frame,
frame_len)) != 0) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic ctlr frame trace error");
}
@@ -650,7 +650,7 @@ static int fnic_send_frame(struct fnic *
if (!vnic_wq_desc_avail(wq)) {
dma_unmap_single(&fnic->pdev->dev, pa, frame_len, DMA_TO_DEVICE);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"vnic work queue descriptor is not available");
ret = -1;
goto fnic_send_frame_end;
@@ -706,13 +706,13 @@ fdls_send_fcoe_frame(struct fnic *fnic,
&& (fnic->state != FNIC_IN_ETH_MODE)) {
frame_elem = mempool_alloc(fnic->frame_elem_pool, GFP_ATOMIC);
if (!frame_elem) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Failed to allocate memory for frame elem");
return -ENOMEM;
}
memset(frame_elem, 0, sizeof(struct fnic_frame_list));
- FNIC_FCS_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Queueing FC frame: sid/did/type/oxid = 0x%x/0x%x/0x%x/0x%x\n",
ntoh24(fchdr->fh_s_id), ntoh24(fchdr->fh_d_id),
fchdr->fh_type, FNIC_STD_GET_OX_ID(fchdr));
@@ -778,7 +778,7 @@ void fnic_flush_tx(struct work_struct *w
struct fc_frame *fp;
struct fnic_frame_list *cur_frame, *next;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Flush queued frames");
list_for_each_entry_safe(cur_frame, next, &fnic->tx_queue, links) {
@@ -797,7 +797,7 @@ fnic_fdls_register_portid(struct fnic_ip
struct ethhdr *ethhdr;
int ret;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Setting port id: 0x%x fp: 0x%p fnic state: %d", port_id,
fp, fnic->state);
@@ -810,7 +810,7 @@ fnic_fdls_register_portid(struct fnic_ip
if (fnic->state == FNIC_IN_ETH_MODE || fnic->state == FNIC_IN_FC_MODE)
fnic->state = FNIC_IN_ETH_TRANS_FC_MODE;
else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Unexpected fnic state while processing FLOGI response\n");
return -1;
}
@@ -821,7 +821,7 @@ fnic_fdls_register_portid(struct fnic_ip
*/
ret = fnic_flogi_reg_handler(fnic, port_id);
if (ret < 0) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI registration error ret: %d fnic state: %d\n",
ret, fnic->state);
if (fnic->state == FNIC_IN_ETH_TRANS_FC_MODE)
@@ -831,7 +831,7 @@ fnic_fdls_register_portid(struct fnic_ip
}
iport->fabric.flags |= FNIC_FDLS_FPMA_LEARNT;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI registration success\n");
return 0;
}
@@ -931,7 +931,7 @@ fnic_fdls_add_tport(struct fnic_iport_s
struct fc_rport_identifiers ids;
struct rport_dd_data_s *rdd_data;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Adding rport fcid: 0x%x", tport->fcid);
ids.node_name = tport->wwnn;
@@ -943,12 +943,12 @@ fnic_fdls_add_tport(struct fnic_iport_s
rport = fc_remote_port_add(fnic->host, 0, &ids);
spin_lock_irqsave(&fnic->fnic_lock, flags);
if (!rport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Failed to add rport for tport: 0x%x", tport->fcid);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Added rport fcid: 0x%x", tport->fcid);
/* Mimic these assignments in queuecommand to avoid timing issues */
@@ -987,7 +987,7 @@ fnic_fdls_remove_tport(struct fnic_iport
fc_remote_port_delete(rport);
spin_lock_irqsave(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Deregistered and freed tport fcid: 0x%x from scsi transport fc",
tport->fcid);
@@ -1014,7 +1014,7 @@ void fnic_delete_fcp_tports(struct fnic
spin_lock_irqsave(&fnic->fnic_lock, flags);
list_for_each_entry_safe(tport, next, &fnic->iport.tport_list, links) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"removing fcp rport fcid: 0x%x", tport->fcid);
fdls_set_tport_state(tport, FDLS_TGT_STATE_OFFLINING);
fnic_del_tport_timer_sync(fnic, tport);
@@ -1041,36 +1041,36 @@ void fnic_tport_event_handler(struct wor
tport = cur_evt->arg1;
switch (cur_evt->event) {
case TGT_EV_RPORT_ADD:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Add rport event");
if (tport->state == FDLS_TGT_STATE_READY) {
fnic_fdls_add_tport(&fnic->iport,
(struct fnic_tport_s *) cur_evt->arg1, flags);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Target not ready. Add rport event dropped: 0x%x",
tport->fcid);
}
break;
case TGT_EV_RPORT_DEL:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Remove rport event");
if (tport->state == FDLS_TGT_STATE_OFFLINING) {
fnic_fdls_remove_tport(&fnic->iport,
(struct fnic_tport_s *) cur_evt->arg1, flags);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"remove rport event dropped tport fcid: 0x%x",
tport->fcid);
}
break;
case TGT_EV_TPORT_DELETE:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Delete tport event");
fdls_delete_tport(tport->iport, tport);
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Unknown tport event");
break;
}
@@ -1142,7 +1142,7 @@ void fnic_fcpio_reset(struct fnic *fnic)
if (unlikely(fnic->state == FNIC_IN_FC_TRANS_ETH_MODE)) {
/* fw reset is in progress, poll for its completion */
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic is in unexpected state: %d for fw_reset\n",
fnic->state);
return;
@@ -1155,7 +1155,7 @@ void fnic_fcpio_reset(struct fnic *fnic)
fnic->fw_reset_done = &fw_reset_done;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Issuing fw reset\n");
if (fnic_fw_reset_handler(fnic)) {
spin_lock_irqsave(&fnic->fnic_lock, flags);
@@ -1163,14 +1163,14 @@ void fnic_fcpio_reset(struct fnic *fnic)
fnic->state = old_state;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Waiting for fw completion\n");
time_remain = wait_for_completion_timeout(&fw_reset_done,
msecs_to_jiffies(FNIC_FW_RESET_TIMEOUT));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Woken up after fw completion timeout\n");
if (time_remain == 0) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FW reset completion timed out after %d ms\n",
FNIC_FW_RESET_TIMEOUT);
}
--- a/drivers/scsi/fnic/fnic_isr.c
+++ b/drivers/scsi/fnic/fnic_isr.c
@@ -222,7 +222,7 @@ int fnic_request_intr(struct fnic *fnic)
fnic->msix[i].devname,
fnic->msix[i].devid);
if (err) {
- FNIC_ISR_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_ERR, fnic,
"request_irq failed with error: %d\n",
err);
fnic_free_intr(fnic);
@@ -250,10 +250,10 @@ int fnic_set_intr_mode_msix(struct fnic
* We need n RQs, m WQs, o Copy WQs, n+m+o CQs, and n+m+o+1 INTRs
* (last INTR is used for WQ/RQ errors and notification area)
*/
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"rq-array size: %d wq-array size: %d copy-wq array size: %d\n",
n, m, o);
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"rq_count: %d raw_wq_count: %d wq_copy_count: %d cq_count: %d\n",
fnic->rq_count, fnic->raw_wq_count,
fnic->wq_copy_count, fnic->cq_count);
@@ -265,17 +265,17 @@ int fnic_set_intr_mode_msix(struct fnic
vec_count = pci_alloc_irq_vectors(fnic->pdev, min_irqs, vecs,
PCI_IRQ_MSIX | PCI_IRQ_AFFINITY);
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"allocated %d MSI-X vectors\n",
vec_count);
if (vec_count > 0) {
if (vec_count < vecs) {
- FNIC_ISR_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_ERR, fnic,
"interrupts number mismatch: vec_count: %d vecs: %d\n",
vec_count, vecs);
if (vec_count < min_irqs) {
- FNIC_ISR_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_ERR, fnic,
"no interrupts for copy wq\n");
return 1;
}
@@ -287,7 +287,7 @@ int fnic_set_intr_mode_msix(struct fnic
fnic->wq_copy_count = vec_count - n - m - 1;
fnic->wq_count = fnic->raw_wq_count + fnic->wq_copy_count;
if (fnic->cq_count != vec_count - 1) {
- FNIC_ISR_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_ERR, fnic,
"CQ count: %d does not match MSI-X vector count: %d\n",
fnic->cq_count, vec_count);
fnic->cq_count = vec_count - 1;
@@ -295,23 +295,23 @@ int fnic_set_intr_mode_msix(struct fnic
fnic->intr_count = vec_count;
fnic->err_intr_offset = fnic->rq_count + fnic->wq_count;
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"rq_count: %d raw_wq_count: %d copy_wq_base: %d\n",
fnic->rq_count,
fnic->raw_wq_count, fnic->copy_wq_base);
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"wq_copy_count: %d wq_count: %d cq_count: %d\n",
fnic->wq_copy_count,
fnic->wq_count, fnic->cq_count);
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "intr_count: %d err_intr_offset: %u",
+ FNIC_ISR_DBG(KERN_INFO, fnic,
+ "intr_count: %d err_intr_offset: %u\n",
fnic->intr_count,
fnic->err_intr_offset);
vnic_dev_set_intr_mode(fnic->vdev, VNIC_DEV_INTR_MODE_MSIX);
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"fnic using MSI-X\n");
return 0;
}
@@ -351,7 +351,7 @@ int fnic_set_intr_mode(struct fnic *fnic
fnic->intr_count = 1;
fnic->err_intr_offset = 0;
- FNIC_ISR_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_DEBUG, fnic,
"Using MSI Interrupts\n");
vnic_dev_set_intr_mode(fnic->vdev, VNIC_DEV_INTR_MODE_MSI);
@@ -377,7 +377,7 @@ int fnic_set_intr_mode(struct fnic *fnic
fnic->cq_count = 3;
fnic->intr_count = 3;
- FNIC_ISR_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_DEBUG, fnic,
"Using Legacy Interrupts\n");
vnic_dev_set_intr_mode(fnic->vdev, VNIC_DEV_INTR_MODE_INTX);
--- a/drivers/scsi/fnic/fnic_main.c
+++ b/drivers/scsi/fnic/fnic_main.c
@@ -185,7 +185,7 @@ static void fnic_get_host_speed(struct S
u32 port_speed = vnic_dev_port_speed(fnic->vdev);
struct fnic_stats *fnic_stats = &fnic->fnic_stats;
- FNIC_MAIN_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_INFO, fnic,
"port_speed: %d Mbps", port_speed);
atomic64_set(&fnic_stats->misc_stats.port_speed_in_mbps, port_speed);
@@ -235,7 +235,7 @@ static void fnic_get_host_speed(struct S
fc_host_speed(shost) = FC_PORTSPEED_128GBIT;
break;
default:
- FNIC_MAIN_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_INFO, fnic,
"Unknown FC speed: %d Mbps", port_speed);
fc_host_speed(shost) = FC_PORTSPEED_UNKNOWN;
break;
@@ -261,7 +261,7 @@ static struct fc_host_statistics *fnic_g
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
if (ret) {
- FNIC_MAIN_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_DEBUG, fnic,
"fnic: Get vnic stats failed: 0x%x", ret);
return stats;
}
@@ -287,64 +287,66 @@ static struct fc_host_statistics *fnic_g
void fnic_dump_fchost_stats(struct Scsi_Host *host,
struct fc_host_statistics *stats)
{
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ struct fnic *fnic = *((struct fnic **) shost_priv(host));
+
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: seconds since last reset = %llu\n",
stats->seconds_since_last_reset);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: tx frames = %llu\n",
stats->tx_frames);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: tx words = %llu\n",
stats->tx_words);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: rx frames = %llu\n",
stats->rx_frames);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: rx words = %llu\n",
stats->rx_words);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: lip count = %llu\n",
stats->lip_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: nos count = %llu\n",
stats->nos_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: error frames = %llu\n",
stats->error_frames);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: dumped frames = %llu\n",
stats->dumped_frames);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: link failure count = %llu\n",
stats->link_failure_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: loss of sync count = %llu\n",
stats->loss_of_sync_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: loss of signal count = %llu\n",
stats->loss_of_signal_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: prim seq protocol err count = %llu\n",
stats->prim_seq_protocol_err_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: invalid tx word count= %llu\n",
stats->invalid_tx_word_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: invalid crc count = %llu\n",
stats->invalid_crc_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: fcp input requests = %llu\n",
stats->fcp_input_requests);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: fcp output requests = %llu\n",
stats->fcp_output_requests);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: fcp control requests = %llu\n",
stats->fcp_control_requests);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: fcp input megabytes = %llu\n",
stats->fcp_input_megabytes);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: fcp output megabytes = %llu\n",
stats->fcp_output_megabytes);
return;
@@ -370,7 +372,7 @@ static void fnic_reset_host_stats(struct
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
if (ret) {
- FNIC_MAIN_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_DEBUG, fnic,
"fnic: Reset vnic stats failed"
" 0x%x", ret);
return;
@@ -684,16 +686,16 @@ void fnic_mq_map_queues_cpus(struct Scsi
struct blk_mq_queue_map *qmap = &host->tag_set.map[HCTX_TYPE_DEFAULT];
if (intr_mode == VNIC_DEV_INTR_MODE_MSI || intr_mode == VNIC_DEV_INTR_MODE_INTX) {
- FNIC_MAIN_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_ERR, fnic,
"intr_mode is not msix\n");
return;
}
- FNIC_MAIN_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_INFO, fnic,
"qmap->nr_queues: %d\n", qmap->nr_queues);
if (l_pdev == NULL) {
- FNIC_MAIN_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_ERR, fnic,
"l_pdev is null\n");
return;
}
--- a/drivers/scsi/fnic/fnic_scsi.c
+++ b/drivers/scsi/fnic/fnic_scsi.c
@@ -148,7 +148,7 @@ unsigned int fnic_count_ioreqs(struct fn
fnic_scsi_io_iter(fnic, fnic_count_portid_ioreqs_iter,
&portid, &count);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"portid = 0x%x count = %u\n", portid, count);
return count;
}
@@ -180,7 +180,7 @@ fnic_count_lun_ioreqs(struct fnic *fnic,
fnic_scsi_io_iter(fnic, fnic_count_lun_ioreqs_iter,
scsi_device, &count);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"lun = %p count = %u\n", scsi_device, count);
return count;
}
@@ -268,7 +268,7 @@ int fnic_fw_reset_handler(struct fnic *f
if (!vnic_wq_copy_desc_avail(wq))
ret = -EAGAIN;
else {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"ioreq_count: %u\n", ioreq_count);
fnic_queue_wq_copy_desc_fw_reset(wq, SCSI_NO_TAG);
atomic64_inc(&fnic->fnic_stats.fw_stats.active_fw_reqs);
@@ -283,11 +283,11 @@ int fnic_fw_reset_handler(struct fnic *f
if (!ret) {
atomic64_inc(&fnic->fnic_stats.reset_stats.fw_resets);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"Issued fw reset\n");
} else {
fnic_clear_state_flags(fnic, FNIC_FLAGS_FWRESET);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Failed to issue fw reset\n");
}
@@ -326,13 +326,13 @@ int fnic_flogi_reg_handler(struct fnic *
fc_id, gw_mac,
fnic->iport.fpma,
iport->r_a_tov, iport->e_d_tov);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"FLOGI FIP reg issued fcid: 0x%x src %p dest %p\n",
fc_id, fnic->iport.fpma, gw_mac);
} else {
fnic_queue_wq_copy_desc_flogi_reg(wq, SCSI_NO_TAG,
format, fc_id, gw_mac);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"FLOGI reg issued fcid 0x%x dest %p\n",
fc_id, gw_mac);
}
@@ -413,7 +413,7 @@ static inline int fnic_queue_wq_copy_des
free_wq_copy_descs(fnic, wq, hwq);
if (unlikely(!vnic_wq_copy_desc_avail(wq))) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"fnic_queue_wq_copy_desc failure - no descriptors\n");
atomic64_inc(&misc_stats->io_cpwq_alloc_failures);
return SCSI_MLQUEUE_HOST_BUSY;
@@ -478,7 +478,7 @@ enum scsi_qc_status fnic_queuecommand(st
rport = starget_to_rport(scsi_target(sc->device));
if (!rport) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"returning DID_NO_CONNECT for IO as rport is NULL\n");
sc->result = DID_NO_CONNECT << 16;
done(sc);
@@ -487,7 +487,7 @@ enum scsi_qc_status fnic_queuecommand(st
ret = fc_remote_port_chkready(rport);
if (ret) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"rport is not ready\n");
atomic64_inc(&fnic_stats->misc_stats.tport_not_ready);
sc->result = ret;
@@ -501,7 +501,7 @@ enum scsi_qc_status fnic_queuecommand(st
if (iport->state != FNIC_IPORT_STATE_READY) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"returning DID_NO_CONNECT for IO as iport state: %d\n",
iport->state);
sc->result = DID_NO_CONNECT << 16;
@@ -515,13 +515,13 @@ enum scsi_qc_status fnic_queuecommand(st
rdd_data = rport->dd_data;
tport = rdd_data->tport;
if (!tport || (rdd_data->iport != iport)) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"dd_data not yet set in SCSI for rport portid: 0x%x\n",
rport->port_id);
tport = fnic_find_tport_by_fcid(iport, rport->port_id);
if (!tport) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"returning DID_BUS_BUSY for IO as tport not found for: 0x%x\n",
rport->port_id);
sc->result = DID_BUS_BUSY << 16;
@@ -544,7 +544,7 @@ enum scsi_qc_status fnic_queuecommand(st
if ((tport->state != FDLS_TGT_STATE_READY)
&& (tport->state != FDLS_TGT_STATE_ADISC)) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"returning DID_NO_CONNECT for IO as tport state: %d\n",
tport->state);
sc->result = DID_NO_CONNECT << 16;
@@ -564,7 +564,7 @@ enum scsi_qc_status fnic_queuecommand(st
if (unlikely(fnic_chk_state_flags_locked(fnic, FNIC_FLAGS_FWRESET))) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"fnic flags FW reset: 0x%lx. Returning SCSI_MLQUEUE_HOST_BUSY\n",
fnic->state_flags);
return SCSI_MLQUEUE_HOST_BUSY;
@@ -704,7 +704,7 @@ out:
atomic_dec(&tport->in_flight);
if (lun0_delay) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"LUN0 delay\n");
mdelay(LUN0_DELAY_TIME);
}
@@ -744,12 +744,12 @@ static int fnic_fcpio_fw_reset_cmpl_hand
if (fnic->state == FNIC_IN_FC_TRANS_ETH_MODE) {
/* Check status of reset completion */
if (!hdr_status) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"reset cmpl success\n");
/* Ready to send flogi out */
fnic->state = FNIC_IN_ETH_MODE;
} else {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"reset failed with header status: %s\n",
fnic_fcpio_status_to_str(hdr_status));
@@ -758,7 +758,7 @@ static int fnic_fcpio_fw_reset_cmpl_hand
ret = -1;
}
} else {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Unexpected state while processing reset completion: %s\n",
fnic_state_to_str(fnic->state));
atomic64_inc(&reset_stats->fw_reset_failures);
@@ -810,19 +810,18 @@ static int fnic_fcpio_flogi_reg_cmpl_han
/* Check flogi registration completion status */
if (!hdr_status) {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"FLOGI reg succeeded\n");
fnic->state = FNIC_IN_FC_MODE;
} else {
- FNIC_SCSI_DBG(KERN_DEBUG,
- fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fnic flogi reg failed: %s\n",
fnic_fcpio_status_to_str(hdr_status));
fnic->state = FNIC_IN_ETH_MODE;
ret = -1;
}
} else {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Unexpected fnic state %s while"
" processing flogi reg completion\n",
fnic_state_to_str(fnic->state));
@@ -933,19 +932,19 @@ static void fnic_fcpio_icmnd_cmpl_handle
hwq = blk_mq_unique_tag_to_hwq(mqtag);
if (hwq != cq_index) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x cq index: %d ",
hwq, mqtag, tag, cq_index);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hdr status: %s icmnd completion on the wrong queue\n",
fnic_fcpio_status_to_str(hdr_status));
}
if (tag >= fnic->fnic_max_tag_id) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x cq index: %d ",
hwq, mqtag, tag, cq_index);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hdr status: %s Out of range tag\n",
fnic_fcpio_status_to_str(hdr_status));
return;
@@ -957,7 +956,7 @@ static void fnic_fcpio_icmnd_cmpl_handle
if (!sc) {
atomic64_inc(&fnic_stats->io_stats.sc_null);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"icmnd_cmpl sc is null - "
"hdr status = %s tag = 0x%x desc = 0x%p\n",
fnic_fcpio_status_to_str(hdr_status), id, desc);
@@ -985,7 +984,7 @@ static void fnic_fcpio_icmnd_cmpl_handle
atomic64_inc(&fnic_stats->io_stats.ioreq_null);
fnic_priv(sc)->flags |= FNIC_IO_REQ_NULL;
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"icmnd_cmpl io_req is null - "
"hdr status = %s tag = 0x%x sc 0x%p\n",
fnic_fcpio_status_to_str(hdr_status), id, sc);
@@ -1012,7 +1011,7 @@ static void fnic_fcpio_icmnd_cmpl_handle
if(FCPIO_ABORTED == hdr_status)
fnic_priv(sc)->flags |= FNIC_IO_ABORTED;
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"icmnd_cmpl abts pending "
"hdr status = %s tag = 0x%x sc = 0x%p "
"scsi_status = %x residual = %d\n",
@@ -1044,7 +1043,7 @@ static void fnic_fcpio_icmnd_cmpl_handle
if (icmnd_cmpl->scsi_status == SAM_STAT_TASK_SET_FULL)
atomic64_inc(&fnic_stats->misc_stats.queue_fulls);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"xfer_len: %llu", xfer_len);
break;
@@ -1107,7 +1106,7 @@ static void fnic_fcpio_icmnd_cmpl_handle
if (hdr_status != FCPIO_SUCCESS) {
atomic64_inc(&fnic_stats->io_stats.io_failures);
- shost_printk(KERN_ERR, fnic->host, "hdr status = %s\n",
+ fnic_printk(KERN_ERR, fnic, "hdr status = %s\n",
fnic_fcpio_status_to_str(hdr_status));
}
@@ -1200,27 +1199,27 @@ static void fnic_fcpio_itmf_cmpl_handler
hwq = blk_mq_unique_tag_to_hwq(id & FNIC_TAG_MASK);
if (hwq != cq_index) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x cq index: %d ",
hwq, mqtag, tag, cq_index);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hdr status: %s ITMF completion on the wrong queue\n",
fnic_fcpio_status_to_str(hdr_status));
}
if (tag > fnic->fnic_max_tag_id) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x cq index: %d ",
hwq, mqtag, tag, cq_index);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hdr status: %s Tag out of range\n",
fnic_fcpio_status_to_str(hdr_status));
return;
} else if ((tag == fnic->fnic_max_tag_id) && !(id & FNIC_TAG_DEV_RST)) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x cq index: %d ",
hwq, mqtag, tag, cq_index);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hdr status: %s Tag out of range\n",
fnic_fcpio_status_to_str(hdr_status));
return;
@@ -1243,7 +1242,7 @@ static void fnic_fcpio_itmf_cmpl_handler
if (!sc) {
atomic64_inc(&fnic_stats->io_stats.sc_null);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"itmf_cmpl sc is null - hdr status = %s tag = 0x%x\n",
fnic_fcpio_status_to_str(hdr_status), tag);
return;
@@ -1255,7 +1254,7 @@ static void fnic_fcpio_itmf_cmpl_handler
atomic64_inc(&fnic_stats->io_stats.ioreq_null);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
fnic_priv(sc)->flags |= FNIC_IO_ABT_TERM_REQ_NULL;
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"itmf_cmpl io_req is null - "
"hdr status = %s tag = 0x%x sc 0x%p\n",
fnic_fcpio_status_to_str(hdr_status), tag, sc);
@@ -1266,7 +1265,7 @@ static void fnic_fcpio_itmf_cmpl_handler
if ((id & FNIC_TAG_ABORT) && (id & FNIC_TAG_DEV_RST)) {
/* Abort and terminate completion of device reset req */
/* REVISIT : Add asserts about various flags */
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x hst: %s Abt/term completion received\n",
hwq, mqtag, tag,
fnic_fcpio_status_to_str(hdr_status));
@@ -1278,7 +1277,7 @@ static void fnic_fcpio_itmf_cmpl_handler
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
} else if (id & FNIC_TAG_ABORT) {
/* Completion of abort cmd */
- shost_printk(KERN_DEBUG, fnic->host,
+ fnic_printk(KERN_DEBUG, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x Abort header status: %s\n",
hwq, mqtag, tag,
fnic_fcpio_status_to_str(hdr_status));
@@ -1293,7 +1292,7 @@ static void fnic_fcpio_itmf_cmpl_handler
&term_stats->terminate_fw_timeouts);
break;
case FCPIO_ITMF_REJECTED:
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"abort reject recd. id %d\n",
(int)(id & FNIC_TAG_MASK));
break;
@@ -1328,7 +1327,7 @@ static void fnic_fcpio_itmf_cmpl_handler
if (!(fnic_priv(sc)->flags & (FNIC_IO_ABORTED | FNIC_IO_DONE)))
atomic64_inc(&misc_stats->no_icmnd_itmf_cmpls);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"abts cmpl recd. id %d status %s\n",
(int)(id & FNIC_TAG_MASK),
fnic_fcpio_status_to_str(hdr_status));
@@ -1341,11 +1340,11 @@ static void fnic_fcpio_itmf_cmpl_handler
if (io_req->abts_done) {
complete(io_req->abts_done);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- shost_printk(KERN_INFO, fnic->host,
+ fnic_printk(KERN_INFO, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x Waking up abort thread\n",
hwq, mqtag, tag);
} else {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x hst: %s Completing IO\n",
hwq, mqtag,
tag, fnic_fcpio_status_to_str(hdr_status));
@@ -1376,7 +1375,7 @@ static void fnic_fcpio_itmf_cmpl_handler
}
} else if (id & FNIC_TAG_DEV_RST) {
/* Completion of device reset */
- shost_printk(KERN_INFO, fnic->host,
+ fnic_printk(KERN_INFO, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x DR hst: %s\n",
hwq, mqtag,
tag, fnic_fcpio_status_to_str(hdr_status));
@@ -1388,7 +1387,7 @@ static void fnic_fcpio_itmf_cmpl_handler
sc->device->host->host_no, id, sc,
jiffies_to_msecs(jiffies - start_time),
desc, 0, fnic_flags_and_state(sc));
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x hst: %s Terminate pending\n",
hwq, mqtag,
tag, fnic_fcpio_status_to_str(hdr_status));
@@ -1401,7 +1400,7 @@ static void fnic_fcpio_itmf_cmpl_handler
sc->device->host->host_no, id, sc,
jiffies_to_msecs(jiffies - start_time),
desc, 0, fnic_flags_and_state(sc));
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"dev reset cmpl recd after time out. "
"id %d status %s\n",
(int)(id & FNIC_TAG_MASK),
@@ -1410,7 +1409,7 @@ static void fnic_fcpio_itmf_cmpl_handler
}
fnic_priv(sc)->state = FNIC_IOREQ_CMD_COMPLETE;
fnic_priv(sc)->flags |= FNIC_DEV_RST_DONE;
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x hst: %s DR completion received\n",
hwq, mqtag,
tag, fnic_fcpio_status_to_str(hdr_status));
@@ -1419,7 +1418,7 @@ static void fnic_fcpio_itmf_cmpl_handler
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
} else {
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"%s: Unexpected itmf io state: hwq: %d tag 0x%x %s\n",
__func__, hwq, id, fnic_ioreq_state_to_str(fnic_priv(sc)->state));
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
@@ -1474,7 +1473,7 @@ static int fnic_fcpio_cmpl_handler(struc
break;
default:
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"firmware completion type %d\n",
desc->hdr.type);
break;
@@ -1535,7 +1534,7 @@ static bool fnic_cleanup_io_iter(struct
io_req = fnic_priv(sc)->io_req;
if (!io_req) {
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x flags: 0x%x No ioreq. Returning\n",
hwq, mqtag, tag, fnic_priv(sc)->flags);
return true;
@@ -1573,7 +1572,7 @@ static bool fnic_cleanup_io_iter(struct
mempool_free(io_req, fnic->io_req_pool);
sc->result = DID_TRANSPORT_DISRUPTED << 16;
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"mqtag: 0x%x tag: 0x%x sc: 0x%p duration = %lu DID_TRANSPORT_DISRUPTED\n",
mqtag, tag, sc, (jiffies - start_time));
@@ -1605,7 +1604,7 @@ static void fnic_cleanup_io(struct fnic
struct scsi_cmnd *sc = NULL;
io_count = fnic_count_all_ioreqs(fnic);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Outstanding ioreq count: %d active io count: %lld Waiting\n",
io_count,
atomic64_read(&fnic->fnic_stats.io_stats.active_ios));
@@ -1630,7 +1629,7 @@ static void fnic_cleanup_io(struct fnic
spin_unlock_irqrestore(&fnic->wq_copy_lock[0], flags);
while ((io_count = fnic_count_all_ioreqs(fnic))) {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Outstanding ioreq count: %d active io count: %lld Waiting\n",
io_count,
atomic64_read(&fnic->fnic_stats.io_stats.active_ios));
@@ -1686,7 +1685,7 @@ void fnic_wq_copy_cleanup_handler(struct
wq_copy_cleanup_scsi_cmd:
sc->result = DID_NO_CONNECT << 16;
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num, "wq_copy_cleanup_handler:"
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic, "wq_copy_cleanup_handler:"
" DID_NO_CONNECT\n");
FNIC_TRACE(fnic_wq_copy_cleanup_handler,
@@ -1730,7 +1729,7 @@ static inline int fnic_queue_abort_io_re
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
atomic_dec(&fnic->in_flight);
atomic_dec(&tport->in_flight);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fnic_queue_abort_io_req: failure: no descriptors\n");
atomic64_inc(&misc_stats->abts_cpwq_alloc_failures);
return 1;
@@ -1775,7 +1774,7 @@ static bool fnic_rport_abort_io_iter(str
hwq = blk_mq_unique_tag_to_hwq(abt_tag);
if (!sc) {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"sc is NULL abt_tag: 0x%x hwq: %d\n", abt_tag, hwq);
return true;
}
@@ -1789,7 +1788,7 @@ static bool fnic_rport_abort_io_iter(str
if ((fnic_priv(sc)->flags & FNIC_DEVICE_RESET) &&
!(fnic_priv(sc)->flags & FNIC_DEV_RST_ISSUED)) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d abt_tag: 0x%x flags: 0x%x Device reset is not pending\n",
hwq, abt_tag, fnic_priv(sc)->flags);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
@@ -1806,16 +1805,16 @@ static bool fnic_rport_abort_io_iter(str
}
if (io_req->abts_done) {
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"fnic_rport_exch_reset: io_req->abts_done is set state is %s\n",
fnic_ioreq_state_to_str(fnic_priv(sc)->state));
}
if (!(fnic_priv(sc)->flags & FNIC_IO_ISSUED)) {
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"rport_exch_reset IO not yet issued %p abt_tag 0x%x",
sc, abt_tag);
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"flags %x state %d\n", fnic_priv(sc)->flags,
fnic_priv(sc)->state);
}
@@ -1826,13 +1825,13 @@ static bool fnic_rport_abort_io_iter(str
if (fnic_priv(sc)->flags & FNIC_DEVICE_RESET) {
atomic64_inc(&reset_stats->device_reset_terminates);
abt_tag |= FNIC_TAG_DEV_RST;
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"dev reset sc 0x%p\n", sc);
}
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fnic_rport_exch_reset: dev rst sc 0x%p\n", sc);
WARN_ON_ONCE(io_req->abts_done);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fnic_rport_reset_exch: Issuing abts\n");
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
@@ -1850,7 +1849,7 @@ static bool fnic_rport_abort_io_iter(str
* lun reset
*/
spin_lock_irqsave(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d abt_tag: 0x%x flags: 0x%x Queuing abort failed\n",
hwq, abt_tag, fnic_priv(sc)->flags);
if (fnic_priv(sc)->state == FNIC_IOREQ_ABTS_PENDING)
@@ -1881,7 +1880,7 @@ void fnic_rport_exch_reset(struct fnic *
.term_cnt = 0,
};
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fnic rport exchange reset for tport: 0x%06x\n",
port_id);
@@ -1889,7 +1888,7 @@ void fnic_rport_exch_reset(struct fnic *
return;
io_count = fnic_count_ioreqs(fnic, port_id);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Starting terminates: rport:0x%x portid-io-count: %d active-io-count: %lld\n",
port_id, io_count,
atomic64_read(&fnic->fnic_stats.io_stats.active_ios));
@@ -1915,7 +1914,7 @@ void fnic_rport_exch_reset(struct fnic *
while ((io_count = fnic_count_ioreqs(fnic, port_id)))
schedule_timeout(msecs_to_jiffies(1000));
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"rport: 0x%x remaining portid-io-count: %d ",
port_id, io_count);
}
@@ -2040,10 +2039,10 @@ int fnic_abort_cmd(struct scsi_cmnd *sc)
tport = rdd_data->tport;
if (!tport) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Abort cmd called after tport delete! rport fcid: 0x%x",
rport->port_id);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"lun: %llu hwq: 0x%x mqtag: 0x%x Op: 0x%x flags: 0x%x\n",
sc->device->lun, hwq, mqtag,
sc->cmnd[0], fnic_priv(sc)->flags);
@@ -2052,18 +2051,18 @@ int fnic_abort_cmd(struct scsi_cmnd *sc)
goto fnic_abort_cmd_end;
}
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"Abort cmd called rport fcid: 0x%x lun: %llu hwq: 0x%x mqtag: 0x%x",
rport->port_id, sc->device->lun, hwq, mqtag);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"Op: 0x%x flags: 0x%x\n",
sc->cmnd[0],
fnic_priv(sc)->flags);
if (iport->state != FNIC_IPORT_STATE_READY) {
atomic64_inc(&fnic_stats->misc_stats.iport_not_ready);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"iport NOT in READY state");
ret = FAILED;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
@@ -2072,7 +2071,7 @@ int fnic_abort_cmd(struct scsi_cmnd *sc)
if ((tport->state != FDLS_TGT_STATE_READY) &&
(tport->state != FDLS_TGT_STATE_ADISC)) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"tport state: %d\n", tport->state);
ret = FAILED;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
@@ -2123,7 +2122,7 @@ int fnic_abort_cmd(struct scsi_cmnd *sc)
else
atomic64_inc(&abts_stats->abort_issued_greater_than_60_sec);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"CDB Opcode: 0x%02x Abort issued time: %lu msec\n",
sc->cmnd[0], abt_issued_time);
/*
@@ -2214,7 +2213,7 @@ int fnic_abort_cmd(struct scsi_cmnd *sc)
if (!(fnic_priv(sc)->flags & (FNIC_IO_ABORTED | FNIC_IO_DONE))) {
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Issuing host reset due to out of order IO\n");
ret = FAILED;
@@ -2262,7 +2261,7 @@ fnic_abort_cmd_end:
(u64)sc->cmnd[4] << 8 | sc->cmnd[5]),
fnic_flags_and_state(sc));
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Returning from abort cmd type %x %s\n", task_req,
(ret == SUCCESS) ?
"SUCCESS" : "FAILED");
@@ -2303,7 +2302,7 @@ static inline int fnic_queue_dr_io_req(s
free_wq_copy_descs(fnic, wq, hwq);
if (!vnic_wq_copy_desc_avail(wq)) {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"queue_dr_io_req failure - no descriptors\n");
atomic64_inc(&misc_stats->devrst_cpwq_alloc_failures);
ret = -EAGAIN;
@@ -2371,7 +2370,7 @@ static bool fnic_pending_aborts_iter(str
* Found IO that is still pending with firmware and
* belongs to the LUN that we are resetting
*/
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Found IO in %s on lun\n",
fnic_ioreq_state_to_str(fnic_priv(sc)->state));
@@ -2381,14 +2380,14 @@ static bool fnic_pending_aborts_iter(str
}
if ((fnic_priv(sc)->flags & FNIC_DEVICE_RESET) &&
(!(fnic_priv(sc)->flags & FNIC_DEV_RST_ISSUED))) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"dev rst not pending sc 0x%p\n", sc);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
return true;
}
if (io_req->abts_done)
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"%s: io_req->abts_done is set state is %s\n",
__func__, fnic_ioreq_state_to_str(fnic_priv(sc)->state));
old_ioreq_state = fnic_priv(sc)->state;
@@ -2404,7 +2403,7 @@ static bool fnic_pending_aborts_iter(str
BUG_ON(io_req->abts_done);
if (fnic_priv(sc)->flags & FNIC_DEVICE_RESET) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"dev rst sc 0x%p\n", sc);
}
@@ -2426,7 +2425,7 @@ static bool fnic_pending_aborts_iter(str
fnic_priv(sc)->state = old_ioreq_state;
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
iter_data->ret = FAILED;
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d abt_tag: 0x%lx Abort could not be queued\n",
hwq, abt_tag);
return false;
@@ -2518,7 +2517,7 @@ static int fnic_clean_pending_aborts(str
ret = 1;
clean_pending_aborts_end:
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"exit status: %d\n", ret);
return ret;
}
@@ -2568,7 +2567,7 @@ int fnic_device_reset(struct scsi_cmnd *
rport = starget_to_rport(scsi_target(sc->device));
spin_lock_irqsave(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fcid: 0x%x lun: %llu hwq: %d mqtag: 0x%x flags: 0x%x Device reset\n",
rport->port_id, sc->device->lun, hwq, mqtag,
fnic_priv(sc)->flags);
@@ -2576,7 +2575,7 @@ int fnic_device_reset(struct scsi_cmnd *
rdd_data = rport->dd_data;
tport = rdd_data->tport;
if (!tport) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Dev rst called after tport delete! rport fcid: 0x%x lun: %llu\n",
rport->port_id, sc->device->lun);
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
@@ -2585,7 +2584,7 @@ int fnic_device_reset(struct scsi_cmnd *
if (iport->state != FNIC_IPORT_STATE_READY) {
atomic64_inc(&fnic_stats->misc_stats.iport_not_ready);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"iport NOT in READY state");
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
goto fnic_device_reset_end;
@@ -2593,7 +2592,7 @@ int fnic_device_reset(struct scsi_cmnd *
if ((tport->state != FDLS_TGT_STATE_READY) &&
(tport->state != FDLS_TGT_STATE_ADISC)) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"tport state: %d\n", tport->state);
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
goto fnic_device_reset_end;
@@ -2656,7 +2655,7 @@ int fnic_device_reset(struct scsi_cmnd *
fnic_priv(sc)->lr_status = FCPIO_INVALID_CODE;
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num, "TAG %x\n", mqtag);
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic, "TAG %x\n", mqtag);
/*
* issue the device reset, if enqueue failed, clean up the ioreq
@@ -2707,13 +2706,13 @@ int fnic_device_reset(struct scsi_cmnd *
io_req = fnic_priv(sc)->io_req;
if (!io_req) {
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"io_req is null mqtag 0x%x sc 0x%p\n", mqtag, sc);
goto fnic_device_reset_end;
}
if (exit_dr) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Host reset called for fnic. Exit device reset\n");
io_req->dr_done = NULL;
goto fnic_device_reset_clean;
@@ -2728,7 +2727,7 @@ int fnic_device_reset(struct scsi_cmnd *
*/
if (status == FCPIO_INVALID_CODE) {
atomic64_inc(&reset_stats->device_reset_timeouts);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Device reset timed out\n");
fnic_priv(sc)->flags |= FNIC_DEV_RST_TIMED_OUT;
int_to_scsilun(sc->device->lun, &fc_lun);
@@ -2740,8 +2739,7 @@ int fnic_device_reset(struct scsi_cmnd *
/* Completed, but not successful, clean up the io_req, return fail */
if (status != FCPIO_SUCCESS) {
spin_lock_irqsave(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_DEBUG,
- fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Device reset completed - failed\n");
io_req = fnic_priv(sc)->io_req;
goto fnic_device_reset_clean;
@@ -2757,7 +2755,7 @@ int fnic_device_reset(struct scsi_cmnd *
if (fnic_clean_pending_aborts(fnic, sc, new_sc)) {
spin_lock_irqsave(&fnic->wq_copy_lock[hwq], flags);
io_req = fnic_priv(sc)->io_req;
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Device reset failed: Cannot abort all IOs\n");
goto fnic_device_reset_clean;
}
@@ -2811,13 +2809,13 @@ fnic_device_reset_end:
ret = FAILED;
break;
}
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Cannot clean up all IOs for the LUN\n");
schedule_timeout(msecs_to_jiffies(1000));
count++;
}
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Returning from device reset %s\n",
(ret == SUCCESS) ?
"SUCCESS" : "FAILED");
@@ -2852,13 +2850,13 @@ void fnic_reset(struct Scsi_Host *shost)
fnic = *((struct fnic **) shost_priv(shost));
reset_stats = &fnic->fnic_stats.reset_stats;
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"Issuing fnic reset\n");
atomic64_inc(&reset_stats->fnic_resets);
fnic_post_flogo_linkflap(fnic);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"Returning from fnic reset");
atomic64_inc(&reset_stats->fnic_reset_completions);
@@ -2869,7 +2867,7 @@ int fnic_issue_fc_host_lip(struct Scsi_H
int ret = 0;
struct fnic *fnic = *((struct fnic **) shost_priv(shost));
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"FC host lip issued");
ret = fnic_host_reset(shost);
@@ -2895,7 +2893,7 @@ int fnic_host_reset(struct Scsi_Host *sh
spin_lock_irqsave(&fnic->fnic_lock, flags);
if (fnic->reset_in_progress == IN_PROGRESS) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_WARNING, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_WARNING, fnic,
"Firmware reset in progress. Skipping another host reset\n");
return SUCCESS;
}
@@ -2933,7 +2931,7 @@ int fnic_host_reset(struct Scsi_Host *sh
}
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"host reset return status: %d\n", ret);
return ret;
}
@@ -2973,7 +2971,7 @@ static bool fnic_abts_pending_iter(struc
* Found IO that is still pending with firmware and
* belongs to the LUN that we are resetting
*/
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"hwq: %d tag: 0x%x Found IO in state: %s on lun\n",
hwq, tag,
fnic_ioreq_state_to_str(fnic_priv(sc)->state));
@@ -3027,7 +3025,7 @@ int fnic_eh_host_reset_handler(struct sc
struct Scsi_Host *shost = sc->device->host;
struct fnic *fnic = *((struct fnic **) shost_priv(shost));
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"SCSI error handling: fnic host reset");
ret = fnic_host_reset(shost);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 377/398] scsi: fnic: Make debug logging protocol independent
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (373 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 376/398] scsi: fnic: Bump up version number Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 378/398] scsi: fnic: Bump up version number again Greg Kroah-Hartman
` (27 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sesidhar Baddela,
Arulprabhu Ponnusamy, Gian Carlo Boffa, Arun Easi,
Hannes Reinecke, Lee Duncan, Karan Tilak Kumar,
Martin K. Petersen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karan Tilak Kumar <kartilak@cisco.com>
[ Upstream commit b93c38a9f2ce5441c90de55776f8df97679cf8a2 ]
Make the fnic debug macros take struct fnic instead of struct Scsi_Host so
FCP and NVMe initiator roles can share the same logging interface.
Add fnic_printk() to route FCP initiator messages through shost_printk()
and non-SCSI role messages through printk(). Add role and non-SCSI role
messages through printk(). Add role predicates and separate FDLS, FIP, and
NVMe logging masks.
Convert FCS, FIP, SCSI, ISR, and main debug call sites to pass the fnic
instance directly, and keep FIP VLAN MAC descriptors skipped while
reporting unexpected descriptor types.
