Archive-only list for patches
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: stable@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	patches@lists.linux.dev, Tom Lendacky <thomas.lendacky@amd.com>,
	"Borislav Petkov (AMD)" <bp@alien8.de>,
	Sasha Levin <sashal@kernel.org>
Subject: [PATCH 6.18 379/395] x86/sev: Carve out the SVSM code into a separate compilation unit
Date: Wed, 30 Sep 2026 17:30:41 +0200	[thread overview]
Message-ID: <20260930152348.919824678@linuxfoundation.org> (raw)
In-Reply-To: <20260930152340.591469096@linuxfoundation.org>

6.18-stable review patch.  If anyone has any objections, please let me know.

------------------

From: "Borislav Petkov (AMD)" <bp@alien8.de>

[ Upstream commit e21279b73ef6c7d27237912c914f2db0c5a74786 ]

Move the SVSM-related machinery into a separate compilation unit in
order to keep sev/core.c slim and "on-topic".

No functional changes.

Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Link: https://patch.msgid.link/20251204124809.31783-4-bp@kernel.org
Stable-dep-of: 6c43c72748ff ("x86/sev: Make vTPM SVSM calls preemption-safe")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/coco/sev/Makefile   |    2 
 arch/x86/coco/sev/core.c     |  377 -------------------------------------------
 arch/x86/coco/sev/internal.h |   29 +++
 arch/x86/coco/sev/svsm.c     |  362 +++++++++++++++++++++++++++++++++++++++++
 4 files changed, 392 insertions(+), 378 deletions(-)
 create mode 100644 arch/x86/coco/sev/svsm.c

--- a/arch/x86/coco/sev/Makefile
+++ b/arch/x86/coco/sev/Makefile
@@ -1,6 +1,6 @@
 # SPDX-License-Identifier: GPL-2.0
 
-obj-y += core.o noinstr.o vc-handle.o
+obj-y += core.o noinstr.o vc-handle.o svsm.o
 
 # Clang 14 and older may fail to respect __no_sanitize_undefined when inlining
 UBSAN_SANITIZE_noinstr.o	:= n
--- a/arch/x86/coco/sev/core.c
+++ b/arch/x86/coco/sev/core.c
@@ -55,40 +55,6 @@ SYM_PIC_ALIAS(sev_hv_features);
 u64 sev_secrets_pa __ro_after_init;
 SYM_PIC_ALIAS(sev_secrets_pa);
 
-/* For early boot SVSM communication */
-struct svsm_ca boot_svsm_ca_page __aligned(PAGE_SIZE);
-SYM_PIC_ALIAS(boot_svsm_ca_page);
-
-/*
- * SVSM related information:
- *   During boot, the page tables are set up as identity mapped and later
- *   changed to use kernel virtual addresses. Maintain separate virtual and
- *   physical addresses for the CAA to allow SVSM functions to be used during
- *   early boot, both with identity mapped virtual addresses and proper kernel
- *   virtual addresses.
- */
-u64 boot_svsm_caa_pa __ro_after_init;
-SYM_PIC_ALIAS(boot_svsm_caa_pa);
-
-DEFINE_PER_CPU(struct svsm_ca *, svsm_caa);
-DEFINE_PER_CPU(u64, svsm_caa_pa);
-
-static inline struct svsm_ca *svsm_get_caa(void)
-{
-	if (sev_cfg.use_cas)
-		return this_cpu_read(svsm_caa);
-	else
-		return rip_rel_ptr(&boot_svsm_ca_page);
-}
-
-static inline u64 svsm_get_caa_pa(void)
-{
-	if (sev_cfg.use_cas)
-		return this_cpu_read(svsm_caa_pa);
-	else
-		return boot_svsm_caa_pa;
-}
-
 /* AP INIT values as documented in the APM2  section "Processor Initialization State" */
 #define AP_INIT_CS_LIMIT		0xffff
 #define AP_INIT_DS_LIMIT		0xffff
@@ -219,95 +185,6 @@ static u64 __init get_jump_table_addr(vo
 	return ret;
 }
 