Reviewed-by: Sesidhar Baddela <sebaddel@cisco.com>
Reviewed-by: Arulprabhu Ponnusamy <arulponn@cisco.com>
Reviewed-by: Gian Carlo Boffa <gcboffa@cisco.com>
Reviewed-by: Arun Easi <aeasi@cisco.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Reviewed-by: Lee Duncan <lduncan@suse.com>
Signed-off-by: Karan Tilak Kumar <kartilak@cisco.com>
Co-developed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260724174811.5118-2-kartilak@cisco.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: 0cb1fd924126 ("scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/fnic/fdls_disc.c | 726 +++++++++++++++++++++---------------------
drivers/scsi/fnic/fip.c | 117 +++---
drivers/scsi/fnic/fip.h | 2
drivers/scsi/fnic/fnic.h | 74 ++--
drivers/scsi/fnic/fnic_fcs.c | 126 +++----
drivers/scsi/fnic/fnic_isr.c | 28 -
drivers/scsi/fnic/fnic_main.c | 56 +--
drivers/scsi/fnic/fnic_scsi.c | 210 ++++++------
8 files changed, 675 insertions(+), 664 deletions(-)
--- a/drivers/scsi/fnic/fdls_disc.c
+++ b/drivers/scsi/fnic/fdls_disc.c
@@ -104,7 +104,7 @@ uint8_t *fdls_alloc_frame(struct fnic_ip
frame = mempool_alloc(fnic->frame_pool, GFP_ATOMIC);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame");
return NULL;
}
@@ -136,7 +136,7 @@ uint16_t fdls_alloc_oxid(struct fnic_ipo
*/
idx = find_next_zero_bit(oxid_pool->bitmap, FNIC_OXID_POOL_SZ, oxid_pool->next_idx);
if (idx == FNIC_OXID_POOL_SZ) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Alloc oxid: all oxid slots are busy iport state:%d\n",
iport->state);
return FNIC_UNASSIGNED_OXID;
@@ -148,7 +148,7 @@ uint16_t fdls_alloc_oxid(struct fnic_ipo
oxid = FNIC_OXID_ENCODE(idx, oxid_frame_type);
*active_oxid = oxid;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"alloc oxid: 0x%x, iport state: %d\n",
oxid, iport->state);
return oxid;
@@ -169,7 +169,7 @@ static void fdls_free_oxid_idx(struct fn
lockdep_assert_held(&fnic->fnic_lock);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"free oxid idx: 0x%x\n", oxid_idx);
WARN_ON(!test_and_clear_bit(oxid_idx, oxid_pool->bitmap));
@@ -194,7 +194,7 @@ void fdls_reclaim_oxid_handler(struct wo
struct reclaim_entry_s *reclaim_entry, *next;
unsigned long delay_j, cur_jiffies;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Reclaim oxid callback\n");
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
@@ -223,7 +223,7 @@ void fdls_reclaim_oxid_handler(struct wo
delay_j = reclaim_entry->expires - cur_jiffies;
schedule_delayed_work(&oxid_pool->oxid_reclaim_work, delay_j);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Scheduling next callback at:%ld jiffies\n", delay_j);
}
@@ -266,7 +266,7 @@ void fdls_schedule_oxid_free(struct fnic
lockdep_assert_held(&fnic->fnic_lock);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Schedule oxid free. oxid: 0x%x\n", *active_oxid);
*active_oxid = FNIC_UNASSIGNED_OXID;
@@ -275,7 +275,7 @@ void fdls_schedule_oxid_free(struct fnic
kzalloc(sizeof(struct reclaim_entry_s), GFP_ATOMIC);
if (!reclaim_entry) {
- FNIC_FCS_DBG(KERN_WARNING, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_WARNING, fnic,
"Failed to allocate memory for reclaim struct for oxid idx: %d\n",
oxid_idx);
@@ -313,7 +313,7 @@ void fdls_schedule_oxid_free_retry_work(
for_each_set_bit(idx, oxid_pool->pending_schedule_free, FNIC_OXID_POOL_SZ) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Schedule oxid free. oxid idx: %d\n", idx);
reclaim_entry = kzalloc(sizeof(*reclaim_entry), GFP_KERNEL);
@@ -416,7 +416,7 @@ fdls_start_fabric_timer(struct fnic_ipor
struct fnic *fnic = iport->fnic;
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x: Canceling fabric disc timer\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -429,7 +429,7 @@ fdls_start_fabric_timer(struct fnic_ipor
fabric_tov = jiffies + msecs_to_jiffies(timeout);
mod_timer(&iport->fabric.retry_timer, round_jiffies(fabric_tov));
iport->fabric.timer_pending = 1;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fabric timer is %d ", timeout);
}
@@ -441,7 +441,7 @@ fdls_start_tport_timer(struct fnic_iport
struct fnic *fnic = iport->fnic;
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid 0x%x: Canceling disc timer\n",
tport->fcid);
fnic_del_tport_timer_sync(fnic, tport);
@@ -575,7 +575,7 @@ fdls_send_rscn_resp(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send RSCN response");
return;
}
@@ -588,7 +588,7 @@ fdls_send_rscn_resp(struct fnic_iport_s
oxid = FNIC_STD_GET_OX_ID(rscn_fchdr);
FNIC_STD_SET_OX_ID(pels_acc->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send RSCN response with oxid: 0x%x",
iport->fcid, oxid);
@@ -608,7 +608,7 @@ fdls_send_logo_resp(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send LOGO response");
return;
}
@@ -621,7 +621,7 @@ fdls_send_logo_resp(struct fnic_iport_s
oxid = FNIC_STD_GET_OX_ID(req_fchdr);
FNIC_STD_SET_OX_ID(plogo_resp->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send LOGO response with oxid: 0x%x",
iport->fcid, oxid);
@@ -642,7 +642,7 @@ fdls_send_tport_abts(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send tport ABTS");
return;
}
@@ -665,7 +665,7 @@ fdls_send_tport_abts(struct fnic_iport_s
FNIC_STD_SET_OX_ID(*ptport_abts, tport->active_oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send tport abts: tport->state: %d ",
iport->fcid, tport->state);
@@ -687,7 +687,7 @@ static void fdls_send_fabric_abts(struct
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send fabric ABTS");
return;
}
@@ -750,7 +750,7 @@ static void fdls_send_fabric_abts(struct
oxid = iport->active_oxid_fabric_req;
FNIC_STD_SET_OX_ID(*pfabric_abts, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send fabric abts. iport->fabric.state: %d oxid: 0x%x",
iport->fcid, iport->fabric.state, oxid);
@@ -773,7 +773,7 @@ static uint8_t *fdls_alloc_init_fdmi_abt
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send FDMI ABTS");
return NULL;
}
@@ -802,7 +802,7 @@ static void fdls_send_fdmi_abts(struct f
if (frame == NULL)
return;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI PLOGI abts. iport->fabric.state: %d oxid: 0x%x",
iport->fcid, iport->fabric.state, iport->active_oxid_fdmi_plogi);
fnic_send_fcoe_frame(iport, frame, frame_size);
@@ -813,7 +813,7 @@ static void fdls_send_fdmi_abts(struct f
if (frame == NULL)
return;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI RHBA abts. iport->fabric.state: %d oxid: 0x%x",
iport->fcid, iport->fabric.state, iport->active_oxid_fdmi_rhba);
fnic_send_fcoe_frame(iport, frame, frame_size);
@@ -828,7 +828,7 @@ static void fdls_send_fdmi_abts(struct f
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI RPA abts. iport->fabric.state: %d oxid: 0x%x",
iport->fcid, iport->fabric.state, iport->active_oxid_fdmi_rpa);
fnic_send_fcoe_frame(iport, frame, frame_size);
@@ -840,7 +840,7 @@ arm_timer:
mod_timer(&iport->fabric.fdmi_timer, round_jiffies(fdmi_tov));
iport->fabric.fdmi_pending |= FDLS_FDMI_ABORT_PENDING;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
}
@@ -856,7 +856,7 @@ static void fdls_send_fabric_flogi(struc
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send FLOGI");
iport->fabric.flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -885,7 +885,7 @@ static void fdls_send_fabric_flogi(struc
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send FLOGI",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -894,7 +894,7 @@ static void fdls_send_fabric_flogi(struc
}
FNIC_STD_SET_OX_ID(pflogi->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send fabric FLOGI with oxid: 0x%x", iport->fcid,
oxid);
@@ -916,7 +916,7 @@ static void fdls_send_fabric_plogi(struc
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send PLOGI");
iport->fabric.flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -928,7 +928,7 @@ static void fdls_send_fabric_plogi(struc
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_FABRIC_PLOGI,
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send fabric PLOGI",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -937,7 +937,7 @@ static void fdls_send_fabric_plogi(struc
}
FNIC_STD_SET_OX_ID(pplogi->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send fabric PLOGI with oxid: 0x%x", iport->fcid,
oxid);
@@ -962,7 +962,7 @@ static void fdls_send_fdmi_plogi(struct
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send FDMI PLOGI");
goto err_out;
}
@@ -974,7 +974,7 @@ static void fdls_send_fdmi_plogi(struct
&iport->active_oxid_fdmi_plogi);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send FDMI PLOGI",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -985,7 +985,7 @@ static void fdls_send_fdmi_plogi(struct
hton24(d_id, FC_FID_MGMT_SERV);
FNIC_STD_SET_D_ID(pplogi->fchdr, d_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI PLOGI with oxid: 0x%x",
iport->fcid, oxid);
@@ -1009,7 +1009,7 @@ static void fdls_send_rpn_id(struct fnic
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send RPN_ID");
iport->fabric.flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1036,7 +1036,7 @@ static void fdls_send_rpn_id(struct fnic
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send RPN_ID",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1045,7 +1045,7 @@ static void fdls_send_rpn_id(struct fnic
}
FNIC_STD_SET_OX_ID(prpn_id->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send RPN ID with oxid: 0x%x", iport->fcid,
oxid);
@@ -1068,7 +1068,7 @@ static void fdls_send_scr(struct fnic_ip
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send SCR");
iport->fabric.flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1090,7 +1090,7 @@ static void fdls_send_scr(struct fnic_ip
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_FABRIC_SCR,
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send SCR",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1099,7 +1099,7 @@ static void fdls_send_scr(struct fnic_ip
}
FNIC_STD_SET_OX_ID(pscr->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send SCR with oxid: 0x%x", iport->fcid,
oxid);
@@ -1123,7 +1123,7 @@ static void fdls_send_gpn_ft(struct fnic
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send GPN FT");
iport->fabric.flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1148,7 +1148,7 @@ static void fdls_send_gpn_ft(struct fnic
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send GPN FT",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1157,7 +1157,7 @@ static void fdls_send_gpn_ft(struct fnic
}
FNIC_STD_SET_OX_ID(pgpn_ft->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send GPN FT with oxid: 0x%x", iport->fcid,
oxid);
@@ -1183,7 +1183,7 @@ fdls_send_tgt_adisc(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send TGT ADISC");
tport->flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1203,7 +1203,7 @@ fdls_send_tgt_adisc(struct fnic_iport_s
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_TGT_ADISC, &tport->active_oxid);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send TGT ADISC",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1222,7 +1222,7 @@ fdls_send_tgt_adisc(struct fnic_iport_s
padisc->els.adisc_cmd = ELS_ADISC;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send ADISC to tgt fcid: 0x%x",
iport->fcid, tport->fcid);
@@ -1242,7 +1242,7 @@ bool fdls_delete_tport(struct fnic_iport
if ((tport->state == FDLS_TGT_STATE_OFFLINING)
|| (tport->state == FDLS_TGT_STATE_OFFLINE)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid 0x%x: tport state is offlining/offline\n",
tport->fcid);
return false;
@@ -1257,7 +1257,7 @@ bool fdls_delete_tport(struct fnic_iport
tport->flags |= FNIC_FDLS_TPORT_TERMINATING;
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid 0x%x: Canceling disc timer\n",
tport->fcid);
fnic_del_tport_timer_sync(fnic, tport);
@@ -1272,9 +1272,9 @@ bool fdls_delete_tport(struct fnic_iport
tport_del_evt =
kzalloc(sizeof(struct fnic_tport_event_s), GFP_ATOMIC);
if (!tport_del_evt) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "Failed to allocate memory for tport fcid: 0x%0x\n",
- tport->fcid);
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "iport: 0x%x tport 0x%x: Failed to allocate memory\n",
+ iport->fcid, tport->fcid);
return false;
}
tport_del_evt->event = TGT_EV_RPORT_DEL;
@@ -1282,9 +1282,9 @@ bool fdls_delete_tport(struct fnic_iport
list_add_tail(&tport_del_evt->links, &fnic->tport_event_list);
queue_work(fnic_event_queue, &fnic->tport_work);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "tport 0x%x not reg with scsi_transport. Freeing locally",
- tport->fcid);
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "tport 0x%x not registered, freeing locally\n",
+ tport->fcid);
list_del(&tport->links);
kfree(tport);
}
@@ -1305,7 +1305,7 @@ fdls_send_tgt_plogi(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send TGT PLOGI");
tport->flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1316,7 +1316,7 @@ fdls_send_tgt_plogi(struct fnic_iport_s
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_TGT_PLOGI, &tport->active_oxid);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate oxid to send PLOGI to fcid: 0x%x",
iport->fcid, tport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1330,7 +1330,7 @@ fdls_send_tgt_plogi(struct fnic_iport_s
hton24(d_id, tport->fcid);
FNIC_STD_SET_D_ID(pplogi->fchdr, d_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send tgt PLOGI to tgt: 0x%x with oxid: 0x%x",
iport->fcid, tport->fcid, oxid);
@@ -1353,7 +1353,7 @@ fnic_fc_plogi_rsp_rdf(struct fnic_iport_
be16_to_cpu(plogi_rsp->els.fl_cssp[2].cp_rdfs) & FNIC_FC_C3_RDF;
struct fnic *fnic = iport->fnic;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MFS: b2b_rdf_size: 0x%x spc3_rdf_size: 0x%x",
b2b_rdf_size, spc3_rdf_size);
@@ -1372,7 +1372,7 @@ static void fdls_send_register_fc4_types
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send RFT");
return;
}
@@ -1396,7 +1396,7 @@ static void fdls_send_register_fc4_types
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send RFT",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1404,15 +1404,18 @@ static void fdls_send_register_fc4_types
}
FNIC_STD_SET_OX_ID(prft_id->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "0x%x: FDLS send RFT with oxid: 0x%x", iport->fcid,
- oxid);
prft_id->rft_id.fr_fts.ff_type_map[0] =
cpu_to_be32(1 << FC_TYPE_FCP);
prft_id->rft_id.fr_fts.ff_type_map[1] =
cpu_to_be32(1 << (FC_TYPE_CT % FC_NS_BPW));
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "0x%x: FDLS send RFT 0x%08x 0x%08x 0x%08x with oxid: 0x%x",
+ iport->fcid, prft_id->rft_id.fr_fts.ff_type_map[0],
+ prft_id->rft_id.fr_fts.ff_type_map[1],
+ prft_id->rft_id.fr_fts.ff_type_map[2],
+ oxid);
fnic_send_fcoe_frame(iport, frame, frame_size);
@@ -1432,7 +1435,7 @@ static void fdls_send_register_fc4_featu
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send RFF");
return;
}
@@ -1458,7 +1461,7 @@ static void fdls_send_register_fc4_featu
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send RFF",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1466,12 +1469,13 @@ static void fdls_send_register_fc4_featu
}
FNIC_STD_SET_OX_ID(prff_id->fchdr, oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "0x%x: FDLS send RFF with oxid: 0x%x", iport->fcid,
- oxid);
-
prff_id->rff_id.fr_type = FC_TYPE_FCP;
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "0x%x: FDLS send RFF with oxid: 0x%x type 0%x feat 0%x",
+ iport->fcid, oxid, prff_id->rff_id.fr_type,
+ prff_id->rff_id.fr_feat);
+
fnic_send_fcoe_frame(iport, frame, frame_size);
/* Even if fnic_send_fcoe_frame() fails we want to retry after timeout */
@@ -1493,7 +1497,7 @@ fdls_send_tgt_prli(struct fnic_iport_s *
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send TGT PRLI");
tport->flags |= FNIC_FDLS_RETRY_FRAME;
goto err_out;
@@ -1513,7 +1517,7 @@ fdls_send_tgt_prli(struct fnic_iport_s *
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_TGT_PRLI, &tport->active_oxid);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"0x%x: Failed to allocate OXID to send TGT PRLI to 0x%x",
iport->fcid, tport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1530,7 +1534,7 @@ fdls_send_tgt_prli(struct fnic_iport_s *
FNIC_STD_SET_S_ID(pprli->fchdr, s_id);
FNIC_STD_SET_D_ID(pprli->fchdr, d_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send PRLI to tgt: 0x%x with oxid: 0x%x",
iport->fcid, tport->fcid, oxid);
@@ -1564,7 +1568,7 @@ void fdls_send_fabric_logo(struct fnic_i
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send fabric LOGO");
return;
}
@@ -1576,7 +1580,7 @@ void fdls_send_fabric_logo(struct fnic_i
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send fabric LOGO",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1589,7 +1593,7 @@ void fdls_send_fabric_logo(struct fnic_i
iport->fabric.flags &= ~FNIC_FDLS_FABRIC_ABORT_ISSUED;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send fabric LOGO with oxid: 0x%x",
iport->fcid, oxid);
@@ -1621,7 +1625,7 @@ void fdls_tgt_logout(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send fabric LOGO");
return;
}
@@ -1631,7 +1635,7 @@ void fdls_tgt_logout(struct fnic_iport_s
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_TGT_LOGO, &tport->active_oxid);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send tgt LOGO",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1642,7 +1646,7 @@ void fdls_tgt_logout(struct fnic_iport_s
hton24(d_id, tport->fcid);
FNIC_STD_SET_D_ID(plogo->fchdr, d_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send tgt LOGO with oxid: 0x%x",
iport->fcid, oxid);
@@ -1657,7 +1661,7 @@ static void fdls_tgt_discovery_start(str
u32 old_link_down_cnt = iport->fnic->link_down_cnt;
struct fnic *fnic = iport->fnic;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Starting FDLS target discovery", iport->fcid);
list_for_each_entry_safe(tport, next, &iport->tport_list, links) {
@@ -1711,7 +1715,7 @@ static void fdls_target_restart_nexus(st
struct fnic *fnic = iport->fnic;
bool retval = true;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid: 0x%x state: %d restart_count: %d",
tport->fcid, tport->state, tport->nexus_restart_count);
@@ -1721,13 +1725,13 @@ static void fdls_target_restart_nexus(st
retval = fdls_delete_tport(iport, tport);
if (retval != true) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Error deleting tport: 0x%x", fcid);
return;
}
if (nexus_restart_count >= FNIC_TPORT_MAX_NEXUS_RESTART) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Exceeded nexus restart retries tport: 0x%x",
fcid);
return;
@@ -1744,7 +1748,7 @@ static void fdls_target_restart_nexus(st
*/
new_tport = fdls_create_tport(iport, fcid, wwpn);
if (!new_tport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Error creating new tport: 0x%x", fcid);
return;
}
@@ -1773,12 +1777,12 @@ static struct fnic_tport_s *fdls_create_
struct fnic_tport_s *tport;
struct fnic *fnic = iport->fnic;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS create tport: fcid: 0x%x wwpn: 0x%llx", fcid, wwpn);
tport = kzalloc(sizeof(struct fnic_tport_s), GFP_ATOMIC);
if (!tport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Memory allocation failure while creating tport: 0x%x\n",
fcid);
return NULL;
@@ -1791,12 +1795,12 @@ static struct fnic_tport_s *fdls_create_
tport->wwpn = wwpn;
tport->iport = iport;
- FNIC_FCS_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_DEBUG, fnic,
"Need to setup tport timer callback");
timer_setup(&tport->retry_timer, fdls_tport_timer_callback, 0);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Added tport 0x%x", tport->fcid);
fdls_set_tport_state(tport, FDLS_TGT_STATE_INIT);
list_add_tail(&tport->links, &iport->tport_list);
@@ -1847,7 +1851,7 @@ static void fdls_fdmi_register_hba(struc
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send FDMI RHBA");
return;
}
@@ -1875,7 +1879,7 @@ static void fdls_fdmi_register_hba(struc
&iport->active_oxid_fdmi_rhba);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send FDMI RHBA",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -1896,14 +1900,14 @@ static void fdls_fdmi_register_hba(struc
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_NODE_NAME,
FNIC_FDMI_NN_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"NN set, off=%d", attr_off_bytes);
strscpy_pad(data, FNIC_FDMI_MANUFACTURER, FNIC_FDMI_MANU_LEN);
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_MANUFACTURER,
FNIC_FDMI_MANU_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MFG set <%s>, off=%d", data, attr_off_bytes);
err = vnic_dev_fw_info(fnic->vdev, &fw_info);
@@ -1912,7 +1916,7 @@ static void fdls_fdmi_register_hba(struc
FNIC_FDMI_SERIAL_LEN);
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_SERIAL_NUMBER,
FNIC_FDMI_SERIAL_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"SERIAL set <%s>, off=%d", data, attr_off_bytes);
}
@@ -1923,21 +1927,21 @@ static void fdls_fdmi_register_hba(struc
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_MODEL, FNIC_FDMI_MODEL_LEN,
data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MODEL set <%s>, off=%d", data, attr_off_bytes);
strscpy_pad(data, FNIC_FDMI_MODEL_DESCRIPTION, FNIC_FDMI_MODEL_DES_LEN);
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_MODEL_DES,
FNIC_FDMI_MODEL_DES_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MODEL_DESC set <%s>, off=%d", data, attr_off_bytes);
if (!err) {
strscpy_pad(data, fw_info->hw_version, FNIC_FDMI_HW_VER_LEN);
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_HARDWARE_VERSION,
FNIC_FDMI_HW_VER_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"HW_VER set <%s>, off=%d", data, attr_off_bytes);
}
@@ -1946,14 +1950,14 @@ static void fdls_fdmi_register_hba(struc
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_DRIVER_VERSION,
FNIC_FDMI_DR_VER_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"DRV_VER set <%s>, off=%d", data, attr_off_bytes);
strscpy_pad(data, "N/A", FNIC_FDMI_ROM_VER_LEN);
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_ROM_VERSION,
FNIC_FDMI_ROM_VER_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ROM_VER set <%s>, off=%d", data, attr_off_bytes);
if (!err) {
@@ -1961,14 +1965,14 @@ static void fdls_fdmi_register_hba(struc
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_FIRMWARE_VERSION,
FNIC_FDMI_FW_VER_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FW_VER set <%s>, off=%d", data, attr_off_bytes);
}
len = sizeof(struct fc_std_fdmi_rhba) + attr_off_bytes;
frame_size += len;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI RHBA with oxid: 0x%x fs: %d", iport->fcid,
oxid, frame_size);
@@ -1992,7 +1996,7 @@ static void fdls_fdmi_register_pa(struct
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send FDMI RPA");
return;
}
@@ -2020,7 +2024,7 @@ static void fdls_fdmi_register_pa(struct
&iport->active_oxid_fdmi_rpa);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Failed to allocate OXID to send FDMI RPA",
iport->fcid);
mempool_free(frame, fnic->frame_pool);
@@ -2085,7 +2089,7 @@ static void fdls_fdmi_register_pa(struct
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_OS_NAME,
FNIC_FDMI_OS_NAME_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"OS name set <%s>, off=%d", data, attr_off_bytes);
sprintf(fc_host_system_hostname(fnic->host), "%s", utsname()->nodename);
@@ -2094,13 +2098,13 @@ static void fdls_fdmi_register_pa(struct
fnic_fdmi_attr_set(fdmi_attr, FNIC_FDMI_TYPE_HOST_NAME,
FNIC_FDMI_HN_LEN, data, &attr_off_bytes);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Host name set <%s>, off=%d", data, attr_off_bytes);
len = sizeof(struct fc_std_fdmi_rpa) + attr_off_bytes;
frame_size += len;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send FDMI RPA with oxid: 0x%x fs: %d", iport->fcid,
oxid, frame_size);
@@ -2117,7 +2121,7 @@ void fdls_fabric_timer_callback(struct t
struct fnic *fnic = iport->fnic;
unsigned long flags;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tp: %d fab state: %d fab retry counter: %d max_flogi_retries: %d",
iport->fabric.timer_pending, iport->fabric.state,
iport->fabric.retry_counter, iport->max_flogi_retries);
@@ -2132,7 +2136,7 @@ void fdls_fabric_timer_callback(struct t
if (iport->fabric.del_timer_inprogress) {
iport->fabric.del_timer_inprogress = 0;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fabric_del_timer inprogress(%d). Skip timer cb",
iport->fabric.del_timer_inprogress);
return;
@@ -2160,7 +2164,7 @@ void fdls_fabric_timer_callback(struct t
iport->fabric.flags &= ~FNIC_FDLS_FABRIC_ABORT_ISSUED;
fdls_send_fabric_flogi(iport);
} else
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Exceeded max FLOGI retries");
}
break;
@@ -2182,7 +2186,7 @@ void fdls_fabric_timer_callback(struct t
iport->fabric.flags &= ~FNIC_FDLS_FABRIC_ABORT_ISSUED;
fdls_send_fabric_plogi(iport);
} else
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Exceeded max PLOGI retries");
}
break;
@@ -2213,7 +2217,7 @@ void fdls_fabric_timer_callback(struct t
else {
/* ABTS has timed out */
fdls_schedule_oxid_free(iport, &iport->active_oxid_fabric_req);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ABTS timed out. Starting PLOGI: %p", iport);
fnic_fdls_start_plogi(iport);
}
@@ -2230,7 +2234,7 @@ void fdls_fabric_timer_callback(struct t
} else {
/* ABTS has timed out */
fdls_schedule_oxid_free(iport, &iport->active_oxid_fabric_req);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ABTS timed out. Starting PLOGI: %p", iport);
fnic_fdls_start_plogi(iport); /* go back to fabric Plogi */
}
@@ -2247,7 +2251,7 @@ void fdls_fabric_timer_callback(struct t
else {
/* ABTS has timed out */
fdls_schedule_oxid_free(iport, &iport->active_oxid_fabric_req);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ABTS timed out. Starting PLOGI %p", iport);
fnic_fdls_start_plogi(iport); /* go back to fabric Plogi */
}
@@ -2269,7 +2273,7 @@ void fdls_fabric_timer_callback(struct t
if (iport->fabric.retry_counter < FDLS_RETRY_COUNT) {
fdls_send_gpn_ft(iport, iport->fabric.state);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ABTS timeout for fabric GPN_FT. Check name server: %p",
iport);
}
@@ -2289,7 +2293,7 @@ void fdls_fdmi_retry_plogi(struct fnic_i
/* If max retries not exhausted, start over from fdmi plogi */
if (iport->fabric.fdmi_retry < FDLS_FDMI_MAX_RETRY) {
iport->fabric.fdmi_retry++;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Retry FDMI PLOGI. FDMI retry: %d",
iport->fabric.fdmi_retry);
fdls_send_fdmi_plogi(iport);
@@ -2307,7 +2311,7 @@ void fdls_fdmi_timer_callback(struct tim
spin_lock_irqsave(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->fabric.fdmi_pending: 0x%x\n", iport->fabric.fdmi_pending);
if (!iport->fabric.fdmi_pending) {
@@ -2315,7 +2319,7 @@ void fdls_fdmi_timer_callback(struct tim
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->fabric.fdmi_pending: 0x%x\n", iport->fabric.fdmi_pending);
/* if not abort pending, send an abort */
@@ -2324,7 +2328,7 @@ void fdls_fdmi_timer_callback(struct tim
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->fabric.fdmi_pending: 0x%x\n", iport->fabric.fdmi_pending);
/* ABTS pending for an active fdmi request that is pending.
@@ -2332,29 +2336,36 @@ void fdls_fdmi_timer_callback(struct tim
* Schedule to free the OXID after 2*r_a_tov and proceed
*/
if (iport->fabric.fdmi_pending & FDLS_FDMI_PLOGI_PENDING) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDMI PLOGI ABTS timed out. Schedule oxid free: 0x%x\n",
iport->active_oxid_fdmi_plogi);
fdls_schedule_oxid_free(iport, &iport->active_oxid_fdmi_plogi);
} else {
if (iport->fabric.fdmi_pending & FDLS_FDMI_REG_HBA_PENDING) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDMI RHBA ABTS timed out. Schedule oxid free: 0x%x\n",
iport->active_oxid_fdmi_rhba);
fdls_schedule_oxid_free(iport, &iport->active_oxid_fdmi_rhba);
}
if (iport->fabric.fdmi_pending & FDLS_FDMI_RPA_PENDING) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDMI RPA ABTS timed out. Schedule oxid free: 0x%x\n",
iport->active_oxid_fdmi_rpa);
fdls_schedule_oxid_free(iport, &iport->active_oxid_fdmi_rpa);
}
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->fabric.fdmi_pending: 0x%x\n", iport->fabric.fdmi_pending);
- fdls_fdmi_retry_plogi(iport);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ iport->fabric.fdmi_pending = 0;
+ /* If max retries not exhaused, start over from fdmi plogi */
+ if (iport->fabric.fdmi_retry < FDLS_FDMI_MAX_RETRY) {
+ iport->fabric.fdmi_retry++;
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "retry fdmi timer %d", iport->fabric.fdmi_retry);
+ fdls_send_fdmi_plogi(iport);
+ }
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->fabric.fdmi_pending: 0x%x\n", iport->fabric.fdmi_pending);
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
}
@@ -2367,7 +2378,7 @@ static void fdls_send_delete_tport_msg(s
tport_del_evt = kzalloc(sizeof(struct fnic_tport_event_s), GFP_ATOMIC);
if (!tport_del_evt) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Failed to allocate memory for tport event fcid: 0x%x",
tport->fcid);
return;
@@ -2400,13 +2411,13 @@ static void fdls_tport_timer_callback(st
if (tport->del_timer_inprogress) {
tport->del_timer_inprogress = 0;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport_del_timer inprogress. Skip timer cb tport fcid: 0x%x\n",
tport->fcid);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid: 0x%x timer pending: %d state: %d retry counter: %d",
tport->fcid, tport->timer_pending, tport->state,
tport->retry_counter);
@@ -2467,15 +2478,16 @@ static void fdls_tport_timer_callback(st
} else {
/* exceeded retry count */
fdls_schedule_oxid_free(iport, &tport->active_oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ADISC not responding. Deleting target port: 0x%x",
tport->fcid);
fdls_send_delete_tport_msg(tport);
}
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "oxid: 0x%x Unknown tport state: 0x%x", oxid, tport->state);
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "0x%x timeout tport 0x%x oxid 0x%x state %d\n",
+ iport->fcid, tport->fcid, oxid, tport->state);
break;
}
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
@@ -2524,26 +2536,26 @@ fdls_process_tgt_adisc_rsp(struct fnic_i
tport = fnic_find_tport_by_fcid(iport, tgt_fcid);
if (!tport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Tgt ADISC response tport not found: 0x%x", tgt_fcid);
return;
}
if ((iport->state != FNIC_IPORT_STATE_READY)
|| (tport->state != FDLS_TGT_STATE_ADISC)
|| (tport->flags & FNIC_FDLS_TGT_ABORT_ISSUED)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping this ADISC response");
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport state: %d tport state: %d Is abort issued on PRLI? %d",
iport->state, tport->state,
(tport->flags & FNIC_FDLS_TGT_ABORT_ISSUED));
return;
}
if (FNIC_STD_GET_OX_ID(fchdr) != tport->active_oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping frame from target: 0x%x",
tgt_fcid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Reason: Stale ADISC/Aborted ADISC/OOO frame delivery");
return;
}
@@ -2555,7 +2567,7 @@ fdls_process_tgt_adisc_rsp(struct fnic_i
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.tport_adisc_ls_accepts);
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport 0x%p Canceling fabric disc timer\n",
tport);
fnic_del_tport_timer_sync(fnic, tport);
@@ -2565,12 +2577,12 @@ fdls_process_tgt_adisc_rsp(struct fnic_i
frame_wwnn = get_unaligned_be64(&adisc_rsp->els.adisc_wwnn);
frame_wwpn = get_unaligned_be64(&adisc_rsp->els.adisc_wwpn);
if ((frame_wwnn == tport->wwnn) && (frame_wwpn == tport->wwpn)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ADISC accepted from target: 0x%x. Target logged in",
tgt_fcid);
fdls_set_tport_state(tport, FDLS_TGT_STATE_READY);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Error mismatch frame: ADISC");
}
break;
@@ -2580,14 +2592,14 @@ fdls_process_tgt_adisc_rsp(struct fnic_i
if (((els_rjt->rej.er_reason == ELS_RJT_BUSY)
|| (els_rjt->rej.er_reason == ELS_RJT_UNAB))
&& (tport->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ADISC ret ELS_LS_RJT BUSY. Retry from timer routine: 0x%x",
tgt_fcid);
/* Retry ADISC again from the timer routine. */
tport->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"ADISC returned ELS_LS_RJT from target: 0x%x",
tgt_fcid);
fdls_delete_tport(iport, tport);
@@ -2611,33 +2623,33 @@ fdls_process_tgt_plogi_rsp(struct fnic_i
fcid = FNIC_STD_GET_S_ID(fchdr);
tgt_fcid = ntoh24(fcid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS processing target PLOGI response: tgt_fcid: 0x%x",
tgt_fcid);
tport = fnic_find_tport_by_fcid(iport, tgt_fcid);
if (!tport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport not found: 0x%x", tgt_fcid);
return;
}
if ((iport->state != FNIC_IPORT_STATE_READY)
|| (tport->flags & FNIC_FDLS_TGT_ABORT_ISSUED)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping frame! iport state: %d tport state: %d",
iport->state, tport->state);
return;
}
if (tport->state != FDLS_TGT_STATE_PLOGI) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI rsp recvd in wrong state. Drop the frame and restart nexus");
fdls_target_restart_nexus(tport);
return;
}
if (FNIC_STD_GET_OX_ID(fchdr) != tport->active_oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI response from target: 0x%x. Dropping frame",
tgt_fcid);
return;
@@ -2649,7 +2661,7 @@ fdls_process_tgt_plogi_rsp(struct fnic_i
switch (plogi_rsp->els.fl_cmd) {
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.tport_plogi_ls_accepts);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI accepted by target: 0x%x", tgt_fcid);
break;
@@ -2658,14 +2670,14 @@ fdls_process_tgt_plogi_rsp(struct fnic_i
if (((els_rjt->rej.er_reason == ELS_RJT_BUSY)
|| (els_rjt->rej.er_reason == ELS_RJT_UNAB))
&& (tport->retry_counter < iport->max_plogi_retries)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI ret ELS_LS_RJT BUSY. Retry from timer routine: 0x%x",
tgt_fcid);
/* Retry plogi again from the timer routine. */
tport->flags |= FNIC_FDLS_RETRY_FRAME;
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI returned ELS_LS_RJT from target: 0x%x",
tgt_fcid);
fdls_delete_tport(iport, tport);
@@ -2673,18 +2685,18 @@ fdls_process_tgt_plogi_rsp(struct fnic_i
default:
atomic64_inc(&iport->iport_stats.tport_plogi_misc_rejects);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI not accepted from target fcid: 0x%x",
tgt_fcid);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Found the PLOGI target: 0x%x and state: %d",
(unsigned int) tgt_fcid, tport->state);
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid 0x%x: Canceling disc timer\n",
tport->fcid);
fnic_del_tport_timer_sync(fnic, tport);
@@ -2702,13 +2714,13 @@ fdls_process_tgt_plogi_rsp(struct fnic_i
min(max_payload_size, iport->max_payload_size);
if (tport->max_payload_size < FNIC_MIN_DATA_FIELD_SIZE) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MFS: tport max frame size below spec bounds: %d",
tport->max_payload_size);
tport->max_payload_size = FNIC_MIN_DATA_FIELD_SIZE;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"MAX frame size: %u iport max_payload_size: %d tport mfs: %d",
max_payload_size, iport->max_payload_size,
tport->max_payload_size);
@@ -2736,12 +2748,12 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
fcid = FNIC_STD_GET_S_ID(fchdr);
tgt_fcid = ntoh24(fcid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process tgt PRLI response: 0x%x", tgt_fcid);
tport = fnic_find_tport_by_fcid(iport, tgt_fcid);
if (!tport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport not found: 0x%x", tgt_fcid);
/* Handle or just drop? */
return;
@@ -2749,24 +2761,24 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
if ((iport->state != FNIC_IPORT_STATE_READY)
|| (tport->flags & FNIC_FDLS_TGT_ABORT_ISSUED)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping frame! iport st: %d tport st: %d tport fcid: 0x%x",
iport->state, tport->state, tport->fcid);
return;
}
if (tport->state != FDLS_TGT_STATE_PRLI) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI rsp recvd in wrong state. Drop frame. Restarting nexus");
fdls_target_restart_nexus(tport);
return;
}
if (FNIC_STD_GET_OX_ID(fchdr) != tport->active_oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping PRLI response from target: 0x%x ",
tgt_fcid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Reason: Stale PRLI response/Aborted PDISC/OOO frame delivery");
return;
}
@@ -2777,11 +2789,11 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
switch (prli_rsp->els_prli.prli_cmd) {
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.tport_prli_ls_accepts);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI accepted from target: 0x%x", tgt_fcid);
if (prli_rsp->sp.spp_type != FC_FC4_TYPE_SCSI) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"mismatched target zoned with FC SCSI initiator: 0x%x",
tgt_fcid);
mismatched_tgt = true;
@@ -2798,7 +2810,7 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
|| (els_rjt->rej.er_reason == ELS_RJT_UNAB))
&& (tport->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI ret ELS_LS_RJT BUSY. Retry from timer routine: 0x%x",
tgt_fcid);
@@ -2806,7 +2818,7 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
tport->flags |= FNIC_FDLS_RETRY_FRAME;
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI returned ELS_LS_RJT from target: 0x%x",
tgt_fcid);
@@ -2815,17 +2827,17 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
return;
default:
atomic64_inc(&iport->iport_stats.tport_prli_misc_rejects);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI not accepted from target: 0x%x", tgt_fcid);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Found the PRLI target: 0x%x and state: %d",
(unsigned int) tgt_fcid, tport->state);
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport fcid 0x%x: Canceling disc timer\n",
tport->fcid);
fnic_del_tport_timer_sync(fnic, tport);
@@ -2841,7 +2853,7 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
/* Check if the device plays Target Mode Function */
if (!(tport->fcp_csp & FCP_PRLI_FUNC_TARGET)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Remote port(0x%x): no target support. Deleting it\n",
tgt_fcid);
fdls_tgt_logout(iport, tport);
@@ -2854,16 +2866,16 @@ fdls_process_tgt_prli_rsp(struct fnic_ip
/* Inform the driver about new target added */
tport_add_evt = kzalloc(sizeof(struct fnic_tport_event_s), GFP_ATOMIC);
if (!tport_add_evt) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "tport event memory allocation failure: 0x%0x\n",
- tport->fcid);
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "iport fcid: 0x%x tport event memory allocation failure: 0x%0x\n",
+ iport->fcid, tport->fcid);
return;
}
tport_add_evt->event = TGT_EV_RPORT_ADD;
tport_add_evt->arg1 = (void *) tport;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "iport fcid: 0x%x add tport event fcid: 0x%x\n",
- tport->fcid, iport->fcid);
+ FNIC_FCS_DBG(KERN_INFO, fnic,
+ "iport fcid: 0x%x add tport event fcid: 0x%x\n",
+ tport->fcid, iport->fcid);
list_add_tail(&tport_add_evt->links, &fnic->tport_event_list);
queue_work(fnic_event_queue, &fnic->tport_work);
}
@@ -2881,21 +2893,21 @@ fdls_process_rff_id_rsp(struct fnic_ipor
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (fdls_get_state(fdls) != FDLS_STATE_REGISTER_FC4_FEATURES) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFF_ID resp recvd in state(%d). Dropping.",
fdls_get_state(fdls));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
return;
}
rsp = FNIC_STD_GET_FC_CT_CMD((&rff_rsp->fc_std_ct_hdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS process RFF ID response: 0x%04x", iport->fcid,
(uint32_t) rsp);
@@ -2904,7 +2916,7 @@ fdls_process_rff_id_rsp(struct fnic_ipor
switch (rsp) {
case FC_FS_ACC:
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -2918,18 +2930,18 @@ fdls_process_rff_id_rsp(struct fnic_ipor
if (((reason_code == FC_FS_RJT_BSY)
|| (reason_code == FC_FS_RJT_UNABL))
&& (fdls->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFF_ID ret ELS_LS_RJT BUSY. Retry from timer routine %p",
iport);
/* Retry again from the timer routine */
fdls->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFF_ID returned ELS_LS_RJT. Halting discovery %p",
iport);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -2954,14 +2966,14 @@ fdls_process_rft_id_rsp(struct fnic_ipor
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (fdls_get_state(fdls) != FDLS_STATE_REGISTER_FC4_TYPES) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFT_ID resp recvd in state(%d). Dropping.",
fdls_get_state(fdls));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
return;
@@ -2969,7 +2981,7 @@ fdls_process_rft_id_rsp(struct fnic_ipor
rsp = FNIC_STD_GET_FC_CT_CMD((&rft_rsp->fc_std_ct_hdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS process RFT ID response: 0x%04x", iport->fcid,
(uint32_t) rsp);
@@ -2978,7 +2990,7 @@ fdls_process_rft_id_rsp(struct fnic_ipor
switch (rsp) {
case FC_FS_ACC:
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -2992,19 +3004,19 @@ fdls_process_rft_id_rsp(struct fnic_ipor
if (((reason_code == FC_FS_RJT_BSY)
|| (reason_code == FC_FS_RJT_UNABL))
&& (fdls->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: RFT_ID ret ELS_LS_RJT BUSY. Retry from timer routine",
iport->fcid);
/* Retry again from the timer routine */
fdls->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: RFT_ID REJ. Halting discovery reason %d expl %d",
iport->fcid, reason_code,
rft_rsp->fc_std_ct_hdr.ct_explan);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -3029,20 +3041,20 @@ fdls_process_rpn_id_rsp(struct fnic_ipor
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (fdls_get_state(fdls) != FDLS_STATE_RPN_ID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RPN_ID resp recvd in state(%d). Dropping.",
fdls_get_state(fdls));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
return;
}
rsp = FNIC_STD_GET_FC_CT_CMD((&rpn_rsp->fc_std_ct_hdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS process RPN ID response: 0x%04x", iport->fcid,
(uint32_t) rsp);
fdls_free_oxid(iport, oxid, &iport->active_oxid_fabric_req);
@@ -3050,7 +3062,7 @@ fdls_process_rpn_id_rsp(struct fnic_ipor
switch (rsp) {
case FC_FS_ACC:
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -3064,17 +3076,17 @@ fdls_process_rpn_id_rsp(struct fnic_ipor
if (((reason_code == FC_FS_RJT_BSY)
|| (reason_code == FC_FS_RJT_UNABL))
&& (fdls->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RPN_ID returned REJ BUSY. Retry from timer routine %p",
iport);
/* Retry again from the timer routine */
fdls->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RPN_ID ELS_LS_RJT. Halting discovery %p", iport);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -3097,18 +3109,18 @@ fdls_process_scr_rsp(struct fnic_iport_s
struct fnic *fnic = iport->fnic;
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process SCR response: 0x%04x",
(uint32_t) scr_rsp->scr.scr_cmd);
if (fdls_get_state(fdls) != FDLS_STATE_SCR) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"SCR resp recvd in state(%d). Dropping.",
fdls_get_state(fdls));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
}
@@ -3119,7 +3131,7 @@ fdls_process_scr_rsp(struct fnic_iport_s
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.fabric_scr_ls_accepts);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -3133,17 +3145,17 @@ fdls_process_scr_rsp(struct fnic_iport_s
if (((els_rjt->rej.er_reason == ELS_RJT_BUSY)
|| (els_rjt->rej.er_reason == ELS_RJT_UNAB))
&& (fdls->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"SCR ELS_LS_RJT BUSY. Retry from timer routine %p",
iport);
/* Retry again from the timer routine */
fdls->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"SCR returned ELS_LS_RJT. Halting discovery %p",
iport);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n",
iport);
fnic_del_fabric_timer_sync(fnic);
@@ -3171,7 +3183,7 @@ fdls_process_gpn_ft_tgt_list(struct fnic
u32 old_link_down_cnt = iport->fnic->link_down_cnt;
struct fnic *fnic = iport->fnic;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS process GPN_FT tgt list", iport->fcid);
gpn_ft_tgt =
@@ -3185,7 +3197,7 @@ fdls_process_gpn_ft_tgt_list(struct fnic
fcid = ntoh24(gpn_ft_tgt->fcid);
wwpn = be64_to_cpu(gpn_ft_tgt->wwpn);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"tport: 0x%x: ctrl:0x%x", fcid, gpn_ft_tgt->ctrl);
if (fcid == iport->fcid) {
@@ -3232,7 +3244,7 @@ fdls_process_gpn_ft_tgt_list(struct fnic
rem_len -= sizeof(struct fc_gpn_ft_rsp_iu);
}
if (rem_len <= 0) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"GPN_FT response: malformed/corrupt frame rxlen: %d remlen: %d",
len, rem_len);
}
@@ -3242,7 +3254,7 @@ fdls_process_gpn_ft_tgt_list(struct fnic
list_for_each_entry_safe(tport, next, &iport->tport_list, links) {
if (!(tport->flags & FNIC_FDLS_TPORT_IN_GPN_FT_LIST)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Remove port: 0x%x not found in GPN_FT list",
tport->fcid);
fdls_delete_tport(iport, tport);
@@ -3271,7 +3283,7 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
struct fnic *fnic = iport->fnic;
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process GPN_FT response: iport state: %d len: %d",
iport->state, len);
@@ -3291,14 +3303,14 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
&& ((fdls_get_state(fdls) == FDLS_STATE_RSCN_GPN_FT)
|| (fdls_get_state(fdls) == FDLS_STATE_SEND_GPNFT)
|| (fdls_get_state(fdls) == FDLS_STATE_TGT_DISCOVERY))))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"GPNFT resp recvd in fab state(%d) iport_state(%d). Dropping.",
fdls_get_state(fdls), iport->state);
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
}
@@ -3311,10 +3323,10 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
switch (rsp) {
case FC_FS_ACC:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: GPNFT_RSP accept", iport->fcid);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Canceling fabric disc timer\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -3329,7 +3341,7 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
* that will be taken care in next link up event
*/
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Halting target discovery: fab st: %d iport st: %d ",
fdls_get_state(fdls), iport->state);
break;
@@ -3339,22 +3351,22 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
case FC_FS_RJT:
reason_code = gpn_ft_rsp->fc_std_ct_hdr.ct_reason;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: GPNFT_RSP Reject reason: %d", iport->fcid, reason_code);
if (((reason_code == FC_FS_RJT_BSY)
|| (reason_code == FC_FS_RJT_UNABL))
&& (fdls->retry_counter < FDLS_RETRY_COUNT)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: GPNFT_RSP ret REJ/BSY. Retry from timer routine",
iport->fcid);
/* Retry again from the timer routine */
fdls->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: GPNFT_RSP reject", iport->fcid);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Canceling fabric disc timer\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -3368,7 +3380,7 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
count = 0;
list_for_each_entry_safe(tport, next, &iport->tport_list,
links) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"GPN_FT_REJECT: Remove port: 0x%x",
tport->fcid);
fdls_delete_tport(iport, tport);
@@ -3378,7 +3390,7 @@ fdls_process_gpn_ft_rsp(struct fnic_ipor
}
count++;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"GPN_FT_REJECT: Removed (0x%x) ports", count);
}
break;
@@ -3403,7 +3415,7 @@ fdls_process_fabric_logo_rsp(struct fnic
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
}
@@ -3412,7 +3424,7 @@ fdls_process_fabric_logo_rsp(struct fnic
switch (flogo_rsp->els.fl_cmd) {
case ELS_LS_ACC:
if (iport->fabric.state != FDLS_STATE_FABRIC_LOGO) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Flogo response. Fabric not in LOGO state. Dropping! %p",
iport);
return;
@@ -3422,25 +3434,25 @@ fdls_process_fabric_logo_rsp(struct fnic
iport->state = FNIC_IPORT_STATE_LINK_WAIT;
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport 0x%p Canceling fabric disc timer\n",
iport);
fnic_del_fabric_timer_sync(fnic);
}
iport->fabric.timer_pending = 0;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Flogo response from Fabric for did: 0x%x",
ntoh24(fchdr->fh_d_id));
return;
case ELS_LS_RJT:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Flogo response from Fabric for did: 0x%x returned ELS_LS_RJT",
ntoh24(fchdr->fh_d_id));
return;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGO response not accepted or rejected: 0x%x",
flogo_rsp->els.fl_cmd);
}
@@ -3458,17 +3470,17 @@ fdls_process_flogi_rsp(struct fnic_iport
struct fnic *fnic = iport->fnic;
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS processing FLOGI response", iport->fcid);
if (fdls_get_state(fabric) != FDLS_STATE_FABRIC_FLOGI) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI response received in state (%d). Dropping frame",
fdls_get_state(fabric));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fabric), oxid, iport->active_oxid_fabric_req);
return;
@@ -3480,7 +3492,7 @@ fdls_process_flogi_rsp(struct fnic_iport
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.fabric_flogi_ls_accepts);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x Canceling fabric disc timer\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -3490,7 +3502,7 @@ fdls_process_flogi_rsp(struct fnic_iport
iport->fabric.retry_counter = 0;
fcid = FNIC_STD_GET_D_ID(fchdr);
iport->fcid = ntoh24(fcid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FLOGI response accepted", iport->fcid);
/* Learn the Service Params */
@@ -3500,7 +3512,7 @@ fdls_process_flogi_rsp(struct fnic_iport
iport->max_payload_size = min(rdf_size,
iport->max_payload_size);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"max_payload_size from fabric: %u set: %d", rdf_size,
iport->max_payload_size);
@@ -3510,7 +3522,7 @@ fdls_process_flogi_rsp(struct fnic_iport
if (FNIC_LOGI_FEATURES(flogi_rsp->els) & FNIC_FC_EDTOV_NSEC)
iport->e_d_tov = iport->e_d_tov / FNIC_NSEC_TO_MSEC;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"From fabric: R_A_TOV: %d E_D_TOV: %d",
iport->r_a_tov, iport->e_d_tov);
@@ -3521,13 +3533,13 @@ fdls_process_flogi_rsp(struct fnic_iport
fnic_fdls_learn_fcoe_macs(iport, rx_frame, fcid);
if (fnic_fdls_register_portid(iport, iport->fcid, rx_frame) != 0) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FLOGI registration failed", iport->fcid);
break;
}
memcpy(&fcmac[3], fcid, 3);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Adding vNIC device MAC addr: %02x:%02x:%02x:%02x:%02x:%02x",
fcmac[0], fcmac[1], fcmac[2], fcmac[3], fcmac[4],
fcmac[5]);
@@ -3535,7 +3547,7 @@ fdls_process_flogi_rsp(struct fnic_iport
if (fdls_get_state(fabric) == FDLS_STATE_FABRIC_FLOGI) {
fnic_fdls_start_plogi(iport);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI response received. Starting PLOGI");
} else {
/* From FDLS_STATE_FABRIC_FLOGI state fabric can only go to
@@ -3543,7 +3555,7 @@ fdls_process_flogi_rsp(struct fnic_iport
* state, hence we don't have to worry about undoing:
* the fnic_fdls_register_portid and vnic_dev_add_addr
*/
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI response received in state (%d). Dropping frame",
fdls_get_state(fabric));
}
@@ -3552,7 +3564,7 @@ fdls_process_flogi_rsp(struct fnic_iport
case ELS_LS_RJT:
atomic64_inc(&iport->iport_stats.fabric_flogi_ls_rejects);
if (fabric->retry_counter < iport->max_flogi_retries) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI returned ELS_LS_RJT BUSY. Retry from timer routine %p",
iport);
@@ -3560,11 +3572,11 @@ fdls_process_flogi_rsp(struct fnic_iport
fabric->flags |= FNIC_FDLS_RETRY_FRAME;
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI returned ELS_LS_RJT. Halting discovery %p",
iport);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport 0x%p Canceling fabric disc timer\n",
iport);
fnic_del_fabric_timer_sync(fnic);
@@ -3575,7 +3587,7 @@ fdls_process_flogi_rsp(struct fnic_iport
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI response not accepted: 0x%x",
flogi_rsp->els.fl_cmd);
atomic64_inc(&iport->iport_stats.fabric_flogi_misc_rejects);
@@ -3594,13 +3606,13 @@ fdls_process_fabric_plogi_rsp(struct fni
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (fdls_get_state((&iport->fabric)) != FDLS_STATE_FABRIC_PLOGI) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Fabric PLOGI response received in state (%d). Dropping frame",
fdls_get_state(&iport->fabric));
return;
}
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fabric_req);
return;
@@ -3611,7 +3623,7 @@ fdls_process_fabric_plogi_rsp(struct fni
case ELS_LS_ACC:
atomic64_inc(&iport->iport_stats.fabric_plogi_ls_accepts);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x fabric PLOGI response: Accepted\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -3626,15 +3638,15 @@ fdls_process_fabric_plogi_rsp(struct fni
if (((els_rjt->rej.er_reason == ELS_RJT_BUSY)
|| (els_rjt->rej.er_reason == ELS_RJT_UNAB))
&& (iport->fabric.retry_counter < iport->max_plogi_retries)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Fabric PLOGI ELS_LS_RJT BUSY. Retry from timer routine",
iport->fcid);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Fabric PLOGI ELS_LS_RJT. Halting discovery",
iport->fcid);
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x Canceling fabric disc timer\n",
iport->fcid);
fnic_del_fabric_timer_sync(fnic);
@@ -3645,7 +3657,7 @@ fdls_process_fabric_plogi_rsp(struct fni
}
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI response not accepted: 0x%x",
plogi_rsp->els.fl_cmd);
atomic64_inc(&iport->iport_stats.fabric_plogi_misc_rejects);
@@ -3664,7 +3676,7 @@ static void fdls_process_fdmi_plogi_rsp(
uint16_t oxid = FNIC_STD_GET_OX_ID(fchdr);
if (iport->active_oxid_fdmi_plogi != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. state: %d, oxid recvd: 0x%x, active oxid: 0x%x\n",
fdls_get_state(fdls), oxid, iport->active_oxid_fdmi_plogi);
return;
@@ -3678,9 +3690,9 @@ static void fdls_process_fdmi_plogi_rsp(
iport->fabric.fdmi_pending = 0;
switch (plogi_rsp->els.fl_cmd) {
case ELS_LS_ACC:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process fdmi PLOGI response status: ELS_LS_ACC\n");
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Sending fdmi registration for port 0x%x\n",
iport->fcid);
@@ -3691,7 +3703,7 @@ static void fdls_process_fdmi_plogi_rsp(
round_jiffies(fdmi_tov));
break;
case ELS_LS_RJT:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Fabric FDMI PLOGI returned ELS_LS_RJT reason: 0x%x",
els_rjt->rej.er_reason);
@@ -3715,7 +3727,7 @@ static void fdls_process_fdmi_reg_ack(st
uint16_t oxid;
if (!iport->fabric.fdmi_pending) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received FDMI ack while not waiting: 0x%x\n",
FNIC_STD_GET_OX_ID(fchdr));
return;
@@ -3725,7 +3737,7 @@ static void fdls_process_fdmi_reg_ack(st
if ((iport->active_oxid_fdmi_rhba != oxid) &&
(iport->active_oxid_fdmi_rpa != oxid)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Incorrect OXID in response. oxid recvd: 0x%x, active oxids(rhba,rpa): 0x%x, 0x%x\n",
oxid, iport->active_oxid_fdmi_rhba, iport->active_oxid_fdmi_rpa);
return;
@@ -3738,13 +3750,13 @@ static void fdls_process_fdmi_reg_ack(st
fdls_free_oxid(iport, oxid, &iport->active_oxid_fdmi_rpa);
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x: Received FDMI registration ack\n",
iport->fcid);
if (!iport->fabric.fdmi_pending) {
timer_delete_sync(&iport->fabric.fdmi_timer);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport fcid: 0x%x: Canceling FDMI timer\n",
iport->fcid);
}
@@ -3760,7 +3772,7 @@ static void fdls_process_fdmi_abts_rsp(s
s_id = ntoh24(FNIC_STD_GET_S_ID(fchdr));
if (!(s_id != FC_FID_MGMT_SERV)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abts rsp with invalid SID: 0x%x. Dropping frame",
s_id);
return;
@@ -3770,23 +3782,23 @@ static void fdls_process_fdmi_abts_rsp(s
switch (FNIC_FRAME_TYPE(oxid)) {
case FNIC_FRAME_TYPE_FDMI_PLOGI:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received FDMI PLOGI ABTS rsp with oxid: 0x%x", oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
fdls_free_oxid(iport, oxid, &iport->active_oxid_fdmi_plogi);
iport->fabric.fdmi_pending &= ~FDLS_FDMI_PLOGI_PENDING;
iport->fabric.fdmi_pending &= ~FDLS_FDMI_ABORT_PENDING;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
break;
case FNIC_FRAME_TYPE_FDMI_RHBA:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received FDMI RHBA ABTS rsp with oxid: 0x%x", oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
@@ -3800,14 +3812,14 @@ static void fdls_process_fdmi_abts_rsp(s
iport->fabric.fdmi_pending &= ~FDLS_FDMI_ABORT_PENDING;
fdls_free_oxid(iport, oxid, &iport->active_oxid_fdmi_rhba);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
break;
case FNIC_FRAME_TYPE_FDMI_RPA:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received FDMI RPA ABTS rsp with oxid: 0x%x", oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
@@ -3821,12 +3833,12 @@ static void fdls_process_fdmi_abts_rsp(s
iport->fabric.fdmi_pending &= ~FDLS_FDMI_ABORT_PENDING;
fdls_free_oxid(iport, oxid, &iport->active_oxid_fdmi_rpa);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: iport->fabric.fdmi_pending: 0x%x",
iport->fcid, iport->fabric.fdmi_pending);
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abts rsp with invalid oxid: 0x%x. Dropping frame",
oxid);
break;
@@ -3861,7 +3873,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (!((s_id == FC_FID_DIR_SERV) || (s_id == FC_FID_FLOGI)
|| (s_id == FC_FID_FCTRL))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abts rsp with invalid SID: 0x%x. Dropping frame",
s_id);
return;
@@ -3869,14 +3881,14 @@ fdls_process_fabric_abts_rsp(struct fnic
oxid = FNIC_STD_GET_OX_ID(fchdr);
if (iport->active_oxid_fabric_req != oxid) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abts rsp with invalid oxid: 0x%x. Dropping frame",
oxid);
return;
}
if (iport->fabric.timer_pending) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Canceling fabric disc timer %p\n", iport);
fnic_del_fabric_timer_sync(fnic);
}
@@ -3884,11 +3896,11 @@ fdls_process_fabric_abts_rsp(struct fnic
iport->fabric.flags &= ~FNIC_FDLS_FABRIC_ABORT_ISSUED;
if (fchdr->fh_r_ctl == FC_RCTL_BA_ACC) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abts rsp BA_ACC for fabric_state: %d OX_ID: 0x%x",
fabric_state, be16_to_cpu(ba_acc->acc.ba_ox_id));
} else if (fchdr->fh_r_ctl == FC_RCTL_BA_RJT) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"BA_RJT fs: %d OX_ID: 0x%x rc: 0x%x rce: 0x%x",
fabric_state, FNIC_STD_GET_OX_ID(&ba_rjt->fchdr),
ba_rjt->rjt.br_reason, ba_rjt->rjt.br_explan);
@@ -3903,7 +3915,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter < iport->max_flogi_retries)
fdls_send_fabric_flogi(iport);
else
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Exceeded max FLOGI retries");
break;
case FNIC_FRAME_TYPE_FABRIC_LOGO:
@@ -3914,7 +3926,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter < iport->max_plogi_retries)
fdls_send_fabric_plogi(iport);
else
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Exceeded max PLOGI retries");
break;
case FNIC_FRAME_TYPE_FABRIC_RPN:
@@ -3928,7 +3940,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter < FDLS_RETRY_COUNT)
fdls_send_scr(iport);
else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"SCR exhausted retries. Start fabric PLOGI %p",
iport);
fnic_fdls_start_plogi(iport); /* go back to fabric Plogi */
@@ -3938,7 +3950,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter < FDLS_RETRY_COUNT)
fdls_send_register_fc4_types(iport);
else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFT exhausted retries. Start fabric PLOGI %p",
iport);
fnic_fdls_start_plogi(iport); /* go back to fabric Plogi */
@@ -3948,7 +3960,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter < FDLS_RETRY_COUNT)
fdls_send_register_fc4_features(iport);
else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RFF exhausted retries. Start fabric PLOGI %p",
iport);
fnic_fdls_start_plogi(iport); /* go back to fabric Plogi */
@@ -3958,7 +3970,7 @@ fdls_process_fabric_abts_rsp(struct fnic
if (iport->fabric.retry_counter <= FDLS_RETRY_COUNT)
fdls_send_gpn_ft(iport, fabric_state);
else
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"GPN FT exhausted retries. Start fabric PLOGI %p",
iport);
break;
@@ -3967,7 +3979,7 @@ fdls_process_fabric_abts_rsp(struct fnic
* We should not be here since we already validated rx oxid with
* our active_oxid_fabric_req
*/
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Invalid OXID/active oxid 0x%x\n", oxid);
WARN_ON(true);
return;
@@ -3987,7 +3999,7 @@ fdls_process_abts_req(struct fnic_iport_
sizeof(struct fc_std_abts_ba_acc);
nport_id = ntoh24(fchdr->fh_s_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received abort from SID 0x%8x", nport_id);
tport = fnic_find_tport_by_fcid(iport, nport_id);
@@ -4000,7 +4012,7 @@ fdls_process_abts_req(struct fnic_iport_
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"0x%x: Failed to allocate frame to send response for ABTS req",
iport->fcid);
return;
@@ -4021,7 +4033,7 @@ fdls_process_abts_req(struct fnic_iport_
pba_acc->acc.ba_rx_id = cpu_to_be16(FNIC_STD_GET_RX_ID(fchdr));
pba_acc->acc.ba_ox_id = cpu_to_be16(FNIC_STD_GET_OX_ID(fchdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS send BA ACC with oxid: 0x%x",
iport->fcid, oxid);
@@ -4041,7 +4053,7 @@ fdls_process_unsupported_els_req(struct
sizeof(struct fc_std_els_rjt_rsp);
if (iport->fcid != d_id) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping unsupported ELS with illegal frame bits 0x%x\n",
d_id);
atomic64_inc(&iport->iport_stats.unsupported_frames_dropped);
@@ -4050,7 +4062,7 @@ fdls_process_unsupported_els_req(struct
if ((iport->state != FNIC_IPORT_STATE_READY)
&& (iport->state != FNIC_IPORT_STATE_FABRIC_DISC)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping unsupported ELS request in iport state: %d",
iport->state);
atomic64_inc(&iport->iport_stats.unsupported_frames_dropped);
@@ -4059,7 +4071,7 @@ fdls_process_unsupported_els_req(struct
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send response to unsupported ELS request");
return;
}
@@ -4067,7 +4079,7 @@ fdls_process_unsupported_els_req(struct
pls_rsp = (struct fc_std_els_rjt_rsp *) (frame + FNIC_ETH_FCOE_HDRS_OFFSET);
fdls_init_els_rjt_frame(frame, iport);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Process unsupported ELS request from SID: 0x%x",
iport->fcid, ntoh24(fchdr->fh_s_id));
@@ -4094,12 +4106,12 @@ fdls_process_rls_req(struct fnic_iport_s
uint16_t frame_size = FNIC_ETH_FCOE_HDRS_OFFSET +
sizeof(struct fc_std_rls_acc);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Process RLS request %d", iport->fnic->fnic_num);
if ((iport->state != FNIC_IPORT_STATE_READY)
&& (iport->state != FNIC_IPORT_STATE_FABRIC_DISC)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received RLS req in iport state: %d. Dropping the frame.",
iport->state);
return;
@@ -4107,7 +4119,7 @@ fdls_process_rls_req(struct fnic_iport_s
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send RLS accept");
return;
}
@@ -4148,33 +4160,33 @@ fdls_process_els_req(struct fnic_iport_s
if ((iport->state != FNIC_IPORT_STATE_READY)
&& (iport->state != FNIC_IPORT_STATE_FABRIC_DISC)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping ELS frame type: 0x%x in iport state: %d",
type, iport->state);
return;
}
switch (type) {
case ELS_ECHO:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"sending LS_ACC for ECHO request %d\n",
iport->fnic->fnic_num);
break;
case ELS_RRQ:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"sending LS_ACC for RRQ request %d\n",
iport->fnic->fnic_num);
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"sending LS_ACC for 0x%x ELS frame\n", type);
break;
}
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send ELS response for 0x%x",
type);
return;
@@ -4220,17 +4232,17 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
tport = fnic_find_tport_by_fcid(iport, s_id);
if (!tport) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received tgt abts rsp with invalid SID: 0x%x", s_id);
return;
}
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"tport 0x%p Canceling fabric disc timer\n", tport);
fnic_del_tport_timer_sync(fnic, tport);
}
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received tgt abts rsp in iport state(%d). Dropping.",
iport->state);
return;
@@ -4245,15 +4257,15 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
switch (frame_type) {
case FNIC_FRAME_TYPE_TGT_ADISC:
if (fchdr->fh_r_ctl == FC_RCTL_BA_ACC) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"OX_ID: 0x%x tgt_fcid: 0x%x rcvd tgt adisc abts resp BA_ACC",
be16_to_cpu(ba_acc->acc.ba_ox_id),
tport->fcid);
} else if (fchdr->fh_r_ctl == FC_RCTL_BA_RJT) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"ADISC BA_RJT rcvd tport_fcid: 0x%x tport_state: %d ",
tport->fcid, tport_state);
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"reason code: 0x%x reason code explanation:0x%x ",
ba_rjt->rjt.br_reason,
ba_rjt->rjt.br_explan);
@@ -4265,7 +4277,7 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
return;
}
fdls_free_oxid(iport, oxid, &tport->active_oxid);
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"ADISC not responding. Deleting target port: 0x%x",
tport->fcid);
fdls_delete_tport(iport, tport);
@@ -4278,14 +4290,14 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
break;
case FNIC_FRAME_TYPE_TGT_PLOGI:
if (fchdr->fh_r_ctl == FC_RCTL_BA_ACC) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received tgt PLOGI abts response BA_ACC tgt_fcid: 0x%x",
tport->fcid);
} else if (fchdr->fh_r_ctl == FC_RCTL_BA_RJT) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PLOGI BA_RJT received for tport_fcid: 0x%x OX_ID: 0x%x",
tport->fcid, FNIC_STD_GET_OX_ID(fchdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"reason code: 0x%x reason code explanation: 0x%x",
ba_rjt->rjt.br_reason,
ba_rjt->rjt.br_explan);
@@ -4308,14 +4320,14 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
break;
case FNIC_FRAME_TYPE_TGT_PRLI:
if (fchdr->fh_r_ctl == FC_RCTL_BA_ACC) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Received tgt PRLI abts response BA_ACC",
tport->fcid);
} else if (fchdr->fh_r_ctl == FC_RCTL_BA_RJT) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PRLI BA_RJT received for tport_fcid: 0x%x OX_ID: 0x%x ",
tport->fcid, FNIC_STD_GET_OX_ID(fchdr));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"reason code: 0x%x reason code explanation: 0x%x",
ba_rjt->rjt.br_reason,
ba_rjt->rjt.br_explan);
@@ -4331,7 +4343,7 @@ fdls_process_tgt_abts_rsp(struct fnic_ip
fdls_set_tport_state(tport, FDLS_TGT_STATE_PLOGI);
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received ABTS response for unknown frame %p", iport);
break;
}
@@ -4351,14 +4363,14 @@ fdls_process_plogi_req(struct fnic_iport
sizeof(struct fc_std_els_rjt_rsp);
if (iport->fcid != d_id) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received PLOGI with illegal frame bits. Dropping frame from 0x%x",
d_id);
return;
}
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received PLOGI request in iport state: %d Dropping frame",
iport->state);
return;
@@ -4366,7 +4378,7 @@ fdls_process_plogi_req(struct fnic_iport
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send response to PLOGI request");
return;
}
@@ -4374,7 +4386,7 @@ fdls_process_plogi_req(struct fnic_iport
pplogi_rsp = (struct fc_std_els_rjt_rsp *) (frame + FNIC_ETH_FCOE_HDRS_OFFSET);
fdls_init_els_rjt_frame(frame, iport);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: Process PLOGI request from SID: 0x%x",
iport->fcid, ntoh24(fchdr->fh_s_id));
@@ -4404,11 +4416,11 @@ fdls_process_logo_req(struct fnic_iport_
nport_id = ntoh24(logo->els.fl_n_port_id);
nport_name = be64_to_cpu(logo->els.fl_n_port_wwn);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Process LOGO request from fcid: 0x%x", nport_id);
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Dropping LOGO req from 0x%x in iport state: %d",
nport_id, iport->state);
return;
@@ -4418,19 +4430,19 @@ fdls_process_logo_req(struct fnic_iport_
if (!tport) {
/* We are not logged in with the nport, log and drop... */
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received LOGO from an nport not logged in: 0x%x(0x%llx)",
nport_id, nport_name);
return;
}
if (tport->fcid != nport_id) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Received LOGO with invalid target port fcid: 0x%x(0x%llx)",
nport_id, nport_name);
return;
}
if (tport->timer_pending) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"tport fcid 0x%x: Canceling disc timer\n",
tport->fcid);
fnic_del_tport_timer_sync(fnic, tport);
@@ -4447,7 +4459,7 @@ fdls_process_logo_req(struct fnic_iport_
if ((iport->state == FNIC_IPORT_STATE_READY)
&& (fdls_get_state(&iport->fabric) != FDLS_STATE_SEND_GPNFT)
&& (fdls_get_state(&iport->fabric) != FDLS_STATE_RSCN_GPN_FT)) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Sending GPNFT in response to LOGO from Target:0x%x",
nport_id);
fdls_send_gpn_ft(iport, FDLS_STATE_SEND_GPNFT);
@@ -4460,7 +4472,7 @@ fdls_process_logo_req(struct fnic_iport_
fdls_send_logo_resp(iport, &logo->fchdr);
if ((fdls_get_state(&iport->fabric) != FDLS_STATE_SEND_GPNFT) &&
(fdls_get_state(&iport->fabric) != FDLS_STATE_RSCN_GPN_FT)) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Sending GPNFT in response to LOGO from Target:0x%x",
nport_id);
fdls_send_gpn_ft(iport, FDLS_STATE_SEND_GPNFT);
@@ -4487,11 +4499,11 @@ fdls_process_rscn(struct fnic_iport_s *i
atomic64_inc(&iport->iport_stats.num_rscns);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process RSCN %p", iport);
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS RSCN received in state(%d). Dropping",
fdls_get_state(fdls));
return;
@@ -4508,18 +4520,18 @@ fdls_process_rscn(struct fnic_iport_s *i
if ((rscn_payload_len == 0xFFFF)
&& (sid == FC_FID_FCTRL)) {
rscn_type = PC_RSCN;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"pcrscn: PCRSCN received. sid: 0x%x payload len: 0x%x",
sid, rscn_payload_len);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RSCN payload_len: 0x%x page_len: 0x%x",
rscn_payload_len, rscn->els.rscn_page_len);
/* if this happens then we need to send ADISC to all the tports. */
list_for_each_entry_safe(tport, next, &iport->tport_list, links) {
if (tport->state == FDLS_TGT_STATE_READY)
tport->flags |= FNIC_FDLS_TPORT_SEND_ADISC;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RSCN for port id: 0x%x", tport->fcid);
}
} /* end else */
@@ -4527,7 +4539,7 @@ fdls_process_rscn(struct fnic_iport_s *i
num_ports = (rscn_payload_len - 4) / rscn->els.rscn_page_len;
rscn_port = (struct fc_els_rscn_page *)(rscn + 1);
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RSCN received for num_ports: %d payload_len: %d page_len: %d ",
num_ports, rscn_payload_len, rscn->els.rscn_page_len);
@@ -4551,14 +4563,14 @@ fdls_process_rscn(struct fnic_iport_s *i
if (tport->state == FDLS_TGT_STATE_READY)
tport->flags |= FNIC_FDLS_TPORT_SEND_ADISC;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RSCN for port id: 0x%x", tport->fcid);
}
break;
}
tport = fnic_find_tport_by_fcid(iport, nport_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"RSCN port id list: 0x%x", nport_id);
if (!tport) {
@@ -4573,13 +4585,13 @@ fdls_process_rscn(struct fnic_iport_s *i
rscn_type == PC_RSCN && fnic->role == FNIC_ROLE_FCP_INITIATOR) {
if (fnic->pc_rscn_handling_status == PC_RSCN_HANDLING_IN_PROGRESS) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PCRSCN handling already in progress. Skip host reset: %d",
iport->fnic->fnic_num);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Processing PCRSCN. Queuing fnic for host reset: %d",
iport->fnic->fnic_num);
fnic->pc_rscn_handling_status = PC_RSCN_HANDLING_IN_PROGRESS;
@@ -4595,7 +4607,7 @@ fdls_process_rscn(struct fnic_iport_s *i
queue_work(reset_fnic_work_queue, &reset_fnic_work);
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FDLS process RSCN sending GPN_FT: newports: %d", newports);
fdls_send_gpn_ft(iport, FDLS_STATE_RSCN_GPN_FT);
fdls_send_rscn_resp(iport, fchdr);
@@ -4644,20 +4656,20 @@ fdls_process_adisc_req(struct fnic_iport
uint16_t acc_frame_size = FNIC_ETH_FCOE_HDRS_OFFSET +
sizeof(struct fc_std_els_adisc);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Process ADISC request %d", iport->fnic->fnic_num);
fcid = FNIC_STD_GET_S_ID(fchdr);
tgt_fcid = ntoh24(fcid);
tport = fnic_find_tport_by_fcid(iport, tgt_fcid);
if (!tport) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"tport for fcid: 0x%x not found. Dropping ADISC req.",
tgt_fcid);
return;
}
if (iport->state != FNIC_IPORT_STATE_READY) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Dropping ADISC req from fcid: 0x%x in iport state: %d",
tgt_fcid, iport->state);
return;
@@ -4668,16 +4680,16 @@ fdls_process_adisc_req(struct fnic_iport
if ((frame_wwnn != tport->wwnn) || (frame_wwpn != tport->wwpn)) {
/* send reject */
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"ADISC req from fcid: 0x%x mismatch wwpn: 0x%llx wwnn: 0x%llx",
tgt_fcid, frame_wwpn, frame_wwnn);
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"local tport wwpn: 0x%llx wwnn: 0x%llx. Sending RJT",
tport->wwpn, tport->wwnn);
rjt_frame = fdls_alloc_frame(iport);
if (rjt_frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate rjt_frame to send response to ADISC request");
return;
}
@@ -4700,7 +4712,7 @@ fdls_process_adisc_req(struct fnic_iport
acc_frame = fdls_alloc_frame(iport);
if (acc_frame == NULL) {
- FNIC_FCS_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send ADISC accept");
return;
}
@@ -4754,7 +4766,7 @@ fnic_fdls_validate_and_get_frame_type(st
/* some common validation */
if (fdls_get_state(fabric) > FDLS_STATE_FABRIC_FLOGI) {
if (iport->fcid != d_id || (!FNIC_FC_FRAME_CS_CTL(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"invalid frame received. Dropping frame");
return -1;
}
@@ -4764,14 +4776,14 @@ fnic_fdls_validate_and_get_frame_type(st
if ((fchdr->fh_r_ctl == FC_RCTL_BA_ACC)
|| (fchdr->fh_r_ctl == FC_RCTL_BA_RJT)) {
if (!(FNIC_FC_FRAME_TYPE_BLS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received ABTS invalid frame. Dropping frame");
return -1;
}
if (fdls_is_oxid_fabric_req(oxid)) {
if (!(iport->fabric.flags & FNIC_FDLS_FABRIC_ABORT_ISSUED)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unexpected ABTS RSP(oxid:0x%x) from 0x%x. Dropping frame",
oxid, s_id);
return -1;
@@ -4782,7 +4794,7 @@ fnic_fdls_validate_and_get_frame_type(st
} else if (fdls_is_oxid_tgt_req(oxid)) {
return FNIC_TPORT_BLS_ABTS_RSP;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received ABTS rsp with unknown oxid(0x%x) from 0x%x. Dropping frame",
oxid, s_id);
return -1;
@@ -4791,7 +4803,7 @@ fnic_fdls_validate_and_get_frame_type(st
/* BLS ABTS Req */
if ((fchdr->fh_r_ctl == FC_RCTL_BA_ABTS)
&& (FNIC_FC_FRAME_TYPE_BLS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Receiving Abort Request from s_id: 0x%x", s_id);
return FNIC_BLS_ABTS_REQ;
}
@@ -4803,7 +4815,7 @@ fnic_fdls_validate_and_get_frame_type(st
if ((!FNIC_FC_FRAME_FCTL_FIRST_LAST_SEQINIT(fchdr))
|| (!FNIC_FC_FRAME_UNSOLICITED(fchdr))
|| (!FNIC_FC_FRAME_TYPE_ELS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received LOGO invalid frame. Dropping frame");
return -1;
}
@@ -4812,12 +4824,12 @@ fnic_fdls_validate_and_get_frame_type(st
if ((!FNIC_FC_FRAME_FCTL_FIRST_LAST_SEQINIT(fchdr))
|| (!FNIC_FC_FRAME_TYPE_ELS(fchdr))
|| (!FNIC_FC_FRAME_UNSOLICITED(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received RSCN invalid FCTL. Dropping frame");
return -1;
}
if (s_id != FC_FID_FCTRL)
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received RSCN from target FCTL: 0x%x type: 0x%x s_id: 0x%x.",
fchdr->fh_f_ctl[0], fchdr->fh_type, s_id);
return FNIC_ELS_RSCN_REQ;
@@ -4832,7 +4844,7 @@ fnic_fdls_validate_and_get_frame_type(st
case ELS_RRQ:
return FNIC_ELS_RRQ;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Unsupported frame (type:0x%02x) from fcid: 0x%x",
type, s_id);
return FNIC_ELS_UNSUPPORTED_REQ;
@@ -4841,14 +4853,14 @@ fnic_fdls_validate_and_get_frame_type(st
/* solicited response from fabric or target */
oxid_frame_type = FNIC_FRAME_TYPE(oxid);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"oxid frame code: 0x%x, oxid: 0x%x\n", oxid_frame_type, oxid);
switch (oxid_frame_type) {
case FNIC_FRAME_TYPE_FABRIC_FLOGI:
if (type == ELS_LS_ACC) {
if ((s_id != FC_FID_FLOGI)
|| (!FNIC_FC_FRAME_TYPE_ELS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4859,7 +4871,7 @@ fnic_fdls_validate_and_get_frame_type(st
if (type == ELS_LS_ACC) {
if ((s_id != FC_FID_DIR_SERV)
|| (!FNIC_FC_FRAME_TYPE_ELS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4870,7 +4882,7 @@ fnic_fdls_validate_and_get_frame_type(st
if (type == ELS_LS_ACC) {
if ((s_id != FC_FID_FCTRL)
|| (!FNIC_FC_FRAME_TYPE_ELS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4879,7 +4891,7 @@ fnic_fdls_validate_and_get_frame_type(st
case FNIC_FRAME_TYPE_FABRIC_RPN:
if ((s_id != FC_FID_DIR_SERV) || (!FNIC_FC_FRAME_TYPE_FC_GS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4887,7 +4899,7 @@ fnic_fdls_validate_and_get_frame_type(st
case FNIC_FRAME_TYPE_FABRIC_RFT:
if ((s_id != FC_FID_DIR_SERV) || (!FNIC_FC_FRAME_TYPE_FC_GS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4895,7 +4907,7 @@ fnic_fdls_validate_and_get_frame_type(st
case FNIC_FRAME_TYPE_FABRIC_RFF:
if ((s_id != FC_FID_DIR_SERV) || (!FNIC_FC_FRAME_TYPE_FC_GS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4903,7 +4915,7 @@ fnic_fdls_validate_and_get_frame_type(st
case FNIC_FRAME_TYPE_FABRIC_GPN_FT:
if ((s_id != FC_FID_DIR_SERV) || (!FNIC_FC_FRAME_TYPE_FC_GS(fchdr))) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown frame. Dropping frame");
return -1;
}
@@ -4925,7 +4937,7 @@ fnic_fdls_validate_and_get_frame_type(st
return FNIC_TPORT_ADISC_RSP;
case FNIC_FRAME_TYPE_TGT_LOGO:
if (!FNIC_FC_FRAME_TYPE_ELS(fchdr)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping Unknown frame in tport solicited exchange range type: 0x%x.",
fchdr->fh_type);
return -1;
@@ -4933,7 +4945,7 @@ fnic_fdls_validate_and_get_frame_type(st
return FNIC_TPORT_LOGO_RSP;
default:
/* Drop the Rx frame and log/stats it */
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Solicited response: unknown OXID: 0x%x", oxid);
return -1;
}
@@ -5003,7 +5015,7 @@ void fnic_fdls_recv_frame(struct fnic_ip
break;
case FNIC_TPORT_LOGO_RSP:
/* Logo response from tgt which we have deleted */
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Logo response from tgt: 0x%x",
ntoh24(fchdr->fh_s_id));
break;
@@ -5046,9 +5058,9 @@ void fnic_fdls_recv_frame(struct fnic_ip
fdls_process_fdmi_reg_ack(iport, fchdr, frame_type);
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"s_id: 0x%x d_did: 0x%x", s_id, d_id);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Received unknown FCoE frame of len: %d. Dropping frame", len);
break;
}
@@ -5065,7 +5077,7 @@ void fnic_fdls_link_down(struct fnic_ipo
struct fnic_tport_s *tport, *next;
struct fnic *fnic = iport->fnic;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS processing link down", iport->fcid);
fdls_set_state((&iport->fabric), FDLS_STATE_LINKDOWN);
@@ -5075,7 +5087,7 @@ void fnic_fdls_link_down(struct fnic_ipo
fnic_fcpio_reset(iport->fnic);
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
list_for_each_entry_safe(tport, next, &iport->tport_list, links) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"removing rport: 0x%x", tport->fcid);
fdls_delete_tport(iport, tport);
}
@@ -5088,6 +5100,6 @@ void fnic_fdls_link_down(struct fnic_ipo
iport->flags &= ~FNIC_FDMI_ACTIVE;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"0x%x: FDLS finish processing link down", iport->fcid);
}
--- a/drivers/scsi/fnic/fip.c
+++ b/drivers/scsi/fnic/fip.c
@@ -27,7 +27,7 @@ void fnic_fcoe_reset_vlans(struct fnic *
}
spin_unlock_irqrestore(&fnic->vlans_lock, flags);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Reset vlan complete\n");
}
@@ -46,7 +46,7 @@ void fnic_fcoe_send_vlan_req(struct fnic
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FIP_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send VLAN req");
return;
}
@@ -54,10 +54,10 @@ void fnic_fcoe_send_vlan_req(struct fnic
fnic_fcoe_reset_vlans(fnic);
fnic->set_vlan(fnic, 0);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"set vlan done\n");
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"got MAC 0x%x:%x:%x:%x:%x:%x\n", iport->hwmac[0],
iport->hwmac[1], iport->hwmac[2], iport->hwmac[3],
iport->hwmac[4], iport->hwmac[5]);
@@ -81,13 +81,13 @@ void fnic_fcoe_send_vlan_req(struct fnic
iport->fip.state = FDLS_FIP_VLAN_DISCOVERY_STARTED;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Send VLAN req\n");
fnic_send_fip_frame(iport, frame, frame_size);
vlan_tov = jiffies + msecs_to_jiffies(FCOE_CTLR_FIPVLAN_TOV);
mod_timer(&fnic->retry_fip_timer, round_jiffies(vlan_tov));
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fip timer set\n");
}
@@ -111,11 +111,11 @@ void fnic_fcoe_process_vlan_resp(struct
struct fip_vlan_desc *vlan_desc;
unsigned long flags;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p got vlan resp\n", fnic);
desc_len = be16_to_cpu(vlan_notif->fip.fip_dl_len);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"desc_len %d\n", desc_len);
spin_lock_irqsave(&fnic->vlans_lock, flags);
@@ -128,23 +128,20 @@ void fnic_fcoe_process_vlan_resp(struct
if (vlan_desc->fd_desc.fip_dtype == FIP_DT_VLAN) {
if (vlan_desc->fd_desc.fip_dlen != 1) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Invalid descriptor length(%x) in VLan response\n",
vlan_desc->fd_desc.fip_dlen);
}
num_vlan++;
vid = be16_to_cpu(vlan_desc->fd_vlan);
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"process_vlan_resp: FIP VLAN %d\n", vid);
vlan = kzalloc(sizeof(*vlan), GFP_ATOMIC);
if (!vlan) {
/* retry from timer */
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Mem Alloc failure\n");
spin_unlock_irqrestore(&fnic->vlans_lock,
flags);
@@ -155,14 +152,14 @@ void fnic_fcoe_process_vlan_resp(struct
list_add_tail(&vlan->list, &fnic->vlan_list);
break;
}
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
- "Invalid descriptor type(%x) in VLan response\n",
- vlan_desc->fd_desc.fip_dtype);
/*
- * Note : received a type=2 descriptor here i.e. FIP
- * MAC Address Descriptor
+ * Note : skip any type=2 descriptor here
+ * (i.e. FIP MAC Address Descriptor)
*/
+ if (vlan_desc->fd_desc.fip_dtype != FIP_DT_MAC)
+ FNIC_FIP_DBG(KERN_INFO, fnic,
+ "Invalid descriptor type(0x%x) in vlan response\n",
+ vlan_desc->fd_desc.fip_dtype);
cur_desc += vlan_desc->fd_desc.fip_dlen;
desc_len -= vlan_desc->fd_desc.fip_dlen;
}
@@ -170,7 +167,7 @@ void fnic_fcoe_process_vlan_resp(struct
/* any VLAN descriptors present ? */
if (num_vlan == 0) {
atomic64_inc(&fnic_stats->vlan_stats.resp_withno_vlanID);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p No VLAN descriptors in FIP VLAN response\n",
fnic);
}
@@ -195,7 +192,7 @@ void fnic_fcoe_start_fcf_discovery(struc
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FIP_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_ERR, fnic,
"Failed to allocate frame to start FCF discovery");
return;
}
@@ -222,7 +219,7 @@ void fnic_fcoe_start_fcf_discovery(struc
FNIC_STD_SET_NODE_NAME(&pdisc_sol->name_desc.fd_wwn, iport->wwnn);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Start FCF discovery\n");
fnic_send_fip_frame(iport, frame, frame_size);
@@ -257,16 +254,14 @@ void fnic_fcoe_fip_discovery_resp(struct
switch (iport->fip.state) {
case FDLS_FIP_FCF_DISCOVERY_STARTED:
if (be16_to_cpu(disc_adv->fip.fip_flags) & FIP_FL_SOL) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p Solicited adv\n", fnic);
if ((disc_adv->prio_desc.fd_pri <
iport->selected_fcf.fcf_priority)
&& (be16_to_cpu(disc_adv->fip.fip_flags) & FIP_FL_AVAIL)) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p FCF Available\n", fnic);
memcpy(iport->selected_fcf.fcf_mac,
disc_adv->mac_desc.fd_mac, ETH_ALEN);
@@ -274,8 +269,8 @@ void fnic_fcoe_fip_discovery_resp(struct
disc_adv->prio_desc.fd_pri;
iport->selected_fcf.fka_adv_period =
be32_to_cpu(disc_adv->fka_adv_desc.fd_fka_period);
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num, "adv time %d",
+ FNIC_FIP_DBG(KERN_INFO, fnic,
+ "adv time %d",
iport->selected_fcf.fka_adv_period);
iport->selected_fcf.ka_disabled =
(disc_adv->fka_adv_desc.fd_flags & 1);
@@ -294,8 +289,7 @@ void fnic_fcoe_fip_discovery_resp(struct
iport->selected_fcf.fka_adv_period =
be32_to_cpu(disc_adv->fka_adv_desc.fd_fka_period);
FNIC_FIP_DBG(KERN_INFO,
- fnic->host,
- fnic->fnic_num,
+ fnic,
"change fka to %d",
iport->selected_fcf.fka_adv_period);
}
@@ -362,7 +356,7 @@ void fnic_fcoe_start_flogi(struct fnic *
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FIP_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_ERR, fnic,
"Failed to allocate frame to start FIP FLOGI");
return;
}
@@ -415,7 +409,7 @@ void fnic_fcoe_start_flogi(struct fnic *
oxid = fdls_alloc_oxid(iport, FNIC_FRAME_TYPE_FABRIC_FLOGI,
&iport->active_oxid_fabric_req);
if (oxid == FNIC_UNASSIGNED_OXID) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Failed to allocate OXID to send FIP FLOGI");
mempool_free(frame, fnic->frame_pool);
return;
@@ -427,7 +421,7 @@ void fnic_fcoe_start_flogi(struct fnic *
FNIC_STD_SET_NODE_NAME(&pflogi_req->flogi_desc.flogi.els.fl_wwnn,
iport->wwnn);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"FIP start FLOGI\n");
fnic_send_fip_frame(iport, frame, frame_size);
iport->fip.flogi_retry++;
@@ -457,11 +451,11 @@ void fnic_fcoe_process_flogi_resp(struct
struct fnic_stats *fnic_stats = &fnic->fnic_stats;
struct fc_frame_header *fchdr = &flogi_rsp->rsp_desc.flogi.fchdr;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p FIP FLOGI rsp\n", fnic);
desc_len = be16_to_cpu(flogi_rsp->fip.fip_dl_len);
if (desc_len != 38) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Invalid Descriptor List len (%x). Dropping frame\n",
desc_len);
return;
@@ -471,7 +465,7 @@ void fnic_fcoe_process_flogi_resp(struct
&& (flogi_rsp->rsp_desc.fd_desc.fip_dlen == 36))
|| !((flogi_rsp->mac_desc.fd_desc.fip_dtype == 2)
&& (flogi_rsp->mac_desc.fd_desc.fip_dlen == 2))) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Dropping frame invalid type and len mix\n");
return;
}
@@ -484,7 +478,7 @@ void fnic_fcoe_process_flogi_resp(struct
|| (s_id != FC_FID_FLOGI)
|| (frame_type != FNIC_FABRIC_FLOGI_RSP)
|| (fchdr->fh_type != 0x01)) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Dropping invalid frame: s_id %x F %x R %x t %x OX_ID %x\n",
s_id, fchdr->fh_f_ctl[0], fchdr->fh_r_ctl,
fchdr->fh_type, FNIC_STD_GET_OX_ID(fchdr));
@@ -492,7 +486,7 @@ void fnic_fcoe_process_flogi_resp(struct
}
if (iport->fip.state == FDLS_FIP_FLOGI_STARTED) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p rsp for pending FLOGI\n", fnic);
oxid = FNIC_STD_GET_OX_ID(fchdr);
@@ -502,8 +496,7 @@ void fnic_fcoe_process_flogi_resp(struct
if ((be16_to_cpu(flogi_rsp->fip.fip_dl_len) == FIP_FLOGI_LEN)
&& (flogi_rsp->rsp_desc.flogi.els.fl_cmd == ELS_LS_ACC)) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p FLOGI success\n", fnic);
memcpy(iport->fpma, flogi_rsp->mac_desc.fd_mac, ETH_ALEN);
iport->fcid =
@@ -519,8 +512,7 @@ void fnic_fcoe_process_flogi_resp(struct
if (fnic_fdls_register_portid(iport, iport->fcid, NULL)
!= 0) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p flogi registration failed\n",
fnic);
return;
@@ -528,8 +520,8 @@ void fnic_fcoe_process_flogi_resp(struct
iport->fip.state = FDLS_FIP_FLOGI_COMPLETE;
iport->state = FNIC_IPORT_STATE_FABRIC_DISC;
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num, "iport->state:%d\n",
+ FNIC_FIP_DBG(KERN_INFO, fnic,
+ "iport->state:%d\n",
iport->state);
fnic_fdls_disc_start(iport);
if (!((iport->selected_fcf.ka_disabled)
@@ -575,7 +567,7 @@ void fnic_common_fip_cleanup(struct fnic
if (!iport->usefip)
return;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p fip cleanup\n", fnic);
iport->fip.state = FDLS_FIP_INIT;
@@ -617,7 +609,7 @@ void fnic_fcoe_process_cvl(struct fnic *
int found = false;
int max_count = 0;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p clear virtual link handler\n", fnic);
if (!((cvl_msg->fcf_mac_desc.fd_desc.fip_dtype == 2)
@@ -625,7 +617,7 @@ void fnic_fcoe_process_cvl(struct fnic *
|| !((cvl_msg->name_desc.fd_desc.fip_dtype == 4)
&& (cvl_msg->name_desc.fd_desc.fip_dlen == 3))) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"invalid mix: ft %x fl %x ndt %x ndl %x",
cvl_msg->fcf_mac_desc.fd_desc.fip_dtype,
cvl_msg->fcf_mac_desc.fd_desc.fip_dlen,
@@ -640,8 +632,7 @@ void fnic_fcoe_process_cvl(struct fnic *
if (!((cvl_msg->vn_ports_desc[i].fd_desc.fip_dtype == 11)
&& (cvl_msg->vn_ports_desc[i].fd_desc.fip_dlen == 5))) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Invalid type and len mix type: %d len: %d\n",
cvl_msg->vn_ports_desc[i].fd_desc.fip_dtype,
cvl_msg->vn_ports_desc[i].fd_desc.fip_dlen);
@@ -664,12 +655,12 @@ void fnic_fcoe_process_cvl(struct fnic *
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
max_count++;
if (max_count >= FIP_FNIC_RESET_WAIT_COUNT) {
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"Rthr waited too long. Skipping handle link event %p\n",
fnic);
return;
}
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic reset in progress. Link event needs to wait %p",
fnic);
}
@@ -714,7 +705,7 @@ int fdls_fip_recv_frame(struct fnic *fni
return true;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Not a FIP Frame");
return false;
}
@@ -724,7 +715,7 @@ void fnic_work_on_fip_timer(struct work_
struct fnic *fnic = container_of(work, struct fnic, fip_timer_work);
struct fnic_iport_s *iport = &fnic->iport;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"FIP timeout\n");
if (iport->fip.state == FDLS_FIP_VLAN_DISCOVERY_STARTED) {
@@ -732,7 +723,7 @@ void fnic_work_on_fip_timer(struct work_
} else if (iport->fip.state == FDLS_FIP_FCF_DISCOVERY_STARTED) {
u8 zmac[ETH_ALEN] = { 0, 0, 0, 0, 0, 0 };
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"FCF Discovery timeout\n");
if (memcmp(iport->selected_fcf.fcf_mac, zmac, ETH_ALEN) != 0) {
@@ -754,13 +745,13 @@ void fnic_work_on_fip_timer(struct work_
round_jiffies(fcf_tov));
}
} else {
- FNIC_FIP_DBG(KERN_INFO, fnic->host,
- fnic->fnic_num, "FCF Discovery timeout\n");
+ FNIC_FIP_DBG(KERN_INFO, fnic,
+ "FCF Discovery timeout\n");
fnic_vlan_discovery_timeout(fnic);
}
} else if (iport->fip.state == FDLS_FIP_FLOGI_STARTED) {
fdls_schedule_oxid_free(iport, &iport->active_oxid_fabric_req);
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"FLOGI timeout\n");
if (iport->fip.flogi_retry < fnic->config.flogi_retries)
fnic_fcoe_start_flogi(fnic);
@@ -807,7 +798,7 @@ void fnic_handle_enode_ka_timer(struct t
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FIP_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send enode ka");
return;
}
@@ -828,7 +819,7 @@ void fnic_handle_enode_ka_timer(struct t
memcpy(penode_ka->eth.h_dest, iport->selected_fcf.fcf_mac, ETH_ALEN);
memcpy(penode_ka->mac_desc.fd_mac, iport->hwmac, ETH_ALEN);
- FNIC_FIP_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_DEBUG, fnic,
"Handle enode KA timer\n");
fnic_send_fip_frame(iport, frame, frame_size);
enode_ka_tov = jiffies
@@ -861,7 +852,7 @@ void fnic_handle_vn_ka_timer(struct time
frame = fdls_alloc_frame(iport);
if (frame == NULL) {
- FNIC_FIP_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_ERR, fnic,
"Failed to allocate frame to send vn ka");
return;
}
@@ -887,7 +878,7 @@ void fnic_handle_vn_ka_timer(struct time
memcpy(pvn_port_ka->vn_port_desc.fd_fc_id, fcid, 3);
FNIC_STD_SET_NPORT_NAME(&pvn_port_ka->vn_port_desc.fd_wwpn, iport->wwpn);
- FNIC_FIP_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_DEBUG, fnic,
"Handle vnport KA timer\n");
fnic_send_fip_frame(iport, frame, frame_size);
vn_ka_tov = jiffies + msecs_to_jiffies(FIP_VN_KA_PERIOD);
@@ -977,7 +968,7 @@ void fnic_work_on_fcs_ka_timer(struct wo
*fnic = container_of(work, struct fnic, fip_timer_work);
struct fnic_iport_s *iport = &fnic->iport;
- FNIC_FIP_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FIP_DBG(KERN_INFO, fnic,
"fnic 0x%p fcs ka timeout\n", fnic);
fnic_common_fip_cleanup(fnic);
--- a/drivers/scsi/fnic/fip.h
+++ b/drivers/scsi/fnic/fip.h
@@ -142,7 +142,7 @@ fnic_debug_dump_fip_frame(struct fnic *f
u16 op = be16_to_cpu(fiph->fip_op);
u8 sub = fiph->fip_subcode;
- FNIC_FCS_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_DEBUG, fnic,
"FIP %s packet contents: op: 0x%x sub: 0x%x (len = %d)",
pfx, op, sub, len);
--- a/drivers/scsi/fnic/fnic.h
+++ b/drivers/scsi/fnic/fnic.h
@@ -144,6 +144,9 @@
#define PCI_SUBDEVICE_ID_CISCO_HELSINKI 0x02e4 /* VIC 15235 */
#define PCI_SUBDEVICE_ID_CISCO_GOTHENBURG 0x02f2 /* VIC 15425 */
+#define IS_FNIC_FCP_INITIATOR(fnic) (fnic->role == FNIC_ROLE_FCP_INITIATOR)
+#define IS_FNIC_NVME_INITIATOR(fnic) (fnic->role == FNIC_ROLE_NVME_INITIATOR)
+
struct fnic_pcie_device {
u32 device;
u8 *desc;
@@ -240,6 +243,9 @@ extern struct work_struct reset_fnic_wor
#define FNIC_FCS_LOGGING 0x02
#define FNIC_SCSI_LOGGING 0x04
#define FNIC_ISR_LOGGING 0x08
+#define FNIC_FDLS_LOGGING 0x10
+#define FNIC_NVME_LOGGING 0x20
+#define FNIC_FIP_LOGGING 0x40
#define FNIC_CHECK_LOGGING(LEVEL, CMD) \
do { \
@@ -249,38 +255,39 @@ do { \
} while (0); \
} while (0)
-#define FNIC_MAIN_DBG(kern_level, host, fnic_num, fmt, args...) \
- FNIC_CHECK_LOGGING(FNIC_MAIN_LOGGING, \
- shost_printk(kern_level, host, \
- "fnic<%d>: %s: %d: " fmt, fnic_num,\
- __func__, __LINE__, ##args);)
-
-#define FNIC_FCS_DBG(kern_level, host, fnic_num, fmt, args...) \
- FNIC_CHECK_LOGGING(FNIC_FCS_LOGGING, \
- shost_printk(kern_level, host, \
- "fnic<%d>: %s: %d: " fmt, fnic_num,\
- __func__, __LINE__, ##args);)
-
-#define FNIC_FIP_DBG(kern_level, host, fnic_num, fmt, args...) \
- FNIC_CHECK_LOGGING(FNIC_FCS_LOGGING, \
- shost_printk(kern_level, host, \
- "fnic<%d>: %s: %d: " fmt, fnic_num,\
- __func__, __LINE__, ##args);)
-
-#define FNIC_SCSI_DBG(kern_level, host, fnic_num, fmt, args...) \
- FNIC_CHECK_LOGGING(FNIC_SCSI_LOGGING, \
- shost_printk(kern_level, host, \
- "fnic<%d>: %s: %d: " fmt, fnic_num,\
- __func__, __LINE__, ##args);)
-
-#define FNIC_ISR_DBG(kern_level, host, fnic_num, fmt, args...) \
- FNIC_CHECK_LOGGING(FNIC_ISR_LOGGING, \
- shost_printk(kern_level, host, \
- "fnic<%d>: %s: %d: " fmt, fnic_num,\
- __func__, __LINE__, ##args);)
+#define fnic_printk(kern_level, fnic, fmt, ...) \
+ (IS_FNIC_FCP_INITIATOR(fnic) ? \
+ shost_printk(kern_level, fnic->host, "fnic<%d>: %s: %d: " fmt, \
+ fnic->fnic_num, __func__, __LINE__, ##__VA_ARGS__) : \
+ printk(kern_level "fnic<%d>: %s: %d: " fmt, fnic->fnic_num, \
+ __func__, __LINE__, ##__VA_ARGS__))
+
+#define FNIC_MAIN_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_MAIN_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
+
+#define FNIC_FCS_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_FCS_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
+
+#define FNIC_FIP_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_FIP_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
+
+#define FNIC_SCSI_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_SCSI_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
+
+#define FNIC_ISR_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_ISR_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
+
+#define FNIC_NVME_DBG(kern_level, fnic, fmt, args...) \
+ FNIC_CHECK_LOGGING(FNIC_NVME_LOGGING, \
+ fnic_printk(kern_level, fnic, fmt, ##args);)
-#define FNIC_MAIN_NOTE(kern_level, host, fmt, args...) \
- shost_printk(kern_level, host, fmt, ##args)
+#define FNIC_MAIN_NOTE(kern_level, fnic, fmt, args...) \
+ fnic_printk(kern_level, fnic, fmt, ##args)
#define FNIC_WQ_COPY_MAX 64
#define FNIC_WQ_MAX 1
@@ -325,6 +332,7 @@ enum fnic_state {
enum fnic_role_e {
FNIC_ROLE_FCP_INITIATOR = 0,
+ FNIC_ROLE_NVME_INITIATOR,
};
enum fnic_evt {
@@ -595,7 +603,7 @@ fnic_debug_dump(struct fnic *fnic, uint8
int i;
for (i = 0; i < len; i = i+8) {
- FNIC_FCS_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"%d: %02x %02x %02x %02x %02x %02x %02x %02x", i / 8,
u8arr[i + 0], u8arr[i + 1], u8arr[i + 2], u8arr[i + 3],
u8arr[i + 4], u8arr[i + 5], u8arr[i + 6], u8arr[i + 7]);
@@ -610,7 +618,7 @@ fnic_debug_dump_fc_frame(struct fnic *fn
s_id = ntoh24(fchdr->fh_s_id);
d_id = ntoh24(fchdr->fh_d_id);
- FNIC_FCS_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"%s packet contents: sid/did/type/oxid = 0x%x/0x%x/0x%x/0x%x (len = %d)\n",
pfx, s_id, d_id, fchdr->fh_type,
FNIC_STD_GET_OX_ID(fchdr), len);
--- a/drivers/scsi/fnic/fnic_fcs.c
+++ b/drivers/scsi/fnic/fnic_fcs.c
@@ -39,7 +39,7 @@ static uint8_t FCOE_ALL_FCF_MAC[6] = FC_
static inline void fnic_fdls_set_fcoe_srcmac(struct fnic *fnic,
uint8_t *src_mac)
{
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Setting src mac: %02x:%02x:%02x:%02x:%02x:%02x",
src_mac[0], src_mac[1], src_mac[2], src_mac[3],
src_mac[4], src_mac[5]);
@@ -54,7 +54,7 @@ static inline void fnic_fdls_set_fcoe_sr
static inline void fnic_fdls_set_fcoe_dstmac(struct fnic *fnic,
uint8_t *dst_mac)
{
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Setting dst mac: %02x:%02x:%02x:%02x:%02x:%02x",
dst_mac[0], dst_mac[1], dst_mac[2], dst_mac[3],
dst_mac[4], dst_mac[5]);
@@ -82,7 +82,7 @@ void fnic_fdls_link_status_change(struct
{
struct fnic_iport_s *iport = &fnic->iport;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"link up: %d, usefip: %d", linkup, iport->usefip);
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
@@ -90,12 +90,12 @@ void fnic_fdls_link_status_change(struct
if (linkup) {
if (iport->usefip) {
iport->state = FNIC_IPORT_STATE_FIP;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"link up: %d, usefip: %d", linkup, iport->usefip);
fnic_fcoe_send_vlan_req(fnic);
} else {
iport->state = FNIC_IPORT_STATE_FABRIC_DISC;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iport->state: %d", iport->state);
fnic_fdls_disc_start(iport);
}
@@ -125,13 +125,13 @@ void fnic_fdls_learn_fcoe_macs(struct fn
memcpy(&fcmac[3], fcid, 3);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"learn fcoe: dst_mac: %02x:%02x:%02x:%02x:%02x:%02x",
ethhdr->h_dest[0], ethhdr->h_dest[1],
ethhdr->h_dest[2], ethhdr->h_dest[3],
ethhdr->h_dest[4], ethhdr->h_dest[5]);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"learn fcoe: fc_mac: %02x:%02x:%02x:%02x:%02x:%02x",
fcmac[0], fcmac[1], fcmac[2], fcmac[3], fcmac[4],
fcmac[5]);
@@ -149,7 +149,7 @@ void fnic_fdls_init(struct fnic *fnic, i
iport->fnic = fnic;
iport->usefip = usefip;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"iportsrcmac: %02x:%02x:%02x:%02x:%02x:%02x",
iport->hwmac[0], iport->hwmac[1], iport->hwmac[2],
iport->hwmac[3], iport->hwmac[4], iport->hwmac[5]);
@@ -168,14 +168,14 @@ void fnic_handle_link(struct work_struct
int max_count = 0;
if (vnic_dev_get_intr_mode(fnic->vdev) != VNIC_DEV_INTR_MODE_MSI)
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Interrupt mode is not MSI\n");
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
if (fnic->stop_rx_link_events) {
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Stop link rx events\n");
return;
}
@@ -184,10 +184,10 @@ void fnic_handle_link(struct work_struct
if ((fnic->state != FNIC_IN_ETH_MODE)
&& (fnic->state != FNIC_IN_FC_MODE)) {
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic in transitional state: %d. link up: %d ignored",
fnic->state, vnic_dev_link_status(fnic->vdev));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Current link status: %d iport state: %d\n",
fnic->link_status, fnic->iport.state);
return;
@@ -199,36 +199,36 @@ void fnic_handle_link(struct work_struct
fnic->link_down_cnt = vnic_dev_link_down_cnt(fnic->vdev);
while (fnic->reset_in_progress == IN_PROGRESS) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic reset in progress. Link event needs to wait\n");
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"waiting for reset completion\n");
wait_for_completion_timeout(&fnic->reset_completion_wait,
msecs_to_jiffies(5000));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"woken up from reset completion wait\n");
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
max_count++;
if (max_count >= MAX_RESET_WAIT_COUNT) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Rstth waited for too long. Skipping handle link event\n");
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
return;
}
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Marking fnic reset in progress\n");
fnic->reset_in_progress = IN_PROGRESS;
if ((vnic_dev_get_intr_mode(fnic->vdev) != VNIC_DEV_INTR_MODE_MSI) ||
(fnic->link_status != old_link_status)) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"old link status: %d link status: %d\n",
old_link_status, (int) fnic->link_status);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"old down count %d down count: %d\n",
old_link_down_cnt, (int) fnic->link_down_cnt);
}
@@ -237,36 +237,36 @@ void fnic_handle_link(struct work_struct
if (!fnic->link_status) {
/* DOWN -> DOWN */
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"down->down\n");
} else {
if (old_link_down_cnt != fnic->link_down_cnt) {
/* UP -> DOWN -> UP */
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"up->down. Link down\n");
fnic_fdls_link_status_change(fnic, 0);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"down->up. Link up\n");
fnic_fdls_link_status_change(fnic, 1);
} else {
/* UP -> UP */
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"up->up\n");
}
}
} else if (fnic->link_status) {
/* DOWN -> UP */
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"down->up. Link up\n");
fnic_fdls_link_status_change(fnic, 1);
} else {
/* UP -> DOWN */
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"up->down. Link down\n");
fnic_fdls_link_status_change(fnic, 0);
}
@@ -275,7 +275,7 @@ void fnic_handle_link(struct work_struct
fnic->reset_in_progress = NOT_IN_PROGRESS;
complete(&fnic->reset_completion_wait);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Marking fnic reset completion\n");
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
}
@@ -302,7 +302,7 @@ void fnic_handle_frame(struct work_struc
*/
if (fnic->state != FNIC_IN_FC_MODE &&
fnic->state != FNIC_IN_ETH_MODE) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Cannot process frame in transitional state\n");
spin_unlock_irqrestore(&fnic->fnic_lock, fnic->lock_flags);
return;
@@ -328,7 +328,7 @@ void fnic_handle_fip_frame(struct work_s
struct fnic_frame_list *cur_frame, *next;
struct fnic *fnic = container_of(work, struct fnic, fip_frame_work);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Processing FIP frame\n");
spin_lock_irqsave(&fnic->fnic_lock, fnic->lock_flags);
@@ -407,7 +407,7 @@ void fnic_update_mac_locked(struct fnic
if (ether_addr_equal(data, new))
return;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Update MAC: %u\n", *new);
if (!is_zero_ether_addr(data) && !ether_addr_equal(data, ctl))
@@ -477,7 +477,7 @@ static void fnic_rq_cmpl_frame_recv(stru
if (!fcs_ok) {
atomic64_inc(&fnic_stats->misc_stats.frame_errors);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic 0x%p fcs error. Dropping packet.\n", fnic);
goto drop;
}
@@ -487,21 +487,21 @@ static void fnic_rq_cmpl_frame_recv(stru
if (fnic_import_rq_eth_pkt(fnic, fp))