-static int svsm_perform_ghcb_protocol(struct ghcb *ghcb, struct svsm_call *call)
-{
-	struct es_em_ctxt ctxt;
-	u8 pending = 0;
-
-	vc_ghcb_invalidate(ghcb);
-
-	/*
-	 * Fill in protocol and format specifiers. This can be called very early
-	 * in the boot, so use rip-relative references as needed.
-	 */
-	ghcb->protocol_version = ghcb_version;
-	ghcb->ghcb_usage       = GHCB_DEFAULT_USAGE;
-
-	ghcb_set_sw_exit_code(ghcb, SVM_VMGEXIT_SNP_RUN_VMPL);
-	ghcb_set_sw_exit_info_1(ghcb, 0);
-	ghcb_set_sw_exit_info_2(ghcb, 0);
-
-	sev_es_wr_ghcb_msr(__pa(ghcb));
-
-	svsm_issue_call(call, &pending);
-
-	if (pending)
-		return -EINVAL;
-
-	switch (verify_exception_info(ghcb, &ctxt)) {
-	case ES_OK:
-		break;
-	case ES_EXCEPTION:
-		vc_forward_exception(&ctxt);
-		fallthrough;
-	default:
-		return -EINVAL;
-	}
-
-	return svsm_process_result_codes(call);
-}
-
-static int svsm_perform_call_protocol(struct svsm_call *call)
-{
-	struct ghcb_state state;
-	unsigned long flags;
-	struct ghcb *ghcb;
-	int ret;
-
-	flags = native_local_irq_save();
-
-	if (sev_cfg.ghcbs_initialized)
-		ghcb = __sev_get_ghcb(&state);
-	else if (boot_ghcb)
-		ghcb = boot_ghcb;
-	else
-		ghcb = NULL;
-
-	do {
-		ret = ghcb ? svsm_perform_ghcb_protocol(ghcb, call)
-			   : __pi_svsm_perform_msr_protocol(call);
-	} while (ret == -EAGAIN);
-
-	if (sev_cfg.ghcbs_initialized)
-		__sev_put_ghcb(&state);
-
-	native_local_irq_restore(flags);
-
-	return ret;
-}
-
-static inline void __pval_terminate(u64 pfn, bool action, unsigned int page_size,
-				    int ret, u64 svsm_ret)
-{
-	WARN(1, "PVALIDATE failure: pfn: 0x%llx, action: %u, size: %u, ret: %d, svsm_ret: 0x%llx\n",
-	     pfn, action, page_size, ret, svsm_ret);
-
-	sev_es_terminate(SEV_TERM_SET_LINUX, GHCB_TERM_PVALIDATE);
-}
-
-static void svsm_pval_terminate(struct svsm_pvalidate_call *pc, int ret, u64 svsm_ret)
-{
-	unsigned int page_size;
-	bool action;
-	u64 pfn;
-
-	pfn = pc->entry[pc->cur_index].pfn;
-	action = pc->entry[pc->cur_index].action;
-	page_size = pc->entry[pc->cur_index].page_size;
-
-	__pval_terminate(pfn, action, page_size, ret, svsm_ret);
-}
-
 static void pval_pages(struct snp_psc_desc *desc)
 {
 	struct psc_entry *e;
@@ -344,152 +221,6 @@ static void pval_pages(struct snp_psc_de
 	}
 }
 