return;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Dropping h_proto 0x%x",
be16_to_cpu(eh->h_proto));
goto drop;
}
} else {
/* wrong CQ type */
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic rq_cmpl wrong cq type x%x\n", type);
goto drop;
}
if (!fcs_ok || packet_error || !fcoe_fnic_crc_ok || fcoe_enc_error) {
atomic64_inc(&fnic_stats->misc_stats.frame_errors);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fcoe %x fcsok %x pkterr %x ffco %x fee %x\n",
fcoe, fcs_ok, packet_error,
fcoe_fnic_crc_ok, fcoe_enc_error);
@@ -511,7 +511,7 @@ static void fnic_rq_cmpl_frame_recv(stru
spin_lock_irqsave(&fnic->fnic_lock, flags);
if (fnic->stop_rx_link_events) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic->stop_rx_link_events: %d\n",
fnic->stop_rx_link_events);
goto drop;
@@ -522,7 +522,7 @@ static void fnic_rq_cmpl_frame_recv(stru
frame_elem = mempool_alloc(fnic->frame_elem_pool,
GFP_ATOMIC | __GFP_ZERO);
if (!frame_elem) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Failed to allocate memory for frame elem");
goto drop;
}
@@ -567,7 +567,7 @@ int fnic_rq_cmpl_handler(struct fnic *fn
if (cur_work_done && fnic->stop_rx_link_events != 1) {
err = vnic_rq_fill(&fnic->rq[i], fnic_alloc_rq_frame);
if (err)
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"fnic_alloc_rq_frame can't alloc"
" frame\n");
}
@@ -593,7 +593,7 @@ int fnic_alloc_rq_frame(struct vnic_rq *
len = FNIC_FRAME_HT_ROOM;
buf = kmalloc(len, GFP_ATOMIC);
if (!buf) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Unable to allocate RQ buffer of size: %d\n", len);
return -ENOMEM;
}
@@ -601,7 +601,7 @@ int fnic_alloc_rq_frame(struct vnic_rq *
pa = dma_map_single(&fnic->pdev->dev, buf, len, DMA_FROM_DEVICE);
if (dma_mapping_error(&fnic->pdev->dev, pa)) {
ret = -ENOMEM;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"PCI mapping failed with error %d\n", ret);
goto free_buf;
}
@@ -642,7 +642,7 @@ static int fnic_send_frame(struct fnic *
if ((fnic_fc_trace_set_data(fnic->fnic_num,
FNIC_FC_SEND | 0x80, (char *) frame,
frame_len)) != 0) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic ctlr frame trace error");
}
@@ -650,7 +650,7 @@ static int fnic_send_frame(struct fnic *
if (!vnic_wq_desc_avail(wq)) {
dma_unmap_single(&fnic->pdev->dev, pa, frame_len, DMA_TO_DEVICE);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"vnic work queue descriptor is not available");
ret = -1;
goto fnic_send_frame_end;
@@ -707,12 +707,12 @@ fdls_send_fcoe_frame(struct fnic *fnic,
frame_elem = mempool_alloc(fnic->frame_elem_pool,
GFP_ATOMIC | __GFP_ZERO);
if (!frame_elem) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Failed to allocate memory for frame elem");
return -ENOMEM;
}
- FNIC_FCS_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Queueing FC frame: sid/did/type/oxid = 0x%x/0x%x/0x%x/0x%x\n",
ntoh24(fchdr->fh_s_id), ntoh24(fchdr->fh_d_id),
fchdr->fh_type, FNIC_STD_GET_OX_ID(fchdr));
@@ -778,7 +778,7 @@ void fnic_flush_tx(struct work_struct *w
struct fc_frame *fp;
struct fnic_frame_list *cur_frame, *next;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Flush queued frames");
list_for_each_entry_safe(cur_frame, next, &fnic->tx_queue, links) {
@@ -797,7 +797,7 @@ fnic_fdls_register_portid(struct fnic_ip
struct ethhdr *ethhdr;
int ret;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Setting port id: 0x%x fp: 0x%p fnic state: %d", port_id,
fp, fnic->state);
@@ -810,7 +810,7 @@ fnic_fdls_register_portid(struct fnic_ip
if (fnic->state == FNIC_IN_ETH_MODE || fnic->state == FNIC_IN_FC_MODE)
fnic->state = FNIC_IN_ETH_TRANS_FC_MODE;
else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Unexpected fnic state while processing FLOGI response\n");
return -1;
}
@@ -821,7 +821,7 @@ fnic_fdls_register_portid(struct fnic_ip
*/
ret = fnic_flogi_reg_handler(fnic, port_id);
if (ret < 0) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI registration error ret: %d fnic state: %d\n",
ret, fnic->state);
if (fnic->state == FNIC_IN_ETH_TRANS_FC_MODE)
@@ -831,7 +831,7 @@ fnic_fdls_register_portid(struct fnic_ip
}
iport->fabric.flags |= FNIC_FDLS_FPMA_LEARNT;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FLOGI registration success\n");
return 0;
}
@@ -911,7 +911,7 @@ fnic_fdls_add_tport(struct fnic_iport_s
struct fc_rport_identifiers ids;
struct rport_dd_data_s *rdd_data;
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Adding rport fcid: 0x%x", tport->fcid);
ids.node_name = tport->wwnn;
@@ -923,12 +923,12 @@ fnic_fdls_add_tport(struct fnic_iport_s
rport = fc_remote_port_add(fnic->host, 0, &ids);
spin_lock_irqsave(&fnic->fnic_lock, flags);
if (!rport) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Failed to add rport for tport: 0x%x", tport->fcid);
return;
}
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Added rport fcid: 0x%x", tport->fcid);
/* Mimic these assignments in queuecommand to avoid timing issues */
@@ -967,7 +967,7 @@ fnic_fdls_remove_tport(struct fnic_iport
fc_remote_port_delete(rport);
spin_lock_irqsave(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Deregistered and freed tport fcid: 0x%x from scsi transport fc",
tport->fcid);
@@ -994,7 +994,7 @@ void fnic_delete_fcp_tports(struct fnic
spin_lock_irqsave(&fnic->fnic_lock, flags);
list_for_each_entry_safe(tport, next, &fnic->iport.tport_list, links) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"removing fcp rport fcid: 0x%x", tport->fcid);
fdls_set_tport_state(tport, FDLS_TGT_STATE_OFFLINING);
fnic_del_tport_timer_sync(fnic, tport);
@@ -1021,36 +1021,36 @@ void fnic_tport_event_handler(struct wor
tport = cur_evt->arg1;
switch (cur_evt->event) {
case TGT_EV_RPORT_ADD:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Add rport event");
if (tport->state == FDLS_TGT_STATE_READY) {
fnic_fdls_add_tport(&fnic->iport,
(struct fnic_tport_s *) cur_evt->arg1, flags);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Target not ready. Add rport event dropped: 0x%x",
tport->fcid);
}
break;
case TGT_EV_RPORT_DEL:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Remove rport event");
if (tport->state == FDLS_TGT_STATE_OFFLINING) {
fnic_fdls_remove_tport(&fnic->iport,
(struct fnic_tport_s *) cur_evt->arg1, flags);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"remove rport event dropped tport fcid: 0x%x",
tport->fcid);
}
break;
case TGT_EV_TPORT_DELETE:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Delete tport event");
fdls_delete_tport(tport->iport, tport);
break;
default:
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Unknown tport event");
break;
}
@@ -1122,7 +1122,7 @@ void fnic_fcpio_reset(struct fnic *fnic)
if (unlikely(fnic->state == FNIC_IN_FC_TRANS_ETH_MODE)) {
/* fw reset is in progress, poll for its completion */
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"fnic is in unexpected state: %d for fw_reset\n",
fnic->state);
return;
@@ -1135,7 +1135,7 @@ void fnic_fcpio_reset(struct fnic *fnic)
fnic->fw_reset_done = &fw_reset_done;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Issuing fw reset\n");
if (fnic_fw_reset_handler(fnic)) {
spin_lock_irqsave(&fnic->fnic_lock, flags);
@@ -1143,14 +1143,14 @@ void fnic_fcpio_reset(struct fnic *fnic)
fnic->state = old_state;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
} else {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Waiting for fw completion\n");
time_remain = wait_for_completion_timeout(&fw_reset_done,
msecs_to_jiffies(FNIC_FW_RESET_TIMEOUT));
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"Woken up after fw completion timeout\n");
if (time_remain == 0) {
- FNIC_FCS_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_FCS_DBG(KERN_INFO, fnic,
"FW reset completion timed out after %d ms\n",
FNIC_FW_RESET_TIMEOUT);
}
--- a/drivers/scsi/fnic/fnic_isr.c
+++ b/drivers/scsi/fnic/fnic_isr.c
@@ -222,7 +222,7 @@ int fnic_request_intr(struct fnic *fnic)
fnic->msix[i].devname,
fnic->msix[i].devid);
if (err) {
- FNIC_ISR_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_ERR, fnic,
"request_irq failed with error: %d\n",
err);
fnic_free_intr(fnic);
@@ -250,10 +250,10 @@ int fnic_set_intr_mode_msix(struct fnic
* We need n RQs, m WQs, o Copy WQs, n+m+o CQs, and n+m+o+1 INTRs
* (last INTR is used for WQ/RQ errors and notification area)
*/
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"rq-array size: %d wq-array size: %d copy-wq array size: %d\n",
n, m, o);
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"rq_count: %d raw_wq_count: %d wq_copy_count: %d cq_count: %d\n",
fnic->rq_count, fnic->raw_wq_count,
fnic->wq_copy_count, fnic->cq_count);
@@ -265,17 +265,17 @@ int fnic_set_intr_mode_msix(struct fnic
vec_count = pci_alloc_irq_vectors(fnic->pdev, min_irqs, vecs,
PCI_IRQ_MSIX | PCI_IRQ_AFFINITY);
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"allocated %d MSI-X vectors\n",
vec_count);
if (vec_count > 0) {
if (vec_count < vecs) {
- FNIC_ISR_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_ERR, fnic,
"interrupts number mismatch: vec_count: %d vecs: %d\n",
vec_count, vecs);
if (vec_count < min_irqs) {
- FNIC_ISR_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_ERR, fnic,
"no interrupts for copy wq\n");
return 1;
}
@@ -287,7 +287,7 @@ int fnic_set_intr_mode_msix(struct fnic
fnic->wq_copy_count = vec_count - n - m - 1;
fnic->wq_count = fnic->raw_wq_count + fnic->wq_copy_count;
if (fnic->cq_count != vec_count - 1) {
- FNIC_ISR_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_ERR, fnic,
"CQ count: %d does not match MSI-X vector count: %d\n",
fnic->cq_count, vec_count);
fnic->cq_count = vec_count - 1;
@@ -295,23 +295,23 @@ int fnic_set_intr_mode_msix(struct fnic
fnic->intr_count = vec_count;
fnic->err_intr_offset = fnic->rq_count + fnic->wq_count;
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"rq_count: %d raw_wq_count: %d copy_wq_base: %d\n",
fnic->rq_count,
fnic->raw_wq_count, fnic->copy_wq_base);
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"wq_copy_count: %d wq_count: %d cq_count: %d\n",
fnic->wq_copy_count,
fnic->wq_count, fnic->cq_count);
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
- "intr_count: %d err_intr_offset: %u",
+ FNIC_ISR_DBG(KERN_INFO, fnic,
+ "intr_count: %d err_intr_offset: %u\n",
fnic->intr_count,
fnic->err_intr_offset);
vnic_dev_set_intr_mode(fnic->vdev, VNIC_DEV_INTR_MODE_MSIX);
- FNIC_ISR_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_INFO, fnic,
"fnic using MSI-X\n");
return 0;
}
@@ -351,7 +351,7 @@ int fnic_set_intr_mode(struct fnic *fnic
fnic->intr_count = 1;
fnic->err_intr_offset = 0;
- FNIC_ISR_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_DEBUG, fnic,
"Using MSI Interrupts\n");
vnic_dev_set_intr_mode(fnic->vdev, VNIC_DEV_INTR_MODE_MSI);
@@ -377,7 +377,7 @@ int fnic_set_intr_mode(struct fnic *fnic
fnic->cq_count = 3;
fnic->intr_count = 3;
- FNIC_ISR_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_ISR_DBG(KERN_DEBUG, fnic,
"Using Legacy Interrupts\n");
vnic_dev_set_intr_mode(fnic->vdev, VNIC_DEV_INTR_MODE_INTX);
--- a/drivers/scsi/fnic/fnic_main.c
+++ b/drivers/scsi/fnic/fnic_main.c
@@ -184,7 +184,7 @@ static void fnic_get_host_speed(struct S
u32 port_speed = vnic_dev_port_speed(fnic->vdev);
struct fnic_stats *fnic_stats = &fnic->fnic_stats;
- FNIC_MAIN_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_INFO, fnic,
"port_speed: %d Mbps", port_speed);
atomic64_set(&fnic_stats->misc_stats.port_speed_in_mbps, port_speed);
@@ -234,7 +234,7 @@ static void fnic_get_host_speed(struct S
fc_host_speed(shost) = FC_PORTSPEED_128GBIT;
break;
default:
- FNIC_MAIN_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_INFO, fnic,
"Unknown FC speed: %d Mbps", port_speed);
fc_host_speed(shost) = FC_PORTSPEED_UNKNOWN;
break;
@@ -260,7 +260,7 @@ static struct fc_host_statistics *fnic_g
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
if (ret) {
- FNIC_MAIN_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_DEBUG, fnic,
"fnic: Get vnic stats failed: 0x%x", ret);
return stats;
}
@@ -286,64 +286,66 @@ static struct fc_host_statistics *fnic_g
void fnic_dump_fchost_stats(struct Scsi_Host *host,
struct fc_host_statistics *stats)
{
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ struct fnic *fnic = *((struct fnic **) shost_priv(host));
+
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: seconds since last reset = %llu\n",
stats->seconds_since_last_reset);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: tx frames = %llu\n",
stats->tx_frames);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: tx words = %llu\n",
stats->tx_words);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: rx frames = %llu\n",
stats->rx_frames);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: rx words = %llu\n",
stats->rx_words);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: lip count = %llu\n",
stats->lip_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: nos count = %llu\n",
stats->nos_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: error frames = %llu\n",
stats->error_frames);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: dumped frames = %llu\n",
stats->dumped_frames);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: link failure count = %llu\n",
stats->link_failure_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: loss of sync count = %llu\n",
stats->loss_of_sync_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: loss of signal count = %llu\n",
stats->loss_of_signal_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: prim seq protocol err count = %llu\n",
stats->prim_seq_protocol_err_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: invalid tx word count= %llu\n",
stats->invalid_tx_word_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: invalid crc count = %llu\n",
stats->invalid_crc_count);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: fcp input requests = %llu\n",
stats->fcp_input_requests);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: fcp output requests = %llu\n",
stats->fcp_output_requests);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: fcp control requests = %llu\n",
stats->fcp_control_requests);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: fcp input megabytes = %llu\n",
stats->fcp_input_megabytes);
- FNIC_MAIN_NOTE(KERN_NOTICE, host,
+ FNIC_MAIN_NOTE(KERN_NOTICE, fnic,
"fnic: fcp output megabytes = %llu\n",
stats->fcp_output_megabytes);
return;
@@ -369,7 +371,7 @@ static void fnic_reset_host_stats(struct
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
if (ret) {
- FNIC_MAIN_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_DEBUG, fnic,
"fnic: Reset vnic stats failed"
" 0x%x", ret);
return;
@@ -682,16 +684,16 @@ void fnic_mq_map_queues_cpus(struct Scsi
struct blk_mq_queue_map *qmap = &host->tag_set.map[HCTX_TYPE_DEFAULT];
if (intr_mode == VNIC_DEV_INTR_MODE_MSI || intr_mode == VNIC_DEV_INTR_MODE_INTX) {
- FNIC_MAIN_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_ERR, fnic,
"intr_mode is not msix\n");
return;
}
- FNIC_MAIN_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_INFO, fnic,
"qmap->nr_queues: %d\n", qmap->nr_queues);
if (l_pdev == NULL) {
- FNIC_MAIN_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_MAIN_DBG(KERN_ERR, fnic,
"l_pdev is null\n");
return;
}
--- a/drivers/scsi/fnic/fnic_scsi.c
+++ b/drivers/scsi/fnic/fnic_scsi.c
@@ -148,7 +148,7 @@ unsigned int fnic_count_ioreqs(struct fn
fnic_scsi_io_iter(fnic, fnic_count_portid_ioreqs_iter,
&portid, &count);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"portid = 0x%x count = %u\n", portid, count);
return count;
}
@@ -180,7 +180,7 @@ fnic_count_lun_ioreqs(struct fnic *fnic,
fnic_scsi_io_iter(fnic, fnic_count_lun_ioreqs_iter,
scsi_device, &count);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"lun = %p count = %u\n", scsi_device, count);
return count;
}
@@ -268,7 +268,7 @@ int fnic_fw_reset_handler(struct fnic *f
if (!vnic_wq_copy_desc_avail(wq))
ret = -EAGAIN;
else {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"ioreq_count: %u\n", ioreq_count);
fnic_queue_wq_copy_desc_fw_reset(wq, SCSI_NO_TAG);
atomic64_inc(&fnic->fnic_stats.fw_stats.active_fw_reqs);
@@ -283,11 +283,11 @@ int fnic_fw_reset_handler(struct fnic *f
if (!ret) {
atomic64_inc(&fnic->fnic_stats.reset_stats.fw_resets);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"Issued fw reset\n");
} else {
fnic_clear_state_flags(fnic, FNIC_FLAGS_FWRESET);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Failed to issue fw reset\n");
}
@@ -326,13 +326,13 @@ int fnic_flogi_reg_handler(struct fnic *
fc_id, gw_mac,
fnic->iport.fpma,
iport->r_a_tov, iport->e_d_tov);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"FLOGI FIP reg issued fcid: 0x%x src %p dest %p\n",
fc_id, fnic->iport.fpma, gw_mac);
} else {
fnic_queue_wq_copy_desc_flogi_reg(wq, SCSI_NO_TAG,
format, fc_id, gw_mac);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"FLOGI reg issued fcid 0x%x dest %p\n",
fc_id, gw_mac);
}
@@ -413,7 +413,7 @@ static inline int fnic_queue_wq_copy_des
free_wq_copy_descs(fnic, wq, hwq);
if (unlikely(!vnic_wq_copy_desc_avail(wq))) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"fnic_queue_wq_copy_desc failure - no descriptors\n");
atomic64_inc(&misc_stats->io_cpwq_alloc_failures);
return SCSI_MLQUEUE_HOST_BUSY;
@@ -478,7 +478,7 @@ int fnic_queuecommand(struct Scsi_Host *
rport = starget_to_rport(scsi_target(sc->device));
if (!rport) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"returning DID_NO_CONNECT for IO as rport is NULL\n");
sc->result = DID_NO_CONNECT << 16;
done(sc);
@@ -487,7 +487,7 @@ int fnic_queuecommand(struct Scsi_Host *
ret = fc_remote_port_chkready(rport);
if (ret) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"rport is not ready\n");
atomic64_inc(&fnic_stats->misc_stats.tport_not_ready);
sc->result = ret;
@@ -501,7 +501,7 @@ int fnic_queuecommand(struct Scsi_Host *
if (iport->state != FNIC_IPORT_STATE_READY) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"returning DID_NO_CONNECT for IO as iport state: %d\n",
iport->state);
sc->result = DID_NO_CONNECT << 16;
@@ -515,13 +515,13 @@ int fnic_queuecommand(struct Scsi_Host *
rdd_data = rport->dd_data;
tport = rdd_data->tport;
if (!tport || (rdd_data->iport != iport)) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"dd_data not yet set in SCSI for rport portid: 0x%x\n",
rport->port_id);
tport = fnic_find_tport_by_fcid(iport, rport->port_id);
if (!tport) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"returning DID_BUS_BUSY for IO as tport not found for: 0x%x\n",
rport->port_id);
sc->result = DID_BUS_BUSY << 16;
@@ -544,7 +544,7 @@ int fnic_queuecommand(struct Scsi_Host *
if ((tport->state != FDLS_TGT_STATE_READY)
&& (tport->state != FDLS_TGT_STATE_ADISC)) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"returning DID_NO_CONNECT for IO as tport state: %d\n",
tport->state);
sc->result = DID_NO_CONNECT << 16;
@@ -564,7 +564,7 @@ int fnic_queuecommand(struct Scsi_Host *
if (unlikely(fnic_chk_state_flags_locked(fnic, FNIC_FLAGS_FWRESET))) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"fnic flags FW reset: 0x%lx. Returning SCSI_MLQUEUE_HOST_BUSY\n",
fnic->state_flags);
return SCSI_MLQUEUE_HOST_BUSY;
@@ -706,7 +706,7 @@ out:
atomic_dec(&tport->in_flight);
if (lun0_delay) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"LUN0 delay\n");
mdelay(LUN0_DELAY_TIME);
}
@@ -746,12 +746,12 @@ static int fnic_fcpio_fw_reset_cmpl_hand
if (fnic->state == FNIC_IN_FC_TRANS_ETH_MODE) {
/* Check status of reset completion */
if (!hdr_status) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"reset cmpl success\n");
/* Ready to send flogi out */
fnic->state = FNIC_IN_ETH_MODE;
} else {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"reset failed with header status: %s\n",
fnic_fcpio_status_to_str(hdr_status));
@@ -760,7 +760,7 @@ static int fnic_fcpio_fw_reset_cmpl_hand
ret = -1;
}
} else {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Unexpected state while processing reset completion: %s\n",
fnic_state_to_str(fnic->state));
atomic64_inc(&reset_stats->fw_reset_failures);
@@ -812,19 +812,18 @@ static int fnic_fcpio_flogi_reg_cmpl_han
/* Check flogi registration completion status */
if (!hdr_status) {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"FLOGI reg succeeded\n");
fnic->state = FNIC_IN_FC_MODE;
} else {
- FNIC_SCSI_DBG(KERN_DEBUG,
- fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fnic flogi reg failed: %s\n",
fnic_fcpio_status_to_str(hdr_status));
fnic->state = FNIC_IN_ETH_MODE;
ret = -1;
}
} else {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Unexpected fnic state %s while"
" processing flogi reg completion\n",
fnic_state_to_str(fnic->state));
@@ -935,19 +934,19 @@ static void fnic_fcpio_icmnd_cmpl_handle
hwq = blk_mq_unique_tag_to_hwq(mqtag);
if (hwq != cq_index) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x cq index: %d ",
hwq, mqtag, tag, cq_index);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hdr status: %s icmnd completion on the wrong queue\n",
fnic_fcpio_status_to_str(hdr_status));
}
if (tag >= fnic->fnic_max_tag_id) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x cq index: %d ",
hwq, mqtag, tag, cq_index);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hdr status: %s Out of range tag\n",
fnic_fcpio_status_to_str(hdr_status));
return;
@@ -959,7 +958,7 @@ static void fnic_fcpio_icmnd_cmpl_handle
if (!sc) {
atomic64_inc(&fnic_stats->io_stats.sc_null);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"icmnd_cmpl sc is null - "
"hdr status = %s tag = 0x%x desc = 0x%p\n",
fnic_fcpio_status_to_str(hdr_status), id, desc);
@@ -987,7 +986,7 @@ static void fnic_fcpio_icmnd_cmpl_handle
atomic64_inc(&fnic_stats->io_stats.ioreq_null);
fnic_priv(sc)->flags |= FNIC_IO_REQ_NULL;
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"icmnd_cmpl io_req is null - "
"hdr status = %s tag = 0x%x sc 0x%p\n",
fnic_fcpio_status_to_str(hdr_status), id, sc);
@@ -1014,7 +1013,7 @@ static void fnic_fcpio_icmnd_cmpl_handle
if(FCPIO_ABORTED == hdr_status)
fnic_priv(sc)->flags |= FNIC_IO_ABORTED;
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"icmnd_cmpl abts pending "
"hdr status = %s tag = 0x%x sc = 0x%p "
"scsi_status = %x residual = %d\n",
@@ -1046,7 +1045,7 @@ static void fnic_fcpio_icmnd_cmpl_handle
if (icmnd_cmpl->scsi_status == SAM_STAT_TASK_SET_FULL)
atomic64_inc(&fnic_stats->misc_stats.queue_fulls);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"xfer_len: %llu", xfer_len);
break;
@@ -1109,7 +1108,7 @@ static void fnic_fcpio_icmnd_cmpl_handle
if (hdr_status != FCPIO_SUCCESS) {
atomic64_inc(&fnic_stats->io_stats.io_failures);
- shost_printk(KERN_ERR, fnic->host, "hdr status = %s\n",
+ fnic_printk(KERN_ERR, fnic, "hdr status = %s\n",
fnic_fcpio_status_to_str(hdr_status));
}
@@ -1202,27 +1201,27 @@ static void fnic_fcpio_itmf_cmpl_handler
hwq = blk_mq_unique_tag_to_hwq(id & FNIC_TAG_MASK);
if (hwq != cq_index) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x cq index: %d ",
hwq, mqtag, tag, cq_index);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hdr status: %s ITMF completion on the wrong queue\n",
fnic_fcpio_status_to_str(hdr_status));
}
if (tag > fnic->fnic_max_tag_id) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x cq index: %d ",
hwq, mqtag, tag, cq_index);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hdr status: %s Tag out of range\n",
fnic_fcpio_status_to_str(hdr_status));
return;
} else if ((tag == fnic->fnic_max_tag_id) && !(id & FNIC_TAG_DEV_RST)) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x cq index: %d ",
hwq, mqtag, tag, cq_index);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hdr status: %s Tag out of range\n",
fnic_fcpio_status_to_str(hdr_status));
return;
@@ -1245,7 +1244,7 @@ static void fnic_fcpio_itmf_cmpl_handler
if (!sc) {
atomic64_inc(&fnic_stats->io_stats.sc_null);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"itmf_cmpl sc is null - hdr status = %s tag = 0x%x\n",
fnic_fcpio_status_to_str(hdr_status), tag);
return;
@@ -1257,7 +1256,7 @@ static void fnic_fcpio_itmf_cmpl_handler
atomic64_inc(&fnic_stats->io_stats.ioreq_null);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
fnic_priv(sc)->flags |= FNIC_IO_ABT_TERM_REQ_NULL;
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"itmf_cmpl io_req is null - "
"hdr status = %s tag = 0x%x sc 0x%p\n",
fnic_fcpio_status_to_str(hdr_status), tag, sc);
@@ -1268,7 +1267,7 @@ static void fnic_fcpio_itmf_cmpl_handler
if ((id & FNIC_TAG_ABORT) && (id & FNIC_TAG_DEV_RST)) {
/* Abort and terminate completion of device reset req */
/* REVISIT : Add asserts about various flags */
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x hst: %s Abt/term completion received\n",
hwq, mqtag, tag,
fnic_fcpio_status_to_str(hdr_status));
@@ -1280,7 +1279,7 @@ static void fnic_fcpio_itmf_cmpl_handler
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
} else if (id & FNIC_TAG_ABORT) {
/* Completion of abort cmd */
- shost_printk(KERN_DEBUG, fnic->host,
+ fnic_printk(KERN_DEBUG, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x Abort header status: %s\n",
hwq, mqtag, tag,
fnic_fcpio_status_to_str(hdr_status));
@@ -1295,7 +1294,7 @@ static void fnic_fcpio_itmf_cmpl_handler
&term_stats->terminate_fw_timeouts);
break;
case FCPIO_ITMF_REJECTED:
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"abort reject recd. id %d\n",
(int)(id & FNIC_TAG_MASK));
break;
@@ -1330,7 +1329,7 @@ static void fnic_fcpio_itmf_cmpl_handler
if (!(fnic_priv(sc)->flags & (FNIC_IO_ABORTED | FNIC_IO_DONE)))
atomic64_inc(&misc_stats->no_icmnd_itmf_cmpls);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"abts cmpl recd. id %d status %s\n",
(int)(id & FNIC_TAG_MASK),
fnic_fcpio_status_to_str(hdr_status));
@@ -1343,11 +1342,11 @@ static void fnic_fcpio_itmf_cmpl_handler
if (io_req->abts_done) {
complete(io_req->abts_done);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- shost_printk(KERN_INFO, fnic->host,
+ fnic_printk(KERN_INFO, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x Waking up abort thread\n",
hwq, mqtag, tag);
} else {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x hst: %s Completing IO\n",
hwq, mqtag,
tag, fnic_fcpio_status_to_str(hdr_status));
@@ -1378,7 +1377,7 @@ static void fnic_fcpio_itmf_cmpl_handler
}
} else if (id & FNIC_TAG_DEV_RST) {
/* Completion of device reset */
- shost_printk(KERN_INFO, fnic->host,
+ fnic_printk(KERN_INFO, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x DR hst: %s\n",
hwq, mqtag,
tag, fnic_fcpio_status_to_str(hdr_status));
@@ -1390,7 +1389,7 @@ static void fnic_fcpio_itmf_cmpl_handler
sc->device->host->host_no, id, sc,
jiffies_to_msecs(jiffies - start_time),
desc, 0, fnic_flags_and_state(sc));
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x hst: %s Terminate pending\n",
hwq, mqtag,
tag, fnic_fcpio_status_to_str(hdr_status));
@@ -1403,7 +1402,7 @@ static void fnic_fcpio_itmf_cmpl_handler
sc->device->host->host_no, id, sc,
jiffies_to_msecs(jiffies - start_time),
desc, 0, fnic_flags_and_state(sc));
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"dev reset cmpl recd after time out. "
"id %d status %s\n",
(int)(id & FNIC_TAG_MASK),
@@ -1412,7 +1411,7 @@ static void fnic_fcpio_itmf_cmpl_handler
}
fnic_priv(sc)->state = FNIC_IOREQ_CMD_COMPLETE;
fnic_priv(sc)->flags |= FNIC_DEV_RST_DONE;
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x hst: %s DR completion received\n",
hwq, mqtag,
tag, fnic_fcpio_status_to_str(hdr_status));
@@ -1421,7 +1420,7 @@ static void fnic_fcpio_itmf_cmpl_handler
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
} else {
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"%s: Unexpected itmf io state: hwq: %d tag 0x%x %s\n",
__func__, hwq, id, fnic_ioreq_state_to_str(fnic_priv(sc)->state));
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
@@ -1476,7 +1475,7 @@ static int fnic_fcpio_cmpl_handler(struc
break;
default:
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"firmware completion type %d\n",
desc->hdr.type);
break;
@@ -1537,7 +1536,7 @@ static bool fnic_cleanup_io_iter(struct
io_req = fnic_priv(sc)->io_req;
if (!io_req) {
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d mqtag: 0x%x tag: 0x%x flags: 0x%x No ioreq. Returning\n",
hwq, mqtag, tag, fnic_priv(sc)->flags);
return true;
@@ -1575,7 +1574,7 @@ static bool fnic_cleanup_io_iter(struct
mempool_free(io_req, fnic->io_req_pool);
sc->result = DID_TRANSPORT_DISRUPTED << 16;
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"mqtag: 0x%x tag: 0x%x sc: 0x%p duration = %lu DID_TRANSPORT_DISRUPTED\n",
mqtag, tag, sc, (jiffies - start_time));
@@ -1607,7 +1606,7 @@ static void fnic_cleanup_io(struct fnic
struct scsi_cmnd *sc = NULL;
io_count = fnic_count_all_ioreqs(fnic);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Outstanding ioreq count: %d active io count: %lld Waiting\n",
io_count,
atomic64_read(&fnic->fnic_stats.io_stats.active_ios));
@@ -1632,7 +1631,7 @@ static void fnic_cleanup_io(struct fnic
spin_unlock_irqrestore(&fnic->wq_copy_lock[0], flags);
while ((io_count = fnic_count_all_ioreqs(fnic))) {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Outstanding ioreq count: %d active io count: %lld Waiting\n",
io_count,
atomic64_read(&fnic->fnic_stats.io_stats.active_ios));
@@ -1688,7 +1687,7 @@ void fnic_wq_copy_cleanup_handler(struct
wq_copy_cleanup_scsi_cmd:
sc->result = DID_NO_CONNECT << 16;
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num, "wq_copy_cleanup_handler:"
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic, "wq_copy_cleanup_handler:"
" DID_NO_CONNECT\n");
FNIC_TRACE(fnic_wq_copy_cleanup_handler,
@@ -1732,7 +1731,7 @@ static inline int fnic_queue_abort_io_re
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
atomic_dec(&fnic->in_flight);
atomic_dec(&tport->in_flight);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fnic_queue_abort_io_req: failure: no descriptors\n");
atomic64_inc(&misc_stats->abts_cpwq_alloc_failures);
return 1;
@@ -1777,7 +1776,7 @@ static bool fnic_rport_abort_io_iter(str
hwq = blk_mq_unique_tag_to_hwq(abt_tag);
if (!sc) {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"sc is NULL abt_tag: 0x%x hwq: %d\n", abt_tag, hwq);
return true;
}
@@ -1791,7 +1790,7 @@ static bool fnic_rport_abort_io_iter(str
if ((fnic_priv(sc)->flags & FNIC_DEVICE_RESET) &&
!(fnic_priv(sc)->flags & FNIC_DEV_RST_ISSUED)) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d abt_tag: 0x%x flags: 0x%x Device reset is not pending\n",
hwq, abt_tag, fnic_priv(sc)->flags);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
@@ -1808,16 +1807,16 @@ static bool fnic_rport_abort_io_iter(str
}
if (io_req->abts_done) {
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"fnic_rport_exch_reset: io_req->abts_done is set state is %s\n",
fnic_ioreq_state_to_str(fnic_priv(sc)->state));
}
if (!(fnic_priv(sc)->flags & FNIC_IO_ISSUED)) {
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"rport_exch_reset IO not yet issued %p abt_tag 0x%x",
sc, abt_tag);
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"flags %x state %d\n", fnic_priv(sc)->flags,
fnic_priv(sc)->state);
}
@@ -1828,13 +1827,13 @@ static bool fnic_rport_abort_io_iter(str
if (fnic_priv(sc)->flags & FNIC_DEVICE_RESET) {
atomic64_inc(&reset_stats->device_reset_terminates);
abt_tag |= FNIC_TAG_DEV_RST;
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"dev reset sc 0x%p\n", sc);
}
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fnic_rport_exch_reset: dev rst sc 0x%p\n", sc);
WARN_ON_ONCE(io_req->abts_done);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fnic_rport_reset_exch: Issuing abts\n");
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
@@ -1852,7 +1851,7 @@ static bool fnic_rport_abort_io_iter(str
* lun reset
*/
spin_lock_irqsave(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d abt_tag: 0x%x flags: 0x%x Queuing abort failed\n",
hwq, abt_tag, fnic_priv(sc)->flags);
if (fnic_priv(sc)->state == FNIC_IOREQ_ABTS_PENDING)
@@ -1883,7 +1882,7 @@ void fnic_rport_exch_reset(struct fnic *
.term_cnt = 0,
};
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fnic rport exchange reset for tport: 0x%06x\n",
port_id);
@@ -1891,7 +1890,7 @@ void fnic_rport_exch_reset(struct fnic *
return;
io_count = fnic_count_ioreqs(fnic, port_id);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Starting terminates: rport:0x%x portid-io-count: %d active-io-count: %lld\n",
port_id, io_count,
atomic64_read(&fnic->fnic_stats.io_stats.active_ios));
@@ -1917,7 +1916,7 @@ void fnic_rport_exch_reset(struct fnic *
while ((io_count = fnic_count_ioreqs(fnic, port_id)))
schedule_timeout(msecs_to_jiffies(1000));
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"rport: 0x%x remaining portid-io-count: %d ",
port_id, io_count);
}
@@ -2045,10 +2044,10 @@ int fnic_abort_cmd(struct scsi_cmnd *sc)
tport = rdd_data->tport;
if (!tport) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Abort cmd called after tport delete! rport fcid: 0x%x",
rport->port_id);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"lun: %llu hwq: 0x%x mqtag: 0x%x Op: 0x%x flags: 0x%x\n",
sc->device->lun, hwq, mqtag,
sc->cmnd[0], fnic_priv(sc)->flags);
@@ -2057,18 +2056,18 @@ int fnic_abort_cmd(struct scsi_cmnd *sc)
goto fnic_abort_cmd_end;
}
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"Abort cmd called rport fcid: 0x%x lun: %llu hwq: 0x%x mqtag: 0x%x",
rport->port_id, sc->device->lun, hwq, mqtag);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"Op: 0x%x flags: 0x%x\n",
sc->cmnd[0],
fnic_priv(sc)->flags);
if (iport->state != FNIC_IPORT_STATE_READY) {
atomic64_inc(&fnic_stats->misc_stats.iport_not_ready);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"iport NOT in READY state");
ret = FAILED;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
@@ -2077,7 +2076,7 @@ int fnic_abort_cmd(struct scsi_cmnd *sc)
if ((tport->state != FDLS_TGT_STATE_READY) &&
(tport->state != FDLS_TGT_STATE_ADISC)) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"tport state: %d\n", tport->state);
ret = FAILED;
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
@@ -2128,7 +2127,7 @@ int fnic_abort_cmd(struct scsi_cmnd *sc)
else
atomic64_inc(&abts_stats->abort_issued_greater_than_60_sec);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"CDB Opcode: 0x%02x Abort issued time: %lu msec\n",
sc->cmnd[0], abt_issued_time);
/*
@@ -2219,7 +2218,7 @@ int fnic_abort_cmd(struct scsi_cmnd *sc)
if (!(fnic_priv(sc)->flags & (FNIC_IO_ABORTED | FNIC_IO_DONE))) {
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Issuing host reset due to out of order IO\n");
ret = FAILED;
@@ -2267,7 +2266,7 @@ fnic_abort_cmd_end:
(u64)sc->cmnd[4] << 8 | sc->cmnd[5]),
fnic_flags_and_state(sc));
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Returning from abort cmd type %x %s\n", task_req,
(ret == SUCCESS) ?
"SUCCESS" : "FAILED");
@@ -2308,7 +2307,7 @@ static inline int fnic_queue_dr_io_req(s
free_wq_copy_descs(fnic, wq, hwq);
if (!vnic_wq_copy_desc_avail(wq)) {
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"queue_dr_io_req failure - no descriptors\n");
atomic64_inc(&misc_stats->devrst_cpwq_alloc_failures);
ret = -EAGAIN;
@@ -2376,7 +2375,7 @@ static bool fnic_pending_aborts_iter(str
* Found IO that is still pending with firmware and
* belongs to the LUN that we are resetting
*/
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Found IO in %s on lun\n",
fnic_ioreq_state_to_str(fnic_priv(sc)->state));
@@ -2386,14 +2385,14 @@ static bool fnic_pending_aborts_iter(str
}
if ((fnic_priv(sc)->flags & FNIC_DEVICE_RESET) &&
(!(fnic_priv(sc)->flags & FNIC_DEV_RST_ISSUED))) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"dev rst not pending sc 0x%p\n", sc);
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
return true;
}
if (io_req->abts_done)
- shost_printk(KERN_ERR, fnic->host,
+ fnic_printk(KERN_ERR, fnic,
"%s: io_req->abts_done is set state is %s\n",
__func__, fnic_ioreq_state_to_str(fnic_priv(sc)->state));
old_ioreq_state = fnic_priv(sc)->state;
@@ -2409,7 +2408,7 @@ static bool fnic_pending_aborts_iter(str
BUG_ON(io_req->abts_done);
if (fnic_priv(sc)->flags & FNIC_DEVICE_RESET) {
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"dev rst sc 0x%p\n", sc);
}
@@ -2431,7 +2430,7 @@ static bool fnic_pending_aborts_iter(str
fnic_priv(sc)->state = old_ioreq_state;
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
iter_data->ret = FAILED;
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"hwq: %d abt_tag: 0x%lx Abort could not be queued\n",
hwq, abt_tag);
return false;
@@ -2523,7 +2522,7 @@ static int fnic_clean_pending_aborts(str
ret = 1;
clean_pending_aborts_end:
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"exit status: %d\n", ret);
return ret;
}
@@ -2573,7 +2572,7 @@ int fnic_device_reset(struct scsi_cmnd *
rport = starget_to_rport(scsi_target(sc->device));
spin_lock_irqsave(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"fcid: 0x%x lun: %llu hwq: %d mqtag: 0x%x flags: 0x%x Device reset\n",
rport->port_id, sc->device->lun, hwq, mqtag,
fnic_priv(sc)->flags);
@@ -2581,7 +2580,7 @@ int fnic_device_reset(struct scsi_cmnd *
rdd_data = rport->dd_data;
tport = rdd_data->tport;
if (!tport) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Dev rst called after tport delete! rport fcid: 0x%x lun: %llu\n",
rport->port_id, sc->device->lun);
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
@@ -2590,7 +2589,7 @@ int fnic_device_reset(struct scsi_cmnd *
if (iport->state != FNIC_IPORT_STATE_READY) {
atomic64_inc(&fnic_stats->misc_stats.iport_not_ready);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"iport NOT in READY state");
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
goto fnic_device_reset_end;
@@ -2598,7 +2597,7 @@ int fnic_device_reset(struct scsi_cmnd *
if ((tport->state != FDLS_TGT_STATE_READY) &&
(tport->state != FDLS_TGT_STATE_ADISC)) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"tport state: %d\n", tport->state);
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
goto fnic_device_reset_end;
@@ -2661,7 +2660,7 @@ int fnic_device_reset(struct scsi_cmnd *
fnic_priv(sc)->lr_status = FCPIO_INVALID_CODE;
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num, "TAG %x\n", mqtag);
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic, "TAG %x\n", mqtag);
/*
* issue the device reset, if enqueue failed, clean up the ioreq
@@ -2712,13 +2711,13 @@ int fnic_device_reset(struct scsi_cmnd *
io_req = fnic_priv(sc)->io_req;
if (!io_req) {
spin_unlock_irqrestore(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"io_req is null mqtag 0x%x sc 0x%p\n", mqtag, sc);
goto fnic_device_reset_end;
}
if (exit_dr) {
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Host reset called for fnic. Exit device reset\n");
io_req->dr_done = NULL;
goto fnic_device_reset_clean;
@@ -2733,7 +2732,7 @@ int fnic_device_reset(struct scsi_cmnd *
*/
if (status == FCPIO_INVALID_CODE) {
atomic64_inc(&reset_stats->device_reset_timeouts);
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Device reset timed out\n");
fnic_priv(sc)->flags |= FNIC_DEV_RST_TIMED_OUT;
int_to_scsilun(sc->device->lun, &fc_lun);
@@ -2745,8 +2744,7 @@ int fnic_device_reset(struct scsi_cmnd *
/* Completed, but not successful, clean up the io_req, return fail */
if (status != FCPIO_SUCCESS) {
spin_lock_irqsave(&fnic->wq_copy_lock[hwq], flags);
- FNIC_SCSI_DBG(KERN_DEBUG,
- fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Device reset completed - failed\n");
io_req = fnic_priv(sc)->io_req;
goto fnic_device_reset_clean;
@@ -2762,7 +2760,7 @@ int fnic_device_reset(struct scsi_cmnd *
if (fnic_clean_pending_aborts(fnic, sc, new_sc)) {
spin_lock_irqsave(&fnic->wq_copy_lock[hwq], flags);
io_req = fnic_priv(sc)->io_req;
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Device reset failed: Cannot abort all IOs\n");
goto fnic_device_reset_clean;
}
@@ -2816,13 +2814,13 @@ fnic_device_reset_end:
ret = FAILED;
break;
}
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"Cannot clean up all IOs for the LUN\n");
schedule_timeout(msecs_to_jiffies(1000));
count++;
}
- FNIC_SCSI_DBG(KERN_DEBUG, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_DEBUG, fnic,
"Returning from device reset %s\n",
(ret == SUCCESS) ?
"SUCCESS" : "FAILED");
@@ -2857,13 +2855,13 @@ void fnic_reset(struct Scsi_Host *shost)
fnic = *((struct fnic **) shost_priv(shost));
reset_stats = &fnic->fnic_stats.reset_stats;
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"Issuing fnic reset\n");
atomic64_inc(&reset_stats->fnic_resets);
fnic_post_flogo_linkflap(fnic);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"Returning from fnic reset");
atomic64_inc(&reset_stats->fnic_reset_completions);
@@ -2874,7 +2872,7 @@ int fnic_issue_fc_host_lip(struct Scsi_H
int ret = 0;
struct fnic *fnic = *((struct fnic **) shost_priv(shost));
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"FC host lip issued");
ret = fnic_host_reset(shost);
@@ -2900,7 +2898,7 @@ int fnic_host_reset(struct Scsi_Host *sh
spin_lock_irqsave(&fnic->fnic_lock, flags);
if (fnic->reset_in_progress == IN_PROGRESS) {
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_WARNING, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_WARNING, fnic,
"Firmware reset in progress. Skipping another host reset\n");
return SUCCESS;
}
@@ -2938,7 +2936,7 @@ int fnic_host_reset(struct Scsi_Host *sh
}
spin_unlock_irqrestore(&fnic->fnic_lock, flags);
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"host reset return status: %d\n", ret);
return ret;
}
@@ -2978,7 +2976,7 @@ static bool fnic_abts_pending_iter(struc
* Found IO that is still pending with firmware and
* belongs to the LUN that we are resetting
*/
- FNIC_SCSI_DBG(KERN_INFO, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_INFO, fnic,
"hwq: %d tag: 0x%x Found IO in state: %s on lun\n",
hwq, tag,
fnic_ioreq_state_to_str(fnic_priv(sc)->state));
@@ -3032,7 +3030,7 @@ int fnic_eh_host_reset_handler(struct sc
struct Scsi_Host *shost = sc->device->host;
struct fnic *fnic = *((struct fnic **) shost_priv(shost));
- FNIC_SCSI_DBG(KERN_ERR, fnic->host, fnic->fnic_num,
+ FNIC_SCSI_DBG(KERN_ERR, fnic,
"SCSI error handling: fnic host reset");
ret = fnic_host_reset(shost);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 431/438] scsi: fnic: Bump up version number
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (429 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 430/438] scsi: fnic: Make debug logging protocol independent Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 432/438] scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU Greg Kroah-Hartman
` (18 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sesidhar Baddela,
Arulprabhu Ponnusamy, Gian Carlo Boffa, Arun Easi,
Hannes Reinecke, Lee Duncan, Karan Tilak Kumar,
Martin K. Petersen, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karan Tilak Kumar <kartilak@cisco.com>
[ Upstream commit 2265541d221dc550dc89b52e49e9d9eb2f824996 ]
Bump up version number to 1.9.0.0.
Reviewed-by: Sesidhar Baddela <sebaddel@cisco.com>
Reviewed-by: Arulprabhu Ponnusamy <arulponn@cisco.com>
Reviewed-by: Gian Carlo Boffa <gcboffa@cisco.com>
Reviewed-by: Arun Easi <aeasi@cisco.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Reviewed-by: Lee Duncan <lduncan@suse.com>
Tested-by: Karan Tilak Kumar <kartilak@cisco.com>
Signed-off-by: Karan Tilak Kumar <kartilak@cisco.com>
Co-developed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260724174811.5118-14-kartilak@cisco.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: 0cb1fd924126 ("scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/fnic/fnic.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/scsi/fnic/fnic.h
+++ b/drivers/scsi/fnic/fnic.h
@@ -30,7 +30,7 @@
#define DRV_NAME "fnic"
#define DRV_DESCRIPTION "Cisco FCoE HBA Driver"
-#define DRV_VERSION "1.8.0.3"
+#define DRV_VERSION "1.9.0.0"
#define PFX DRV_NAME ": "
#define DFX DRV_NAME "%d: "
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 378/398] scsi: fnic: Bump up version number again
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (374 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 377/398] scsi: fnic: Make debug logging protocol independent Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 379/398] scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU Greg Kroah-Hartman
` (26 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sesidhar Baddela,
Arulprabhu Ponnusamy, Gian Carlo Boffa, Arun Easi,
Hannes Reinecke, Lee Duncan, Karan Tilak Kumar,
Martin K. Petersen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karan Tilak Kumar <kartilak@cisco.com>
[ Upstream commit 2265541d221dc550dc89b52e49e9d9eb2f824996 ]
Bump up version number to 1.9.0.0.
Reviewed-by: Sesidhar Baddela <sebaddel@cisco.com>
Reviewed-by: Arulprabhu Ponnusamy <arulponn@cisco.com>
Reviewed-by: Gian Carlo Boffa <gcboffa@cisco.com>
Reviewed-by: Arun Easi <aeasi@cisco.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Reviewed-by: Lee Duncan <lduncan@suse.com>
Tested-by: Karan Tilak Kumar <kartilak@cisco.com>
Signed-off-by: Karan Tilak Kumar <kartilak@cisco.com>
Co-developed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260724174811.5118-14-kartilak@cisco.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: 0cb1fd924126 ("scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/fnic/fnic.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/scsi/fnic/fnic.h
+++ b/drivers/scsi/fnic/fnic.h
@@ -30,7 +30,7 @@
#define DRV_NAME "fnic"
#define DRV_DESCRIPTION "Cisco FCoE HBA Driver"
-#define DRV_VERSION "1.8.0.3"
+#define DRV_VERSION "1.9.0.0"
#define PFX DRV_NAME ": "
#define DFX DRV_NAME "%d: "
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 432/438] scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (430 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 431/438] scsi: fnic: Bump up version number Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 433/438] drm/amdgpu: reduce early full GPU access during SR-IOV init Greg Kroah-Hartman
` (17 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sesidhar Baddela,
Arulprabhu Ponnusamy, Gian Carlo Boffa, Karan Tilak Kumar,
Arun Easi, Laurence Oberman, Martin K. Petersen (Oracle),
Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arun Easi <aeasi@cisco.com>
[ Upstream commit 0cb1fd924126f1f581621a5e804df98a02be9dff ]
When CPU Hyper Threading is disabled, sibling CPUs remain present but
are reported offline. Managed MSI-X IRQs can still receive affinity
masks that include those offline CPUs. If a driver-critical vector is
managed, it can be parked on an offline CPU and the driver may miss
critical events such as link-up.
Keep driver-critical vectors unmanaged so they can be migrated by the
IRQ core when their target CPU is offlined.
Since HWQ-0 is unmanaged now, in some queue combinations there can be no
mappings to it in mq_map. So without the blk-mq fix mentioned below,
system may crash during cpu offline/online tests.
Fixes: 8a8449ca5e33 ("scsi: fnic: Modify ISRs to support multiqueue (MQ)")
Cc: stable@vger.kernel.org
Depends-on: commit 10845a105bbc ("blk-mq: skip CPU offline notify on unmapped hctx")
Reviewed-by: Sesidhar Baddela <sebaddel@cisco.com>
Reviewed-by: Arulprabhu Ponnusamy <arulponn@cisco.com>
Reviewed-by: Gian Carlo Boffa <gcboffa@cisco.com>
Reviewed-by: Karan Tilak Kumar <kartilak@cisco.com>
Signed-off-by: Arun Easi <aeasi@cisco.com>
Reviewed-by: Laurence Oberman <loberman@redhat.com>
Link: https://patch.msgid.link/20260903175547.57971-1-aeasi@cisco.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
[ Inlined fnic_mq_init_queue_map() into fnic_mq_map_queues_cpus() using the existing cpu variable. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/fnic/fnic.h | 2 +-
drivers/scsi/fnic/fnic_isr.c | 13 ++++++++++---
drivers/scsi/fnic/fnic_main.c | 33 ++++++++++++++++++++++++++++++++-
3 files changed, 43 insertions(+), 5 deletions(-)
--- a/drivers/scsi/fnic/fnic.h
+++ b/drivers/scsi/fnic/fnic.h
@@ -30,7 +30,7 @@
#define DRV_NAME "fnic"
#define DRV_DESCRIPTION "Cisco FCoE HBA Driver"
-#define DRV_VERSION "1.9.0.0"
+#define DRV_VERSION "1.9.0.1"
#define PFX DRV_NAME ": "
#define DFX DRV_NAME "%d: "
--- a/drivers/scsi/fnic/fnic_isr.c
+++ b/drivers/scsi/fnic/fnic_isr.c
@@ -245,7 +245,14 @@ int fnic_set_intr_mode_msix(struct fnic
unsigned int m = ARRAY_SIZE(fnic->wq);
unsigned int o = ARRAY_SIZE(fnic->hw_copy_wq);
unsigned int min_irqs = n + m + 1 + 1; /*rq, raw wq, wq, err*/
-
+ /*
+ * Make driver critical vectors unmanaged, or else it can get tied
+ * to an offline CPU. This can happen when hyper-threading is off.
+ */
+ struct irq_affinity affd = {
+ .pre_vectors = n + m + 1, /* rq, raw wq, 1 ioq */
+ .post_vectors = 1, /* err */
+ };
/*
* We need n RQs, m WQs, o Copy WQs, n+m+o CQs, and n+m+o+1 INTRs
* (last INTR is used for WQ/RQ errors and notification area)
@@ -263,8 +270,8 @@ int fnic_set_intr_mode_msix(struct fnic
int vec_count = 0;
int vecs = fnic->rq_count + fnic->raw_wq_count + fnic->wq_copy_count + 1;
- vec_count = pci_alloc_irq_vectors(fnic->pdev, min_irqs, vecs,
- PCI_IRQ_MSIX | PCI_IRQ_AFFINITY);
+ vec_count = pci_alloc_irq_vectors_affinity(fnic->pdev, min_irqs,
+ vecs, PCI_IRQ_MSIX|PCI_IRQ_AFFINITY, &affd);
FNIC_ISR_DBG(KERN_INFO, fnic,
"allocated %d MSI-X vectors\n",
vec_count);
--- a/drivers/scsi/fnic/fnic_main.c
+++ b/drivers/scsi/fnic/fnic_main.c
@@ -680,6 +680,8 @@ static int fnic_scsi_drv_init(struct fni
void fnic_mq_map_queues_cpus(struct Scsi_Host *host)
{
+ const struct cpumask *mask;
+ unsigned int queue, cpu;
struct fnic *fnic = *((struct fnic **) shost_priv(host));
struct pci_dev *l_pdev = fnic->pdev;
int intr_mode = fnic->config.intr_mode;
@@ -700,7 +702,36 @@ void fnic_mq_map_queues_cpus(struct Scsi
return;
}
- blk_mq_map_hw_queues(qmap, &l_pdev->dev, FNIC_PCI_OFFSET);
+ for_each_possible_cpu(cpu)
+ qmap->mq_map[cpu] = 0;
+
+ /*
+ * Setup CPU to Queue mapping for all managed MSI-X IRQs.
+ * Q0 is driver critical and non-managed, hence start from Q1.
+ */
+ for (queue = 1; queue < qmap->nr_queues; queue++) {
+ int irq_num = pci_irq_vector(fnic->pdev,
+ queue + FNIC_PCI_OFFSET);
+
+ if (irq_num < 0)
+ continue;
+
+ mask = pci_irq_get_affinity(fnic->pdev,
+ queue + FNIC_PCI_OFFSET);
+ if (!mask) {
+ shost_printk(KERN_ERR, host,
+ "failed to get irq_affinity map for queue:%d\n", irq_num);
+ continue;
+ }
+ FNIC_MAIN_DBG(KERN_INFO, fnic,
+ "got irq_affinity map for %d:\n", irq_num);
+ for_each_cpu(cpu, mask) {
+ qmap->mq_map[cpu] = qmap->queue_offset + queue;
+ FNIC_MAIN_DBG(KERN_INFO, fnic,
+ "[Q%d] cpu:%d <=> irq:%d\n",
+ queue, cpu, irq_num);
+ }
+ }
}
static int fnic_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 379/398] scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (375 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 378/398] scsi: fnic: Bump up version number again Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 380/398] smb: client: fix cifsFileInfo reference leak in deferred close Greg Kroah-Hartman
` (25 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sesidhar Baddela,
Arulprabhu Ponnusamy, Gian Carlo Boffa, Karan Tilak Kumar,
Arun Easi, Laurence Oberman, Martin K. Petersen (Oracle),
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arun Easi <aeasi@cisco.com>
[ Upstream commit 0cb1fd924126f1f581621a5e804df98a02be9dff ]
When CPU Hyper Threading is disabled, sibling CPUs remain present but
are reported offline. Managed MSI-X IRQs can still receive affinity
masks that include those offline CPUs. If a driver-critical vector is
managed, it can be parked on an offline CPU and the driver may miss
critical events such as link-up.