-static u64 svsm_build_ca_from_pfn_range(u64 pfn, u64 pfn_end, bool action,
-					struct svsm_pvalidate_call *pc)
-{
-	struct svsm_pvalidate_entry *pe;
-
-	/* Nothing in the CA yet */
-	pc->num_entries = 0;
-	pc->cur_index   = 0;
-
-	pe = &pc->entry[0];
-
-	while (pfn < pfn_end) {
-		pe->page_size = RMP_PG_SIZE_4K;
-		pe->action    = action;
-		pe->ignore_cf = 0;
-		pe->rsvd      = 0;
-		pe->pfn       = pfn;
-
-		pe++;
-		pfn++;
-
-		pc->num_entries++;
-		if (pc->num_entries == SVSM_PVALIDATE_MAX_COUNT)
-			break;
-	}
-
-	return pfn;
-}
-
-static int svsm_build_ca_from_psc_desc(struct snp_psc_desc *desc, unsigned int desc_entry,
-				       struct svsm_pvalidate_call *pc)
-{
-	struct svsm_pvalidate_entry *pe;
-	struct psc_entry *e;
-
-	/* Nothing in the CA yet */
-	pc->num_entries = 0;
-	pc->cur_index   = 0;
-
-	pe = &pc->entry[0];
-	e  = &desc->entries[desc_entry];
-
-	while (desc_entry <= desc->hdr.end_entry) {
-		pe->page_size = e->pagesize ? RMP_PG_SIZE_2M : RMP_PG_SIZE_4K;
-		pe->action    = e->operation == SNP_PAGE_STATE_PRIVATE;
-		pe->ignore_cf = 0;
-		pe->rsvd      = 0;
-		pe->pfn       = e->gfn;
-
-		pe++;
-		e++;
-
-		desc_entry++;
-		pc->num_entries++;
-		if (pc->num_entries == SVSM_PVALIDATE_MAX_COUNT)
-			break;
-	}
-
-	return desc_entry;
-}
-
-static void svsm_pval_pages(struct snp_psc_desc *desc)
-{
-	struct svsm_pvalidate_entry pv_4k[VMGEXIT_PSC_MAX_ENTRY];
-	unsigned int i, pv_4k_count = 0;
-	struct svsm_pvalidate_call *pc;
-	struct svsm_call call = {};
-	unsigned long flags;
-	bool action;
-	u64 pc_pa;
-	int ret;
-
-	/*
-	 * This can be called very early in the boot, use native functions in
-	 * order to avoid paravirt issues.
-	 */
-	flags = native_local_irq_save();
-
-	/*
-	 * The SVSM calling area (CA) can support processing 510 entries at a
-	 * time. Loop through the Page State Change descriptor until the CA is
-	 * full or the last entry in the descriptor is reached, at which time
-	 * the SVSM is invoked. This repeats until all entries in the descriptor
-	 * are processed.
-	 */
-	call.caa = svsm_get_caa();
-
-	pc = (struct svsm_pvalidate_call *)call.caa->svsm_buffer;
-	pc_pa = svsm_get_caa_pa() + offsetof(struct svsm_ca, svsm_buffer);
-
-	/* Protocol 0, Call ID 1 */
-	call.rax = SVSM_CORE_CALL(SVSM_CORE_PVALIDATE);
-	call.rcx = pc_pa;
-
-	for (i = 0; i <= desc->hdr.end_entry;) {
-		i = svsm_build_ca_from_psc_desc(desc, i, pc);
-
-		do {
-			ret = svsm_perform_call_protocol(&call);
-			if (!ret)
-				continue;
-
-			/*
-			 * Check if the entry failed because of an RMP mismatch (a
-			 * PVALIDATE at 2M was requested, but the page is mapped in
-			 * the RMP as 4K).
-			 */
-
-			if (call.rax_out == SVSM_PVALIDATE_FAIL_SIZEMISMATCH &&
-			    pc->entry[pc->cur_index].page_size == RMP_PG_SIZE_2M) {
-				/* Save this entry for post-processing at 4K */
-				pv_4k[pv_4k_count++] = pc->entry[pc->cur_index];
-
-				/* Skip to the next one unless at the end of the list */
-				pc->cur_index++;
-				if (pc->cur_index < pc->num_entries)
-					ret = -EAGAIN;
-				else
-					ret = 0;
-			}
-		} while (ret == -EAGAIN);
-
-		if (ret)
-			svsm_pval_terminate(pc, ret, call.rax_out);
-	}
-
-	/* Process any entries that failed to be validated at 2M and validate them at 4K */
-	for (i = 0; i < pv_4k_count; i++) {
-		u64 pfn, pfn_end;
-
-		action  = pv_4k[i].action;
-		pfn     = pv_4k[i].pfn;
-		pfn_end = pfn + 512;
-
-		while (pfn < pfn_end) {
-			pfn = svsm_build_ca_from_pfn_range(pfn, pfn_end, action, pc);
-
-			ret = svsm_perform_call_protocol(&call);
-			if (ret)
-				svsm_pval_terminate(pc, ret, call.rax_out);
-		}
-	}
-
-	native_local_irq_restore(flags);
-}
-
 static void pvalidate_pages(struct snp_psc_desc *desc)
 {
 	struct psc_entry *e;
@@ -1590,56 +1321,6 @@ static int __init report_snp_info(void)
 }
 arch_initcall(report_snp_info);
 
-static void update_attest_input(struct svsm_call *call, struct svsm_attest_call *input)
-{
-	/* If (new) lengths have been returned, propagate them up */
-	if (call->rcx_out != call->rcx)
-		input->manifest_buf.len = call->rcx_out;
-
-	if (call->rdx_out != call->rdx)
-		input->certificates_buf.len = call->rdx_out;
-
-	if (call->r8_out != call->r8)
-		input->report_buf.len = call->r8_out;
-}
-
-int snp_issue_svsm_attest_req(u64 call_id, struct svsm_call *call,
-			      struct svsm_attest_call *input)
-{
-	struct svsm_attest_call *ac;
-	unsigned long flags;
-	u64 attest_call_pa;
-	int ret;
-
-	if (!snp_vmpl)
-		return -EINVAL;
-
-	local_irq_save(flags);
-
-	call->caa = svsm_get_caa();
-
-	ac = (struct svsm_attest_call *)call->caa->svsm_buffer;
-	attest_call_pa = svsm_get_caa_pa() + offsetof(struct svsm_ca, svsm_buffer);
-
-	*ac = *input;
-
-	/*
-	 * Set input registers for the request and set RDX and R8 to known
-	 * values in order to detect length values being returned in them.
-	 */
-	call->rax = call_id;
-	call->rcx = attest_call_pa;
-	call->rdx = -1;
-	call->r8 = -1;
-	ret = svsm_perform_call_protocol(call);
-	update_attest_input(call, input);
-
-	local_irq_restore(flags);
-
-	return ret;
-}
-EXPORT_SYMBOL_GPL(snp_issue_svsm_attest_req);
-
 static int snp_issue_guest_request(struct snp_guest_req *req)
 {
 	struct snp_req_data *input = &req->input;
@@ -1704,64 +1385,6 @@ e_restore_irq:
 	return ret;
 }
 