Keep driver-critical vectors unmanaged so they can be migrated by the
IRQ core when their target CPU is offlined.
Since HWQ-0 is unmanaged now, in some queue combinations there can be no
mappings to it in mq_map. So without the blk-mq fix mentioned below,
system may crash during cpu offline/online tests.
Fixes: 8a8449ca5e33 ("scsi: fnic: Modify ISRs to support multiqueue (MQ)")
Cc: stable@vger.kernel.org
Depends-on: commit 10845a105bbc ("blk-mq: skip CPU offline notify on unmapped hctx")
Reviewed-by: Sesidhar Baddela <sebaddel@cisco.com>
Reviewed-by: Arulprabhu Ponnusamy <arulponn@cisco.com>
Reviewed-by: Gian Carlo Boffa <gcboffa@cisco.com>
Reviewed-by: Karan Tilak Kumar <kartilak@cisco.com>
Signed-off-by: Arun Easi <aeasi@cisco.com>
Reviewed-by: Laurence Oberman <loberman@redhat.com>
Link: https://patch.msgid.link/20260903175547.57971-1-aeasi@cisco.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/scsi/fnic/fnic.h | 2 +-
drivers/scsi/fnic/fnic_isr.c | 13 ++++++++++---
drivers/scsi/fnic/fnic_main.c | 33 ++++++++++++++++++++++++++++++++-
3 files changed, 43 insertions(+), 5 deletions(-)
--- a/drivers/scsi/fnic/fnic.h
+++ b/drivers/scsi/fnic/fnic.h
@@ -30,7 +30,7 @@
#define DRV_NAME "fnic"
#define DRV_DESCRIPTION "Cisco FCoE HBA Driver"
-#define DRV_VERSION "1.9.0.0"
+#define DRV_VERSION "1.9.0.1"
#define PFX DRV_NAME ": "
#define DFX DRV_NAME "%d: "
--- a/drivers/scsi/fnic/fnic_isr.c
+++ b/drivers/scsi/fnic/fnic_isr.c
@@ -245,7 +245,14 @@ int fnic_set_intr_mode_msix(struct fnic
unsigned int m = ARRAY_SIZE(fnic->wq);
unsigned int o = ARRAY_SIZE(fnic->hw_copy_wq);
unsigned int min_irqs = n + m + 1 + 1; /*rq, raw wq, wq, err*/
-
+ /*
+ * Make driver critical vectors unmanaged, or else it can get tied
+ * to an offline CPU. This can happen when hyper-threading is off.
+ */
+ struct irq_affinity affd = {
+ .pre_vectors = n + m + 1, /* rq, raw wq, 1 ioq */
+ .post_vectors = 1, /* err */
+ };
/*
* We need n RQs, m WQs, o Copy WQs, n+m+o CQs, and n+m+o+1 INTRs
* (last INTR is used for WQ/RQ errors and notification area)
@@ -263,8 +270,8 @@ int fnic_set_intr_mode_msix(struct fnic
int vec_count = 0;
int vecs = fnic->rq_count + fnic->raw_wq_count + fnic->wq_copy_count + 1;
- vec_count = pci_alloc_irq_vectors(fnic->pdev, min_irqs, vecs,
- PCI_IRQ_MSIX | PCI_IRQ_AFFINITY);
+ vec_count = pci_alloc_irq_vectors_affinity(fnic->pdev, min_irqs,
+ vecs, PCI_IRQ_MSIX|PCI_IRQ_AFFINITY, &affd);
FNIC_ISR_DBG(KERN_INFO, fnic,
"allocated %d MSI-X vectors\n",
vec_count);
--- a/drivers/scsi/fnic/fnic_main.c
+++ b/drivers/scsi/fnic/fnic_main.c
@@ -678,6 +678,8 @@ static int fnic_scsi_drv_init(struct fni
void fnic_mq_map_queues_cpus(struct Scsi_Host *host)
{
+ const struct cpumask *mask;
+ unsigned int queue, cpu;
struct fnic *fnic = *((struct fnic **) shost_priv(host));
struct pci_dev *l_pdev = fnic->pdev;
int intr_mode = fnic->config.intr_mode;
@@ -698,7 +700,36 @@ void fnic_mq_map_queues_cpus(struct Scsi
return;
}
- blk_mq_map_hw_queues(qmap, &l_pdev->dev, FNIC_PCI_OFFSET);
+ for_each_possible_cpu(cpu)
+ qmap->mq_map[cpu] = 0;
+
+ /*
+ * Setup CPU to Queue mapping for all managed MSI-X IRQs.
+ * Q0 is driver critical and non-managed, hence start from Q1.
+ */
+ for (queue = 1; queue < qmap->nr_queues; queue++) {
+ int irq_num = pci_irq_vector(fnic->pdev,
+ queue + FNIC_PCI_OFFSET);
+
+ if (irq_num < 0)
+ continue;
+
+ mask = pci_irq_get_affinity(fnic->pdev,
+ queue + FNIC_PCI_OFFSET);
+ if (!mask) {
+ shost_printk(KERN_ERR, host,
+ "failed to get irq_affinity map for queue:%d\n", irq_num);
+ continue;
+ }
+ FNIC_MAIN_DBG(KERN_INFO, fnic,
+ "got irq_affinity map for %d:\n", irq_num);
+ for_each_cpu(cpu, mask) {
+ qmap->mq_map[cpu] = qmap->queue_offset + queue;
+ FNIC_MAIN_DBG(KERN_INFO, fnic,
+ "[Q%d] cpu:%d <=> irq:%d\n",
+ queue, cpu, irq_num);
+ }
+ }
}
static int fnic_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 433/438] drm/amdgpu: reduce early full GPU access during SR-IOV init
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (431 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 432/438] scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 434/438] drm/amdgpu: Fix GPU PCIe link capability reporting Greg Kroah-Hartman
` (16 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, chong li, Alex Deucher, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: chong li <chongli2@amd.com>
[ Upstream commit cba4928cdffaa0f9012acff0ec4f896320107077 ]
Allow early FB reads to fall back to BAR0 when the VRAM aperture is not ready.
This lets SR-IOV VFs consume host-provided init data before requesting full GPU access.
For ASICs that support request_init_data,
defer full GPU access until after non-GPU early init to shorten the full-access window.
Legacy ASICs(before NV12) do not send request_init_data;
the host dumps init data only during full GPU access,
so keep the original early full-access request path for them.
Signed-off-by: chong li <chongli2@amd.com>
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Stable-dep-of: 04de4007d323 ("drm/amdgpu: Fix GPU PCIe link capability reporting")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_device.c | 88 +++++++++++++++++++++++++++--
drivers/gpu/drm/amd/amdgpu/mxgpu_ai.c | 7 +-
2 files changed, 88 insertions(+), 7 deletions(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -750,6 +750,64 @@ void amdgpu_device_mm_access(struct amdg
drm_dev_exit(idx);
}
+#ifdef CONFIG_64BIT
+/*
+ * During early SR-IOV VF init, host-provided init data can live in FB before
+ * the normal VRAM aperture mapping is ready. Use a temporary BAR0 mapping for
+ * reads only, and verify it matches the VRAM aperture when aperture information
+ * is already available.
+ */
+static int amdgpu_device_read_fb_via_bar0(struct amdgpu_device *adev,
+ u64 offset, void *buf, size_t size)
+{
+ resource_size_t aper_base, aper_size, bar_start, bar_size, map_base;
+ void __iomem *vram;
+ size_t map_offset, map_size;
+ unsigned long flags;
+ u64 end;
+
+ if (!buf || !size)
+ return -EINVAL;
+
+ flags = pci_resource_flags(adev->pdev, 0);
+ if ((flags & IORESOURCE_UNSET) || !(flags & IORESOURCE_MEM))
+ return -EINVAL;
+
+ bar_start = pci_resource_start(adev->pdev, 0);
+ bar_size = pci_resource_len(adev->pdev, 0);
+ if (!bar_size)
+ return -ENODEV;
+
+ aper_base = adev->gmc.aper_base;
+ aper_size = adev->gmc.visible_vram_size ? adev->gmc.visible_vram_size :
+ adev->gmc.aper_size;
+
+ if (aper_base || aper_size) {
+ if (aper_base != bar_start || aper_size > bar_size)
+ return -EINVAL;
+ } else {
+ aper_base = bar_start;
+ aper_size = bar_size;
+ }
+
+ if (check_add_overflow(offset, size, &end) || end > aper_size)
+ return -EINVAL;
+
+ map_offset = offset_in_page(offset);
+ map_base = aper_base + (offset & PAGE_MASK);
+ map_size = PAGE_ALIGN(map_offset + size);
+
+ vram = ioremap_wc(map_base, map_size);
+ if (!vram)
+ return -ENOMEM;
+
+ memcpy_fromio(buf, (u8 __iomem *)vram + map_offset, size);
+ iounmap(vram);
+
+ return 0;
+}
+#endif
+
/**
* amdgpu_device_aper_access - access vram by vram aperture
*
@@ -769,8 +827,12 @@ size_t amdgpu_device_aper_access(struct
size_t count = 0;
uint64_t last;
- if (!adev->mman.aper_base_kaddr)
+ if (!adev->mman.aper_base_kaddr) {
+ /* Writes still require the regular aperture/MM path. */
+ if (!write && !amdgpu_device_read_fb_via_bar0(adev, pos, buf, size))
+ return size;
return 0;
+ }
last = min(pos + size, adev->gmc.visible_vram_size);
if (last > pos) {
@@ -2011,16 +2073,25 @@ static int amdgpu_device_ip_early_init(s
{
struct amdgpu_ip_block *ip_block;
struct pci_dev *parent;
- bool total, skip_bios;
+ bool total, skip_bios, early_full_gpu_access = false;
uint32_t bios_flags;
int i, r;
amdgpu_device_enable_virtual_display(adev);
if (amdgpu_sriov_vf(adev)) {
- r = amdgpu_virt_request_full_gpu(adev, true);
- if (r)
- return r;
+ /*
+ * Legacy hosts do not provide init data before early init, so
+ * keep the original early full GPU access request for them. Newer
+ * hosts publish the init data through VF FB, which lets us defer
+ * full GPU access until after non-GPU early init work is done.
+ */
+ early_full_gpu_access = (adev->virt.req_init_data_ver == 0);
+ if (early_full_gpu_access) {
+ r = amdgpu_virt_request_full_gpu(adev, true);
+ if (r)
+ return r;
+ }
r = amdgpu_virt_init_critical_region(adev);
if (r)
@@ -2183,6 +2254,13 @@ static int amdgpu_device_ip_early_init(s
if (!total)
return -ENODEV;
+ /* Request full GPU access only for the remaining SR-IOV init work. */
+ if (amdgpu_sriov_vf(adev) && !early_full_gpu_access) {
+ r = amdgpu_virt_request_full_gpu(adev, true);
+ if (r)
+ return r;
+ }
+
if (adev->gmc.xgmi.supported)
amdgpu_xgmi_early_init(adev);
--- a/drivers/gpu/drm/amd/amdgpu/mxgpu_ai.c
+++ b/drivers/gpu/drm/amd/amdgpu/mxgpu_ai.c
@@ -185,8 +185,11 @@ static int xgpu_ai_send_access_requests(
} else if (req == IDH_REQ_GPU_INIT_DATA){
/* Dummy REQ_GPU_INIT_DATA handling */
r = xgpu_ai_poll_msg(adev, IDH_REQ_GPU_INIT_DATA_READY);
- /* version set to 0 since dummy */
- adev->virt.req_init_data_ver = 0;
+ /*
+ * AI uses the GPU_CRIT_REGION_V1 layout in practice, so fix the
+ * dummy version value to match the actual init-data format.
+ */
+ adev->virt.req_init_data_ver = GPU_CRIT_REGION_V1;
}
return 0;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 380/398] smb: client: fix cifsFileInfo reference leak in deferred close
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (376 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 379/398] scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 381/398] xfs: add a xfs_rmap_inode_owner helper Greg Kroah-Hartman
` (24 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Song Li, Fan Wu, Paulo Alcantara,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
[ Upstream commit 5520e89a5a4f834bced64cf2ac927001cc513a40 ]
When cifs_close() defers a close, it hands the cifsFileInfo reference
of the closing struct file to the queued work. Each execution of
smb2_deferred_work_close() drops one such reference.
deferred_close_scheduled can be false while the work is pending: the
workqueue clears PENDING when the callback starts to run, before the
callback clears the flag under deferred_lock. A close in that
interval requeues the running work, and the callback then clears the
flag, leaving the requeued work pending with the flag down. A later
cifs_open() can reuse the handle and its cifs_close() reaches the
same branch: queue_delayed_work() fails because the work is still
pending, but cifs_close() returns without dropping the closing file's
reference. The cifsFileInfo count stays pinned and its tlink, dentry
and server handle are leaked.
Check the return value and hand off the reference only when work was
actually queued. Otherwise, use the shared _cifsFileInfo_put(), like
the mod_delayed_work() branch above: the pending execution already
owns its reference.
This issue was found by an in-house static analysis tool.
Fixes: c3f207ab29f7 ("cifs: Deferred close for files")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Co-developed-by: Song Li <songl@zju.edu.cn>
Signed-off-by: Song Li <songl@zju.edu.cn>
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
[ Adjusted cifs_close() context due to missing trace_smb3_close_cached(). ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/file.c | 17 ++++++++++++-----
1 file changed, 12 insertions(+), 5 deletions(-)
--- a/fs/smb/client/file.c
+++ b/fs/smb/client/file.c
@@ -1467,11 +1467,18 @@ int cifs_close(struct inode *inode, stru
cifsFileInfo_get(cfile);
} else {
/* Deferred close for files */
- queue_delayed_work(deferredclose_wq,
- &cfile->deferred, cifs_sb->ctx->closetimeo);
- cfile->deferred_close_scheduled = true;
- spin_unlock(&cinode->deferred_lock);
- return 0;
+ /*
+ * Each queued execution owns one reference.
+ * If nothing was queued, the reference of
+ * the closing file is dropped below.
+ */
+ if (queue_delayed_work(deferredclose_wq,
+ &cfile->deferred,
+ cifs_sb->ctx->closetimeo)) {
+ cfile->deferred_close_scheduled = true;
+ spin_unlock(&cinode->deferred_lock);
+ return 0;
+ }
}
spin_unlock(&cinode->deferred_lock);
_cifsFileInfo_put(cfile, true, false);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 434/438] drm/amdgpu: Fix GPU PCIe link capability reporting
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (432 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 433/438] drm/amdgpu: reduce early full GPU access during SR-IOV init Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 435/438] ntsync: reject wait ioctls with zero owner Greg Kroah-Hartman
` (15 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marek Olšák, Lijo Lazar,
Alex Deucher, Mario Limonciello, Sasha Levin
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello <mario.limonciello@amd.com>
[ Upstream commit 04de4007d32385b8b6a5dd72bff3146dfdc592c3 ]
Commit eb53125a7ad9 ("drm/amd: Add dedicated helper for
amdgpu_device_find_parent()") made amdgpu_device_gpu_bandwidth() query
the first device outside the dGPU. That is the host side of the
physical link, not the GPU side.
As a result, the ASIC and platform capability masks can both be based
on the host port. drm_amdgpu_info_device then exposes the host
capabilities to userspace, such as Gen5 x16 for a Gen4 x8 GPU.
Cache both ends of the physical link during device initialization.
Use link_dev for the GPU capability and link_partner for the platform
capability and _PR3 detection.
Reported-by: "Marek Olšák" <maraeo@gmail.com>
Closes: https://lore.kernel.org/amd-gfx/CAAxE2A4VhsAzzO1QjBjUg+NgnbD04ZzMyN6xsUJxjKJHH6hxiw@mail.gmail.com/
Suggested-by: Lijo Lazar <lijo.lazar@amd.com>
Fixes: eb53125a7ad9 ("drm/amd: Add dedicated helper for amdgpu_device_find_parent()")
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 7ea6a47224e2c6e89a3a682d7fbaace4817a55aa)
Cc: stable@vger.kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu.h | 3 +
drivers/gpu/drm/amd/amdgpu/amdgpu_device.c | 48 ++++++++++-------------------
2 files changed, 20 insertions(+), 31 deletions(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu.h
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu.h
@@ -822,6 +822,9 @@ enum amdgpu_enforce_isolation_mode {
struct amdgpu_device {
struct device *dev;
struct pci_dev *pdev;
+ /* The two ends of the physical PCIe link outside the device. */
+ struct pci_dev *link_dev;
+ struct pci_dev *link_partner;
struct drm_device ddev;
#ifdef CONFIG_DRM_AMD_ACP
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -2045,18 +2045,17 @@ static void amdgpu_uid_fini(struct amdgp
adev->uid_info = NULL;
}
-static struct pci_dev *amdgpu_device_find_parent(struct amdgpu_device *adev)
+static void amdgpu_device_init_pcie_links(struct amdgpu_device *adev)
{
- struct pci_dev *parent = adev->pdev;
+ adev->link_dev = adev->pdev;
+ adev->link_partner = pci_upstream_bridge(adev->link_dev);
- /* skip upstream/downstream switches internal to dGPU */
- while ((parent = pci_upstream_bridge(parent))) {
- if (parent->vendor == PCI_VENDOR_ID_ATI)
- continue;
- break;
+ /* Skip upstream/downstream switches internal to the dGPU. */
+ while (adev->link_partner &&
+ adev->link_partner->vendor == PCI_VENDOR_ID_ATI) {
+ adev->link_dev = adev->link_partner;
+ adev->link_partner = pci_upstream_bridge(adev->link_dev);
}
-
- return parent;
}
/**
@@ -2072,7 +2071,6 @@ static struct pci_dev *amdgpu_device_fin
static int amdgpu_device_ip_early_init(struct amdgpu_device *adev)
{
struct amdgpu_ip_block *ip_block;
- struct pci_dev *parent;
bool total, skip_bios, early_full_gpu_access = false;
uint32_t bios_flags;
int i, r;
@@ -2168,10 +2166,9 @@ static int amdgpu_device_ip_early_init(s
!dev_is_removable(&adev->pdev->dev))
adev->flags |= AMD_IS_PX;
- if (!(adev->flags & AMD_IS_APU)) {
- parent = amdgpu_device_find_parent(adev);
- adev->has_pr3 = parent ? pci_pr3_present(parent) : false;
- }
+ if (!(adev->flags & AMD_IS_APU))
+ adev->has_pr3 = adev->link_partner &&
+ pci_pr3_present(adev->link_partner);
adev->pm.pp_feature = amdgpu_pp_feature_mask;
if (amdgpu_sriov_vf(adev) || sched_policy == KFD_SCHED_POLICY_NO_HWS)
@@ -3863,6 +3860,7 @@ int amdgpu_device_init(struct amdgpu_dev
adev->shutdown = false;
adev->flags = flags;
+ amdgpu_device_init_pcie_links(adev);
if (amdgpu_force_asic_type >= 0 && amdgpu_force_asic_type < CHIP_LAST)
adev->asic_type = amdgpu_force_asic_type;
@@ -6124,11 +6122,9 @@ static void amdgpu_device_partner_bandwi
*width = PCIE_LNK_WIDTH_UNKNOWN;
if (amdgpu_device_pcie_dynamic_switching_supported(adev)) {
- struct pci_dev *parent = amdgpu_device_find_parent(adev);
-
- if (parent) {
- *speed = pcie_get_speed_cap(parent);
- *width = pcie_get_width_cap(parent);
+ if (adev->link_partner) {
+ *speed = pcie_get_speed_cap(adev->link_partner);
+ *width = pcie_get_width_cap(adev->link_partner);
}
} else {
/* use the current speeds rather than max if switching is not supported */
@@ -6150,21 +6146,11 @@ static void amdgpu_device_gpu_bandwidth(
enum pci_bus_speed *speed,
enum pcie_link_width *width)
{
- struct pci_dev *parent = adev->pdev;
-
if (!speed || !width)
return;
- /* use the device itself */
- *speed = pcie_get_speed_cap(adev->pdev);
- *width = pcie_get_width_cap(adev->pdev);
-
- /* use the link outside the device */
- parent = amdgpu_device_find_parent(adev);
- if (parent) {
- *speed = pcie_get_speed_cap(parent);
- *width = pcie_get_width_cap(parent);
- }
+ *speed = pcie_get_speed_cap(adev->link_dev);
+ *width = pcie_get_width_cap(adev->link_dev);
}
/**
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 381/398] xfs: add a xfs_rmap_inode_owner helper
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (377 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 380/398] smb: client: fix cifsFileInfo reference leak in deferred close Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 382/398] xfs: convert xchk_inode_xref_set_corrupt to xchk_ip_xref_set_corrupt Greg Kroah-Hartman
` (23 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Carlos Maiolino,
Darrick J. Wong, Carlos Maiolino, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit f882fc7dd9f04f73d94379deb9e68d8db613c976 ]
Add a small wrapper for initializing the rmap owner to i_ino.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Carlos Maiolino <cmaiolino@redhat.com>
Reviewed-by: "Darrick J. Wong" <djwong@kernel.org>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Stable-dep-of: 4d3c07591534 ("xfs: fix under-reservation of blocks when repairing sf directories")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/libxfs/xfs_bmap.c | 2 +-
fs/xfs/libxfs/xfs_rmap.h | 2 ++
fs/xfs/scrub/bmap.c | 6 +++---
fs/xfs/scrub/reap.c | 3 +--
4 files changed, 7 insertions(+), 6 deletions(-)
--- a/fs/xfs/libxfs/xfs_bmap.c
+++ b/fs/xfs/libxfs/xfs_bmap.c
@@ -820,7 +820,7 @@ xfs_bmap_local_to_extents(
args.mp = ip->i_mount;
args.total = total;
args.minlen = args.maxlen = args.prod = 1;
- xfs_rmap_ino_owner(&args.oinfo, ip->i_ino, whichfork, 0);
+ xfs_rmap_inode_owner(&args.oinfo, ip, whichfork, 0);
/*
* Allocate a block. We know we need only one, since the
--- a/fs/xfs/libxfs/xfs_rmap.h
+++ b/fs/xfs/libxfs/xfs_rmap.h
@@ -35,6 +35,8 @@ xfs_rmap_ino_owner(
if (whichfork == XFS_ATTR_FORK)
oi->oi_flags |= XFS_OWNER_INFO_ATTR_FORK;
}
+#define xfs_rmap_inode_owner(oi, ip, whichfork, offset) \
+ xfs_rmap_ino_owner(oi, (ip)->i_ino, whichfork, offset)
static inline bool
xfs_rmap_should_skip_owner_update(
--- a/fs/xfs/scrub/bmap.c
+++ b/fs/xfs/scrub/bmap.c
@@ -352,7 +352,7 @@ xchk_bmap_rt_iextent_xref(
case XFS_DATA_FORK:
xchk_bmap_xref_rmap(info, irec, rgbno);
if (!xfs_is_reflink_inode(info->sc->ip)) {
- xfs_rmap_ino_owner(&oinfo, info->sc->ip->i_ino,
+ xfs_rmap_inode_owner(&oinfo, info->sc->ip,
info->whichfork, irec->br_startoff);
xchk_xref_is_only_rt_owned_by(info->sc, rgbno,
irec->br_blockcount, &oinfo);
@@ -407,7 +407,7 @@ xchk_bmap_iextent_xref(
case XFS_DATA_FORK:
xchk_bmap_xref_rmap(info, irec, agbno);
if (!xfs_is_reflink_inode(info->sc->ip)) {
- xfs_rmap_ino_owner(&oinfo, info->sc->ip->i_ino,
+ xfs_rmap_inode_owner(&oinfo, info->sc->ip,
info->whichfork, irec->br_startoff);
xchk_xref_is_only_owned_by(info->sc, agbno,
irec->br_blockcount, &oinfo);
@@ -419,7 +419,7 @@ xchk_bmap_iextent_xref(
break;
case XFS_ATTR_FORK:
xchk_bmap_xref_rmap(info, irec, agbno);
- xfs_rmap_ino_owner(&oinfo, info->sc->ip->i_ino,
+ xfs_rmap_inode_owner(&oinfo, info->sc->ip,
info->whichfork, irec->br_startoff);
xchk_xref_is_only_owned_by(info->sc, agbno, irec->br_blockcount,
&oinfo);
--- a/fs/xfs/scrub/reap.c
+++ b/fs/xfs/scrub/reap.c
@@ -1249,8 +1249,7 @@ xreap_bmapi_select(
cur = xfs_rmapbt_init_cursor(sc->mp, sc->tp, sc->sa.agf_bp,
sc->sa.pag);
- xfs_rmap_ino_owner(&oinfo, rs->ip->i_ino, rs->whichfork,
- imap->br_startoff);
+ xfs_rmap_inode_owner(&oinfo, rs->ip, rs->whichfork, imap->br_startoff);
error = xfs_rmap_has_other_keys(cur, agbno, 1, &oinfo, crosslinked);
if (error)
goto out_cur;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 435/438] ntsync: reject wait ioctls with zero owner
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (433 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 434/438] drm/amdgpu: Fix GPU PCIe link capability reporting Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 436/438] drm/ttm: fix swapped-out resources never leaving their bulk_move range Greg Kroah-Hartman
` (14 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Iván Ezequiel Rodriguez,
Griffin Kroah-Hartman, Elizabeth Figura, Alice Ryhl
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
commit 61611481f7b599e0526a3782c626b1a9deeb48bd upstream.
setup_wait() already validates pad and flags but not owner, while
Documentation/userspace-api/ntsync.rst requires EINVAL when owner is
zero. Reject early before queueing waiters.
Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com>
Signed-off-by: Griffin Kroah-Hartman <griffin@kroah.com>
Reviewed-by: Elizabeth Figura <zfigura@codeweavers.com>
Signed-off-by: Elizabeth Figura <zfigura@codeweavers.com>
Link: https://patch.msgid.link/20260723201301.11826-4-zfigura@codeweavers.com
Cc: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/misc/ntsync.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/misc/ntsync.c
+++ b/drivers/misc/ntsync.c
@@ -875,6 +875,9 @@ static int setup_wait(struct ntsync_devi
if (args->pad || (args->flags & ~NTSYNC_WAIT_REALTIME))
return -EINVAL;
+ if (!args->owner)
+ return -EINVAL;
+
if (size >= sizeof(fds))
return -EINVAL;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 382/398] xfs: convert xchk_inode_xref_set_corrupt to xchk_ip_xref_set_corrupt
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (378 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 381/398] xfs: add a xfs_rmap_inode_owner helper Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 383/398] xfs: remove the i_ino field in struct xfs_inode Greg Kroah-Hartman
` (22 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Carlos Maiolino,
Darrick J. Wong, Carlos Maiolino, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit bef4cee25fbc26ee8b07028e461190fa57b02788 ]
All xref corruption reports have the xfs_inode structure, so switch
the helper to work based on that.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Carlos Maiolino <cmaiolino@redhat.com>
Reviewed-by: "Darrick J. Wong" <djwong@kernel.org>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Stable-dep-of: 4d3c07591534 ("xfs: fix under-reservation of blocks when repairing sf directories")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/scrub/common.c | 6 +++---
fs/xfs/scrub/common.h | 4 ++--
fs/xfs/scrub/dirtree.c | 4 ++--
fs/xfs/scrub/inode.c | 6 +++---
fs/xfs/scrub/nlinks.c | 2 +-
fs/xfs/scrub/rtbitmap.c | 4 ++--
fs/xfs/scrub/rtsummary.c | 2 +-
7 files changed, 14 insertions(+), 14 deletions(-)
--- a/fs/xfs/scrub/common.c
+++ b/fs/xfs/scrub/common.c
@@ -309,12 +309,12 @@ xchk_ino_set_corrupt(
/* Record a corruption while cross-referencing with an inode. */
void
-xchk_ino_xref_set_corrupt(
+xchk_ip_xref_set_corrupt(
struct xfs_scrub *sc,
- xfs_ino_t ino)
+ struct xfs_inode *ip)
{
sc->sm->sm_flags |= XFS_SCRUB_OFLAG_XCORRUPT;
- trace_xchk_ino_error(sc, ino, __return_address);
+ trace_xchk_ino_error(sc, ip->i_ino, __return_address);
}
/* Record corruption in a block indexed by a file fork. */
--- a/fs/xfs/scrub/common.h
+++ b/fs/xfs/scrub/common.h
@@ -41,8 +41,8 @@ void xchk_qcheck_set_corrupt(struct xfs_
void xchk_block_xref_set_corrupt(struct xfs_scrub *sc,
struct xfs_buf *bp);
-void xchk_ino_xref_set_corrupt(struct xfs_scrub *sc,
- xfs_ino_t ino);
+void xchk_ip_xref_set_corrupt(struct xfs_scrub *sc,
+ struct xfs_inode *ip);
void xchk_fblock_xref_set_corrupt(struct xfs_scrub *sc,
int whichfork, xfs_fileoff_t offset);
--- a/fs/xfs/scrub/dirtree.c
+++ b/fs/xfs/scrub/dirtree.c
@@ -981,7 +981,7 @@ xchk_dirtree(
* parent pointers are corrupt; this scan cannot be completed
* without full information.
*/
- xchk_ino_xref_set_corrupt(sc, sc->ip->i_ino);
+ xchk_ip_xref_set_corrupt(sc, sc->ip);
error = 0;
goto out_scanlock;
}
@@ -1011,7 +1011,7 @@ xchk_dirtree(
if (oc.bad || oc.good + oc.suspect != 1)
xchk_ip_set_corrupt(sc, sc->ip);
if (oc.suspect)
- xchk_ino_xref_set_corrupt(sc, sc->ip->i_ino);
+ xchk_ip_xref_set_corrupt(sc, sc->ip);
}
out_scanlock:
--- a/fs/xfs/scrub/inode.c
+++ b/fs/xfs/scrub/inode.c
@@ -710,17 +710,17 @@ xchk_inode_xref_bmap(
if (!xchk_should_check_xref(sc, &error, NULL))
return;
if (nextents < xfs_dfork_data_extents(dip))
- xchk_ino_xref_set_corrupt(sc, sc->ip->i_ino);
+ xchk_ip_xref_set_corrupt(sc, sc->ip);
error = xchk_inode_count_blocks(sc, XFS_ATTR_FORK, &nextents, &acount);
if (!xchk_should_check_xref(sc, &error, NULL))
return;
if (nextents != xfs_dfork_attr_extents(dip))
- xchk_ino_xref_set_corrupt(sc, sc->ip->i_ino);
+ xchk_ip_xref_set_corrupt(sc, sc->ip);
/* Check nblocks against the inode. */
if (count + acount != be64_to_cpu(dip->di_nblocks))
- xchk_ino_xref_set_corrupt(sc, sc->ip->i_ino);
+ xchk_ip_xref_set_corrupt(sc, sc->ip);
}
/* Cross-reference with the other btrees. */
--- a/fs/xfs/scrub/nlinks.c
+++ b/fs/xfs/scrub/nlinks.c
@@ -741,7 +741,7 @@ xchk_nlinks_compare_inode(
* number of subdirectory entries in the directory.
*/
if (obs.children != obs.backrefs)
- xchk_ino_xref_set_corrupt(sc, ip->i_ino);
+ xchk_ip_xref_set_corrupt(sc, ip);
} else {
/*
* Non-directories and unlinked directories should not have
--- a/fs/xfs/scrub/rtbitmap.c
+++ b/fs/xfs/scrub/rtbitmap.c
@@ -284,7 +284,7 @@ xchk_xref_is_used_rt_space(
if (xfs_has_zoned(sc->mp)) {
if (!xfs_zone_rgbno_is_valid(rtg,
xfs_rtb_to_rgbno(sc->mp, rtbno) + len - 1))
- xchk_ino_xref_set_corrupt(sc, rtg_rmap(rtg)->i_ino);
+ xchk_ip_xref_set_corrupt(sc, rtg_rmap(rtg));
return;
}
@@ -295,5 +295,5 @@ xchk_xref_is_used_rt_space(
if (!xchk_should_check_xref(sc, &error, NULL))
return;
if (is_free)
- xchk_ino_xref_set_corrupt(sc, rtg_bitmap(rtg)->i_ino);
+ xchk_ip_xref_set_corrupt(sc, rtg_bitmap(rtg));
}
--- a/fs/xfs/scrub/rtsummary.c
+++ b/fs/xfs/scrub/rtsummary.c
@@ -190,7 +190,7 @@ xchk_rtsum_record_free(
rtlen = xfs_rtxlen_to_extlen(mp, rec->ar_extcount);
if (!xfs_verify_rtbext(mp, rtbno, rtlen)) {
- xchk_ino_xref_set_corrupt(sc, rtg_bitmap(rtg)->i_ino);
+ xchk_ip_xref_set_corrupt(sc, rtg_bitmap(rtg));
return -EFSCORRUPTED;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 436/438] drm/ttm: fix swapped-out resources never leaving their bulk_move range
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (434 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 435/438] ntsync: reject wait ioctls with zero owner Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 437/438] drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only Greg Kroah-Hartman
` (13 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vadim Nikitushkin,
Thomas Hellström, Christian König
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vadim Nikitushkin <bub4z0r@gmail.com>
commit 3db7d7d583419f7b1f2e141e36418802dbb25cf8 upstream.
ttm_tt_swapout() returns the number of pages swapped out on success and
a negative error code on failure; for a populated ttm it never returns
zero. Commit b2ed01e7ad3d ("drm/ttm: Fix ttm_bo_swapout() infinite LRU
walk on swapout failure") moved the bulk_move bookkeeping in
ttm_bo_swapout_cb() under "if (!ret)", so the
ttm_resource_del_bulk_move_unevictable() / ttm_resource_move_to_lru_tail()
pair is now skipped on every successful swapout. The equivalent change
for the shrinker in commit 1d59f36e95f7 ("drm/ttm: Fix ttm_bo_shrink()
infinite LRU walk on backup failure") tests "lret > 0", which is what
was intended here as well.
Before b2ed01e7ad3d the resource was taken off the bulk_move before the
swapout; since then a swapped-out resource stays inside its BO's
bulk_move range (and on the manager LRU) although it is unevictable.
When it is later freed or the BO leaves the bulk_move
(ttm_resource_free(), ttm_bo_set_bulk_move() via amdgpu_vm_bo_del()),
ttm_resource_del_bulk_move() skips it because of its
!ttm_resource_unevictable() guard, so a range endpoint in pos->first /
pos->last is left pointing at freed memory. The next
ttm_lru_bulk_move_tail() or ttm_resource_add_bulk_move() on that cursor
is a use-after-free, seen as the resv WARN in ttm_lru_bulk_move_add(),
"list_del corruption" in ttm_resource_move_to_lru_tail() or a NULL
dereference in ttm_resource_manager_next() -- minutes to hours after a
hibernation, or at process exit / reboot following one. Samuel
Ainsworth's analysis of drm/amd issue 5387 (see Link) identified the
dangling cursor; the missing removal at swapout time is the reason it
dangles.
Testing the condition for success restores the removal. On an AMD
Phoenix APU (ASUS UM3406GA, gfx1103) running suspend-then-hibernate on
a 7.0.y stable kernel carrying the backport (Ubuntu 7.0.0-31) the bug
crashed 5 of 18 hibernation cycles; a function profile of one
hibernation showed 336 ttm_tt_swapout() calls and zero
ttm_resource_del_bulk_move_unevictable() calls. With this change the
removal happens for every swapped-out resource and 12 further cycles
were clean.
Fixes: b2ed01e7ad3d ("drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure")
Cc: stable@vger.kernel.org # v7.1+
Closes: https://gitlab.freedesktop.org/drm/amd/-/issues/5387
Link: https://lore.kernel.org/dri-devel/CAHYiNPa6aVacJoLOje-qZ1GyYx-9p0tN4NuP8D_eSL+UJeevXw@mail.gmail.com/
Signed-off-by: Vadim Nikitushkin <bub4z0r@gmail.com>
Reviewed-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Christian König <christian.koenig@amd.com>
Link: https://lore.kernel.org/r/20260909205028.13799-1-bub4z0r@gmail.com
[ Squashed with commit fcfe64715b425262af1b36f498f9197f3537ceed
("drm/ttm: apply the swapout bulk_move fix to the intended condition"):
upstream 3db7d7d58341 was applied to the "if (ret)" after
ttm_resource_try_charge() in ttm_bo_alloc_at_place() instead of the
"if (!ret)" after ttm_tt_swapout() in ttm_bo_swapout_cb(), and
fcfe64715b42 restored the former and changed the latter. 7.2.y has no
ttm_resource_try_charge() (dmem cgroup charging is 7.3 material), so
neither commit applies on its own; the net effect of the two is the
single hunk below, which is the change the changelog describes. ]
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/ttm/ttm_bo.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/gpu/drm/ttm/ttm_bo.c
+++ b/drivers/gpu/drm/ttm/ttm_bo.c
@@ -1178,7 +1178,7 @@ ttm_bo_swapout_cb(struct ttm_lru_walk *w
if (ttm_tt_is_populated(tt)) {
ret = ttm_tt_swapout(bdev, tt, swapout_walk->gfp_flags);
- if (!ret) {
+ if (ret > 0) {
spin_lock(&bdev->lru_lock);
ttm_resource_del_bulk_move_unevictable(bo->resource, bo);
ttm_resource_move_to_lru_tail(bo->resource);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 383/398] xfs: remove the i_ino field in struct xfs_inode
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (379 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 382/398] xfs: convert xchk_inode_xref_set_corrupt to xchk_ip_xref_set_corrupt Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 384/398] xfs: fix under-reservation of blocks when repairing sf directories Greg Kroah-Hartman
` (21 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Carlos Maiolino,
Darrick J. Wong, Carlos Maiolino, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit 1113a6d6d5d1336f4415fa1367aac0f853f0892d ]
Now that the VFS inode has a u64 i_ino field, there is no need to store
a copy of the inode number in the xfs_inode structure.
Introduce an I_INO() wrapper as a shortcut to the inode number so that
we don't have to propagate the VFS inode everywhere.
The only non-obvious part is the clearing of i_ino to 0 for RCU freeing
the inode. None of this calls into VFS paths, which makes clearing the
VFS inode field here just as safe as clearing the old field in the
xfs_inode.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Carlos Maiolino <cmaiolino@redhat.com>
Reviewed-by: "Darrick J. Wong" <djwong@kernel.org>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Stable adaptation for dependency of 4d3c07591534517c633945c8d8e6526f10e3fabc:
The stable VFS inode still has an unsigned long i_ino, so retain the
64-bit xfs_inode::i_ino and its existing initialization/reclaim handling.
Define I_INO as a macro over that field instead of adding a function.
Keep only the owner conversions in xrep_xattr_swap_prep and
xrep_dir_swap_prep, which provide the context needed for the target to
apply unchanged. Drop the remaining conversions, including changes to
helpers and health monitoring code absent from this stable tree.
Also finish the preceding dependency's helper conversion in the stable
xchk_rtsummary error path: call xchk_ip_xref_set_corrupt(sc, rbmip)
instead of the removed xchk_ino_xref_set_corrupt. This preserves its
cross-reference corruption reporting and fixes the allmodconfig build.
[ sashal: Reduced backport -- upstream 1113a6d6d5d13 touches 91 file(s), this
backport carries 4. Not backported here:
fs/xfs/libxfs/xfs_attr.c
fs/xfs/libxfs/xfs_attr_leaf.c
fs/xfs/libxfs/xfs_bmap_btree.c
fs/xfs/libxfs/xfs_bmap.c
fs/xfs/libxfs/xfs_btree.c
fs/xfs/libxfs/xfs_btree_staging.c
fs/xfs/libxfs/xfs_da_btree.c
fs/xfs/libxfs/xfs_dir2.c
... and 80 more
This note is generated from the file lists only; see the resolution record
for the reasoning. ]
Stable-dep-of: 4d3c07591534 ("xfs: fix under-reservation of blocks when repairing sf directories")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/scrub/attr_repair.c | 2 +-
fs/xfs/scrub/dir_repair.c | 2 +-
fs/xfs/scrub/rtsummary.c | 2 +-
fs/xfs/xfs_inode.h | 3 +++
4 files changed, 6 insertions(+), 3 deletions(-)
--- a/fs/xfs/scrub/attr_repair.c
+++ b/fs/xfs/scrub/attr_repair.c
@@ -1295,7 +1295,7 @@ xrep_xattr_swap_prep(
.whichfork = XFS_ATTR_FORK,
.trans = sc->tp,
.total = 1,
- .owner = sc->ip->i_ino,
+ .owner = I_INO(sc->ip),
};
error = xfs_attr_shortform_to_leaf(&args);
--- a/fs/xfs/scrub/dir_repair.c
+++ b/fs/xfs/scrub/dir_repair.c
@@ -1474,7 +1474,7 @@ xrep_dir_swap_prep(
.whichfork = XFS_DATA_FORK,
.trans = sc->tp,
.total = 1,
- .owner = sc->ip->i_ino,
+ .owner = I_INO(sc->ip),
};
error = xfs_dir2_sf_to_block(&args);
--- a/fs/xfs/scrub/rtsummary.c
+++ b/fs/xfs/scrub/rtsummary.c
@@ -359,7 +359,7 @@ xchk_rtsummary(
* EFSCORRUPTED means the rtbitmap is corrupt, which is an xref
* error since we're checking the summary file.
*/
- xchk_ino_xref_set_corrupt(sc, rbmip->i_ino);
+ xchk_ip_xref_set_corrupt(sc, rbmip);
return 0;
}
if (error)
--- a/fs/xfs/xfs_inode.h
+++ b/fs/xfs/xfs_inode.h
@@ -184,6 +184,9 @@ static inline const struct inode *VFS_IC
return &ip->i_vnode;
}
+/* The VFS inode number is only unsigned long on this stable branch. */
+#define I_INO(ip) ((ip)->i_ino)
+
/*
* For regular files we only update the on-disk filesize when actually
* writing data back to disk. Until then only the copy in the VFS inode
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 437/438] drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (435 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 436/438] drm/ttm: fix swapped-out resources never leaving their bulk_move range Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 438/438] ksmbd: fix partial normalized name responses Greg Kroah-Hartman
` (12 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, gloveless, Alex Deucher,
Mario Limonciello
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello <mario.limonciello@amd.com>
commit bd1f08246b8a2564d8ac61df715b6bcd5f994729 upstream.
The BAR0 fallback read path was introduced as a workaround for SR-IOV VFs
where the VRAM aperture is not available during early init. Restrict this
workaround to only SR-IOV VFs where it's needed.
Reported-by: gloveless@jqluv.com
Fixes: cba4928cdffa ("drm/amdgpu: reduce early full GPU access during SR-IOV init")
Acked-by: Alex Deucher <alexander.deucher@amd.com>
Link: https://patch.msgid.link/20260826185102.2269511-1-mario.limonciello@amd.com
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit d8a0affd207c813bd063fa2c27786f449eaf92b8)
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_device.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -769,6 +769,9 @@ static int amdgpu_device_read_fb_via_bar
if (!buf || !size)
return -EINVAL;
+ if (!amdgpu_sriov_vf(adev))
+ return -EINVAL;
+
flags = pci_resource_flags(adev->pdev, 0);
if ((flags & IORESOURCE_UNSET) || !(flags & IORESOURCE_MEM))
return -EINVAL;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 384/398] xfs: fix under-reservation of blocks when repairing sf directories
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (380 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 383/398] xfs: remove the i_ino field in struct xfs_inode Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 385/398] drm/amdgpu: lock bo before calling amdgpu_vm_bo_update_shared Greg Kroah-Hartman
` (20 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, floss, dgc, Darrick J. Wong,
Christoph Hellwig, Carlos Maiolino, Carlos Maiolino, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Darrick J. Wong" <djwong@kernel.org>
[ Upstream commit 4d3c07591534517c633945c8d8e6526f10e3fabc ]
Whilst running QA on XFS for-next as of 7.3-rc2 with MKFS_OPTIONS="-n
size=8192", I observed the following (trimmed) dmesg splat:
XFS: Assertion failed: args->total >= dp->i_nblocks - nblks, file: fs/xfs/libxfs/xfs_da_btree.c, line: 2387
WARNING: fs/xfs/xfs_message.c:104 at assfail+0x46/0x4a [xfs], CPU#0: xfs_scrub/1426511
CPU: 0 UID: 0 PID: 1426511 Comm: xfs_scrub Tainted: G W 7.3.0-rc2-djwx #rc2 PREEMPT(lazy) 6e418570b606a39783b0e7e7b30dc407b965f9e8
Tainted: [W]=WARN
RIP: 0010:assfail+0x46/0x4a [xfs]
RSP: 0018:ffffc900010d7890 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 00000000ffffffd1
RDX: 0000000000000000 RSI: 0000000000000021 RDI: ffffffffa059fd38
RBP: 0000000000000002 R08: 0000000000000000 R09: 0000000000000000
R10: 000000000000000a R11: 000000007fffffff R12: ffffc900010d7940
R13: ffff888368d8f980 R14: ffffc900010d7a48 R15: ffffc900010d78d0
FS: 00007f445c5ce680(0000) GS:ffff8884a97ea000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f443803b9a8 CR3: 0000000107a4b000 CR4: 00000000003506f0
Call Trace:
<TASK>
xfs_da_grow_inode_int+0x2e0/0x300 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
xfs_dir2_grow_inode+0x6e/0x150 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
xfs_dir2_sf_to_block+0x149/0x870 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
xrep_dir_swap_prep+0xe2/0x110 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
xrep_dir_swap+0xfb/0x2f0 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
xrep_dir_rebuild_tree+0x99/0x100 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
xrep_directory+0x83/0x1c0 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
xrep_attempt+0x4f/0x1e0 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
xfs_scrub_metadata+0x393/0x5b0 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
xfs_ioc_scrubv_metadata+0x306/0x570 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
xfs_file_ioctl+0xa4f/0x1150 [xfs 5de2257e14108c136f11317e6bbb8ac77efd392c]
__x64_sys_ioctl+0x76/0xc0
do_syscall_64+0x7a/0x3b0
entry_SYSCALL_64_after_hwframe+0x4b/0x53
This is a consequence of commit 0fe77e57588b98, which added the
following assertion to xfs_da_grow_inode_int:
ASSERT(args->total >= dp->i_nblocks - nblks);
Tracing this back to xrep_dir_swap_prep, I noticed that the xfs_da_args
object that's passed to xfs_dir2_sf_to_block sets args->total to 1.
This is incorrect because mkfs set the directory block size to 8k and
the filesystem block size to 4k. In other words, args->total should be
2 here, not 1.
Dave Chinner tripped over the same problem with the same branch through
a different channel -- his test setup set the fs block size to 1k, in
which case the directory block size is still set to 4k. Here,
args->total should be 4.
Changing the assignment of args->total to sc->mp->m_dir_geo->fsbcount
makes the assertion go away, but that isn't a complete fix. In
xrep_tempexch_estimate, we also incorrectly assume that a shortform
conversion requires 1 fsblock when it should be m_dir_geo->fsbcount.
Without that, we can under-reserve space in the transaction and cause a
filesystem shutdown.
Note that the xfs_dabuf_nfsb helper will compute the correct value for
directories and xattr, so we use that instead of open-coding the logic.
Also fix xrep_xattr_swap_prep to assign args->total via xfs_dabuf_nfsb
to avoid one logic bomb if we ever support multi-fsblock attrs.
Cc: stable@vger.kernel.org # v6.10
Cc: floss@jetm.me
Reported-by: dgc@kernel.org
Fixes: 629fdaf5f5b1b7 ("xfs: use atomic extent swapping to fix user file fork data")
Tripped-by: 0fe77e57588b98 ("xfs: assert the reservation covers each da fork growth")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Carlos Maiolino <cmaiolino@redhat.com>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/xfs/libxfs/xfs_da_btree.c | 2 +-
fs/xfs/libxfs/xfs_da_btree.h | 2 ++
fs/xfs/scrub/attr_repair.c | 2 +-
fs/xfs/scrub/dir_repair.c | 2 +-
fs/xfs/scrub/tempfile.c | 29 ++++++++++++++++++++++-------
5 files changed, 27 insertions(+), 10 deletions(-)
--- a/fs/xfs/libxfs/xfs_da_btree.c
+++ b/fs/xfs/libxfs/xfs_da_btree.c
@@ -130,7 +130,7 @@ xfs_da_state_reset(
state->mp = state->args->dp->i_mount;
}
-static inline int xfs_dabuf_nfsb(struct xfs_mount *mp, int whichfork)
+inline int xfs_dabuf_nfsb(struct xfs_mount *mp, int whichfork)
{
if (whichfork == XFS_DATA_FORK)
return mp->m_dir_geo->fsbcount;
--- a/fs/xfs/libxfs/xfs_da_btree.h
+++ b/fs/xfs/libxfs/xfs_da_btree.h
@@ -242,4 +242,6 @@ xfs_failaddr_t xfs_da3_node_header_check
extern struct kmem_cache *xfs_da_state_cache;
+int xfs_dabuf_nfsb(struct xfs_mount *mp, int whichfork);
+
#endif /* __XFS_DA_BTREE_H__ */
--- a/fs/xfs/scrub/attr_repair.c
+++ b/fs/xfs/scrub/attr_repair.c
@@ -1294,7 +1294,7 @@ xrep_xattr_swap_prep(
.geo = sc->mp->m_attr_geo,
.whichfork = XFS_ATTR_FORK,
.trans = sc->tp,
- .total = 1,
+ .total = xfs_dabuf_nfsb(sc->mp, XFS_ATTR_FORK),
.owner = I_INO(sc->ip),
};
--- a/fs/xfs/scrub/dir_repair.c
+++ b/fs/xfs/scrub/dir_repair.c
@@ -1473,7 +1473,7 @@ xrep_dir_swap_prep(
.geo = sc->mp->m_dir_geo,
.whichfork = XFS_DATA_FORK,
.trans = sc->tp,
- .total = 1,
+ .total = xfs_dabuf_nfsb(sc->mp, XFS_DATA_FORK),
.owner = I_INO(sc->ip),
};
--- a/fs/xfs/scrub/tempfile.c
+++ b/fs/xfs/scrub/tempfile.c
@@ -649,6 +649,19 @@ xrep_tempexch_prep_request(
return 0;
}
+static inline unsigned int
+xrep_tempexch_estimate_sf_resblks(
+ struct xfs_scrub *sc,
+ int whichfork)
+{
+ /* repairing a symlink target */
+ if (S_ISLNK(VFS_I(sc->ip)->i_mode) && whichfork == XFS_DATA_FORK)
+ return 1;
+
+ /* everything else is a directory or an xattr structure */
+ return xfs_dabuf_nfsb(sc->mp, whichfork);
+}
+
/*
* Fill out the mapping exchange resource estimation structures in preparation
* for exchanging the contents of a metadata file that we've rebuilt in the
@@ -663,6 +676,8 @@ xrep_tempexch_estimate(
struct xfs_ifork *ifp;
struct xfs_ifork *tifp;
int whichfork = xfs_exchmaps_reqfork(req);
+ unsigned int sf_resblks =
+ xrep_tempexch_estimate_sf_resblks(sc, whichfork);
int state = 0;
/*
@@ -693,9 +708,9 @@ xrep_tempexch_estimate(
* plus the block we converted.
*/
req->ip1_bcount = sc->tempip->i_nblocks;
- req->ip2_bcount = 1;
+ req->ip2_bcount = sf_resblks;
req->nr_exchanges = 1 + tifp->if_nextents;
- req->resblks = 1;
+ req->resblks = sf_resblks;
break;
case 2:
/*
@@ -707,10 +722,10 @@ xrep_tempexch_estimate(
* is (worst case) the extent count of the file being repaired
* plus the block we converted.
*/
- req->ip1_bcount = 1;
+ req->ip1_bcount = sf_resblks;
req->ip2_bcount = sc->ip->i_nblocks;
req->nr_exchanges = 1 + ifp->if_nextents;
- req->resblks = 1;
+ req->resblks = sf_resblks;
break;
case 3:
/*
@@ -722,10 +737,10 @@ xrep_tempexch_estimate(
* fileoff 0. Presumably, the caller could not exchange the
* two inode fork areas directly.
*/
- req->ip1_bcount = 1;
- req->ip2_bcount = 1;
+ req->ip1_bcount = sf_resblks;
+ req->ip2_bcount = sf_resblks;
req->nr_exchanges = 1;
- req->resblks = 2;
+ req->resblks = 2 * sf_resblks;
break;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 7.2 438/438] ksmbd: fix partial normalized name responses
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (436 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 437/438] drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:54 ` [PATCH 7.2 000/438] 7.2.8-rc1 review Brett A C Sheffield
` (11 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mobin Aydinfar, ChenXiaoSong,
Namjae Jeon
7.2-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
commit f4fafaf02174c32bce2f9bb4196fadf13f1fd96e upstream.
Windows may request FILE_NORMALIZED_NAME_INFORMATION with an output
buffer that only fits the fixed portion of the variable-length response.
Treat the fixed portion as FILE_NORMALIZED_NAME_INFORMATION_SIZE so ksmbd
returns STATUS_BUFFER_OVERFLOW instead of STATUS_INFO_LENGTH_MISMATCH.
This avoids rejecting valid partial normalized-name responses.
Fixes: 6b8b79226bc3 ("ksmbd: fix partial file information responses")
Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/server/smb2pdu.c | 3 +++
fs/smb/server/smb2pdu.h | 1 +
2 files changed, 4 insertions(+)
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -6531,6 +6531,9 @@ static int smb2_get_info_file(struct ksm
case FILE_ALTERNATE_NAME_INFORMATION:
fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
break;
+ case FILE_NORMALIZED_NAME_INFORMATION:
+ fixed_len = FILE_NORMALIZED_NAME_INFORMATION_SIZE;
+ break;
case FILE_STREAM_INFORMATION:
fixed_len = FILE_STREAM_INFORMATION_SIZE;
break;
--- a/fs/smb/server/smb2pdu.h
+++ b/fs/smb/server/smb2pdu.h
@@ -197,6 +197,7 @@ struct file_sparse {
#define FILE_ALLOCATION_INFORMATION_SIZE 19
#define FILE_END_OF_FILE_INFORMATION_SIZE 20
#define FILE_ALTERNATE_NAME_INFORMATION_SIZE 8
+#define FILE_NORMALIZED_NAME_INFORMATION_SIZE 8
#define FILE_STREAM_INFORMATION_SIZE 32
#define FILE_PIPE_INFORMATION_SIZE 23
#define FILE_PIPE_LOCAL_INFORMATION_SIZE 24
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 385/398] drm/amdgpu: lock bo before calling amdgpu_vm_bo_update_shared
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (381 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 384/398] xfs: fix under-reservation of blocks when repairing sf directories Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 386/398] drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments Greg Kroah-Hartman
` (19 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pierre-Eric Pelloux-Prayer,
Christian König, Alex Deucher, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
[ Upstream commit 36ffc58b8a8704e690a0ce679db26baa5759256f ]
BO's reservation object must be locked before using
amdgpu_vm_bo_update_shared otherwise dma_resv_assert_held will
complain in amdgpu_vm_update_shared.
Signed-off-by: Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Stable-dep-of: 636139603b99 ("drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c | 7 +++++++
1 file changed, 7 insertions(+)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c
@@ -81,6 +81,7 @@ static int amdgpu_dma_buf_attach(struct
struct drm_gem_object *obj = dmabuf->priv;
struct amdgpu_bo *bo = gem_to_amdgpu_bo(obj);
struct amdgpu_device *adev = amdgpu_ttm_adev(bo->tbo.bdev);
+ int r;
/*
* Disable peer-to-peer access for DCC-enabled VRAM surfaces on GFX12+.
@@ -98,8 +99,14 @@ static int amdgpu_dma_buf_attach(struct
pci_p2pdma_distance(adev->pdev, attach->dev, false) < 0)
attach->peer2peer = false;
+ r = dma_resv_lock(bo->tbo.base.resv, NULL);
+ if (r)
+ return r;
+
amdgpu_vm_bo_update_shared(bo);
+ dma_resv_unlock(bo->tbo.base.resv);
+
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 386/398] drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (382 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 385/398] drm/amdgpu: lock bo before calling amdgpu_vm_bo_update_shared Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 387/398] wifi: ipw2x00: Rename michael_mic() to libipw_michael_mic() Greg Kroah-Hartman
` (18 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian König, Mike Lothian,
Alex Deucher, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mike Lothian <mike@fireburn.co.uk>
[ Upstream commit 636139603b99d2e3a18a46cf3f8d39313ce8042e ]
amdgpu_dma_buf_map() adds VRAM to the allowed domains for a peer2peer
attachment. GTT is only a fallback placement when VRAM is preferred, so
ttm_bo_validate() migrates the buffer from GTT into VRAM. While the
exporting device is runtime suspended its SDMA rings are down and the
move fails:
amdgpu: Move buffer fallback to memcpy unavailable
An importer on a second GPU reaches this holding no runtime PM
reference on the exporter, e.g. a compositor on the APU submitting a
frame that references a buffer exported by an idle dGPU:
amdgpu_cs_ioctl -> amdgpu_cs_parser_bos -> amdgpu_cs_bo_validate
-> ttm_bo_validate -> amdgpu_bo_move -> dma_buf_map_attachment
-> amdgpu_dma_buf_map -> ttm_bo_validate -> amdgpu_bo_move
Pinning a dma-buf into VRAM has the same requirement, which
commit 030631e97b20 ("drm/amdgpu: revert "take runtime pm reference
when we attach a buffer" v2") called out as the one case that would
need the reference back.
Take it in attach and drop it in detach. pm_runtime_get_if_active()
never resumes the device, so it cannot deadlock against the reservation
taken during resume, which is why the old pm_runtime_get_sync() had to
go. If the device is not active, clear peer2peer instead: the buffer
then stays in GTT, which remains accessible while the GPU is powered
down. If runtime PM is disabled, take a plain reference so the put in
detach stays balanced.
Fixes: 030631e97b20 ("drm/amdgpu: revert "take runtime pm reference when we attach a buffer" v2")
Suggested-by: Christian König <christian.koenig@amd.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Mike Lothian <mike@fireburn.co.uk>
Assisted-by: Claude:Opus-5 [Claude Code]
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 062ff15e30a48d14fb7d7558eba84f8dc97197f0)
Cc: stable@vger.kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c | 43 +++++++++++++++++++++++++++-
1 file changed, 42 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_dma_buf.c
@@ -42,6 +42,7 @@
#include <linux/dma-buf.h>
#include <linux/dma-fence-array.h>
#include <linux/pci-p2pdma.h>
+#include <linux/pm_runtime.h>
static const struct dma_buf_attach_ops amdgpu_dma_buf_attach_ops;
@@ -99,15 +100,54 @@ static int amdgpu_dma_buf_attach(struct
pci_p2pdma_distance(adev->pdev, attach->dev, false) < 0)
attach->peer2peer = false;
+ /*
+ * Only allow P2P while the exporter is active, and keep it active
+ * until detach. With runtime PM disabled take a plain reference so
+ * the put in detach stays balanced.
+ */
+ if (attach->peer2peer) {
+ struct device *dev = adev_to_drm(adev)->dev;
+ int ret = pm_runtime_get_if_active(dev);
+
+ if (!ret)
+ attach->peer2peer = false;
+ else if (ret < 0)
+ pm_runtime_get_noresume(dev);
+ }
+
r = dma_resv_lock(bo->tbo.base.resv, NULL);
if (r)
- return r;
+ goto err_pm_put;
amdgpu_vm_bo_update_shared(bo);
dma_resv_unlock(bo->tbo.base.resv);
return 0;
+
+err_pm_put:
+ if (attach->peer2peer)
+ pm_runtime_put_autosuspend(adev_to_drm(adev)->dev);
+ return r;
+}
+
+/**
+ * amdgpu_dma_buf_detach - &dma_buf_ops.detach implementation
+ *
+ * @dmabuf: DMA-buf where we remove the attachment from
+ * @attach: the attachment to remove
+ *
+ * Drop the runtime PM reference taken in amdgpu_dma_buf_attach().
+ */
+static void amdgpu_dma_buf_detach(struct dma_buf *dmabuf,
+ struct dma_buf_attachment *attach)
+{
+ struct drm_gem_object *obj = dmabuf->priv;
+ struct amdgpu_bo *bo = gem_to_amdgpu_bo(obj);
+ struct amdgpu_device *adev = amdgpu_ttm_adev(bo->tbo.bdev);
+
+ if (attach->peer2peer)
+ pm_runtime_put_autosuspend(adev_to_drm(adev)->dev);
}
/**
@@ -336,6 +376,7 @@ static void amdgpu_dma_buf_vunmap(struct
const struct dma_buf_ops amdgpu_dmabuf_ops = {
.attach = amdgpu_dma_buf_attach,
+ .detach = amdgpu_dma_buf_detach,
.pin = amdgpu_dma_buf_pin,
.unpin = amdgpu_dma_buf_unpin,
.map_dma_buf = amdgpu_dma_buf_map,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 387/398] wifi: ipw2x00: Rename michael_mic() to libipw_michael_mic()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (383 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 386/398] drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 388/398] wifi: mac80211, cfg80211: Export michael_mic() and move it to cfg80211 Greg Kroah-Hartman
` (17 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Biggers, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Biggers <ebiggers@kernel.org>
[ Upstream commit ea06baf59bd4b83c2cb13698411909e5e6be001e ]
Rename the driver-local michael_mic() function to libipw_michael_mic()
to prevent a name conflict with the common michael_mic() function.
Note that this code will be superseded later when libipw starts using
the common michael_mic(). This commit just prevents a bisection hazard.
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Link: https://patch.msgid.link/20260408030651.80336-2-ebiggers@kernel.org
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 06f42accaf3c ("wifi: libipw: reject TKIP frames without a full MIC")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
--- a/drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c
@@ -464,7 +464,7 @@ static int libipw_tkip_decrypt(struct sk
return keyidx;
}
-static int michael_mic(struct crypto_shash *tfm_michael, u8 *key, u8 *hdr,
+static int libipw_michael_mic(struct crypto_shash *tfm_michael, u8 *key, u8 *hdr,
u8 *data, size_t data_len, u8 *mic)
{
SHASH_DESC_ON_STACK(desc, tfm_michael);
@@ -546,7 +546,7 @@ static int libipw_michael_mic_add(struct
michael_mic_hdr(skb, tkey->tx_hdr);
pos = skb_put(skb, 8);
- if (michael_mic(tkey->tx_tfm_michael, &tkey->key[16], tkey->tx_hdr,
+ if (libipw_michael_mic(tkey->tx_tfm_michael, &tkey->key[16], tkey->tx_hdr,
skb->data + hdr_len, skb->len - 8 - hdr_len, pos))
return -1;
@@ -584,7 +584,7 @@ static int libipw_michael_mic_verify(str
return -1;
michael_mic_hdr(skb, tkey->rx_hdr);
- if (michael_mic(tkey->rx_tfm_michael, &tkey->key[24], tkey->rx_hdr,
+ if (libipw_michael_mic(tkey->rx_tfm_michael, &tkey->key[24], tkey->rx_hdr,
skb->data + hdr_len, skb->len - 8 - hdr_len, mic))
return -1;
if (memcmp(mic, skb->data + skb->len - 8, 8) != 0) {
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 388/398] wifi: mac80211, cfg80211: Export michael_mic() and move it to cfg80211
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (384 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 387/398] wifi: ipw2x00: Rename michael_mic() to libipw_michael_mic() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 389/398] wifi: ipw2x00: Use michael_mic() from cfg80211 Greg Kroah-Hartman
` (16 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Biggers, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Biggers <ebiggers@kernel.org>
[ Upstream commit 613c83766884503f0f6bfdc45964c84b5286091c ]
Export michael_mic() so that the ath11k and ath12k drivers can call it.
In addition, move it from mac80211 to cfg80211 so that the ipw2x00
drivers, which depend on cfg80211 but not mac80211, can also call it.
Currently these drivers have their own local implementations of
michael_mic() based on crypto_shash, which is redundant and inefficient.
By consolidating all the Michael MIC code into cfg80211, we'll be able
to remove the duplicate Michael MIC code in the crypto/ directory.
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Link: https://patch.msgid.link/20260408030651.80336-3-ebiggers@kernel.org
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 06f42accaf3c ("wifi: libipw: reject TKIP frames without a full MIC")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/ieee80211.h | 5 ++
net/mac80211/Makefile | 1
net/mac80211/michael.c | 83 -------------------------------------------
net/mac80211/michael.h | 22 -----------
net/mac80211/wpa.c | 1
net/wireless/Makefile | 2 -
net/wireless/michael-mic.c | 86 +++++++++++++++++++++++++++++++++++++++++++++
7 files changed, 92 insertions(+), 108 deletions(-)
delete mode 100644 net/mac80211/michael.h
rename net/{mac80211/michael.c => wireless/michael-mic.c} (96%)
--- a/include/linux/ieee80211.h
+++ b/include/linux/ieee80211.h
@@ -2249,6 +2249,11 @@ enum ieee80211_radio_measurement_actionc
#define PMK_MAX_LEN 64
#define SAE_PASSWORD_MAX_LEN 128
+#define MICHAEL_MIC_LEN 8
+
+void michael_mic(const u8 *key, struct ieee80211_hdr *hdr,
+ const u8 *data, size_t data_len, u8 *mic);
+
/* Public action codes (IEEE Std 802.11-2016, 9.6.8.1, Table 9-307) */
enum ieee80211_pub_actioncode {
WLAN_PUB_ACTION_20_40_BSS_COEX = 0,
--- a/net/mac80211/Makefile
+++ b/net/mac80211/Makefile
@@ -18,7 +18,6 @@ mac80211-y := \
iface.o \
link.o \
rate.o \
- michael.o \
tkip.o \
aes_cmac.o \
aes_gmac.o \
--- a/net/mac80211/michael.c
+++ /dev/null
@@ -1,83 +0,0 @@
-// SPDX-License-Identifier: GPL-2.0-only
-/*
- * Michael MIC implementation - optimized for TKIP MIC operations
- * Copyright 2002-2003, Instant802 Networks, Inc.
- */
-#include <linux/types.h>
-#include <linux/bitops.h>
-#include <linux/ieee80211.h>
-#include <linux/unaligned.h>
-
-#include "michael.h"
-
-static void michael_block(struct michael_mic_ctx *mctx, u32 val)
-{
- mctx->l ^= val;
- mctx->r ^= rol32(mctx->l, 17);
- mctx->l += mctx->r;
- mctx->r ^= ((mctx->l & 0xff00ff00) >> 8) |
- ((mctx->l & 0x00ff00ff) << 8);
- mctx->l += mctx->r;
- mctx->r ^= rol32(mctx->l, 3);
- mctx->l += mctx->r;
- mctx->r ^= ror32(mctx->l, 2);
- mctx->l += mctx->r;
-}
-
-static void michael_mic_hdr(struct michael_mic_ctx *mctx, const u8 *key,
- struct ieee80211_hdr *hdr)
-{
- u8 *da, *sa, tid;
-
- da = ieee80211_get_DA(hdr);
- sa = ieee80211_get_SA(hdr);
- if (ieee80211_is_data_qos(hdr->frame_control))
- tid = ieee80211_get_tid(hdr);
- else
- tid = 0;
-
- mctx->l = get_unaligned_le32(key);
- mctx->r = get_unaligned_le32(key + 4);
-
- /*
- * A pseudo header (DA, SA, Priority, 0, 0, 0) is used in Michael MIC
- * calculation, but it is _not_ transmitted
- */
- michael_block(mctx, get_unaligned_le32(da));
- michael_block(mctx, get_unaligned_le16(&da[4]) |
- (get_unaligned_le16(sa) << 16));
- michael_block(mctx, get_unaligned_le32(&sa[2]));
- michael_block(mctx, tid);
-}
-
-void michael_mic(const u8 *key, struct ieee80211_hdr *hdr,
- const u8 *data, size_t data_len, u8 *mic)
-{
- u32 val;
- size_t block, blocks, left;
- struct michael_mic_ctx mctx;
-
- michael_mic_hdr(&mctx, key, hdr);
-
- /* Real data */
- blocks = data_len / 4;
- left = data_len % 4;
-
- for (block = 0; block < blocks; block++)
- michael_block(&mctx, get_unaligned_le32(&data[block * 4]));
-
- /* Partial block of 0..3 bytes and padding: 0x5a + 4..7 zeros to make
- * total length a multiple of 4. */
- val = 0x5a;
- while (left > 0) {
- val <<= 8;
- left--;
- val |= data[blocks * 4 + left];
- }
-
- michael_block(&mctx, val);
- michael_block(&mctx, 0);
-
- put_unaligned_le32(mctx.l, mic);
- put_unaligned_le32(mctx.r, mic + 4);
-}
--- a/net/mac80211/michael.h
+++ /dev/null
@@ -1,22 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0-only */
-/*
- * Michael MIC implementation - optimized for TKIP MIC operations
- * Copyright 2002-2003, Instant802 Networks, Inc.
- */
-
-#ifndef MICHAEL_H
-#define MICHAEL_H
-
-#include <linux/types.h>
-#include <linux/ieee80211.h>
-
-#define MICHAEL_MIC_LEN 8
-
-struct michael_mic_ctx {
- u32 l, r;
-};
-
-void michael_mic(const u8 *key, struct ieee80211_hdr *hdr,
- const u8 *data, size_t data_len, u8 *mic);
-
-#endif /* MICHAEL_H */
--- a/net/mac80211/wpa.c
+++ b/net/mac80211/wpa.c
@@ -18,7 +18,6 @@
#include <crypto/utils.h>
#include "ieee80211_i.h"
-#include "michael.h"
#include "tkip.h"
#include "aes_ccm.h"
#include "aes_cmac.h"
--- a/net/wireless/Makefile
+++ b/net/wireless/Makefile
@@ -8,7 +8,7 @@ obj-$(CONFIG_WEXT_PRIV) += wext-priv.o
cfg80211-y += core.o sysfs.o radiotap.o util.o reg.o scan.o nl80211.o
cfg80211-y += mlme.o ibss.o sme.o chan.o ethtool.o mesh.o ap.o trace.o ocb.o
-cfg80211-y += pmsr.o
+cfg80211-y += michael-mic.o pmsr.o
cfg80211-$(CONFIG_OF) += of.o
cfg80211-$(CONFIG_CFG80211_DEBUGFS) += debugfs.o
cfg80211-$(CONFIG_CFG80211_WEXT) += wext-compat.o wext-sme.o
--- /dev/null
+++ b/net/wireless/michael-mic.c
@@ -0,0 +1,86 @@
+// SPDX-License-Identifier: GPL-2.0-only
+/*
+ * Michael MIC implementation - optimized for TKIP MIC operations
+ * Copyright 2002-2003, Instant802 Networks, Inc.
+ */
+#include <linux/types.h>
+#include <linux/bitops.h>
+#include <linux/ieee80211.h>
+#include <linux/unaligned.h>
+
+struct michael_mic_ctx {
+ u32 l, r;
+};
+
+static void michael_block(struct michael_mic_ctx *mctx, u32 val)
+{
+ mctx->l ^= val;
+ mctx->r ^= rol32(mctx->l, 17);
+ mctx->l += mctx->r;
+ mctx->r ^= ((mctx->l & 0xff00ff00) >> 8) |
+ ((mctx->l & 0x00ff00ff) << 8);
+ mctx->l += mctx->r;
+ mctx->r ^= rol32(mctx->l, 3);
+ mctx->l += mctx->r;
+ mctx->r ^= ror32(mctx->l, 2);
+ mctx->l += mctx->r;
+}
+
+static void michael_mic_hdr(struct michael_mic_ctx *mctx, const u8 *key,
+ struct ieee80211_hdr *hdr)
+{
+ u8 *da, *sa, tid;
+
+ da = ieee80211_get_DA(hdr);
+ sa = ieee80211_get_SA(hdr);
+ if (ieee80211_is_data_qos(hdr->frame_control))
+ tid = ieee80211_get_tid(hdr);
+ else
+ tid = 0;
+
+ mctx->l = get_unaligned_le32(key);
+ mctx->r = get_unaligned_le32(key + 4);
+
+ /*
+ * A pseudo header (DA, SA, Priority, 0, 0, 0) is used in Michael MIC
+ * calculation, but it is _not_ transmitted
+ */
+ michael_block(mctx, get_unaligned_le32(da));
+ michael_block(mctx, get_unaligned_le16(&da[4]) |
+ (get_unaligned_le16(sa) << 16));
+ michael_block(mctx, get_unaligned_le32(&sa[2]));
+ michael_block(mctx, tid);
+}
+
+void michael_mic(const u8 *key, struct ieee80211_hdr *hdr,
+ const u8 *data, size_t data_len, u8 *mic)
+{
+ u32 val;
+ size_t block, blocks, left;
+ struct michael_mic_ctx mctx;
+
+ michael_mic_hdr(&mctx, key, hdr);
+
+ /* Real data */
+ blocks = data_len / 4;
+ left = data_len % 4;
+
+ for (block = 0; block < blocks; block++)
+ michael_block(&mctx, get_unaligned_le32(&data[block * 4]));
+
+ /* Partial block of 0..3 bytes and padding: 0x5a + 4..7 zeros to make
+ * total length a multiple of 4. */
+ val = 0x5a;
+ while (left > 0) {
+ val <<= 8;
+ left--;
+ val |= data[blocks * 4 + left];
+ }
+
+ michael_block(&mctx, val);
+ michael_block(&mctx, 0);
+
+ put_unaligned_le32(mctx.l, mic);
+ put_unaligned_le32(mctx.r, mic + 4);
+}
+EXPORT_SYMBOL_GPL(michael_mic);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 389/398] wifi: ipw2x00: Use michael_mic() from cfg80211
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (385 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 388/398] wifi: mac80211, cfg80211: Export michael_mic() and move it to cfg80211 Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 390/398] wifi: libipw: reject TKIP frames without a full MIC Greg Kroah-Hartman
` (15 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eric Biggers, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eric Biggers <ebiggers@kernel.org>
[ Upstream commit 32a0e1c63cdfaa9a6f1405b552b5f9eb2be61c59 ]
Just use the michael_mic() function from cfg80211 instead of a local
implementation of it using the crypto_shash API.
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Link: https://patch.msgid.link/20260408030651.80336-6-ebiggers@kernel.org
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 06f42accaf3c ("wifi: libipw: reject TKIP frames without a full MIC")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intel/ipw2x00/Kconfig | 1
drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c | 120 ----------------
2 files changed, 5 insertions(+), 116 deletions(-)
--- a/drivers/net/wireless/intel/ipw2x00/Kconfig
+++ b/drivers/net/wireless/intel/ipw2x00/Kconfig
@@ -154,7 +154,6 @@ config LIBIPW
depends on PCI && CFG80211
select WIRELESS_EXT
select CRYPTO
- select CRYPTO_MICHAEL_MIC
select CRYPTO_LIB_ARC4
select CRC32
help
--- a/drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c
@@ -25,8 +25,6 @@
#include <linux/ieee80211.h>
#include <net/iw_handler.h>
#include <crypto/arc4.h>
-#include <crypto/hash.h>
-#include <linux/crypto.h>
#include <linux/crc32.h>
#include "libipw.h"
@@ -57,11 +55,6 @@ struct libipw_tkip_data {
struct arc4_ctx rx_ctx_arc4;
struct arc4_ctx tx_ctx_arc4;
- struct crypto_shash *rx_tfm_michael;
- struct crypto_shash *tx_tfm_michael;
-
- /* scratch buffers for virt_to_page() (crypto API) */
- u8 rx_hdr[16], tx_hdr[16];
unsigned long flags;
};
@@ -89,41 +82,14 @@ static void *libipw_tkip_init(int key_id
priv = kzalloc(sizeof(*priv), GFP_ATOMIC);
if (priv == NULL)
- goto fail;
+ return priv;
priv->key_idx = key_idx;
-
- priv->tx_tfm_michael = crypto_alloc_shash("michael_mic", 0, 0);
- if (IS_ERR(priv->tx_tfm_michael)) {
- priv->tx_tfm_michael = NULL;
- goto fail;
- }
-
- priv->rx_tfm_michael = crypto_alloc_shash("michael_mic", 0, 0);
- if (IS_ERR(priv->rx_tfm_michael)) {
- priv->rx_tfm_michael = NULL;
- goto fail;
- }
-
return priv;
-
- fail:
- if (priv) {
- crypto_free_shash(priv->tx_tfm_michael);
- crypto_free_shash(priv->rx_tfm_michael);
- kfree(priv);
- }
-
- return NULL;
}
static void libipw_tkip_deinit(void *priv)
{
- struct libipw_tkip_data *_priv = priv;
- if (_priv) {
- crypto_free_shash(_priv->tx_tfm_michael);
- crypto_free_shash(_priv->rx_tfm_michael);
- }
kfree_sensitive(priv);
}
@@ -464,73 +430,6 @@ static int libipw_tkip_decrypt(struct sk
return keyidx;
}
-static int libipw_michael_mic(struct crypto_shash *tfm_michael, u8 *key, u8 *hdr,
- u8 *data, size_t data_len, u8 *mic)
-{
- SHASH_DESC_ON_STACK(desc, tfm_michael);
- int err;
-
- if (tfm_michael == NULL) {
- pr_warn("%s(): tfm_michael == NULL\n", __func__);
- return -1;
- }
-
- desc->tfm = tfm_michael;
-
- if (crypto_shash_setkey(tfm_michael, key, 8))
- return -1;
-
- err = crypto_shash_init(desc);
- if (err)
- goto out;
- err = crypto_shash_update(desc, hdr, 16);
- if (err)
- goto out;
- err = crypto_shash_update(desc, data, data_len);
- if (err)
- goto out;
- err = crypto_shash_final(desc, mic);
-
-out:
- shash_desc_zero(desc);
- return err;
-}
-
-static void michael_mic_hdr(struct sk_buff *skb, u8 * hdr)
-{
- struct ieee80211_hdr *hdr11;
-
- hdr11 = (struct ieee80211_hdr *)skb->data;
-
- switch (le16_to_cpu(hdr11->frame_control) &
- (IEEE80211_FCTL_FROMDS | IEEE80211_FCTL_TODS)) {
- case IEEE80211_FCTL_TODS:
- memcpy(hdr, hdr11->addr3, ETH_ALEN); /* DA */
- memcpy(hdr + ETH_ALEN, hdr11->addr2, ETH_ALEN); /* SA */
- break;
- case IEEE80211_FCTL_FROMDS:
- memcpy(hdr, hdr11->addr1, ETH_ALEN); /* DA */
- memcpy(hdr + ETH_ALEN, hdr11->addr3, ETH_ALEN); /* SA */
- break;
- case IEEE80211_FCTL_FROMDS | IEEE80211_FCTL_TODS:
- memcpy(hdr, hdr11->addr3, ETH_ALEN); /* DA */
- memcpy(hdr + ETH_ALEN, hdr11->addr4, ETH_ALEN); /* SA */
- break;
- default:
- memcpy(hdr, hdr11->addr1, ETH_ALEN); /* DA */
- memcpy(hdr + ETH_ALEN, hdr11->addr2, ETH_ALEN); /* SA */
- break;
- }
-
- if (ieee80211_is_data_qos(hdr11->frame_control)) {
- hdr[12] = le16_to_cpu(*((__le16 *)ieee80211_get_qos_ctl(hdr11)))
- & IEEE80211_QOS_CTL_TID_MASK;
- } else
- hdr[12] = 0; /* priority */
-
- hdr[13] = hdr[14] = hdr[15] = 0; /* reserved */
-}
-
static int libipw_michael_mic_add(struct sk_buff *skb, int hdr_len,
void *priv)
{
@@ -544,12 +443,9 @@ static int libipw_michael_mic_add(struct
return -1;
}
- michael_mic_hdr(skb, tkey->tx_hdr);
pos = skb_put(skb, 8);
- if (libipw_michael_mic(tkey->tx_tfm_michael, &tkey->key[16], tkey->tx_hdr,
- skb->data + hdr_len, skb->len - 8 - hdr_len, pos))
- return -1;
-
+ michael_mic(&tkey->key[16], (struct ieee80211_hdr *)skb->data,
+ skb->data + hdr_len, skb->len - 8 - hdr_len, pos);
return 0;
}
@@ -583,10 +479,8 @@ static int libipw_michael_mic_verify(str
if (!tkey->key_set)
return -1;
- michael_mic_hdr(skb, tkey->rx_hdr);
- if (libipw_michael_mic(tkey->rx_tfm_michael, &tkey->key[24], tkey->rx_hdr,
- skb->data + hdr_len, skb->len - 8 - hdr_len, mic))
- return -1;
+ michael_mic(&tkey->key[24], (struct ieee80211_hdr *)skb->data,
+ skb->data + hdr_len, skb->len - 8 - hdr_len, mic);
if (memcmp(mic, skb->data + skb->len - 8, 8) != 0) {
struct ieee80211_hdr *hdr;
hdr = (struct ieee80211_hdr *)skb->data;
@@ -614,17 +508,13 @@ static int libipw_tkip_set_key(void *key
{
struct libipw_tkip_data *tkey = priv;
int keyidx;
- struct crypto_shash *tfm = tkey->tx_tfm_michael;
struct arc4_ctx *tfm2 = &tkey->tx_ctx_arc4;
- struct crypto_shash *tfm3 = tkey->rx_tfm_michael;
struct arc4_ctx *tfm4 = &tkey->rx_ctx_arc4;
keyidx = tkey->key_idx;
memset(tkey, 0, sizeof(*tkey));
tkey->key_idx = keyidx;
- tkey->tx_tfm_michael = tfm;
tkey->tx_ctx_arc4 = *tfm2;
- tkey->rx_tfm_michael = tfm3;
tkey->rx_ctx_arc4 = *tfm4;
if (len == TKIP_KEY_LEN) {
memcpy(tkey->key, key, TKIP_KEY_LEN);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 390/398] wifi: libipw: reject TKIP frames without a full MIC
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (386 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 389/398] wifi: ipw2x00: Use michael_mic() from cfg80211 Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 391/398] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Greg Kroah-Hartman
` (14 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Daehyeon Ko, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daehyeon Ko <4ncienth@gmail.com>
[ Upstream commit 06f42accaf3c6aecab1dcc57f68dde6c06c8b380 ]
libipw_michael_mic_verify() assumes that an skb contains an eight-byte
Michael MIC. A short TKIP frame makes the unsigned payload length wrap,
causing michael_mic() to read past the skb.
Check that the MIC is present before verifying it, and use the existing
MICHAEL_MIC_LEN constant for all MIC lengths in the verifier.
Fixes: b453872c35cf ("[NET] ieee80211 subsystem")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
Link: https://patch.msgid.link/20260909061124.3802517-1-4ncienth@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
--- a/drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c
+++ b/drivers/net/wireless/intel/ipw2x00/libipw_crypto_tkip.c
@@ -474,14 +474,16 @@ static int libipw_michael_mic_verify(str
int hdr_len, void *priv)
{
struct libipw_tkip_data *tkey = priv;
- u8 mic[8];
+ u8 mic[MICHAEL_MIC_LEN];
- if (!tkey->key_set)
+ if (!tkey->key_set || skb->len < hdr_len + MICHAEL_MIC_LEN)
return -1;
michael_mic(&tkey->key[24], (struct ieee80211_hdr *)skb->data,
- skb->data + hdr_len, skb->len - 8 - hdr_len, mic);
- if (memcmp(mic, skb->data + skb->len - 8, 8) != 0) {
+ skb->data + hdr_len,
+ skb->len - MICHAEL_MIC_LEN - hdr_len, mic);
+ if (memcmp(mic, skb->data + skb->len - MICHAEL_MIC_LEN,
+ MICHAEL_MIC_LEN) != 0) {
struct ieee80211_hdr *hdr;
hdr = (struct ieee80211_hdr *)skb->data;
printk(KERN_DEBUG "%s: Michael MIC verification failed for "
@@ -499,7 +501,7 @@ static int libipw_michael_mic_verify(str
tkey->rx_iv32 = tkey->rx_iv32_new;
tkey->rx_iv16 = tkey->rx_iv16_new;
- skb_trim(skb, skb->len - 8);
+ skb_trim(skb, skb->len - MICHAEL_MIC_LEN);
return 0;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 391/398] smb: client: fix reparse buffer bounds in cifs_query_reparse_point()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (387 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 390/398] wifi: libipw: reject TKIP frames without a full MIC Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 392/398] time/namespace: Export init_time_ns and do_timens_ktime_to_host() Greg Kroah-Hartman
` (13 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Sorenson, David Howells,
Paulo Alcantara, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Sorenson <sorenson@redhat.com>
[ Upstream commit 5f0306e731e2f46e91419eae57eee3a241c055e0 ]
In cifs_query_reparse_point(), the start >= end check before casting to
struct reparse_data_buffer * only ensures the start pointer is within the
response. It fails to verify that there is enough space remaining for the
fixed 8-byte header of the structure.
If a server provides a DataOffset that leaves less than 8 bytes remaining,
the check passes, but subsequent reads of ReparseTag and ReparseDataLength
will occur out-of-bounds.
Fix this by ensuring the remaining space is at least the size of the
reparse_data_buffer structure before accessing its fields.
Fixes: 56e84c64fc25 ("cifs: Fix validation of SMB1 query reparse point response")
Cc: stable@vger.kernel.org
Signed-off-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: David Howells <dhowells@redhat.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
[ Adjusted context to retain existing `rc = -EIO` error handling instead of upstream `smb_EIO2()`. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/cifssmb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/fs/smb/client/cifssmb.c
+++ b/fs/smb/client/cifssmb.c
@@ -3015,7 +3015,7 @@ int cifs_query_reparse_point(const unsig
end = 2 + get_bcc(&io_rsp->hdr) + (__u8 *)&io_rsp->ByteCount;
start = (__u8 *)&io_rsp->hdr.Protocol + data_offset;
- if (start >= end) {
+ if (start >= end || (size_t)(end - start) < sizeof(*buf)) {
rc = -EIO;
goto error;
}
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 392/398] time/namespace: Export init_time_ns and do_timens_ktime_to_host()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (388 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 391/398] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 393/398] ksmbd: fix partial normalized name responses Greg Kroah-Hartman
` (12 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Maoyi Xie, Thomas Gleixner
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
commit 766e828b011ca5f971554001611b4acab7c244c1 upstream.
timens_ktime_to_host() in compares the current time namespace against
init_time_ns for the fast path. It calls do_timens_ktime_to_host() for the
offset case. Both symbols are needed at link time by any caller of the
inline.
All current callers are builtin, but ntsync can be built as module, which
prevents it from using it.
Export both with EXPORT_SYMBOL_GPL.
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260528063311.3300393-2-maoyixie.tju@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/time/namespace.c | 2 ++
1 file changed, 2 insertions(+)
--- a/kernel/time/namespace.c
+++ b/kernel/time/namespace.c
@@ -57,6 +57,7 @@ ktime_t do_timens_ktime_to_host(clockid_
return tim;
}
+EXPORT_SYMBOL_GPL(do_timens_ktime_to_host);
static struct ucounts *inc_time_namespaces(struct user_namespace *ns)
{
@@ -364,6 +365,7 @@ struct time_namespace init_time_ns = {
.ns.ops = &timens_operations,
.frozen_offsets = true,
};
+EXPORT_SYMBOL_GPL(init_time_ns);
void __init time_ns_init(void)
{
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 393/398] ksmbd: fix partial normalized name responses
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (389 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 392/398] time/namespace: Export init_time_ns and do_timens_ktime_to_host() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 394/398] wifi: mac80211: fix list iteration in ieee80211_add_virtual_monitor() Greg Kroah-Hartman
` (11 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mobin Aydinfar, ChenXiaoSong,
Namjae Jeon
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namjae Jeon <linkinjeon@kernel.org>
commit f4fafaf02174c32bce2f9bb4196fadf13f1fd96e upstream.
Windows may request FILE_NORMALIZED_NAME_INFORMATION with an output
buffer that only fits the fixed portion of the variable-length response.
Treat the fixed portion as FILE_NORMALIZED_NAME_INFORMATION_SIZE so ksmbd
returns STATUS_BUFFER_OVERFLOW instead of STATUS_INFO_LENGTH_MISMATCH.
This avoids rejecting valid partial normalized-name responses.
Fixes: 6b8b79226bc3 ("ksmbd: fix partial file information responses")
Reported-by: Mobin Aydinfar <mobin@mobintestserver.ir>
Reviewed-by: ChenXiaoSong <chenxiaosong@kylinos.cn>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/server/smb2pdu.c | 3 +++
fs/smb/server/smb2pdu.h | 1 +
2 files changed, 4 insertions(+)
--- a/fs/smb/server/smb2pdu.c
+++ b/fs/smb/server/smb2pdu.c
@@ -5542,6 +5542,9 @@ static int smb2_get_info_file(struct ksm
case FILE_ALTERNATE_NAME_INFORMATION:
fixed_len = FILE_ALTERNATE_NAME_INFORMATION_SIZE;
break;
+ case FILE_NORMALIZED_NAME_INFORMATION:
+ fixed_len = FILE_NORMALIZED_NAME_INFORMATION_SIZE;
+ break;
case FILE_STREAM_INFORMATION:
fixed_len = FILE_STREAM_INFORMATION_SIZE;
break;
--- a/fs/smb/server/smb2pdu.h
+++ b/fs/smb/server/smb2pdu.h
@@ -213,6 +213,7 @@ struct file_sparse {
#define FILE_ALLOCATION_INFORMATION_SIZE 19
#define FILE_END_OF_FILE_INFORMATION_SIZE 20
#define FILE_ALTERNATE_NAME_INFORMATION_SIZE 8
+#define FILE_NORMALIZED_NAME_INFORMATION_SIZE 8
#define FILE_STREAM_INFORMATION_SIZE 32
#define FILE_PIPE_INFORMATION_SIZE 23
#define FILE_PIPE_LOCAL_INFORMATION_SIZE 24
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 394/398] wifi: mac80211: fix list iteration in ieee80211_add_virtual_monitor()
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (390 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 393/398] ksmbd: fix partial normalized name responses Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 395/398] ASoC: sdw_utils: subtract the endpoint that is not present Greg Kroah-Hartman
` (10 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+bc1aabf52d0a31e91f96,
Dmitry Antipov, Johannes Berg
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Antipov <dmantipov@yandex.ru>
commit cbf0dc37bb4e949f1c76566657e71f8e0bdcf338 upstream.
Since 'mon_list' of 'struct ieee80211_local' is RCU-protected and
an instances of 'struct ieee80211_sub_if_data' are linked there
via 'u.mntr.list' member, adjust the corresponding list iteration
in 'ieee80211_add_virtual_monitor()' accordingly.
Reported-by: syzbot+bc1aabf52d0a31e91f96@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=bc1aabf52d0a31e91f96
Fixes: a5aa46f1ac4f ("wifi: mac80211: track MU-MIMO configuration on disabled interfaces")
Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
Link: https://patch.msgid.link/20251204130533.340069-1-dmantipov@yandex.ru
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
net/mac80211/iface.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/net/mac80211/iface.c
+++ b/net/mac80211/iface.c
@@ -1290,7 +1290,7 @@ configure_monitor:
if (!creator_sdata) {
struct ieee80211_sub_if_data *other;
- list_for_each_entry(other, &local->mon_list, list) {
+ list_for_each_entry_rcu(other, &local->mon_list, u.mntr.list) {
if (!other->vif.bss_conf.mu_mimo_owner)
continue;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 395/398] ASoC: sdw_utils: subtract the endpoint that is not present
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (391 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 394/398] wifi: mac80211: fix list iteration in ieee80211_add_virtual_monitor() Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 396/398] Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device Greg Kroah-Hartman
` (9 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bard Liao, Péter Ujfalusi,
Vijendar Mukunda, Charles Keepax, Mark Brown
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bard Liao <yung-chuan.liao@linux.intel.com>
commit cb0ae6f22790ead71a866f94c7a5a70ad56af16a upstream.
When asoc_sdw_count_sdw_endpoints() count the num_ends, it doesn't skip
the unpresented endpoints. But, asoc_sdw_parse_sdw_endpoints() will skip
the unpresented endpoints either by quirk or the SDCA function doesn't
show up the endpoint. The endpoint number mismatches between count and
parse and the machine driver will show up a warning about it.
Fixes: 26ee34d2f5c7 ("ASoC: sdw_utils: Add codec_conf for every DAI")
Closes: https://github.com/thesofproject/linux/issues/5620
Signed-off-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Reviewed-by: Péter Ujfalusi <peter.ujfalusi@linux.intel.com>
Reviewed-by: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
Reviewed-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Link: https://patch.msgid.link/20251212121112.3313017-1-yung-chuan.liao@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/sdw_utils/soc_sdw_utils.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
--- a/sound/soc/sdw_utils/soc_sdw_utils.c
+++ b/sound/soc/sdw_utils/soc_sdw_utils.c
@@ -1441,8 +1441,10 @@ int asoc_sdw_parse_sdw_endpoints(struct
* endpoint check is not necessary
*/
if (dai_info->quirk &&
- !(dai_info->quirk_exclude ^ !!(dai_info->quirk & ctx->mc_quirk)))
+ !(dai_info->quirk_exclude ^ !!(dai_info->quirk & ctx->mc_quirk))) {
+ (*num_devs)--;
continue;
+ }
} else {
/* Check SDCA codec endpoint if there is no matching quirk */
ret = is_sdca_endpoint_present(dev, codec_info, adr_link, i, j);
@@ -1450,8 +1452,10 @@ int asoc_sdw_parse_sdw_endpoints(struct
return ret;
/* The endpoint is not present, skip */
- if (!ret)
+ if (!ret) {
+ (*num_devs)--;
continue;
+ }
}
dev_dbg(dev,
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 396/398] Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (392 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 395/398] ASoC: sdw_utils: subtract the endpoint that is not present Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 397/398] Revert "ksmbd: Fix to handle removal of rfc1002 header from smb_hdr" Greg Kroah-Hartman
` (8 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zijun Hu, Luiz Augusto von Dentz
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zijun Hu <zijun.hu@oss.qualcomm.com>
commit 3ec629fee178d429f01ae843e4ea888de93012bf upstream.
hu->serdev is NULL for hci_uart attached via non-serdev paths, but
qca_setup() unconditionally calls serdev_device_get_drvdata(hu->serdev)
and dereferences the result, causing a NULL pointer dereference.
Fix by guarding the dereference with a NULL check, consistent with the
rest of qca_setup().
Fixes: 22d893eec0d5 ("Bluetooth: hci_qca: Refactor HFP hardware offload capability handling")
Signed-off-by: Zijun Hu <zijun.hu@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/bluetooth/hci_qca.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
--- a/drivers/bluetooth/hci_qca.c
+++ b/drivers/bluetooth/hci_qca.c
@@ -1917,9 +1917,12 @@ static int qca_setup(struct hci_uart *hu
const char *rampatch_name = qca_get_rampatch_name(hu);
int ret;
struct qca_btsoc_version ver;
- struct qca_serdev *qcadev = serdev_device_get_drvdata(hu->serdev);
+ struct qca_serdev *qcadev = NULL;
const char *soc_name;
+ if (hu->serdev)
+ qcadev = serdev_device_get_drvdata(hu->serdev);
+
ret = qca_check_speeds(hu);
if (ret)
return ret;
@@ -1981,7 +1984,7 @@ retry:
case QCA_WCN6750:
case QCA_WCN6855:
case QCA_WCN7850:
- if (qcadev->bdaddr_property_broken)
+ if (qcadev && qcadev->bdaddr_property_broken)
hci_set_quirk(hdev, HCI_QUIRK_BDADDR_PROPERTY_BROKEN);
hci_set_aosp_capable(hdev);
@@ -2074,7 +2077,7 @@ out:
else
hu->hdev->set_bdaddr = qca_set_bdaddr;
- if (qcadev->support_hfp_hw_offload)
+ if (qcadev && qcadev->support_hfp_hw_offload)
qca_configure_hfp_offload(hdev);
qca->fw_version = le16_to_cpu(ver.patch_ver);
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 397/398] Revert "ksmbd: Fix to handle removal of rfc1002 header from smb_hdr"
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (393 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 396/398] Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 398/398] smb/client: send lease break ACKs thru correct session for multiuser mounts Greg Kroah-Hartman
` (7 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, stable@vger.kernel.org, Namjae Jeon,
Namjae Jeon
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
Revert commit 29dbb4e29e1f197172b1a0513f65c3ff6ec4fbc8 which is commit
0a70cac7896712a08e3cd22c16f44be976d40dbf upstream.
Commit 29dbb4e29e1f ("ksmbd: Fix to handle removal of rfc1002 header
from smb_hdr") is a backport of upstream commit 0a70cac78967.
The upstream commit depends on SMB1 header refactoring which removed the
RFC1002 length field from struct smb_hdr. Those prerequisite changes are
not present in the 6.18.y stable tree, where ksmbd still defines struct
smb_hdr with the smb_buf_length field.
As a result, smb_get_msg() advances the buffer by four bytes before it is
cast to a structure that already includes the RFC1002 field. This causes a
four-byte offset mismatch while parsing and constructing the initial SMB1
multi-protocol negotiate response.
Windows clients then receive a malformed negotiate response and abort the
connection.
This reverts commit 29dbb4e29e1f ("ksmbd: Fix to handle removal of
rfc1002 header from smb_hdr").
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/server/server.c | 2 +-
fs/smb/server/smb_common.c | 20 ++++++++++----------
2 files changed, 11 insertions(+), 11 deletions(-)
--- a/fs/smb/server/server.c
+++ b/fs/smb/server/server.c
@@ -95,7 +95,7 @@ static inline int check_conn_state(struc
if (ksmbd_conn_exiting(work->conn) ||
ksmbd_conn_need_reconnect(work->conn)) {
- rsp_hdr = smb_get_msg(work->response_buf);
+ rsp_hdr = work->response_buf;
rsp_hdr->Status.CifsError = STATUS_CONNECTION_DISCONNECTED;
return 1;
}
--- a/fs/smb/server/smb_common.c
+++ b/fs/smb/server/smb_common.c
@@ -140,7 +140,7 @@ int ksmbd_verify_smb_message(struct ksmb
if (smb2_hdr->ProtocolId == SMB2_PROTO_NUMBER)
return ksmbd_smb2_check_message(work);
- hdr = smb_get_msg(work->request_buf);
+ hdr = work->request_buf;
if (*(__le32 *)hdr->Protocol == SMB1_PROTO_NUMBER &&
hdr->Command == SMB_COM_NEGOTIATE) {
work->conn->outstanding_credits++;
@@ -278,14 +278,15 @@ static int ksmbd_negotiate_smb_dialect(v
req->DialectCount);
}
+ proto = *(__le32 *)((struct smb_hdr *)buf)->Protocol;
if (proto == SMB1_PROTO_NUMBER) {
struct smb_negotiate_req *req;
- req = (struct smb_negotiate_req *)smb_get_msg(buf);
+ req = (struct smb_negotiate_req *)buf;
if (le16_to_cpu(req->ByteCount) < 2)
goto err_out;
- if (offsetof(struct smb_negotiate_req, DialectsArray) +
+ if (offsetof(struct smb_negotiate_req, DialectsArray) - 4 +
le16_to_cpu(req->ByteCount) > smb_buf_length) {
goto err_out;
}
@@ -319,8 +320,8 @@ static u16 get_smb1_cmd_val(struct ksmbd
*/
static int init_smb1_rsp_hdr(struct ksmbd_work *work)
{
- struct smb_hdr *rsp_hdr = (struct smb_hdr *)smb_get_msg(work->response_buf);
- struct smb_hdr *rcv_hdr = (struct smb_hdr *)smb_get_msg(work->request_buf);
+ struct smb_hdr *rsp_hdr = (struct smb_hdr *)work->response_buf;
+ struct smb_hdr *rcv_hdr = (struct smb_hdr *)work->request_buf;
rsp_hdr->Command = SMB_COM_NEGOTIATE;
*(__le32 *)rsp_hdr->Protocol = SMB1_PROTO_NUMBER;
@@ -411,10 +412,9 @@ static int init_smb1_server(struct ksmbd
int ksmbd_init_smb_server(struct ksmbd_conn *conn)
{
- struct smb_hdr *rcv_hdr = (struct smb_hdr *)smb_get_msg(conn->request_buf);
__le32 proto;
- proto = *(__le32 *)rcv_hdr->Protocol;
+ proto = *(__le32 *)((struct smb_hdr *)conn->request_buf)->Protocol;
if (conn->need_neg == false) {
if (proto == SMB1_PROTO_NUMBER)
return -EINVAL;
@@ -572,12 +572,12 @@ static int __smb2_negotiate(struct ksmbd
static int smb_handle_negotiate(struct ksmbd_work *work)
{
- struct smb_negotiate_rsp *neg_rsp = smb_get_msg(work->response_buf);
+ struct smb_negotiate_rsp *neg_rsp = work->response_buf;
ksmbd_debug(SMB, "Unsupported SMB1 protocol\n");
- if (ksmbd_iov_pin_rsp(work, (void *)neg_rsp,
- sizeof(struct smb_negotiate_rsp)))
+ if (ksmbd_iov_pin_rsp(work, (void *)neg_rsp + 4,
+ sizeof(struct smb_negotiate_rsp) - 4))
return -ENOMEM;
neg_rsp->hdr.Status.CifsError = STATUS_SUCCESS;
^ permalink raw reply [flat|nested] 873+ messages in thread
* [PATCH 6.18 398/398] smb/client: send lease break ACKs thru correct session for multiuser mounts
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (394 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 397/398] Revert "ksmbd: Fix to handle removal of rfc1002 header from smb_hdr" Greg Kroah-Hartman
@ 2026-09-23 14:07 ` Greg Kroah-Hartman
2026-09-23 14:54 ` [PATCH 6.18 000/398] 6.18.54-rc1 review Brett A C Sheffield
` (6 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-23 14:07 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, April Cardenas, Namjae Jeon,
Bharath S M, Paulo Alcantara, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: April Cardenas <april.cardenas@canonical.com>
[ Upstream commit ebc5660132ddd244b57f03ed324922013a3d7363 ]
Currently, when cifs_oplock_break handles a break request from the server
it searches for the appropriate tlink to handle the request
but incorrectly uses the current fsuid as the search key, eventually
causing read errors for users with multiuser mounts on NetApp.
Fix this by using the tlink from the cfile struct instead to respond
through the correct session.
As breaks are handled in a worker thread, the current fsuid
isn't guaranteed to match the session that the break is intended for.
This means that cifs_sb_tlink may search the rbtree using the wrong fsuid,
and return a tlink with an incorrect session than
the lease break was intended for. As a result, the breaks
may be ACKed through an incorrect session.
While it seems that Samba/Windows Servers 2016-2025 ignore this as long as
the lease key is correct, we ran into a case where if you're using
NetApp ONTAP or Azure NetApp Files they will reject the ACK
and return `STATUS_LOCK_NOT_GRANTED` errors on any future read requests
a user may initiate through their still held open file handle,
and the server will eventually close the file.
In the dmesg logs, the user may see errors like these:
CIFS: Status code returned 0xc0000128 STATUS_FILE_CLOSED
CIFS: VFS: Send error in read = -9
With a multiuser mount using NetApp, this issue is really easy
for users to hit on a wide variety of kernel versions
by attempting to copy a file from the share
to the local machine through GNOME Files/Nautilus.
This copy will always result in Nautilus throwing
a `Bad File Descriptor` error to the user and fail.
With this fix, you can copy files through Nautilus without issue.
>>From looking at the traces, it seems that glib will
open the file first, and call listxattr before actually attempting
to copy the file data. The listxattr call always triggers a break,
causing the copy to fail.
The proposed fix returns to the way the client grabbed the tlink before
commit e8f5f849ffce2 ("cifs: fix potential oops in cifs_oplock_break").
The bulk of that commit (checking for list empty) remains untouched, and
I think the change to using cifs_sb_tlink was intended to avoid a
NULL/ERR deference on the tlink as well as update the reference count.
I believe this fix should preserve those safety properties, but of course
I'd appreciate any corrections here.