-/**
- * snp_svsm_vtpm_probe() - Probe if SVSM provides a vTPM device
- *
- * Check that there is SVSM and that it supports at least TPM_SEND_COMMAND
- * which is the only request used so far.
- *
- * Return: true if the platform provides a vTPM SVSM device, false otherwise.
- */
-static bool snp_svsm_vtpm_probe(void)
-{
-	struct svsm_call call = {};
-
-	/* The vTPM device is available only if a SVSM is present */
-	if (!snp_vmpl)
-		return false;
-
-	call.caa = svsm_get_caa();
-	call.rax = SVSM_VTPM_CALL(SVSM_VTPM_QUERY);
-
-	if (svsm_perform_call_protocol(&call))
-		return false;
-
-	/* Check platform commands contains TPM_SEND_COMMAND - platform command 8 */
-	return call.rcx_out & BIT_ULL(8);
-}
-
-/**
- * snp_svsm_vtpm_send_command() - Execute a vTPM operation on SVSM
- * @buffer: A buffer used to both send the command and receive the response.
- *
- * Execute a SVSM_VTPM_CMD call as defined by
- * "Secure VM Service Module for SEV-SNP Guests" Publication # 58019 Revision: 1.00
- *
- * All command request/response buffers have a common structure as specified by
- * the following table:
- *     Byte      Size       In/Out    Description
- *     Offset    (Bytes)
- *     0x000     4          In        Platform command
- *                          Out       Platform command response size
- *
- * Each command can build upon this common request/response structure to create
- * a structure specific to the command. See include/linux/tpm_svsm.h for more
- * details.
- *
- * Return: 0 on success, -errno on failure
- */
-int snp_svsm_vtpm_send_command(u8 *buffer)
-{
-	struct svsm_call call = {};
-
-	call.caa = svsm_get_caa();
-	call.rax = SVSM_VTPM_CALL(SVSM_VTPM_CMD);
-	call.rcx = __pa(buffer);
-
-	return svsm_perform_call_protocol(&call);
-}
-EXPORT_SYMBOL_GPL(snp_svsm_vtpm_send_command);
-
 static struct platform_device sev_guest_device = {
 	.name		= "sev-guest",
 	.id		= -1,
--- a/arch/x86/coco/sev/internal.h
+++ b/arch/x86/coco/sev/internal.h
@@ -66,6 +66,9 @@ extern u64 boot_svsm_caa_pa;
 
 enum es_result verify_exception_info(struct ghcb *ghcb, struct es_em_ctxt *ctxt);
 void vc_forward_exception(struct es_em_ctxt *ctxt);
+void svsm_pval_pages(struct snp_psc_desc *desc);
+int svsm_perform_call_protocol(struct svsm_call *call);
+bool snp_svsm_vtpm_probe(void);
 
 static inline u64 sev_es_rd_ghcb_msr(void)
 {
@@ -87,4 +90,30 @@ enum es_result sev_es_ghcb_handle_msr(st
 u64 get_hv_features(void);
 
 const struct snp_cpuid_table *snp_cpuid_get_table(void);
+
+static inline struct svsm_ca *svsm_get_caa(void)
+{
+	if (sev_cfg.use_cas)
+		return this_cpu_read(svsm_caa);
+	else
+		return rip_rel_ptr(&boot_svsm_ca_page);
+}
+
+static inline u64 svsm_get_caa_pa(void)
+{
+	if (sev_cfg.use_cas)
+		return this_cpu_read(svsm_caa_pa);
+	else
+		return boot_svsm_caa_pa;
+}
+
+static inline void __pval_terminate(u64 pfn, bool action, unsigned int page_size,
+				    int ret, u64 svsm_ret)
+{
+	WARN(1, "PVALIDATE failure: pfn: 0x%llx, action: %u, size: %u, ret: %d, svsm_ret: 0x%llx\n",
+	     pfn, action, page_size, ret, svsm_ret);
+
+	sev_es_terminate(SEV_TERM_SET_LINUX, GHCB_TERM_PVALIDATE);
+}
+
 #endif /* __X86_COCO_SEV_INTERNAL_H__ */
--- /dev/null
+++ b/arch/x86/coco/sev/svsm.c
@@ -0,0 +1,362 @@
+// SPDX-License-Identifier: GPL-2.0-only
+/*
+ * SVSM support code
+ */
+
+#include <linux/types.h>
+
+#include <asm/sev.h>
+
+#include "internal.h"
+
+/* For early boot SVSM communication */
+struct svsm_ca boot_svsm_ca_page __aligned(PAGE_SIZE);
+SYM_PIC_ALIAS(boot_svsm_ca_page);
+
+/*
+ * SVSM related information:
+ *   During boot, the page tables are set up as identity mapped and later
+ *   changed to use kernel virtual addresses. Maintain separate virtual and
+ *   physical addresses for the CAA to allow SVSM functions to be used during
+ *   early boot, both with identity mapped virtual addresses and proper kernel
+ *   virtual addresses.
+ */
+u64 boot_svsm_caa_pa __ro_after_init;
+SYM_PIC_ALIAS(boot_svsm_caa_pa);
+
+DEFINE_PER_CPU(struct svsm_ca *, svsm_caa);
+DEFINE_PER_CPU(u64, svsm_caa_pa);
+
+static int svsm_perform_ghcb_protocol(struct ghcb *ghcb, struct svsm_call *call)
+{
+	struct es_em_ctxt ctxt;
+	u8 pending = 0;
+
+	vc_ghcb_invalidate(ghcb);
+
+	/*
+	 * Fill in protocol and format specifiers. This can be called very early
+	 * in the boot, so use rip-relative references as needed.
+	 */
+	ghcb->protocol_version = ghcb_version;
+	ghcb->ghcb_usage       = GHCB_DEFAULT_USAGE;
+
+	ghcb_set_sw_exit_code(ghcb, SVM_VMGEXIT_SNP_RUN_VMPL);
+	ghcb_set_sw_exit_info_1(ghcb, 0);
+	ghcb_set_sw_exit_info_2(ghcb, 0);
+
+	sev_es_wr_ghcb_msr(__pa(ghcb));
+
+	svsm_issue_call(call, &pending);
+
+	if (pending)
+		return -EINVAL;
+
+	switch (verify_exception_info(ghcb, &ctxt)) {
+	case ES_OK:
+		break;
+	case ES_EXCEPTION:
+		vc_forward_exception(&ctxt);
+		fallthrough;
+	default:
+		return -EINVAL;
+	}
+
+	return svsm_process_result_codes(call);
+}
+
+int svsm_perform_call_protocol(struct svsm_call *call)
+{
+	struct ghcb_state state;
+	unsigned long flags;
+	struct ghcb *ghcb;
+	int ret;
+
+	flags = native_local_irq_save();
+
+	if (sev_cfg.ghcbs_initialized)
+		ghcb = __sev_get_ghcb(&state);
+	else if (boot_ghcb)
+		ghcb = boot_ghcb;
+	else
+		ghcb = NULL;
+
+	do {
+		ret = ghcb ? svsm_perform_ghcb_protocol(ghcb, call)
+			   : __pi_svsm_perform_msr_protocol(call);
+	} while (ret == -EAGAIN);
+
+	if (sev_cfg.ghcbs_initialized)
+		__sev_put_ghcb(&state);
+
+	native_local_irq_restore(flags);
+
+	return ret;
+}
+
+static u64 svsm_build_ca_from_pfn_range(u64 pfn, u64 pfn_end, bool action,
+					struct svsm_pvalidate_call *pc)
+{
+	struct svsm_pvalidate_entry *pe;
+
+	/* Nothing in the CA yet */
+	pc->num_entries = 0;
+	pc->cur_index   = 0;
+
+	pe = &pc->entry[0];
+
+	while (pfn < pfn_end) {
+		pe->page_size = RMP_PG_SIZE_4K;