Fixes: e8f5f849ffce2 ("cifs: fix potential oops in cifs_oplock_break")
Cc: stable@vger.kernel.org
Signed-off-by: April Cardenas <april.cardenas@canonical.com>
Reviewed-by: Namjae Jeon <linkinjeon@kernel.org>
Reviewed-by: Bharath S M <bharathsm@microsoft.com>
Signed-off-by: Paulo Alcantara <pc@manguebit.org>
[ Removed now-unused sb and cifs_sb declarations from cifs_oplock_break(). ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/smb/client/file.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
--- a/fs/smb/client/file.c
+++ b/fs/smb/client/file.c
@@ -3148,8 +3148,6 @@ void cifs_oplock_break(struct work_struc
struct cifsFileInfo *cfile = container_of(work, struct cifsFileInfo,
oplock_break);
struct inode *inode = d_inode(cfile->dentry);
- struct super_block *sb = inode->i_sb;
- struct cifs_sb_info *cifs_sb = CIFS_SB(sb);
struct cifsInodeInfo *cinode = CIFS_I(inode);
struct cifs_tcon *tcon;
struct TCP_Server_Info *server;
@@ -3162,8 +3160,8 @@ void cifs_oplock_break(struct work_struc
wait_on_bit(&cinode->flags, CIFS_INODE_PENDING_WRITERS,
TASK_UNINTERRUPTIBLE);
- tlink = cifs_sb_tlink(cifs_sb);
- if (IS_ERR(tlink)) {
+ tlink = cifs_get_tlink(cfile->tlink);
+ if (IS_ERR_OR_NULL(tlink)) {
/* drop the reference taken when the break was queued */
_cifsFileInfo_put(cfile, false /* do not wait for ourself */, false);
goto out;
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 000/398] 6.18.54-rc1 review
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (395 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 6.18 398/398] smb/client: send lease break ACKs thru correct session for multiuser mounts Greg Kroah-Hartman
@ 2026-09-23 14:54 ` Brett A C Sheffield
2026-09-23 16:39 ` Peter Schneider
` (5 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Brett A C Sheffield @ 2026-09-23 14:54 UTC (permalink / raw)
To: gregkh
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr,
Brett A C Sheffield
# Librecast Test Results
020/020 [ OK ] liblcrq
010/010 [ OK ] libmld
120/120 [ OK ] liblibrecast
CPU/kernel: Linux auntie 6.18.54-rc1-gef437f2f0758 #1 SMP PREEMPT_DYNAMIC Wed Sep 23 14:48:56 -00 2026 x86_64 AMD Ryzen 9 9950X 16-Core Processor AuthenticAMD GNU/Linux
Tested-by: Brett A C Sheffield <bacs@librecast.net>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (437 preceding siblings ...)
2026-09-23 14:07 ` [PATCH 7.2 438/438] ksmbd: fix partial normalized name responses Greg Kroah-Hartman
@ 2026-09-23 14:54 ` Brett A C Sheffield
2026-09-23 16:15 ` Ronald Warsow
` (10 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Brett A C Sheffield @ 2026-09-23 14:54 UTC (permalink / raw)
To: gregkh
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr,
Brett A C Sheffield
# Librecast Test Results
020/020 [ OK ] liblcrq
010/010 [ OK ] libmld
120/120 [ OK ] liblibrecast
CPU/kernel: Linux auntie 7.2.8-rc1-g54e8ef17140e #2 SMP PREEMPT_DYNAMIC Wed Sep 23 14:52:16 -00 2026 x86_64 AMD Ryzen 9 9950X 16-Core Processor AuthenticAMD GNU/Linux
Tested-by: Brett A C Sheffield <bacs@librecast.net>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (438 preceding siblings ...)
2026-09-23 14:54 ` [PATCH 7.2 000/438] 7.2.8-rc1 review Brett A C Sheffield
@ 2026-09-23 16:15 ` Ronald Warsow
2026-09-23 17:00 ` Florian Fainelli
` (9 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Ronald Warsow @ 2026-09-23 16:15 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
conor, hargar, broonie, achill, sr
Hi
kernel build / boot test on x86_64 (Intel).
No regressions here.
Thanks
Tested-by: Ronald Warsow <rwarsow@gmx.de>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 000/398] 6.18.54-rc1 review
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (396 preceding siblings ...)
2026-09-23 14:54 ` [PATCH 6.18 000/398] 6.18.54-rc1 review Brett A C Sheffield
@ 2026-09-23 16:39 ` Peter Schneider
2026-09-23 19:00 ` Florian Fainelli
` (4 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Peter Schneider @ 2026-09-23 16:39 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
Am 23.09.2026 um 16:01 schrieb Greg Kroah-Hartman:
> This is the start of the stable review cycle for the 6.18.54 release.
> There are 398 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
Builds, boots and works on my 2-socket Ivy Bridge Xeon E5-2697v2 server. No dmesg oddities or regressions found.
Tested-by: Peter Schneider <pschneider1968@googlemail.com>
Beste Grüße,
Peter Schneider
--
Climb the mountain not to plant your flag, but to embrace the challenge,
enjoy the air and behold the view. Climb it so you can see the world,
not so the world can see you. -- David McCullough Jr.
OpenPGP: 0xA3828BD796CCE11A8CADE8866E3A92C92C3FF244
Download: https://www.peters-netzplatz.de/download/pschneider1968_pub.asc
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@googlemail.com
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@gmail.com
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (439 preceding siblings ...)
2026-09-23 16:15 ` Ronald Warsow
@ 2026-09-23 17:00 ` Florian Fainelli
2026-09-23 18:20 ` Peter Schneider
` (8 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Florian Fainelli @ 2026-09-23 17:00 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, sudipm.mukherjee, rwarsow, conor,
hargar, broonie, achill, sr
On 9/23/2026 7:00 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 25 Sep 2026 14:05:46 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.8-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
On ARCH_BRCMSTB using 32-bit and 64-bit ARM kernels, build tested on
BMIPS_GENERIC:
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
--
Florian
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (440 preceding siblings ...)
2026-09-23 17:00 ` Florian Fainelli
@ 2026-09-23 18:20 ` Peter Schneider
2026-09-24 3:47 ` Ron Economos
` (7 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Peter Schneider @ 2026-09-23 18:20 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
Am 23.09.2026 um 16:00 schrieb Greg Kroah-Hartman:
> This is the start of the stable review cycle for the 7.2.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
Builds, boots and works on my 2-socket Ivy Bridge Xeon E5-2697v2 server. No dmesg oddities or regressions found.
Tested-by: Peter Schneider <pschneider1968@googlemail.com>
Beste Grüße,
Peter Schneider
--
Climb the mountain not to plant your flag, but to embrace the challenge,
enjoy the air and behold the view. Climb it so you can see the world,
not so the world can see you. -- David McCullough Jr.
OpenPGP: 0xA3828BD796CCE11A8CADE8866E3A92C92C3FF244
Download: https://www.peters-netzplatz.de/download/pschneider1968_pub.asc
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@googlemail.com
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@gmail.com
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 000/398] 6.18.54-rc1 review
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (397 preceding siblings ...)
2026-09-23 16:39 ` Peter Schneider
@ 2026-09-23 19:00 ` Florian Fainelli
2026-09-24 3:50 ` Ron Economos
` (3 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Florian Fainelli @ 2026-09-23 19:00 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, sudipm.mukherjee, rwarsow, conor,
hargar, broonie, achill, sr
On 9/23/2026 7:01 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 6.18.54 release.
> There are 398 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 25 Sep 2026 14:05:48 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.18.54-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.18.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
On ARCH_BRCMSTB using 32-bit and 64-bit ARM kernels, build tested on
BMIPS_GENERIC:
Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
--
Florian
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 104/438] dma-buf: Make DMABUF_DEBUG default to y on DEBUG_KERNEL kernels
2026-09-23 14:02 ` [PATCH 7.2 104/438] dma-buf: Make DMABUF_DEBUG default to y on DEBUG_KERNEL kernels Greg Kroah-Hartman
@ 2026-09-23 20:41 ` Karl Mehltretter
2026-09-24 1:15 ` Sasha Levin
0 siblings, 1 reply; 873+ messages in thread
From: Karl Mehltretter @ 2026-09-23 20:41 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: Karl Mehltretter, stable, patches, Christian König,
Sasha Levin, Jianfeng Liu, Rob Clark
I object to including this patch in 7.2.8. I authored the upstream
patch, but did not tag it for stable. It corrects a Kconfig default
and thereby enables the DMA-BUF importer checks in configurations
that take the DEBUG_KERNEL default.
Jianfeng has now reported a drm/msm hardware video decode regression
from the upstream change:
https://lore.kernel.org/r/20260923074256.9357-1-liujianfeng1994@gmail.com/
The impact of enabling this by default for stable needs further
discussion.
Thanks,
Karl
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 104/438] dma-buf: Make DMABUF_DEBUG default to y on DEBUG_KERNEL kernels
2026-09-23 20:41 ` Karl Mehltretter
@ 2026-09-24 1:15 ` Sasha Levin
2026-09-24 7:33 ` Christian König
0 siblings, 1 reply; 873+ messages in thread
From: Sasha Levin @ 2026-09-24 1:15 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: Sasha Levin, Karl Mehltretter, stable, patches,
Christian König, Jianfeng Liu, Rob Clark
On Wed, Sep 23, 2026 at 10:41:46PM +0200, Karl Mehltretter wrote:
> I object to including this patch in 7.2.8. I authored the upstream
> patch, but did not tag it for stable. It corrects a Kconfig default
> and thereby enables the DMA-BUF importer checks in configurations
> that take the DEBUG_KERNEL default.
Dropped from the 7.2 queue, so it won't be in 7.2.8.
--
Thanks,
Sasha
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (441 preceding siblings ...)
2026-09-23 18:20 ` Peter Schneider
@ 2026-09-24 3:47 ` Ron Economos
2026-09-24 11:26 ` Pavel Machek
` (6 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Ron Economos @ 2026-09-24 3:47 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
On 9/23/26 07:00, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 25 Sep 2026 14:05:46 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.8-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Built and booted successfully on RISC-V RV64 (HiFive Unmatched).
Tested-by: Ron Economos <re@w6rz.net>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 000/398] 6.18.54-rc1 review
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (398 preceding siblings ...)
2026-09-23 19:00 ` Florian Fainelli
@ 2026-09-24 3:50 ` Ron Economos
2026-09-24 11:27 ` Pavel Machek
` (2 subsequent siblings)
402 siblings, 0 replies; 873+ messages in thread
From: Ron Economos @ 2026-09-24 3:50 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
On 9/23/26 07:01, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 6.18.54 release.
> There are 398 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 25 Sep 2026 14:05:48 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.18.54-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.18.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Built and booted successfully on RISC-V RV64 (HiFive Unmatched).
Tested-by: Ron Economos <re@w6rz.net>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 129/398] net: bcmgenet: convert RX path to page_pool
2026-09-23 14:03 ` [PATCH 6.18 129/398] net: bcmgenet: convert RX path to page_pool Greg Kroah-Hartman
@ 2026-09-24 6:58 ` Karl Mehltretter
2026-09-24 7:28 ` Greg Kroah-Hartman
0 siblings, 1 reply; 873+ messages in thread
From: Karl Mehltretter @ 2026-09-24 6:58 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: Karl Mehltretter, stable, patches, Nicolai Buchwitz, Justin Chen,
Doug Berger, Florian Fainelli,
Broadcom internal kernel review list, netdev, Jakub Kicinski,
Sasha Levin
I have a small objection to taking patch 129 into 6.18.y only as a
dependency for patch 130.
My LLM agent helped me running these tests.
On a 64 KiB arm64 kernel in a custom QEMU Pi 400 model with functional
GENET v5 DMA, patch 129 increased the socket receive-memory charge per
512-byte UDP datagram from 2,752 to 65,792 bytes.
With the same 512 KiB socket receive-buffer limit, this reduced the number
of queued datagrams from 190 to 7 and increased socket receive-buffer drops
from 810 to 993 per 1,000 datagrams. I obtained the same result in five
bursts.
The page-pool conversion otherwise worked in this test, and physical Pi 400
testing with 4 KiB pages found no correctness failure. However, patch 130
was also verified on the Pi 400 to work without patch 129 after a small
contextual adaptation.
I would appreciate the BCMGENET maintainers' view on whether this page-pool
conversion is appropriate for 6.18.y.
Please consider omitting patch 129 from 6.18.y and applying that adapted
version of patch 130 directly.
Full test details and logs are available if useful.
Thanks,
Karl
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 129/398] net: bcmgenet: convert RX path to page_pool
2026-09-24 6:58 ` Karl Mehltretter
@ 2026-09-24 7:28 ` Greg Kroah-Hartman
2026-09-24 8:10 ` Nicolai Buchwitz
2026-09-24 10:36 ` Nicolai Buchwitz
0 siblings, 2 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-24 7:28 UTC (permalink / raw)
To: Karl Mehltretter
Cc: stable, patches, Nicolai Buchwitz, Justin Chen, Doug Berger,
Florian Fainelli, Broadcom internal kernel review list, netdev,
Jakub Kicinski, Sasha Levin
On Thu, Sep 24, 2026 at 08:58:39AM +0200, Karl Mehltretter wrote:
> I have a small objection to taking patch 129 into 6.18.y only as a
> dependency for patch 130.
>
> My LLM agent helped me running these tests.
>
> On a 64 KiB arm64 kernel in a custom QEMU Pi 400 model with functional
> GENET v5 DMA, patch 129 increased the socket receive-memory charge per
> 512-byte UDP datagram from 2,752 to 65,792 bytes.
>
> With the same 512 KiB socket receive-buffer limit, this reduced the number
> of queued datagrams from 190 to 7 and increased socket receive-buffer drops
> from 810 to 993 per 1,000 datagrams. I obtained the same result in five
> bursts.
>
> The page-pool conversion otherwise worked in this test, and physical Pi 400
> testing with 4 KiB pages found no correctness failure. However, patch 130
> was also verified on the Pi 400 to work without patch 129 after a small
> contextual adaptation.
>
> I would appreciate the BCMGENET maintainers' view on whether this page-pool
> conversion is appropriate for 6.18.y.
>
> Please consider omitting patch 129 from 6.18.y and applying that adapted
> version of patch 130 directly.
But when you update to a newer release, that memory increase will
happen, right? So why not fix the root problem upstream first?
Also, there is no context here in the email, please always include that
when replying.
thanks,
greg k-h
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 104/438] dma-buf: Make DMABUF_DEBUG default to y on DEBUG_KERNEL kernels
2026-09-24 1:15 ` Sasha Levin
@ 2026-09-24 7:33 ` Christian König
0 siblings, 0 replies; 873+ messages in thread
From: Christian König @ 2026-09-24 7:33 UTC (permalink / raw)
To: Sasha Levin, Greg Kroah-Hartman
Cc: Karl Mehltretter, stable, patches, Jianfeng Liu, Rob Clark
On 9/24/26 03:15, Sasha Levin wrote:
> On Wed, Sep 23, 2026 at 10:41:46PM +0200, Karl Mehltretter wrote:
>> I object to including this patch in 7.2.8. I authored the upstream
>> patch, but did not tag it for stable. It corrects a Kconfig default
>> and thereby enables the DMA-BUF importer checks in configurations
>> that take the DEBUG_KERNEL default.
>
> Dropped from the 7.2 queue, so it won't be in 7.2.8.
>
Thanks for catching this Karl and I agree completely.
That config option is for phasing out a broken approach in some DRM drivers, but not meant to be added to any stable kernel.
Regards,
Christian.
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 129/398] net: bcmgenet: convert RX path to page_pool
2026-09-24 7:28 ` Greg Kroah-Hartman
@ 2026-09-24 8:10 ` Nicolai Buchwitz
2026-09-24 10:36 ` Nicolai Buchwitz
1 sibling, 0 replies; 873+ messages in thread
From: Nicolai Buchwitz @ 2026-09-24 8:10 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: Karl Mehltretter, stable, patches, Justin Chen, Doug Berger,
Florian Fainelli, Broadcom internal kernel review list, netdev,
Jakub Kicinski, Sasha Levin
Hi Greg
On 24.9.2026 09:28, Greg Kroah-Hartman wrote:
> On Thu, Sep 24, 2026 at 08:58:39AM +0200, Karl Mehltretter wrote:
>> I have a small objection to taking patch 129 into 6.18.y only as a
>> dependency for patch 130.
>>
>> My LLM agent helped me running these tests.
>>
>> On a 64 KiB arm64 kernel in a custom QEMU Pi 400 model with functional
>> GENET v5 DMA, patch 129 increased the socket receive-memory charge per
>> 512-byte UDP datagram from 2,752 to 65,792 bytes.
>>
>> With the same 512 KiB socket receive-buffer limit, this reduced the
>> number
>> of queued datagrams from 190 to 7 and increased socket receive-buffer
>> drops
>> from 810 to 993 per 1,000 datagrams. I obtained the same result in
>> five
>> bursts.
>>
>> The page-pool conversion otherwise worked in this test, and physical
>> Pi 400
>> testing with 4 KiB pages found no correctness failure. However, patch
>> 130
>> was also verified on the Pi 400 to work without patch 129 after a
>> small
>> contextual adaptation.
>>
>> I would appreciate the BCMGENET maintainers' view on whether this
>> page-pool
>> conversion is appropriate for 6.18.y.
>>
>> Please consider omitting patch 129 from 6.18.y and applying that
>> adapted
>> version of patch 130 directly.
>
> But when you update to a newer release, that memory increase will
> happen, right? So why not fix the root problem upstream first?
Agree. I will have a look at Karl's regression report and probably sent
patches via netdev with cc stable.
> [...]
Regards
Nicolai
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 129/398] net: bcmgenet: convert RX path to page_pool
2026-09-24 7:28 ` Greg Kroah-Hartman
2026-09-24 8:10 ` Nicolai Buchwitz
@ 2026-09-24 10:36 ` Nicolai Buchwitz
1 sibling, 0 replies; 873+ messages in thread
From: Nicolai Buchwitz @ 2026-09-24 10:36 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: Karl Mehltretter, stable, patches, Justin Chen, Doug Berger,
Florian Fainelli, Broadcom internal kernel review list, netdev,
Jakub Kicinski, Sasha Levin
Hi Greg, hi Karl
On 24.9.2026 09:28, Greg Kroah-Hartman wrote:
> On Thu, Sep 24, 2026 at 08:58:39AM +0200, Karl Mehltretter wrote:
> [...]
>> I would appreciate the BCMGENET maintainers' view on whether this
>> page-pool
>> conversion is appropriate for 6.18.y.
I would rather have the page_pool conversion in 6.18.y. More fixes will
land on top of it, and carrying it is less work than adapting each of
them. The fix for the regression applies on top of it unchanged.
>> Please consider omitting patch 129 from 6.18.y and applying that
>> adapted
>> version of patch 130 directly.
>
> But when you update to a newer release, that memory increase will
> happen, right? So why not fix the root problem upstream first?
The fix is on netdev, "net: bcmgenet: allocate RX buffers as page
fragments", with a Fixes tag for 7bc054c2d4ed:
https://lore.kernel.org/netdev/20260924101922.2675127-1-nb@tipi-net.de
I was able to reproduce Karl's numbers on a CM4 with a 64 KiB page
kernel
and fortunately the fix was straightforward.
> [...]
Regards
Nicolai
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (442 preceding siblings ...)
2026-09-24 3:47 ` Ron Economos
@ 2026-09-24 11:26 ` Pavel Machek
2026-09-24 11:50 ` Takeshi Ogasawara
` (5 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Pavel Machek @ 2026-09-24 11:26 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
[-- Attachment #1: Type: text/plain, Size: 501 bytes --]
Hi!
> This is the start of the stable review cycle for the 7.2.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
CIP testing did not find any problems here:
https://gitlab.com/cip-project/cip-testing/linux-stable-rc-ci/-/tree/linux-7.2.y
Tested-by: Pavel Machek (CIP) <pavel@nabladev.com>
Best regards,
Pavel
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 195 bytes --]
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 000/398] 6.18.54-rc1 review
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (399 preceding siblings ...)
2026-09-24 3:50 ` Ron Economos
@ 2026-09-24 11:27 ` Pavel Machek
2026-09-25 4:23 ` Barry K. Nathan
2026-09-25 5:25 ` Wentao Guan
402 siblings, 0 replies; 873+ messages in thread
From: Pavel Machek @ 2026-09-24 11:27 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
[-- Attachment #1: Type: text/plain, Size: 504 bytes --]
Hi!
> This is the start of the stable review cycle for the 6.18.54 release.
> There are 398 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
CIP testing did not find any problems here:
https://gitlab.com/cip-project/cip-testing/linux-stable-rc-ci/-/tree/linux-6.18.y
Tested-by: Pavel Machek (CIP) <pavel@nabladev.com>
Best regards,
Pavel
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 195 bytes --]
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (443 preceding siblings ...)
2026-09-24 11:26 ` Pavel Machek
@ 2026-09-24 11:50 ` Takeshi Ogasawara
2026-09-24 16:59 ` Markus Reichelt
` (4 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Takeshi Ogasawara @ 2026-09-24 11:50 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
Hi Greg
On Thu, Sep 24, 2026 at 12:19 AM Greg Kroah-Hartman
<gregkh@linuxfoundation.org> wrote:
>
> This is the start of the stable review cycle for the 7.2.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 25 Sep 2026 14:05:46 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.8-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
>
Linux version 7.2.8-rc1 tested.
Build successfully completed.
Boot successfully completed.
No dmesg regressions.
Video output normal.
Sound output normal.
Lenovo ThinkPad X1 Carbon Gen10(Intel i7-1260P(x86_64) arch linux)
[ 0.000000] Linux version 7.2.8-rc1rv-g54e8ef17140e
(takeshi@ThinkPadX1Gen10J0764) (gcc (GCC) 16.2.1 20260810, GNU ld (GNU
Binutils) 2.47) #1 SMP PREEMPT_DYNAMIC Thu Sep 24 19:15:39 JST 2026
Tested-by: Takeshi Ogasawara <takeshi.ogasawara@futuring-girl.com>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (444 preceding siblings ...)
2026-09-24 11:50 ` Takeshi Ogasawara
@ 2026-09-24 16:59 ` Markus Reichelt
2026-09-24 17:08 ` Justin Forbes
` (3 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Markus Reichelt @ 2026-09-24 16:59 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
* Greg Kroah-Hartman <gregkh@linuxfoundation.org> wrote:
> This is the start of the stable review cycle for the 7.2.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 25 Sep 2026 14:05:46 +0000.
> Anything received after that time might be too late.
7.2.8-rc1 compiles on x86_64 (Xeon E5-1620 v2, Slackware64-15.0),
and boots & runs on x86_64 (AMD Ryzen 5 7520U, Slackware64-current).
No regressions observed during boot & my custom tests.
Tested-by: Markus Reichelt <lkt+2023@mareichelt.com>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (445 preceding siblings ...)
2026-09-24 16:59 ` Markus Reichelt
@ 2026-09-24 17:08 ` Justin Forbes
2026-09-24 20:18 ` Wentao Guan
` (2 subsequent siblings)
449 siblings, 0 replies; 873+ messages in thread
From: Justin Forbes @ 2026-09-24 17:08 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
On Wed, Sep 23, 2026 at 04:00:21PM +0200, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 25 Sep 2026 14:05:46 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.8-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
Tested rc1 against the Fedora build system (aarch64, ppc64le, s390x,
x86_64), and boot tested x86_64. No regressions noted.
Tested-by: Justin M. Forbes <jforbes@fedoraproject.org>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (446 preceding siblings ...)
2026-09-24 17:08 ` Justin Forbes
@ 2026-09-24 20:18 ` Wentao Guan
2026-09-25 2:28 ` Benjamin Boortz
2026-09-25 4:18 ` Barry K. Nathan
449 siblings, 0 replies; 873+ messages in thread
From: Wentao Guan @ 2026-09-24 20:18 UTC (permalink / raw)
To: gregkh
Cc: achill, akpm, broonie, conor, f.fainelli, hargar, jonathanh,
linux-kernel, linux, lkft-triage, patches, patches, pavel,
rwarsow, shuah, sr, stable, sudipm.mukherjee, torvalds,
Wentao Guan
Build tested in our x86 config successfully without error.
Tested-by: Wentao Guan <guanwentao@uniontech.com>
Best Regards
Wentao Guan
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (447 preceding siblings ...)
2026-09-24 20:18 ` Wentao Guan
@ 2026-09-25 2:28 ` Benjamin Boortz
2026-09-25 4:18 ` Barry K. Nathan
449 siblings, 0 replies; 873+ messages in thread
From: Benjamin Boortz @ 2026-09-25 2:28 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
On Wed, Sep 23, 2026 at 04:00:21PM +0200, Greg Kroah-Hartman wrote:
>This is the start of the stable review cycle for the 7.2.8 release.
>There are 438 patches in this series, all will be posted as a response
>to this one. If anyone has any issues with these being applied, please
>let me know.
Build and boot tested with QEMU for x86_64, i386, arm64, and riscv
across multiple configurations, and boots on AMD Ryzen 7 5800H.
No regressions observed.
Tested-by: Benjamin Boortz <bennib@mailbox.org>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 7.2 000/438] 7.2.8-rc1 review
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
` (448 preceding siblings ...)
2026-09-25 2:28 ` Benjamin Boortz
@ 2026-09-25 4:18 ` Barry K. Nathan
449 siblings, 0 replies; 873+ messages in thread
From: Barry K. Nathan @ 2026-09-25 4:18 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
On 9/23/26 7:00 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.8 release.
> There are 438 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 25 Sep 2026 14:05:46 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.8-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
On 3 amd64 systems and 1 arm64 virtual machine, I tested 7.2.7 +
stable-queue as of commit b1b54c5d771a22b69e435ef44b5fe9ac1e714703
("drop 3 patches and reorder one 6.18 patch based on RC review feedback").
Working well, no regressions observed.
Tested-by: Barry K. Nathan <barryn@pobox.com>
--
-Barry K. Nathan <barryn@pobox.com>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 000/398] 6.18.54-rc1 review
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (400 preceding siblings ...)
2026-09-24 11:27 ` Pavel Machek
@ 2026-09-25 4:23 ` Barry K. Nathan
2026-09-25 5:25 ` Wentao Guan
402 siblings, 0 replies; 873+ messages in thread
From: Barry K. Nathan @ 2026-09-25 4:23 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
rwarsow, conor, hargar, broonie, achill, sr
On 9/23/26 7:01 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 6.18.54 release.
> There are 398 patches in this series, all will be posted as a response
> to this one. If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 25 Sep 2026 14:05:48 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.18.54-rc1.gz
> or in the git tree and branch at:
> git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.18.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
On an amd64 laptop (Lenovo ThinkPad T14 Gen 1) and an arm64
virtual machine, I tested 6.18.53 + stable-queue as of commit
b1b54c5d771a22b69e435ef44b5fe9ac1e714703
("drop 3 patches and reorder one 6.18 patch based on RC review feedback").
Working well, no regressions observed.
Tested-by: Barry K. Nathan <barryn@pobox.com>
--
-Barry K. Nathan <barryn@pobox.com>
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 000/398] 6.18.54-rc1 review
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
` (401 preceding siblings ...)
2026-09-25 4:23 ` Barry K. Nathan
@ 2026-09-25 5:25 ` Wentao Guan
402 siblings, 0 replies; 873+ messages in thread
From: Wentao Guan @ 2026-09-25 5:25 UTC (permalink / raw)
To: gregkh
Cc: achill, akpm, broonie, conor, f.fainelli, hargar, jonathanh,
linux-kernel, linux, lkft-triage, patches, patches, pavel,
rwarsow, shuah, sr, stable, sudipm.mukherjee, torvalds,
Wentao Guan
Build tested in our x86 config successfully without error.
Tested-by: Wentao Guan <guanwentao@uniontech.com>
Best Regards
Wentao Guan
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 303/398] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
2026-09-23 14:06 ` [PATCH 6.18 303/398] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Greg Kroah-Hartman
@ 2026-09-26 23:19 ` Daniel Salmun
2026-09-30 12:03 ` Greg Kroah-Hartman
0 siblings, 1 reply; 873+ messages in thread
From: Daniel Salmun @ 2026-09-26 23:19 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable
Cc: patches, Raphaël Larocque, Dmitry Torokhov, linux-input
On 9/23/26 11:06, Greg Kroah-Hartman wrote:
> 6.18-stable review patch. If anyone has any objections, please let
> me know.
>
> ------------------
>
> From: Raphaël Larocque <rlarocque@disroot.org>
>
> commit 26eb3d92c7a4d7adb1ae1740ca6e8e100b11d1ec upstream.
>
> The Lenovo ThinkPad T440p (PNP ID LEN0036, board id 2722) has a
> Synaptics touchpad whose SMBus companion is not ready at boot and
> takes roughly 200 seconds to appear.
[...]
> Disable SMBus InterTouch for board id 2722 so the touchpad and
> TrackPoint work immediately via PS/2 from boot.
I have a concern about this one. Board id 2722 isn't specific to the
T440p. My ThinkPad L440 has the same Synaptics board id, and this patch
would move it from SMBus/RMI4 to PS/2. I have never hit the issue this
commit fixes, and I haven't seen it reported on other potentially
affected models either.
I sent a patch [1] that limits the quirk to the T440p. Previous
attempts to move these touchpads to PS/2 were rejected [2], as
explained in that patch's commit message.
Could this be dropped from the stable queue until it's sorted out
upstream?
[1] https://lore.kernel.org/all/20260925230039.236786-1-
salmundani@gmail.com/
[2] https://lore.kernel.org/linux-
input/65C23A49-5A55-4CF4-9AFD-2DA504DAABF5@duggan.us/
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors
2026-09-23 14:04 ` [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors Greg Kroah-Hartman
@ 2026-09-28 4:41 ` springbreeze
2026-09-28 5:33 ` Greg Kroah-Hartman
2026-09-28 10:25 ` Miguel Ojeda
0 siblings, 2 replies; 873+ messages in thread
From: springbreeze @ 2026-09-28 4:41 UTC (permalink / raw)
To: Greg Kroah-Hartman, stable@vger.kernel.org
Cc: patches@lists.linux.dev, FUJITA Tomonori, Jakub Kicinski
Hi Greg, Sasha,
Please drop the 6.18.y patch as it stands in this review series, or take the
variant below instead.
The queued patch fixes the three accessors with the bindgen-generated raw
accessors (link_raw(), autoneg_raw(), autoneg_complete_raw()), which bindgen
only emits from 0.71 on. This branch's documented minimum is 0.65.1
(scripts/min-tool-version.sh), so the patch applies cleanly but does not
build with the minimum supported toolchain.
The bug itself is present here: 2796ff1e3dca shifted autoneg, link and
autoneg_complete up by one bit, and the hand-written offsets were never
updated. It can be fixed without the raw accessors by correcting the
numbers directly:
is_link_up() 15 (was 14)
is_autoneg_enabled() 14 (was 13)
is_autoneg_completed() 16 (was 15)
I re-checked the backport against v6.18 (rust/kernel/net/phy.rs blob
bf6272d87a7b); the corrected 6.18.y form is below.
Thanks,
Chunfeng Song
________________________________________
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Sent: Wednesday, September 23, 2026 22:04
To: stable@vger.kernel.org <stable@vger.kernel.org>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>; patches@lists.linux.dev <patches@lists.linux.dev>; Chunfeng Song <springbreeze@stu.pku.edu.cn>; FUJITA Tomonori <fujita.tomonori@gmail.com>; Jakub Kicinski <kuba@kernel.org>
Subject: [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chunfeng Song <springbreeze@stu.pku.edu.cn>
commit 6fb0a9d9071f1ff0cc5cfc0782302d9c90d642cb upstream.
The hand-written bitfield offsets in is_link_up(), is_autoneg_enabled()
and is_autoneg_completed() were correct when the abstraction was
merged: at that time autoneg, link, and autoneg_complete were at bits
13, 14, and 15 of struct phy_device's first bitfield unit. Commit
2796ff1e3dca ("net: phy: add flag is_genphy_driven to struct phy_device")
later inserted is_genphy_driven just before autoneg, shifting the three
fields up by one, so the accessors now read:
is_link_up() reads bit 14 = autoneg
is_autoneg_enabled() reads bit 13 = is_genphy_driven
is_autoneg_completed() reads bit 15 = link
The official ax88796b Rust driver uses all three accessors in its
read_status() implementation, so it inherits the bug.
phy_attach_direct() sets is_genphy_driven only when it falls back to
the generic driver, and ax88796b has a real driver, so
is_genphy_driven stays 0. The broken is_autoneg_enabled() therefore
reads bit 13 as 0, compares it against AUTONEG_ENABLE (1), and always
returns false, so read_status() never reaches the
resolve_aneg_linkmode() call.
The ordinary bindgen accessors take &self. Calling them through
(*phydev).link() would create a shared reference to the complete
bindings::phy_device, which is not appropriate for an object wrapped in
Opaque.
Use the bindgen-generated raw accessors (link_raw(), autoneg_raw(),
and autoneg_complete_raw()) instead. They retain the bit positions and
endianness handling generated from the C layout without creating a Rust
reference to the complete phy_device. Drop the hand-written numbers
together with the TODO comment that marked them as a stopgap.
The raw accessors are only emitted by bindgen 0.71 and later, and were
added at the Rust-for-Linux project's request, so this fix can only be
backported to stable branches whose minimum bindgen version is at least
that, hence the scope on the Cc: stable line below.
Found by a static equivalence audit (C2RustDrv, a C-to-Rust driver
migration tool) that compares hand-written bitfield offsets against
the bindgen layout of struct phy_device. Verified by building the
bindings and checking the generated accessors; no runtime testing was
possible without PHY hardware.
Fixes: 2796ff1e3dca ("net: phy: add flag is_genphy_driven to struct phy_device")
Cc: stable@vger.kernel.org # Only 7.1.y and later (requires bindgen's raw pointer accessors).
Link: https://github.com/rust-lang/rust-bindgen/issues/2674
Signed-off-by: Chunfeng Song <springbreeze@stu.pku.edu.cn>
Reviewed-by: FUJITA Tomonori <fujita.tomonori@gmail.com>
Link: https://patch.msgid.link/20260910055110.167110-1-springbreeze@stu.pku.edu.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
rust/kernel/net/phy.rs | 38 ++++++++++++++++++--------------------
1 file changed, 18 insertions(+), 20 deletions(-)
diff --git a/rust/kernel/net/phy.rs b/rust/kernel/net/phy.rs
index 956cda573ddb..c4e7b1d6c6f4 100644
--- a/rust/kernel/net/phy.rs
+++ b/rust/kernel/net/phy.rs
@@ -123,39 +123,37 @@ pub fn state(&self) -> DeviceState {
/// Gets the current link state.
///
/// It returns true if the link is up.
+ #[inline]
pub fn is_link_up(&self) -> bool {
- const LINK_IS_UP: u64 = 1;
- // TODO: the code to access to the bit field will be replaced with automatically
- // generated code by bindgen when it becomes possible.
- // SAFETY: The struct invariant ensures that we may access
- // this field without additional synchronization.
- let bit_field = unsafe { &(*self.0.get())._bitfield_1 };
- bit_field.get(14, 1) == LINK_IS_UP
+ let phydev = self.0.get().cast_const();
+ // SAFETY: By the type invariant of `Device`, `phydev` points to a valid
+ // `struct phy_device`, and there is no concurrent write to this field.
+ let link = unsafe { bindings::phy_device::link_raw(phydev) };
+ link == 1
}
/// Gets the current auto-negotiation configuration.
///
/// It returns true if auto-negotiation is enabled.
+ #[inline]
pub fn is_autoneg_enabled(&self) -> bool {
- // TODO: the code to access to the bit field will be replaced with automatically
- // generated code by bindgen when it becomes possible.
- // SAFETY: The struct invariant ensures that we may access
- // this field without additional synchronization.
- let bit_field = unsafe { &(*self.0.get())._bitfield_1 };
- bit_field.get(13, 1) == u64::from(bindings::AUTONEG_ENABLE)
+ let phydev = self.0.get().cast_const();
+ // SAFETY: By the type invariant of `Device`, `phydev` points to a valid
+ // `struct phy_device`, and there is no concurrent write to this field.
+ let autoneg = unsafe { bindings::phy_device::autoneg_raw(phydev) };
+ autoneg == bindings::AUTONEG_ENABLE
}
/// Gets the current auto-negotiation state.
///
/// It returns true if auto-negotiation is completed.
+ #[inline]
pub fn is_autoneg_completed(&self) -> bool {
- const AUTONEG_COMPLETED: u64 = 1;
- // TODO: the code to access to the bit field will be replaced with automatically
- // generated code by bindgen when it becomes possible.
- // SAFETY: The struct invariant ensures that we may access
- // this field without additional synchronization.
- let bit_field = unsafe { &(*self.0.get())._bitfield_1 };
- bit_field.get(15, 1) == AUTONEG_COMPLETED
+ let phydev = self.0.get().cast_const();
+ // SAFETY: By the type invariant of `Device`, `phydev` points to a valid
+ // `struct phy_device`, and there is no concurrent write to this field.
+ let completed = unsafe { bindings::phy_device::autoneg_complete_raw(phydev) };
+ completed == 1
}
/// Sets the speed of the PHY.
--
2.55.0
^ permalink raw reply related [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors
2026-09-28 4:41 ` springbreeze
@ 2026-09-28 5:33 ` Greg Kroah-Hartman
2026-09-28 10:25 ` Miguel Ojeda
1 sibling, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-28 5:33 UTC (permalink / raw)
To: springbreeze@stu.pku.edu.cn
Cc: stable@vger.kernel.org, patches@lists.linux.dev, FUJITA Tomonori,
Jakub Kicinski
On Mon, Sep 28, 2026 at 04:41:23AM +0000, springbreeze@stu.pku.edu.cn wrote:
> Hi Greg, Sasha,
>
> Please drop the 6.18.y patch as it stands in this review series, or take the
> variant below instead.
This is already in the 6.18.54 kernel release. Please either sbmit a
fix, or a revert and new addition like this.
thanks,
greg k-h
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors
2026-09-28 4:41 ` springbreeze
2026-09-28 5:33 ` Greg Kroah-Hartman
@ 2026-09-28 10:25 ` Miguel Ojeda
2026-09-28 10:54 ` Miguel Ojeda
1 sibling, 1 reply; 873+ messages in thread
From: Miguel Ojeda @ 2026-09-28 10:25 UTC (permalink / raw)
To: springbreeze; +Cc: fujita.tomonori, gregkh, kuba, patches, stable
On Mon, 28 Sep 2026 04:41:23 +0000 "springbreeze@stu.pku.edu.cn" <springbreeze@stu.pku.edu.cn> wrote:
>
> I re-checked the backport against v6.18 (rust/kernel/net/phy.rs blob
> bf6272d87a7b); the corrected 6.18.y form is below.
I think you may have sent the same one?
Let me send a quick series using a revert which is clearer, and if that
is what you meant, then please confirm you are OK with the SoB!
Cheers,
Miguel
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors
2026-09-28 10:25 ` Miguel Ojeda
@ 2026-09-28 10:54 ` Miguel Ojeda
2026-09-29 3:09 ` springbreeze
2026-09-29 3:14 ` 回复: " springbreeze
0 siblings, 2 replies; 873+ messages in thread
From: Miguel Ojeda @ 2026-09-28 10:54 UTC (permalink / raw)
To: ojeda; +Cc: fujita.tomonori, gregkh, kuba, patches, springbreeze, stable
On Mon, 28 Sep 2026 12:25:47 +0200 Miguel Ojeda <ojeda@kernel.org> wrote:
>
> Let me send a quick series using a revert which is clearer, and if that
> is what you meant, then please confirm you are OK with the SoB!
Done:
https://lore.kernel.org/stable/20260928104855.205416-1-ojeda@kernel.org/
I ended up sending #2 in the series with myself as author just in case,
but if you somehow had posted it elsewhere, or if you prefer to be
listed as author, please let us now!
Cheers,
Miguel
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors
2026-09-28 10:54 ` Miguel Ojeda
@ 2026-09-29 3:09 ` springbreeze
2026-09-29 5:13 ` Miguel Ojeda
2026-09-29 3:14 ` 回复: " springbreeze
1 sibling, 1 reply; 873+ messages in thread
From: springbreeze @ 2026-09-29 3:09 UTC (permalink / raw)
To: Miguel Ojeda
Cc: fujita.tomonori@gmail.com, gregkh@linuxfoundation.org,
kuba@kernel.org, patches@lists.linux.dev, stable@vger.kernel.org
Hi Miguel,
Yes, that is exactly what I meant -- thanks a lot for taking care of it.
I re-checked the series against v6.18 and it is correct:
1d17bf1ae87d (6.18.y today) -> bf6272d87a7b (1/2, back to v6.18)
-> 5963dbbd54af (2/2, offsets 15/14/16)
That matches the backport I had prepared locally, so:
Acked-by: Chunfeng Song <springbreeze@stu.pku.edu.cn>
Please keep yourself as the author of 2/2, and of course I am fine with
your SoB -- the upstream Signed-off-by is enough for me.
One nit, feel free to ignore: 2/2 still carries the upstream paragraph
starting "Use the bindgen-generated raw accessors ..." and the Cc: stable
scope line, neither of which matches the diff anymore. Your bracketed
note already explains it, but dropping those two bits may read better.
Thanks again,
Chunfeng
________________________________________
From: Miguel Ojeda <ojeda@kernel.org>
Sent: Monday, September 28, 2026 18:54
To: ojeda@kernel.org
Cc: fujita.tomonori@gmail.com; gregkh@linuxfoundation.org; kuba@kernel.org; patches@lists.linux.dev; springbreeze@stu.pku.edu.cn; stable@vger.kernel.org
Subject: Re: [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors
On Mon, 28 Sep 2026 12:25:47 +0200 Miguel Ojeda <ojeda@kernel.org> wrote:
>
> Let me send a quick series using a revert which is clearer, and if that
> is what you meant, then please confirm you are OK with the SoB!
Done:
https://lore.kernel.org/stable/20260928104855.205416-1-ojeda@kernel.org/
I ended up sending #2 in the series with myself as author just in case,
but if you somehow had posted it elsewhere, or if you prefer to be
listed as author, please let us now!
Cheers,
Miguel
^ permalink raw reply [flat|nested] 873+ messages in thread
* 回复: [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors
2026-09-28 10:54 ` Miguel Ojeda
2026-09-29 3:09 ` springbreeze
@ 2026-09-29 3:14 ` springbreeze
1 sibling, 0 replies; 873+ messages in thread
From: springbreeze @ 2026-09-29 3:14 UTC (permalink / raw)
To: 'Miguel Ojeda'; +Cc: fujita.tomonori, gregkh, kuba, patches, stable
Hi Miguel,
Yes, that is exactly what I meant -- thanks a lot for taking care of it.
I re-checked the series against v6.18 and it is correct:
1d17bf1ae87d (6.18.y today) -> bf6272d87a7b (1/2, back to v6.18)
-> 5963dbbd54af (2/2, offsets 15/14/16)
That matches the backport I had prepared locally, so:
Acked-by: Chunfeng Song <springbreeze@stu.pku.edu.cn>
Please keep yourself as the author of 2/2, and of course I am fine with
your SoB -- the upstream Signed-off-by is enough for me.
One nit, feel free to ignore: 2/2 still carries the upstream paragraph
starting "Use the bindgen-generated raw accessors ..." and the Cc: stable
scope line, neither of which matches the diff anymore. Your bracketed
note already explains it, but dropping those two bits may read better.
Thanks again,
Chunfeng
-----邮件原件-----
发件人: Miguel Ojeda <ojeda@kernel.org>
发送时间: 2026年9月28日 18:55
收件人: ojeda@kernel.org
抄送: fujita.tomonori@gmail.com; gregkh@linuxfoundation.org;
kuba@kernel.org; patches@lists.linux.dev; springbreeze@stu.pku.edu.cn;
stable@vger.kernel.org
主题: Re: [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions
in device status accessors
On Mon, 28 Sep 2026 12:25:47 +0200 Miguel Ojeda <ojeda@kernel.org> wrote:
>
> Let me send a quick series using a revert which is clearer, and if
> that is what you meant, then please confirm you are OK with the SoB!
Done:
https://lore.kernel.org/stable/20260928104855.205416-1-ojeda@kernel.org/
I ended up sending #2 in the series with myself as author just in case, but
if you somehow had posted it elsewhere, or if you prefer to be listed as
author, please let us now!
Cheers,
Miguel
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors
2026-09-29 3:09 ` springbreeze
@ 2026-09-29 5:13 ` Miguel Ojeda
0 siblings, 0 replies; 873+ messages in thread
From: Miguel Ojeda @ 2026-09-29 5:13 UTC (permalink / raw)
To: springbreeze@stu.pku.edu.cn
Cc: Miguel Ojeda, fujita.tomonori@gmail.com,
gregkh@linuxfoundation.org, kuba@kernel.org,
patches@lists.linux.dev, stable@vger.kernel.org
On Tue, Sep 29, 2026 at 5:17 AM springbreeze@stu.pku.edu.cn
<springbreeze@stu.pku.edu.cn> wrote:
>
> Yes, that is exactly what I meant -- thanks a lot for taking care of it.
> I re-checked the series against v6.18 and it is correct:
>
> 1d17bf1ae87d (6.18.y today) -> bf6272d87a7b (1/2, back to v6.18)
> -> 5963dbbd54af (2/2, offsets 15/14/16)
>
> That matches the backport I had prepared locally, so:
>
> Acked-by: Chunfeng Song <springbreeze@stu.pku.edu.cn>
Let me reply with your tag in the patches to make sure it is not missed.
> Please keep yourself as the author of 2/2, and of course I am fine with
> your SoB -- the upstream Signed-off-by is enough for me.
Thanks a lot for double-checking it!
> One nit, feel free to ignore: 2/2 still carries the upstream paragraph
> starting "Use the bindgen-generated raw accessors ..." and the Cc: stable
> scope line, neither of which matches the diff anymore. Your bracketed
> note already explains it, but dropping those two bits may read better.
Yeah, I am not sure what the stable team prefers. Normally, I either
do the square bracket thing (to try to keep the commit "as is") or I
send a completely new one explaining the difference. I was on the
fence about this one, because the original commit had quite a bit of
context that seemed bad to lose, but it is true that of course it
doesn't match the contents.
Cheers,
Miguel
^ permalink raw reply [flat|nested] 873+ messages in thread
* Re: [PATCH 6.18 303/398] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722)
2026-09-26 23:19 ` Daniel Salmun
@ 2026-09-30 12:03 ` Greg Kroah-Hartman
0 siblings, 0 replies; 873+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-30 12:03 UTC (permalink / raw)
To: Daniel Salmun
Cc: stable, patches, Raphaël Larocque, Dmitry Torokhov,
linux-input
On Sat, Sep 26, 2026 at 08:19:55PM -0300, Daniel Salmun wrote:
> On 9/23/26 11:06, Greg Kroah-Hartman wrote:
> > 6.18-stable review patch. If anyone has any objections, please let
> > me know.
> >
> > ------------------
> >
> > From: Raphaël Larocque <rlarocque@disroot.org>
> >
> > commit 26eb3d92c7a4d7adb1ae1740ca6e8e100b11d1ec upstream.
> >
> > The Lenovo ThinkPad T440p (PNP ID LEN0036, board id 2722) has a
> > Synaptics touchpad whose SMBus companion is not ready at boot and
> > takes roughly 200 seconds to appear.
> [...]
> > Disable SMBus InterTouch for board id 2722 so the touchpad and
> > TrackPoint work immediately via PS/2 from boot.
>
> I have a concern about this one. Board id 2722 isn't specific to the
> T440p. My ThinkPad L440 has the same Synaptics board id, and this patch
> would move it from SMBus/RMI4 to PS/2. I have never hit the issue this
> commit fixes, and I haven't seen it reported on other potentially
> affected models either.
>
> I sent a patch [1] that limits the quirk to the T440p. Previous
> attempts to move these touchpads to PS/2 were rejected [2], as
> explained in that patch's commit message.
>
> Could this be dropped from the stable queue until it's sorted out
> upstream?