+		pe->action    = action;
+		pe->ignore_cf = 0;
+		pe->rsvd      = 0;
+		pe->pfn       = pfn;
+
+		pe++;
+		pfn++;
+
+		pc->num_entries++;
+		if (pc->num_entries == SVSM_PVALIDATE_MAX_COUNT)
+			break;
+	}
+
+	return pfn;
+}
+
+static int svsm_build_ca_from_psc_desc(struct snp_psc_desc *desc, unsigned int desc_entry,
+				       struct svsm_pvalidate_call *pc)
+{
+	struct svsm_pvalidate_entry *pe;
+	struct psc_entry *e;
+
+	/* Nothing in the CA yet */
+	pc->num_entries = 0;
+	pc->cur_index   = 0;
+
+	pe = &pc->entry[0];
+	e  = &desc->entries[desc_entry];
+
+	while (desc_entry <= desc->hdr.end_entry) {
+		pe->page_size = e->pagesize ? RMP_PG_SIZE_2M : RMP_PG_SIZE_4K;
+		pe->action    = e->operation == SNP_PAGE_STATE_PRIVATE;
+		pe->ignore_cf = 0;
+		pe->rsvd      = 0;
+		pe->pfn       = e->gfn;
+
+		pe++;
+		e++;
+
+		desc_entry++;
+		pc->num_entries++;
+		if (pc->num_entries == SVSM_PVALIDATE_MAX_COUNT)
+			break;
+	}
+
+	return desc_entry;
+}
+
+static void svsm_pval_terminate(struct svsm_pvalidate_call *pc, int ret, u64 svsm_ret)
+{
+	unsigned int page_size;
+	bool action;
+	u64 pfn;
+
+	pfn = pc->entry[pc->cur_index].pfn;
+	action = pc->entry[pc->cur_index].action;
+	page_size = pc->entry[pc->cur_index].page_size;
+
+	__pval_terminate(pfn, action, page_size, ret, svsm_ret);
+}
+
+void svsm_pval_pages(struct snp_psc_desc *desc)
+{
+	struct svsm_pvalidate_entry pv_4k[VMGEXIT_PSC_MAX_ENTRY];
+	unsigned int i, pv_4k_count = 0;
+	struct svsm_pvalidate_call *pc;
+	struct svsm_call call = {};
+	unsigned long flags;
+	bool action;
+	u64 pc_pa;
+	int ret;
+
+	/*
+	 * This can be called very early in the boot, use native functions in
+	 * order to avoid paravirt issues.
+	 */
+	flags = native_local_irq_save();
+
+	/*
+	 * The SVSM calling area (CA) can support processing 510 entries at a
+	 * time. Loop through the Page State Change descriptor until the CA is
+	 * full or the last entry in the descriptor is reached, at which time
+	 * the SVSM is invoked. This repeats until all entries in the descriptor
+	 * are processed.
+	 */
+	call.caa = svsm_get_caa();
+
+	pc = (struct svsm_pvalidate_call *)call.caa->svsm_buffer;
+	pc_pa = svsm_get_caa_pa() + offsetof(struct svsm_ca, svsm_buffer);
+
+	/* Protocol 0, Call ID 1 */
+	call.rax = SVSM_CORE_CALL(SVSM_CORE_PVALIDATE);
+	call.rcx = pc_pa;
+
+	for (i = 0; i <= desc->hdr.end_entry;) {
+		i = svsm_build_ca_from_psc_desc(desc, i, pc);
+
+		do {
+			ret = svsm_perform_call_protocol(&call);
+			if (!ret)
+				continue;
+
+			/*
+			 * Check if the entry failed because of an RMP mismatch (a
+			 * PVALIDATE at 2M was requested, but the page is mapped in
+			 * the RMP as 4K).
+			 */
+
+			if (call.rax_out == SVSM_PVALIDATE_FAIL_SIZEMISMATCH &&
+			    pc->entry[pc->cur_index].page_size == RMP_PG_SIZE_2M) {
+				/* Save this entry for post-processing at 4K */
+				pv_4k[pv_4k_count++] = pc->entry[pc->cur_index];
+
+				/* Skip to the next one unless at the end of the list */
+				pc->cur_index++;
+				if (pc->cur_index < pc->num_entries)
+					ret = -EAGAIN;
+				else
+					ret = 0;
+			}
+		} while (ret == -EAGAIN);
+
+		if (ret)
+			svsm_pval_terminate(pc, ret, call.rax_out);
+	}
+
+	/* Process any entries that failed to be validated at 2M and validate them at 4K */
+	for (i = 0; i < pv_4k_count; i++) {
+		u64 pfn, pfn_end;
+
+		action  = pv_4k[i].action;
+		pfn     = pv_4k[i].pfn;
+		pfn_end = pfn + 512;
+
+		while (pfn < pfn_end) {
+			pfn = svsm_build_ca_from_pfn_range(pfn, pfn_end, action, pc);
+
+			ret = svsm_perform_call_protocol(&call);
+			if (ret)
+				svsm_pval_terminate(pc, ret, call.rax_out);
+		}
+	}
+
+	native_local_irq_restore(flags);
+}
+
+static void update_attest_input(struct svsm_call *call, struct svsm_attest_call *input)
+{
+	/* If (new) lengths have been returned, propagate them up */
+	if (call->rcx_out != call->rcx)
+		input->manifest_buf.len = call->rcx_out;
+
+	if (call->rdx_out != call->rdx)
+		input->certificates_buf.len = call->rdx_out;
+
+	if (call->r8_out != call->r8)
+		input->report_buf.len = call->r8_out;
+}
+
+int snp_issue_svsm_attest_req(u64 call_id, struct svsm_call *call,
+			      struct svsm_attest_call *input)
+{
+	struct svsm_attest_call *ac;
+	unsigned long flags;
+	u64 attest_call_pa;
+	int ret;
+
+	if (!snp_vmpl)
+		return -EINVAL;
+
+	local_irq_save(flags);
+
+	call->caa = svsm_get_caa();
+
+	ac = (struct svsm_attest_call *)call->caa->svsm_buffer;
+	attest_call_pa = svsm_get_caa_pa() + offsetof(struct svsm_ca, svsm_buffer);
+
+	*ac = *input;
+
+	/*
+	 * Set input registers for the request and set RDX and R8 to known
+	 * values in order to detect length values being returned in them.
+	 */
+	call->rax = call_id;
+	call->rcx = attest_call_pa;
+	call->rdx = -1;
+	call->r8 = -1;
+	ret = svsm_perform_call_protocol(call);
+	update_attest_input(call, input);
+
+	local_irq_restore(flags);
+
+	return ret;
+}
+EXPORT_SYMBOL_GPL(snp_issue_svsm_attest_req);
+
+/**
+ * snp_svsm_vtpm_send_command() - Execute a vTPM operation on SVSM
+ * @buffer: A buffer used to both send the command and receive the response.
+ *
+ * Execute a SVSM_VTPM_CMD call as defined by
+ * "Secure VM Service Module for SEV-SNP Guests" Publication # 58019 Revision: 1.00
+ *
+ * All command request/response buffers have a common structure as specified by
+ * the following table:
+ *     Byte      Size       In/Out    Description
+ *     Offset    (Bytes)
+ *     0x000     4          In        Platform command
+ *                          Out       Platform command response size
+ *
+ * Each command can build upon this common request/response structure to create
+ * a structure specific to the command. See include/linux/tpm_svsm.h for more
+ * details.
+ *
+ * Return: 0 on success, -errno on failure
+ */
+int snp_svsm_vtpm_send_command(u8 *buffer)
+{
+	struct svsm_call call = {};
+
+	call.caa = svsm_get_caa();
+	call.rax = SVSM_VTPM_CALL(SVSM_VTPM_CMD);
+	call.rcx = __pa(buffer);
+
+	return svsm_perform_call_protocol(&call);
+}
+EXPORT_SYMBOL_GPL(snp_svsm_vtpm_send_command);
+
+/**
+ * snp_svsm_vtpm_probe() - Probe if SVSM provides a vTPM device
+ *
+ * Check that there is SVSM and that it supports at least TPM_SEND_COMMAND
+ * which is the only request used so far.
+ *
+ * Return: true if the platform provides a vTPM SVSM device, false otherwise.
+ */
+bool snp_svsm_vtpm_probe(void)
+{
+	struct svsm_call call = {};
+
+	/* The vTPM device is available only if a SVSM is present */
+	if (!snp_vmpl)
+		return false;
+
+	call.caa = svsm_get_caa();
+	call.rax = SVSM_VTPM_CALL(SVSM_VTPM_QUERY);
+
+	if (svsm_perform_call_protocol(&call))
+		return false;
+
+	/* Check platform commands contains TPM_SEND_COMMAND - platform command 8 */
+	return call.rcx_out & BIT_ULL(8);
+}