>
> [1] https://lore.kernel.org/all/20260925230039.236786-1-
> salmundani@gmail.com/
> [2] https://lore.kernel.org/linux-
> input/65C23A49-5A55-4CF4-9AFD-2DA504DAABF5@duggan.us/
>
Let's just queue up whatever gets commited in Linus's tree to resolve
this.
thanks,
greg k-h
^ permalink raw reply [flat|nested] 873+ messages in thread
end of thread, other threads:[~2026-09-30 12:03 UTC | newest]
Thread overview: 873+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-23 14:01 [PATCH 6.18 000/398] 6.18.54-rc1 review Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 001/398] Revert "perf annotate: Fix build with NO_SLANG=1" Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 002/398] landlock: Fix TCP Fast Open connection bypass Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 003/398] selftests/landlock: Add test for TCP fast open Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 004/398] selftests/landlock: Add missing connect(minimal AF_UNSPEC) test Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 005/398] selftests/landlock: Fix socket file descriptor leaks in audit helpers Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 006/398] selftests/landlock: Increase default audit socket timeout Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 007/398] selftests/landlock: Explicitly disable audit in teardowns Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 008/398] selftests/landlock: Add tests for access through disconnected paths Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 009/398] selftests/landlock: Add disconnected leafs and branch test suites Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 010/398] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 011/398] selftests/landlock: Add tests for whiteout object creation Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 012/398] selftests/landlock: Add audit test " Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 013/398] sunvdc: fix -EIO issue due to lack of retries Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 014/398] media: video-i2c: fix buffer queue ordering Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 015/398] ipv6: Select best matching nexthop object in fib6_table_lookup() Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 016/398] ipv6: Honor oif when choosing nexthop for locally generated traffic Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 017/398] xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 018/398] xfrm: iptfs: fix runt reassembly panic from short inner tot_len Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 019/398] xfrm: avoid RCU warnings around the per-netns netlink socket Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 020/398] xfrm: fix compat ALLOCSPI request use-after-free Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 021/398] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 022/398] esp: downgrade zerocopy managed frags before mutating skb frags Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 023/398] ARM: socfpga: select the PL310 erratum 753970 workaround Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 024/398] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 025/398] RDMA/rxe: validate access flags before swapping the MRs PD Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 026/398] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 027/398] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 028/398] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 029/398] RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 030/398] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 031/398] RDMA/mlx5: Remove warn on missing representor in query_port_speed Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 032/398] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 033/398] power: sequencing: Fix build issue with COMPILE_TEST Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 034/398] arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 035/398] arm64: dts: renesas: r9a09g056: " Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 036/398] arm64: dts: renesas: r9a09g047: " Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 037/398] IB/iser: reject a remote invalidation of an unregistered direction Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 038/398] IB/isert: wait for deferred control PDU completions before releasing the connection Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 039/398] RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 040/398] RDMA/mad: Fix receive buffer leak when PKey enforcement fails Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 041/398] RDMA/irdma: Enforce local fence for IB_WR_REG_MR Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 042/398] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 043/398] dmaengine: sprd: Fix runtime PM reference leak in probe Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 044/398] wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 6.18 045/398] wifi: virt_wifi: free skb when disconnected Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 046/398] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 047/398] wifi: brcmfmac: cyw: pass PMKID to firmware if present Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 048/398] wifi: libipw: reject too-short beacon and probe responses Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 049/398] wifi: libipw: reject too-short association responses Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 050/398] IB/IPoIB: Avoid restoring OPER_UP after multicast flush Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 051/398] wifi: cfg80211: dont get the radio mask for netdev-less wdevs Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 052/398] wifi: cfg80211: check IP header size in cfg80211_classify8021d() Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 053/398] soundwire: cadence_master: wait and cancel cdns->work before clock stop Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 054/398] MIPS: Octeon: apply USB FDT fixups also when USB is modular Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 055/398] dma-coherent: report a failed reserved memory assignment Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 056/398] dmaengine: Fix device kref underflow in dma_chan_put() Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 057/398] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 058/398] dmaengine: wait for RCU readers before releasing dma_device Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 059/398] wifi: cfg80211: dont free driver-owned scan requests Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 060/398] wifi: cfg80211: only group hidden BSSes with beacon entries Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 061/398] wifi: cfg80211: dont filter by BSS type when removing stale entries Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 062/398] wifi: mac80211: dont start a ROC while scanning Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 063/398] wifi: mac80211: dont warn when an IBSS has no channel to scan Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 064/398] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 065/398] wifi: mac80211: suppress chanctx warning for debugfs reset Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 066/398] wifi: mac80211: abort chanswitch when leaving a mesh Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 067/398] wifi: mac80211: reset state when starting AP fails Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 068/398] wifi: cfg80211: restore netns_immutable on failures Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 069/398] wifi: cfg80211: undo netns switch if renaming the wiphy fails Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 070/398] wifi: mac80211: unlist vifs when their netdev is unregistered Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 071/398] wifi: cfg80211: get the wiphy out of a dying network namespace Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 072/398] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 073/398] wifi: mac80211: dont allow injecting frames wider than the chanctx Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 074/398] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 075/398] wifi: mac80211: require a peer station for TDLS setup confirm Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 076/398] wifi: mac80211: dont allow link changes when iface is down Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 077/398] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 078/398] wifi: mac80211: dont access the TSF of a down interface Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 079/398] wifi: mac80211: add HE 6 GHz capability in the scan elems len Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 080/398] wifi: mac80211: mesh: reset the CSA state when leaving Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 081/398] wifi: mac80211: mesh: release the channel if start fails Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 082/398] wifi: mac80211: set up the TX info early to fix failure paths Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 083/398] mm: memblock: show all region flags in debugfs Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 084/398] scsi: qla2xxx: Fix the ql2xfc2target parameter description Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 085/398] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 086/398] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 087/398] RDMA/efa: Keep admin queues alive while IRQ is registered Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 088/398] RDMA/efa: Keep EQ resources " Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 089/398] RDMA/siw: Bound fragmented header copies by the remaining length Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 090/398] drm/msm: Fix the separate_gpu_kms parameter description Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 091/398] drm/msm/adreno: Fix the skip_gpu " Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 092/398] netfilter: nft_nat: fully initialise new_addr in netmap setup Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 093/398] netfilter: nf_tables: fix device name and prefix match in hook lookup Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 094/398] netfilter: nf_nat: unregister and release hooks on error Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 095/398] netfilter: flowtable: hold reference on ct until flow is released Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 096/398] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 097/398] arm64: hibernate: clone only the linear map that exists at runtime Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 098/398] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 099/398] keys: fix lost wakeup when reaping a dead key type Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 100/398] neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 101/398] neighbour: Convert RTM_GETNEIGHTBL to RCU Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 102/398] neighbour: Add missing RCU annotation for neightbl_dump_info() Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 103/398] neighbour: Skip default parms when resumed in neightbl_dump_info() Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 104/398] ALSA: bcd2000: Fix race between rawmidi and disconnect Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 6.18 105/398] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 106/398] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 107/398] ALSA: pcm: set timer->private_data before registering the PCM timer Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 108/398] drm/msm/dp: skip PUSH_IDLE when the link was never enabled Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 109/398] drm/msm/dp: fix link bandwidth check when wide bus is enabled Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 110/398] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 111/398] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 112/398] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 113/398] spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 114/398] Input: trackpoint - fix the inertia attribute name in the ABI document Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 115/398] gpio: virtuser: skip free_irq when no IRQ is installed Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 116/398] ALSA: usb: 6fire: Avoid embedded URBs Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 117/398] ALSA: 6fire: fix OOB write from device-reported iso length Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 118/398] wifi: virt_wifi: dont transfer operstate before register Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 119/398] drm/xe/mmio_gem: forbid VMA split Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 120/398] drm/xe/mmio_gem: use write-back mapping for dummy page Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 121/398] drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 122/398] drm/xe/shrinker: Return the freed page count through a parameter Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 123/398] drm/vc4: Use managed KMS polling to fix UAF on unbind Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 124/398] ALSA: hda: trace PCM open only after assigning a stream Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 125/398] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 126/398] btrfs: tree-checker: print dev extent offset in error message Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 127/398] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 128/398] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 129/398] net: bcmgenet: convert RX path to page_pool Greg Kroah-Hartman
2026-09-24 6:58 ` Karl Mehltretter
2026-09-24 7:28 ` Greg Kroah-Hartman
2026-09-24 8:10 ` Nicolai Buchwitz
2026-09-24 10:36 ` Nicolai Buchwitz
2026-09-23 14:03 ` [PATCH 6.18 130/398] net: bcmgenet: restore the hardware filters on open Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 131/398] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 132/398] net: fddi: skfp: fix NULL deref when setting the MAC address while down Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 133/398] wifi: brcmfmac: fix lost 802.1x TX completion wakeup Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 134/398] net: bridge: mst: move switchdev call outside rcu Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 135/398] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 136/398] tcp: do not let tcp_rmem be set below 4096 Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 137/398] ksmbd: return buffer overflow for partial filesystem info Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 138/398] ksmbd: fix partial file information responses Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 139/398] ksmbd: keep compound responses on query info errors Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 140/398] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 141/398] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 142/398] Bluetooth: btintel_pcie: validate TX skb length in send_sync Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 143/398] Bluetooth: coredump: Quiesce dump work on unregister Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 144/398] Bluetooth: hci_qca: Refactor HFP hardware offload capability handling Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 145/398] Bluetooth: qca: Refactor code on the basis of chipset names Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 146/398] Bluetooth: qca: enable pwrseq support for WCN39xx devices Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 147/398] Bluetooth: hci_qca: Do not write to the serial port after it is closed Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 148/398] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 149/398] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 150/398] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 151/398] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 152/398] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 153/398] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 154/398] af_unix: Unify scc_index when finalising SCC in __unix_walk_scc() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 155/398] pppoatm: ensure a writable skb header and linear data Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 156/398] drop_monitor: synchronize tracepoint unregistration on error path Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 157/398] drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 158/398] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 159/398] net: stmmac: do not overwrite phc_index when no PTP clock is registered Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 160/398] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 161/398] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 162/398] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 163/398] futex: Also allocate private hash on vfork() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 164/398] btrfs: more trivial BTRFS_PATH_AUTO_FREE conversions Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 6.18 165/398] btrfs: handle lack of space when cleaning up verity items Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 166/398] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 167/398] ASoC: hdmi-codec: Report a change when the channel status moves Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 168/398] ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 169/398] ASoC: sdw_utils: Add codec_conf for every DAI Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 170/398] ASoC: intel: sof_sdw: Add ability to have auxiliary devices Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 171/398] ASoC: sdw_utils: tidyup .count_sidecar Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 172/398] ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 173/398] ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 174/398] ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 175/398] net: netsec: fix device_node reference leak on phy_np Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 177/398] net: lock the socket in sock_gettstamp() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 178/398] net: ethernet: cortina: Ack RX overrun interrupt correctly Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 179/398] net: stmmac: propagate FPE preemption-class mapping errors Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 180/398] net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 181/398] x86/alternative: Refactor INT3 call emulation selftest Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 182/398] x86/kprobes: Fix crash when probing CS CALL instructions Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 183/398] net: macb: fix ordering around PTP timestamp read Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 184/398] net: mvpp2: prevent buffer overflow in page_pool allocation Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 185/398] net: skbuff: do not leave stale header offsets after pskb_carve() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 186/398] drm/amdgpu: check ras and obj before dereference Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 187/398] btrfs: abort transaction on failure to update inode for hole punching and reflinking Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 188/398] btrfs: check if there is space for chunk item when validating sys chunk array Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 189/398] x86/fred: Reconstruct the #GP context for rejected INT instructions Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 190/398] Input: eeti_ts - publish the OF module alias Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 191/398] hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 192/398] hwmon: (hp-wmi-sensors) Improve raw WMI string handling Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 193/398] watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 194/398] ACPI: processor: Update cpuidle driver check in __acpi_processor_start() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 195/398] wifi: rtw88: TX QOS Null data the same way as Null data Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 196/398] Input: xpad - add support for Victrix Pro BFG Controller Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 197/398] Input: xpad - add support for Azeron devices Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 198/398] Input: xpad - fix PDP Marvel Xbox 360 controller Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 199/398] ALSA: core: Fix potential UAF after asynchronous card release Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 200/398] ALSA: virtio: reset device before deleting virtqueues Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 201/398] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 202/398] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 203/398] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 204/398] cifs: Fix server use-after-free in cifs_chan_skip_or_disable() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 205/398] exec: Cleanup POSIX timers right after de_thread() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 206/398] fs/dax: check zero or empty entry before converting xarray entry Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 207/398] phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 208/398] posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 209/398] rds: ib: use rds_conn_drop() on protocol version mismatch Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 210/398] rust: net: phy: fix off-by-one bit positions in device status accessors Greg Kroah-Hartman
2026-09-28 4:41 ` springbreeze
2026-09-28 5:33 ` Greg Kroah-Hartman
2026-09-28 10:25 ` Miguel Ojeda
2026-09-28 10:54 ` Miguel Ojeda
2026-09-29 3:09 ` springbreeze
2026-09-29 5:13 ` Miguel Ojeda
2026-09-29 3:14 ` 回复: " springbreeze
2026-09-23 14:04 ` [PATCH 6.18 211/398] Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware" Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 212/398] drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 213/398] drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 214/398] drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 215/398] x86/build/64: Prevent native builds from generating EGPR use Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 216/398] x86/microcode/intel: Reject problematic loading on Granite Rapids systems Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 217/398] tcp: exclude old ACKs from tcp fast path Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 218/398] swiotlb: use the adjusted address for the highmem page lookup Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 219/398] spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 220/398] spi: spi-zynqmp-gqspi: stop the controller on shutdown Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 221/398] spi: virtio: Use the per-transfer bits per word Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 222/398] RDMA/ucma: Serialize join and leave on copy_to_user failure Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 223/398] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 224/398] openvswitch: avoid reallocating confirmed conntrack labels Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 225/398] net: xfrm: reject unrepresentable espintcp transport headers Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 226/398] HID: logitech-hidpp: fix race condition when accessing stale stack pointer Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 227/398] kselftest/arm64: Fix size of thread_data values for pthread_join() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 228/398] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 229/398] arm64: dts: renesas: r8a779f0: Set UFS lane count Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 230/398] arm64: percpu: Fix this_cpu_write() casting Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 231/398] arm64: percpu: Fix this_cpu_and() mask generation Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 232/398] arm64: percpu: Fix LSE operations on {8,16}-bit types Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 233/398] Bluetooth: btusb: fix NXP IW610 composite device handling Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 234/398] Bluetooth: eir: validate service data length before reading UUID Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 235/398] Bluetooth: hci_codec: validate vendor codec count length Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 236/398] Bluetooth: hci_sync: Serialize local codec list cleanup Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 237/398] btrfs: take commit root semaphore when iterating in mark_block_group_to_copy() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 238/398] btrfs: clear free space tree creation state on rebuild failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 239/398] dmaengine: sun6i: fix non-atomic read of DMA position registers Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 240/398] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 241/398] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 242/398] ipv6: xfrm: use full sockets in local error paths Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 243/398] net: ip_tunnel: initialize `options_len` before referencing options Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 244/398] net: lan743x: fix RX checksum use-after-free Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 245/398] net: phy: mediatek: do not report link and per-speed LED rules together Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 246/398] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 247/398] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 248/398] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 249/398] net/sched: act_api: release tail references on DELACTION failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 250/398] net/sched: hhf: cap hh_flows_limit at change time Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 251/398] net/packet: clear RX owner on VNET header error Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 252/398] net/packet: avoid truncating TPACKET_V3 private size Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 253/398] scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 254/398] xfrm: serialize state GC with device state flush Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 255/398] xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 256/398] soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 257/398] memcg: avoid charging the root memcg from obj_cgroup_charge_pages() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 258/398] memstick: ms_block: destroy io_queue workqueue on removal Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 259/398] mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 260/398] mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 262/398] mm: filemap: retain mapped dropbehind folios Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 263/398] KEYS: encrypted: fix integer overflow of datablob_len Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 264/398] keys: translate request_key_auth pid for the reading procfs instance Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 265/398] KEYS: trusted: Fix tpm2_load_cmd() boundary check Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 266/398] i2c: at91: release DMA channels on remove and probe error Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 267/398] i2c: atr: fix dangling adapter pointer on add failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 268/398] i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 269/398] i2c: imx: release DMA channels on probe error Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 270/398] i2c: imx: disable autosuspend on remove Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 271/398] IB/mlx4: Fix use-after-free on pkey sysfs registration failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 272/398] IB/hfi1: Resolve the credit-return buffer through the send contexts node Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 273/398] IB/hfi1: Fix the PIO_CRED credit-return mmap Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 274/398] selinux: preserve user SID across nested backing files Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 275/398] selinux: recheck intermediate backing files on mprotect() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 276/398] selinux: always fill AVC decision in avc_has_perm_noaudit() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 277/398] power: sequencing: dont call .post_enable() if pwrseq_unit_enable() failed Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 278/398] power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 279/398] power: sequencing: fix NULL-pointer dereference in pwrseq_device_register() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 280/398] mmc: core: Cancel SDIO IRQ work before freeing host Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 281/398] mmc: core: Fix OF node reference leak on card add failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 282/398] mmc: hsq: Fix use-after-free in retry work Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 283/398] mmc: mmci: Fix use-after-free in busy-timeout work Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 284/398] mmc: mxcmmc: cancel data work and watchdog on remove Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 285/398] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 286/398] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 287/398] mmc: sdio_uart: fix xmit_fifo leak when the port table is full Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 288/398] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 289/398] mmc: spi: reset bytes_xfered before retrying CRC failures Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 290/398] mmc: sdhci_am654: Move tuning_loop to local variable Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 291/398] mmc: sdhci_am654: Reset command and data lines on failed tuning Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 292/398] mmc: sdhci_am654: Clear ITAPDLY on tuning failure Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 293/398] mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 " Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 294/398] Input: adp5588-keys - cache GPIO state before registering the gpiochip Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 295/398] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 296/398] Input: cyttsp5 - clamp the HID report size before memcpy Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 297/398] Input: evdev - zero absinfo before partial copy in EVIOCSABS Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 298/398] Input: hp_sdc - shut down kicker timer on module exit Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 299/398] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 300/398] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 301/398] Input: soc_button_array - fix MS Surface Pro 11 probe failure Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 302/398] Input: soc_button_array - check btns_desc->package.count Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 303/398] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Greg Kroah-Hartman
2026-09-26 23:19 ` Daniel Salmun
2026-09-30 12:03 ` Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 304/398] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 305/398] Input: zero ff_effect before compat copy in input_ff_effect_from_user Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 306/398] hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 307/398] hwmon: (pmbus/core) increase number of phases and add new mask Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 308/398] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 309/398] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676 Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 310/398] hwmon: (pwm-fan) Stop RPM timer before freeing tach data Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 311/398] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 312/398] hwmon: (w83793) release probe data through kref Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 313/398] hwmon: (cgbc-hwmon) Fix current sensors ID lookup Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 314/398] hwmon: (cgbc-hwmon) Add missing sensors Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 315/398] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 316/398] watchdog: digicolor: Avoid division by zero Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 317/398] watchdog: msc313e: Fix premature reset during timeout update Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 318/398] watchdog: msc313e: Propagate error code in resume() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 319/398] watchdog: rtd119x: Avoid division by zero Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 320/398] watchdog: rzv2h: " Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 321/398] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 322/398] watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 323/398] wifi: brcmsmac: fix UAF in brcms_free_timer() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 324/398] wifi: iwlegacy: fix broadcast stations deallocation Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 325/398] wifi: libertas_tf: fix UAF in lbtf_free_adapter() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 326/398] wifi: rsi: fix heap OOB write on key removal Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 327/398] wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 328/398] wifi: wlcore: release runtime PM ref on regdomain config failure Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 329/398] wifi: wilc1000: fix out-of-bounds read in P2P public action frames Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 330/398] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 331/398] wifi: p54: validate curve data length in the calibration curve converters Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 332/398] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 333/398] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 334/398] wifi: mwifiex: validate scan response extents Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 335/398] wifi: mwifiex: prevent authentication frame length truncation Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 336/398] wifi: mwifiex: validate action frame fixed fields Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 337/398] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 338/398] drm/gud: fix out-of-bounds write in gud_plane_atomic_check() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 339/398] drm/gud: Ignore damage clips in full update mode Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 340/398] drm/msm/adreno: fix autosuspend cleanup during teardown Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 341/398] drm/msm/dpu: clear pending peripheral flush state Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 342/398] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 343/398] drm/msm: RCU-free the scheduler-containing ring and VM objects Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 344/398] drm/amdgpu: fix rmmio iounmap skipped on device removal Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 6.18 345/398] smb: client: cancel reconnect work in clean_demultiplex_info() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 346/398] smb: client: fix rlist race and missing initialization Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 347/398] smb: client: fix use-after-free of iface in cifs_try_adding_channels() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 348/398] smb: client: reject short Next offsets in parse_server_interfaces() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 349/398] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 350/398] smb: client: fix unaligned access in WSL reparse point parser Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 351/398] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 352/398] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 353/398] smb: client: fix potential OOB read in smb3_enum_snapshots() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 354/398] smb: client: fix server->total_read for compound encrypted PDUs Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 355/398] smb: client: fix missing lower-bound check on DFS referral string offsets Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 356/398] smb: client: fix missing iov bounds check in parse_posix_sids() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 357/398] HID: asus: fortify keyboard handshake Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 358/398] ntsync: Honour callers time namespace for absolute MONOTONIC timeouts Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 359/398] ntsync: reject wait ioctls with zero owner Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 360/398] smb: client: fix busy dentry warning on unmount after DIO Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 361/398] ALSA: usb-audio: Optimize the copy of packet sizes for implicit fb handling Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 362/398] ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 363/398] signal: Move MMCID exit out of sighand lock Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 364/398] signal: Prevent exec() race Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 365/398] xfrm: Refactor xfrm_input lock to reduce contention with RSS Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 366/398] xfrm: Fix dev use-after-free in xfrm async resumption Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 367/398] xfrm: save input state data before secpath resets Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 368/398] mm: move vma_kernel_pagesize() from hugetlb to mm.h Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 369/398] mm/huge_memory: bypass THP tuneables for huge pfnmap mappings Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 370/398] cifs: Fix specification of function pointers Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 371/398] 9p: Fix v9fs_issue_write() to update i_size and remote_i_size Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 372/398] mm/vma: correctly unaccount on mmap_prepare() failure Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 373/398] wifi: mac80211: track MU-MIMO configuration on disabled interfaces Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 374/398] wifi: mac80211: refuse to make a monitor active when it has no queue Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 375/398] scsi: fnic: Rename fnic_scsi_fcpio_reset() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 376/398] scsi: fnic: Bump up version number Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 377/398] scsi: fnic: Make debug logging protocol independent Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 378/398] scsi: fnic: Bump up version number again Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 379/398] scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 380/398] smb: client: fix cifsFileInfo reference leak in deferred close Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 381/398] xfs: add a xfs_rmap_inode_owner helper Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 382/398] xfs: convert xchk_inode_xref_set_corrupt to xchk_ip_xref_set_corrupt Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 383/398] xfs: remove the i_ino field in struct xfs_inode Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 384/398] xfs: fix under-reservation of blocks when repairing sf directories Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 385/398] drm/amdgpu: lock bo before calling amdgpu_vm_bo_update_shared Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 386/398] drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 387/398] wifi: ipw2x00: Rename michael_mic() to libipw_michael_mic() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 388/398] wifi: mac80211, cfg80211: Export michael_mic() and move it to cfg80211 Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 389/398] wifi: ipw2x00: Use michael_mic() from cfg80211 Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 390/398] wifi: libipw: reject TKIP frames without a full MIC Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 391/398] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 392/398] time/namespace: Export init_time_ns and do_timens_ktime_to_host() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 393/398] ksmbd: fix partial normalized name responses Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 394/398] wifi: mac80211: fix list iteration in ieee80211_add_virtual_monitor() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 395/398] ASoC: sdw_utils: subtract the endpoint that is not present Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 396/398] Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 397/398] Revert "ksmbd: Fix to handle removal of rfc1002 header from smb_hdr" Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 6.18 398/398] smb/client: send lease break ACKs thru correct session for multiuser mounts Greg Kroah-Hartman
2026-09-23 14:54 ` [PATCH 6.18 000/398] 6.18.54-rc1 review Brett A C Sheffield
2026-09-23 16:39 ` Peter Schneider
2026-09-23 19:00 ` Florian Fainelli
2026-09-24 3:50 ` Ron Economos
2026-09-24 11:27 ` Pavel Machek
2026-09-25 4:23 ` Barry K. Nathan
2026-09-25 5:25 ` Wentao Guan
-- strict thread matches above, loose matches on Subject: below --
2026-09-23 14:00 [PATCH 7.2 000/438] 7.2.8-rc1 review Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 001/438] selftests/landlock: Use an actual chardev for MAKE_CHAR audit test Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 002/438] selftests/landlock: Add tests for whiteout object creation Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 003/438] selftests/landlock: Add audit test " Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 004/438] sunvdc: fix -EIO issue due to lack of retries Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 005/438] xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk() Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 006/438] xfrm: add missing RCU read lock in xfrm_send_migrate_state() Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 007/438] xfrm: iptfs: fix runt reassembly panic from short inner tot_len Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 008/438] xfrm: fix compat ALLOCSPI request use-after-free Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 009/438] xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 010/438] esp: downgrade zerocopy managed frags before mutating skb frags Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 011/438] arm64: dts: amlogic: t7: use the real UART pclk Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 012/438] arm64: dts: amlogic: t7: khadas-vim4: allow the SD card to be power cycled Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 013/438] arm64: dts: amlogic: t7: fix the pin groups of two PWM outputs Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 014/438] arm64: dts: amlogic: t7: khadas-vim4: add the PWM-driven supplies Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 015/438] arm64: dts: amlogic: t7: fix the pin groups of the vsync PWM Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 016/438] ARM: socfpga: select the PL310 erratum 753970 workaround Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 017/438] RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 018/438] RDMA/rxe: validate access flags before swapping the MRs PD Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 019/438] RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 020/438] xfrm: hold net_device reference under RCU in bundle creation Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 021/438] firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 022/438] clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 023/438] clk: scpi: register scpi-cpufreq once and clear on failure Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 024/438] RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 025/438] RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 026/438] RDMA/mlx5: Remove warn on missing representor in query_port_speed Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 027/438] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 028/438] RDMA/uverbs: Fix mmap_lock/disassociation_lock circular dependency Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 029/438] power: sequencing: Fix build issue with COMPILE_TEST Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 030/438] arm64: dts: renesas: r9a09g057: Switch GBETH TX queue scheduling to WRR Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 031/438] arm64: dts: renesas: r9a09g056: " Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 032/438] arm64: dts: renesas: r9a09g047: " Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 033/438] arm64: dts: renesas: r9a09g077: " Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 034/438] arm64: dts: renesas: r9a09g087: " Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 035/438] IB/iser: reject a remote invalidation of an unregistered direction Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 036/438] IB/isert: wait for deferred control PDU completions before releasing the connection Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 037/438] RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup Greg Kroah-Hartman
2026-09-23 14:00 ` [PATCH 7.2 038/438] RDMA/rtrs: guard against null kobj name Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 039/438] RDMA/bnxt_re: Avoid exposing umdbr to userspace Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 040/438] RDMA/uverbs: Fix potential leak of resources->collection in flow_resources_alloc() Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 041/438] RDMA/mad: Fix receive buffer leak when PKey enforcement fails Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 042/438] RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 043/438] RDMA/irdma: Enforce local fence for IB_WR_REG_MR Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 044/438] RDMA/rtrs-clt: Fix CQ pool leak when connect is interrupted Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 045/438] dmaengine: mmp_pdma: fix wrong extended DRCMR base for SpacemiT K3 Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 046/438] dmaengine: sprd: Fix runtime PM reference leak in probe Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 047/438] wifi: mac80211: include TIM bitmap control for buffered S1G mcast traffic Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 048/438] wifi: virt_wifi: free skb when disconnected Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 049/438] wifi: mwifiex: fix IRQ leak using wrong index in MSI-X error path Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 050/438] wifi: brcmfmac: cyw: pass PMKID to firmware if present Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 051/438] wifi: libipw: reject too-short beacon and probe responses Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 052/438] wifi: libipw: reject too-short association responses Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 053/438] IB/IPoIB: Avoid restoring OPER_UP after multicast flush Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 054/438] wifi: cfg80211: dont get the radio mask for netdev-less wdevs Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 055/438] wifi: cfg80211: check IP header size in cfg80211_classify8021d() Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 056/438] soundwire: cadence_master: wait and cancel cdns->work before clock stop Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 057/438] mips: econet: fix unmet dependencies for ECONET Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 058/438] MIPS: Octeon: apply USB FDT fixups also when USB is modular Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 059/438] dma-coherent: report a failed reserved memory assignment Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 060/438] dma-mapping: dont trace the DMA address when the allocation fails Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 061/438] dmaengine: Fix device kref underflow in dma_chan_put() Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 062/438] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 063/438] dmaengine: wait for RCU readers before releasing dma_device Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 064/438] wifi: cfg80211: dont free driver-owned scan requests Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 065/438] wifi: cfg80211: only group hidden BSSes with beacon entries Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 066/438] wifi: cfg80211: dont filter by BSS type when removing stale entries Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 067/438] wifi: cfg80211: ibss: ref BSS entry for joined event Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 068/438] wifi: cfg80211: fix NAN regulatory enforcement Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 069/438] wifi: mac80211: dont start a ROC while scanning Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 070/438] wifi: mac80211: dont warn when an IBSS has no channel to scan Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 071/438] wifi: mac80211: dont offload TC setup on AP_VLAN interfaces Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 072/438] wifi: mac80211: suppress chanctx warning for debugfs reset Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 073/438] wifi: mac80211: abort chanswitch when leaving a mesh Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 074/438] wifi: mac80211: reset state when starting AP fails Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 075/438] wifi: mac80211: reset the LED state when ifup fails Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 076/438] wifi: mac80211: only operate on TDLS peers in the TDLS code Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 077/438] wifi: cfg80211: restore netns_immutable on failures Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 078/438] wifi: cfg80211: undo netns switch if renaming the wiphy fails Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 079/438] wifi: mac80211: unlist vifs when their netdev is unregistered Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 080/438] wifi: cfg80211: get the wiphy out of a dying network namespace Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 081/438] wifi: mac80211_hwsim: dont hand frames to mac80211 while stopping Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 082/438] wifi: mac80211: dont allow injecting frames wider than the chanctx Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 083/438] wifi: mac80211: reset the AP_VLAN tailroom counter on ifdown Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 084/438] wifi: mac80211: require a peer station for TDLS setup confirm Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 085/438] wifi: mac80211: dont allow link changes when iface is down Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 086/438] wifi: mac80211: dont RCU-dereference the mesh CSA settings we just set Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 087/438] wifi: mac80211: dont access the TSF of a down interface Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 088/438] wifi: mac80211: add HE 6 GHz capability in the scan elems len Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 089/438] wifi: mac80211: mesh: reset the CSA state when leaving Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 090/438] wifi: mac80211: mesh: release the channel if start fails Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 091/438] wifi: mac80211: set up the TX info early to fix failure paths Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 092/438] mm: memblock: show all region flags in debugfs Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 093/438] scsi: pm80xx: Fix the use_msix, use_tasklet and read_wwn parameter descriptions Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 094/438] scsi: qla2xxx: Fix the ql2xfc2target parameter description Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 095/438] dmaengine: xilinx_dma: Fix hardware buffer descriptor reuse order Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 096/438] dmaengine: pxa: fix double counting of the hw descriptors Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 097/438] dmaengine: xilinx_dma: Fix hardware buffer descriptor chain after cyclic DMA Greg Kroah-Hartman
2026-09-23 14:01 ` [PATCH 7.2 098/438] RDMA/efa: Keep admin queues alive while IRQ is registered Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 099/438] RDMA/efa: Keep EQ resources " Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 100/438] RDMA/siw: Bound fragmented header copies by the remaining length Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 101/438] x86/div64: Fix addition of large constants in mul_u64_add_u64_div_u64() Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 102/438] drm/msm: Fix the separate_gpu_kms parameter description Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 103/438] drm/msm/adreno: Fix the skip_gpu " Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 104/438] dma-buf: Make DMABUF_DEBUG default to y on DEBUG_KERNEL kernels Greg Kroah-Hartman
2026-09-23 20:41 ` Karl Mehltretter
2026-09-24 1:15 ` Sasha Levin
2026-09-24 7:33 ` Christian König
2026-09-23 14:02 ` [PATCH 7.2 105/438] netfilter: nft_nat: fully initialise new_addr in netmap setup Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 106/438] netfilter: nf_tables: fix device name and prefix match in hook lookup Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 107/438] netfilter: nf_nat: unregister and release hooks on error Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 108/438] netfilter: flowtable: hold reference on ct until flow is released Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 109/438] perf/arm-cmn: Fix wp_dev_sel2 setting for multi-DTM configurations Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 110/438] arm64: hibernate: clone only the linear map that exists at runtime Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 111/438] arm64: mte: Fix PTRACE_{PEEK,POKE}MTETAGS error documentation Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 112/438] drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 113/438] smb: client: validate absolute native symlink targets before NT fixups Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 114/438] keys: fix lost wakeup when reaping a dead key type Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 115/438] neighbour: Add missing RCU annotation for neightbl_dump_info() Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 116/438] neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 117/438] neighbour: Dont render blackhole_netdev via RTM_GETNEIGHTBL Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 118/438] neighbour: Skip default parms when resumed in neightbl_dump_info() Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 119/438] ALSA: bcd2000: Fix race between rawmidi and disconnect Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 120/438] ntfs: use dynamic MFT tail reservation Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 121/438] ntfs: repack $MFT/$ATTRIBUTE LIST Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 122/438] ntfs: account for MFT records added during allocation Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 123/438] ntfs: protect runlist updates with the runlist lock Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 124/438] ntfs: propagate folio errors Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 6.18 176/398] eth: fbnic: ring the doorbell if a burst ends in a drop Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 125/438] ntfs: ignore interrupted inode reads as corruption Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 126/438] phy: mediatek: phy-mtk-hdmi-mt8195: Fix PLL calc divisor overflow Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 127/438] phy: mediatek: phy-mtk-hdmi-mt8195: Fix TMDS clk bit ratio setting Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 128/438] ALSA: pcm: set timer->private_data before registering the PCM timer Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 129/438] drm/msm/dp: skip PUSH_IDLE when the link was never enabled Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 130/438] drm/msm/dp: fix link bandwidth check when wide bus is enabled Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 131/438] ASoC: Rename snd_soc_dai_link_ch_map.ch_mask to cpu_ch_mask Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 132/438] ASoC: Add codec_ch_mask to snd_soc_dai_link_ch_map Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 133/438] ASoC: soc-pcm: Apply snd_soc_dai_link_ch_map.codec_ch_mask to codec params Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 134/438] spi: spi-qpic-snand: avoid writing QPIC_EBI2_ECC_BUF_CFG register Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 135/438] Input: trackpoint - fix the inertia attribute name in the ABI document Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 136/438] objtool: Validate disassembler headers in libopcodes probe Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 137/438] gpio: virtuser: skip free_irq when no IRQ is installed Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 138/438] ALSA: usb: 6fire: Avoid embedded URBs Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 139/438] ALSA: 6fire: fix OOB write from device-reported iso length Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 140/438] ksmbd: fix malformed procfs status output Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 141/438] ksmbd: extend procfs server statistics Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 142/438] ksmbd: follow SMB2 session expiration semantics Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 143/438] wifi: virt_wifi: dont transfer operstate before register Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 144/438] drm/xe/mmio_gem: forbid VMA split Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 145/438] drm/xe/mmio_gem: use write-back mapping for dummy page Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 146/438] drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 147/438] drm/xe/shrinker: Return the freed page count through a parameter Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 148/438] drm/xe/shrinker: Take a runtime PM ref before shrinking non-system memory Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 149/438] drm/vc4: Use managed KMS polling to fix UAF on unbind Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 150/438] ALSA: hda: trace PCM open only after assigning a stream Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 151/438] wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 152/438] btrfs: tree-checker: print dev extent offset in error message Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 153/438] drm/msm/dsi: round the byte clock rate after reparenting to the PHY PLL Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 154/438] seg6: set IPSKB_L3SLAVE from IP6SKB_L3SLAVE on IPIP decapsulation Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 155/438] net: dsa: mxl862xx: disable the stats poll on teardown Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 156/438] net: bcmgenet: restore the hardware filters on open Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 157/438] sysctl: Check range in proc_dointvec_ms_jiffies_minmax Greg Kroah-Hartman
2026-09-23 14:02 ` [PATCH 7.2 158/438] ipv4: icmp: reject RTN_UNREACHABLE input routes in icmp_route_lookup Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 159/438] net: fddi: skfp: fix NULL deref when setting the MAC address while down Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 160/438] wifi: brcmfmac: fix lost 802.1x TX completion wakeup Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 161/438] net: bridge: mst: move switchdev call outside rcu Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 162/438] tcp: Dont call skb_clone_and_charge_r() for close()d listener in tcp_v6_do_rcv() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 163/438] tcp: do not let tcp_rmem be set below 4096 Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 164/438] ksmbd: return buffer overflow for partial filesystem info Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 165/438] ksmbd: fix partial file information responses Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 166/438] ksmbd: keep compound responses on query info errors Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 167/438] dmaengine: mmp_pdma: fix wrong sg length in mmp_pdma_prep_slave_sg() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 168/438] Bluetooth: hci_core: Fix queuing tx_work after workqueue is drained Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 169/438] Bluetooth: btintel_pcie: validate TX skb length in send_sync Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 170/438] Bluetooth: coredump: Quiesce dump work on unregister Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 171/438] Bluetooth: put the peers on-air address on air when we cannot resolve Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 172/438] Bluetooth: hci_qca: Do not write to the serial port after it is closed Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 173/438] Bluetooth: ISO: Fix parent socket leak in iso_conn_ready() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 174/438] Bluetooth: ISO: set BT_LISTEN before requesting a BIG sync Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 175/438] Bluetooth: btmtk: fix wrong status for short WMT FUNC_CTRL events Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 176/438] Bluetooth: btmtksdio, btmtkuart: validate WMT event length before struct access Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 177/438] Bluetooth: btmtksdio: Fix PM runtime reference leak in shutdown Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 178/438] Bluetooth: btintel_pcie: fix off-by-one bounds check in RX submit Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 179/438] Bluetooth: RFCOMM: avoid socket lock inversion in listener cleanup Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 180/438] af_unix: Unify scc_index when finalising SCC in __unix_walk_scc() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 181/438] net: stmmac: fix TSO header length truncation Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 182/438] pppoatm: ensure a writable skb header and linear data Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 183/438] drop_monitor: synchronize tracepoint unregistration on error path Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 184/438] drop_monitor: use timer_shutdown_sync() to prevent timer rearming during teardown Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 185/438] drop_monitor: use raw_cpu_ptr() in tracepoint probes Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 186/438] drop_monitor: fix out-of-bounds write in reset_per_cpu_data() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 187/438] net: stmmac: do not overwrite phc_index when no PTP clock is registered Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 188/438] net: bridge: vlan: fix bugs caused by switchdev deletion errors Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 189/438] netlink: do not free nlk->groups while lockless readers can use it Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 190/438] KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 191/438] KVM: PPC: Book3S HV: fix secure device page leak on uv_page_in() failure Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 192/438] powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 193/438] Revert "drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable" Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 194/438] futex: Also allocate private hash on vfork() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 195/438] drm/xe/i2c: Disable IRQ on unbind Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 196/438] btrfs: handle lack of space when cleaning up verity items Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 197/438] ASoC: ux500: Parenthesize MSP_{RX,TX}_CLKPOL_BIT() arguments Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 198/438] ASoC: hdmi-codec: Report a change when the channel status moves Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 199/438] ASoC: cs-amp-lib: Prevent NULL pointer if efi variable is zero length Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 200/438] ASoC: amd: acp: bounds-check SoundWire link ID in machine drivers Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 201/438] ASoC: sdw_utils: tidyup .count_sidecar Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 202/438] ASoC: sdw_utils: tidyup asoc_sdw_parse_sdw_endpoints() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 203/438] ASoC: amd: acp: refactor codec config count in SOF SoundWire machine driver Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 204/438] ASoC: amd: acp: fix ffs() operator precedence for SoundWire link ID Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 205/438] net/sched: codel: bound the dropping loop per dequeue call Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 206/438] net: do not advance stack index from dev_fwd_path() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 207/438] net: pass dst via net_device_path in dev_fill_forward_path() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 208/438] net: pass net_device_path_ctx to dev_fill_forward_path() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 209/438] net: remove WARN_ON_ONCE() from the dev_fill_forward_path() loop check Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 6.18 261/398] mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 210/438] net: netsec: fix device_node reference leak on phy_np Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 211/438] eth: fbnic: ring the doorbell if a burst ends in a drop Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 212/438] net: lock the socket in sock_gettstamp() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 213/438] net: ethernet: cortina: Ack RX overrun interrupt correctly Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 214/438] net: stmmac: propagate FPE preemption-class mapping errors Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 215/438] net: prevent torn reads in netdev_tc_txq Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 216/438] net: stmmac: preserve real_num_tx_queues on mqprio setup failure Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 217/438] net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb() Greg Kroah-Hartman
2026-09-23 14:03 ` [PATCH 7.2 218/438] x86/kprobes: Fix crash when probing CS CALL instructions Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 219/438] net: macb: fix ordering around PTP timestamp read Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 220/438] net: mvpp2: prevent buffer overflow in page_pool allocation Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 221/438] net: skbuff: do not leave stale header offsets after pskb_carve() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 222/438] drm/amdgpu: check ras and obj before dereference Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 223/438] drm/amd/display: fix MALL hysteresis timer underflow at high refresh rates Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 224/438] btrfs: abort transaction on failure to update inode for hole punching and reflinking Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 225/438] btrfs: check if there is space for chunk item when validating sys chunk array Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 226/438] perf: Fix null pointer access in is_include_guest_event() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 227/438] sched/core: Avoid false migration warning for proxy donors Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 228/438] x86/fred: Reconstruct the #GP context for rejected INT instructions Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 229/438] Input: eeti_ts - publish the OF module alias Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 230/438] hwmon: (gpio-fan) return IRQ_HANDLED from the shared alarm IRQ handler Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 231/438] hwmon: (hp-wmi-sensors) Improve raw WMI string handling Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 232/438] watchdog: da9062: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 233/438] Input: xpad - add support for Victrix Pro BFG Controller Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 234/438] Input: xpad - add support for Azeron devices Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 235/438] Input: xpad - fix PDP Marvel Xbox 360 controller Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 236/438] 9p: Fix v9fs_issue_write() to update i_size and remote_i_size Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 237/438] ALSA: core: Fix potential UAF after asynchronous card release Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 238/438] ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 239/438] ALSA: virtio: reset device before deleting virtqueues Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 240/438] ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 241/438] cgroup: Avoid iteration of dying tasks with zero refcount Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 242/438] ata: libahci: clear PxCLBU and PxFBU for AHCI_HFLAG_32BIT_ONLY Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 243/438] ata: libahci_platform: Fix device reference leak in ahci_platform_get_resources() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 244/438] cifs: Fix server use-after-free in cifs_chan_skip_or_disable() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 245/438] exec: Cleanup POSIX timers right after de_thread() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 246/438] fs/dax: check zero or empty entry before converting xarray entry Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 247/438] PCI: imx6: Move clock enable after core reset assertion Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 248/438] phy: renesas: rcar-gen3-usb2: Avoid long delay in atomic context Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 249/438] posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 250/438] rds: ib: use rds_conn_drop() on protocol version mismatch Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 251/438] signal: Prevent exec() race Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 252/438] rust: net: phy: fix off-by-one bit positions in device status accessors Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 253/438] Revert "nouveau/gsp: fix suspend/resume regression on r570 firmware" Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 254/438] drm/nouveau/gsp: Increase delay for magic sleep in r535_gsp_fini() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 255/438] drm/nouveau/gsp/r570: Set GcOff = 0 in fbsr Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 256/438] drm/nouveau/gsp/r570: Enable S/R Display workaround in GSP Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 257/438] x86/build/64: Prevent native builds from generating EGPR use Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 258/438] x86/microcode/intel: Reject problematic loading on Granite Rapids systems Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 259/438] tcp: exclude old ACKs from tcp fast path Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 260/438] swiotlb: use the adjusted address for the highmem page lookup Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 261/438] soundwire: dmi-quirks: Disable ghost Realtek on Asus GX651AX Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 262/438] spi: fsl-qspi: Reprogram the clock rate when the operation frequency changes Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 263/438] spi: spi-zynqmp-gqspi: stop the controller on shutdown Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 264/438] spi: virtio: Use the per-transfer bits per word Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 265/438] RDMA/ucma: Serialize join and leave on copy_to_user failure Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 266/438] RDMA/core: fix refcount bug in iwpm_get_nlmsg_request() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 267/438] openvswitch: avoid reallocating confirmed conntrack labels Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 268/438] nfsd: fix handling of NFSEXP_PNFS in the netlink codepath Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 269/438] net: xfrm: reject unrepresentable espintcp transport headers Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 270/438] kselftest/arm64: Fix size of thread_data values for pthread_join() Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 271/438] arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 272/438] arm64: dts: renesas: r8a779f0: Set UFS lane count Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 273/438] arm64: dts: socfpga: change access permission from 755 to 644 Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 274/438] arm64: percpu: Fix this_cpu_write() casting Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 275/438] arm64: percpu: Fix this_cpu_and() mask generation Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 276/438] arm64: percpu: Fix LSE operations on {8,16}-bit types Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 277/438] Bluetooth: btusb: fix NXP IW610 composite device handling Greg Kroah-Hartman
2026-09-23 14:04 ` [PATCH 7.2 278/438] Bluetooth: eir: validate service data length before reading UUID Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 279/438] Bluetooth: hci_codec: validate vendor codec count length Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 280/438] Bluetooth: hci_sync: Serialize local codec list cleanup Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 281/438] Bluetooth: keep dst_type with dst when reusing an LE connection Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 282/438] btrfs: take commit root semaphore when iterating in mark_block_group_to_copy() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 283/438] btrfs: fix creation of compressed inline extents that dont save space Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 284/438] btrfs: derive f_fsid with dev_t only when temp_fsid is active Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 285/438] btrfs: clear free space tree creation state on rebuild failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 286/438] gpiolib: Put fwnode reference on failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 287/438] gpiolib: of: dont mark hog nodes OF_POPULATED before a chip is found Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 288/438] dmaengine: sun6i: fix non-atomic read of DMA position registers Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 289/438] dmaengine: sun6i: fix undefined behaviour in sun6i_dma_tx_status Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 290/438] dmaengine: ti: k3-udma-glue: fix NULL dereference in k3_udma_glue_release_rx_chn() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 291/438] dma-buf/dma-fence: fix checking signaling bit for timeline and driver name v3 Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 292/438] dma-buf: Fix silent overflow for phys vec to sgt Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 293/438] dma-buf: Split sgl by largest page-aligned chunk Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 294/438] ipv6: xfrm: use full sockets in local error paths Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 295/438] net: ip_tunnel: initialize `options_len` before referencing options Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 296/438] net: lan743x: fix RX checksum use-after-free Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 297/438] net: phy: mediatek: do not report link and per-speed LED rules together Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 298/438] net: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 299/438] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 300/438] net: wwan: mhi_wwan_mbim: check skb_copy_bits() return value Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 301/438] net/sched: act_api: release tail references on DELACTION failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 302/438] net/sched: hhf: cap hh_flows_limit at change time Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 303/438] net/packet: clear RX owner on VNET header error Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 304/438] net/packet: avoid truncating TPACKET_V3 private size Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 305/438] scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 306/438] xfrm: serialize state GC with device state flush Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 307/438] xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 308/438] xfrm: save input state data before secpath resets Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 309/438] soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 310/438] mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 311/438] memcg: avoid charging the root memcg from obj_cgroup_charge_pages() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 312/438] memstick: ms_block: destroy io_queue workqueue on removal Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 313/438] mm, swap: fix SWAP_USAGE_OFFLIST_BIT collision with real usage count Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 314/438] mm/huge_memory: bypass THP tuneables for huge pfnmap mappings Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 315/438] mm/mlock: use the IRQ-safe accessor for NR_MLOCK in __munlock_folio() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 316/438] mm/mremap: account mm->locked_vm correctly for MREMAP_DONTUNMAP Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 317/438] mm/shrinker: fix bogus set_shrinker_bit() with cgroup.memory=nokmem Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 318/438] mm/vma: correctly unaccount on mmap_prepare() failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 319/438] mm: filemap: retain mapped dropbehind folios Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 320/438] KEYS: encrypted: fix integer overflow of datablob_len Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 321/438] keys: translate request_key_auth pid for the reading procfs instance Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 322/438] KEYS: trusted: Fix tpm2_load_cmd() boundary check Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 323/438] sched_ext: Fix NULL sched deref in kfunc sub-sched error paths Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 324/438] sched_ext: Close the pre-enable ops error claim window Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 325/438] i2c: at91: release DMA channels on remove and probe error Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 326/438] i2c: atr: fix dangling adapter pointer on add failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 327/438] i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 328/438] i2c: imx: release DMA channels on probe error Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 329/438] i2c: imx: disable autosuspend on remove Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 330/438] IB/mlx4: Fix use-after-free on pkey sysfs registration failure Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 331/438] IB/hfi1: Resolve the credit-return buffer through the send contexts node Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 332/438] IB/hfi1: Fix the PIO_CRED credit-return mmap Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 333/438] selinux: preserve user SID across nested backing files Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 334/438] selinux: recheck intermediate backing files on mprotect() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 335/438] selinux: always fill AVC decision in avc_has_perm_noaudit() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 336/438] power: sequencing: dont call .post_enable() if pwrseq_unit_enable() failed Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 337/438] power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new() Greg Kroah-Hartman
2026-09-23 14:05 ` [PATCH 7.2 338/438] power: sequencing: fix NULL-pointer dereference in pwrseq_device_register() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 339/438] mmc: core: Cancel SDIO IRQ work before freeing host Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 340/438] mmc: core: Fix OF node reference leak on card add failure Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 341/438] mmc: hsq: Fix use-after-free in retry work Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 342/438] mmc: mmci: Fix use-after-free in busy-timeout work Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 343/438] mmc: mxcmmc: cancel data work and watchdog on remove Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 344/438] mmc: rtsx_pci_sdmmc: ignore broken write-protect on ThinkPad X260 Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 345/438] mmc: sdhci-of-aspeed: Remove children before releasing SDC resources Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 346/438] mmc: sdio_uart: fix xmit_fifo leak when the port table is full Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 347/438] mmc: sh_mmcif: initialize IRQ-thread mutex before requesting interrupt Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 348/438] mmc: spi: reset bytes_xfered before retrying CRC failures Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 349/438] mmc: sdhci_am654: Move tuning_loop to local variable Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 350/438] mmc: sdhci_am654: Reset command and data lines on failed tuning Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 351/438] mmc: sdhci_am654: Clear ITAPDLY on tuning failure Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 352/438] mmc: sdhci_am654: Fallback to DT-provided itap delay on DDR50 " Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 353/438] Input: adp5588-keys - cache GPIO state before registering the gpiochip Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 354/438] Input: atkbd - skip deactivate for Xiaomi Redmi Book Pro 16 2026 Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 355/438] Input: cyttsp5 - clamp the HID report size before memcpy Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 356/438] Input: evdev - zero absinfo before partial copy in EVIOCSABS Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 357/438] Input: hp_sdc - shut down kicker timer on module exit Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 358/438] Input: i8042 - add quirk for Acer Aspire Go 15 AG15-42P Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 359/438] Input: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 360/438] Input: soc_button_array - fix MS Surface Pro 11 probe failure Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 361/438] Input: soc_button_array - check btns_desc->package.count Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 362/438] Input: synaptics - disable InterTouch on ThinkPad T440p (board id 2722) Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 363/438] Input: synaptics-rmi4 - fix GPF in suspend and resume when unbound Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 364/438] Input: zero ff_effect before compat copy in input_ff_effect_from_user Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 365/438] hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 366/438] hwmon: (pmbus/core) increase number of phases and add new mask Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 367/438] hwmon: (pmbus/tps53679) Fix TPS53676 phase page decoding Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 368/438] hwmon: (pmbus/tps53679) Select page 0 for single-page TPS53676 Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 369/438] hwmon: (pwm-fan) Stop RPM timer before freeing tach data Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 370/438] hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 371/438] hwmon: (w83793) release probe data through kref Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 372/438] hwmon: (cgbc-hwmon) Fix current sensors ID lookup Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 373/438] hwmon: (cgbc-hwmon) Add missing sensors Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 374/438] watchdog: da9063: fix suspend/resume handling of HW_RUNNING watchdog Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 375/438] watchdog: digicolor: Avoid division by zero Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 376/438] watchdog: msc313e: Fix premature reset during timeout update Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 377/438] watchdog: msc313e: Propagate error code in resume() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 378/438] watchdog: rtd119x: Avoid division by zero Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 379/438] watchdog: rzv2h: " Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 380/438] watchdog: sp5100_tco: Fix pci_dev reference leak in sp5100_tco_init() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 381/438] watchdog: starfive-wdt: Fix runtime PM leak in starfive_wdt_pm_start() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 382/438] wifi: brcmsmac: fix UAF in brcms_free_timer() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 383/438] wifi: iwlegacy: fix broadcast stations deallocation Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 384/438] wifi: libertas_tf: fix UAF in lbtf_free_adapter() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 385/438] wifi: libipw: reject TKIP frames without a full MIC Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 386/438] wifi: rsi: fix heap OOB write on key removal Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 387/438] wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 388/438] wifi: wlcore: release runtime PM ref on regdomain config failure Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 389/438] wifi: wilc1000: fix out-of-bounds read in P2P public action frames Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 390/438] wifi: wilc1000: fix RX buffer OOB-write in wilc_wlan_handle_isr_ext() Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 391/438] wifi: p54: validate curve data length in the calibration curve converters Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 392/438] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 393/438] wifi: mwifiex: bound the pairwise-cipher OUI walk to the IE length Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 394/438] wifi: mwifiex: validate scan response extents Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 395/438] wifi: mwifiex: prevent authentication frame length truncation Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 396/438] wifi: mwifiex: validate action frame fixed fields Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 397/438] wifi: mac80211: avoid WARN in set_bitrate_mask when sdata not in driver Greg Kroah-Hartman
2026-09-23 14:06 ` [PATCH 7.2 398/438] wifi: mac80211: avoid out-of-bounds read for empty PREQ elements Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 399/438] wifi: mac80211: refuse to make a monitor active when it has no queue Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 400/438] drm/gud: fix out-of-bounds write in gud_plane_atomic_check() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 401/438] drm/gud: Ignore damage clips in full update mode Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 402/438] drm/msm/adreno: fix autosuspend cleanup during teardown Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 403/438] drm/msm/dpu: clear pending peripheral flush state Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 404/438] drm/msm/hdmi_phy: fix runtime PM cleanup on probe failure Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 405/438] drm/msm: RCU-free the scheduler-containing ring and VM objects Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 406/438] drm/sched: Fix virtual runtime race Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 407/438] drm/amdgpu: fix rmmio iounmap skipped on device removal Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 408/438] drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 409/438] drm/amdgpu: Skip KFD mapping clear before initialization Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 410/438] drm/amdkfd: Avoid integer underflow in EOP ring size calculation Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 411/438] drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 412/438] drm/amdkfd: implement restore_mqd callbacks for GFX12/12.1 Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 413/438] smb: client: cancel reconnect work in clean_demultiplex_info() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 414/438] smb/client: send lease break ACKs thru correct session for multiuser mounts Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 415/438] smb: client: fix rlist race and missing initialization Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 416/438] smb: client: fix use-after-free of iface in cifs_try_adding_channels() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 417/438] smb: client: reject short Next offsets in parse_server_interfaces() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 418/438] smb: client: fix smbd_connection leak on cifs_get_tcp_session() error Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 419/438] smb: client: fix unaligned access in WSL reparse point parser Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 420/438] smb: client: fix fattr leaking on wsl_to_fattr() failure Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 421/438] smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 422/438] smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 423/438] smb: client: fix potential OOB read in smb3_enum_snapshots() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 424/438] smb: client: fix reparse buffer bounds in cifs_query_reparse_point() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 425/438] smb: client: fix server->total_read for compound encrypted PDUs Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 426/438] smb: client: fix missing lower-bound check on DFS referral string offsets Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 427/438] smb: client: fix missing iov bounds check in parse_posix_sids() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 428/438] fs/super: skip non-memcg-aware nr_cached_objects in memcg slab shrink Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 429/438] fs: fix missed removal of super_fs_objects_eligible() Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 430/438] scsi: fnic: Make debug logging protocol independent Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 431/438] scsi: fnic: Bump up version number Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 432/438] scsi: fnic: Fix missed link-up when critical IRQ targets offline CPU Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 433/438] drm/amdgpu: reduce early full GPU access during SR-IOV init Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 434/438] drm/amdgpu: Fix GPU PCIe link capability reporting Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 435/438] ntsync: reject wait ioctls with zero owner Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 436/438] drm/ttm: fix swapped-out resources never leaving their bulk_move range Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 437/438] drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only Greg Kroah-Hartman
2026-09-23 14:07 ` [PATCH 7.2 438/438] ksmbd: fix partial normalized name responses Greg Kroah-Hartman
2026-09-23 14:54 ` [PATCH 7.2 000/438] 7.2.8-rc1 review Brett A C Sheffield
2026-09-23 16:15 ` Ronald Warsow
2026-09-23 17:00 ` Florian Fainelli
2026-09-23 18:20 ` Peter Schneider
2026-09-24 3:47 ` Ron Economos
2026-09-24 11:26 ` Pavel Machek
2026-09-24 11:50 ` Takeshi Ogasawara
2026-09-24 16:59 ` Markus Reichelt
2026-09-24 17:08 ` Justin Forbes
2026-09-24 20:18 ` Wentao Guan
2026-09-25 2:28 ` Benjamin Boortz
2026-09-25 4:18 ` Barry K. Nathan
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).