  parent reply	other threads:[~2026-09-30 18:43 UTC|newest]

Thread overview: 404+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 15:24 [PATCH 6.18 000/395] 6.18.55-rc1 review Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 001/395] xfs: dont stash removename operations with unknown ftype Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 002/395] erofs: fix large folio race in erofs_fscache_req_complete Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 003/395] drm/amd/display: Atomize IRQ register read/modify/write ops Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 004/395] ALSA: hda/realtek: Limit Star Labs internal mic boost Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 005/395] ALSA: hda/realtek: Add StarFighter HDA SSID Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 006/395] remoteproc: qcom_q6v5_adsp: Fix iommu_unmap() usage Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 007/395] KVM: s390: Fix IRQ injection with SIGP Stop and Store Status Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 008/395] s390/uv: Fix loop condition in uv_find_secrets Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 009/395] s390/uv: Prevent potential out-of-bounds read Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 010/395] bpf: Fix bpf_skb_change_tail wrt csum partial skbs Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 011/395] bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 012/395] selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 013/395] bpf: Fix divide-by-zero in btf_struct_walk() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 014/395] bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 015/395] tcp: Skip cond_resched() in inet_csk_listen_stop() under BPF context Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 016/395] HID: multitouch: Add report ID mismatch quirk for ASUS ROG Z13 Folio Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 017/395] HID: elecom: fix bus type for M-XGL20DLBK Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 018/395] KVM: x86/pmu: Move Intel PMU global MSRs to intel_is_valid_msr() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 019/395] bpf: Avoid soft lockup in __htab_map_lookup_and_delete_batch() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 020/395] bpf: Fix out-of-bounds read of rtt_min in sock_ops Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 021/395] bpf: Register dtor for freeing special fields Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 022/395] bpf: Fix UAF due to concurrent consumption of ttrace lists in alloc_bulk Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 023/395] bpf, sockmap: Fix self-redirect copied_seq double-counting Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 024/395] bpf, arm64: set up the frame pointer for the exception callback Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 025/395] pinctrl: meson: Fix typo in s4 group name Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 026/395] HID: amd_sfh: Validate PCI BAR size before mapping Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 027/395] HID: bpf: fix __hid_bpf_hw_check_params report length Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 028/395] KVM: riscv: Fix NACL hfence entry update order Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 029/395] RISC-V: KVM: Preserve firmware counter value across stop/start Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 030/395] RISC-V: KVM: Report snapshot write failure to the guest Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 031/395] RISC-V: KVM: Fix perf-backed counter accounting across stop and read Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 032/395] KVM: arm64: vgic-its: Free the caches when GITS_BASER changes Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 033/395] KVM: arm64: vgic-its: Skip unreachable devices instead of failing the save Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 034/395] KVM: arm64: Validate the SVE vector length in pkvm_vcpu_init_sve() Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 035/395] KVM: arm64: Do not clear VM-wide SVE feature on vCPU init failure Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 036/395] KVM: arm64: vgic-v3: Fix GICv3 trapping in protected mode Greg Kroah-Hartman
2026-09-30 15:24 ` [PATCH 6.18 037/395] KVM: arm64: Fix MTE flag initialization for protected VMs Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 038/395] KVM: arm64: Include VM type when checking VM capabilities in pKVM Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 039/395] KVM: arm64: Derive GUEST_HAS_SVE from the SVE feature bit at EL2 Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 040/395] KVM: arm64: Return -EINVAL for an empty SMCCC filter range at base 0 Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 041/395] KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 042/395] squashfs: Add dictionary size range check to prevent shift-out-of-bounds Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 043/395] scsi: sd_zbc: Reject disks with too many zones Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 044/395] pinctrl: sunxi: A523: fix voltage withstand encoding Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 045/395] Bluetooth: SMP: reject Security Request over BR/EDR Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 046/395] Bluetooth: btnxpuart: Fix skb leak in nxp_process_fw_dump() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 047/395] Bluetooth: mgmt: Dequeue pending mesh_send_sync entries on cancel Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 048/395] selftests: cgroup: give the O_TMPFILE open in get_temp_fd() a mode Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 049/395] scsi: megaraid_sas: Protect megasas_get_ctrl_info() in megasas_resume() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 050/395] docs: s390/pci: Improve and update PCI documentation Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 051/395] s390/pci/docs: Fix sriov_numvfs attribute name Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 052/395] s390/cio: Fix cio_update_schib() to not cache invalid schib Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 053/395] s390/cio: Check pmcw.dnv before pmcw.ena in I/O entry points Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 054/395] s390/cio: Guard PMCW field accesses with dnv check Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 055/395] fs: avoid repeated scans in evict_inodes() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 056/395] xsk: Use a 32-bit compare in xsk_map_gen_lookup Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 057/395] bpf: Skip unsettled links in link iterator Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 058/395] eth: fbnic: Fix payload page pool error cleanup Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 059/395] net/sched: cls_u32: fix manual hash table handle IDR aliasing Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 060/395] net: pcs: rzn1-miic: Fix config array initialization Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 061/395] octeontx2-af: use seq_file for rsrc_alloc debugfs Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 062/395] net/mlx5: devcom, Base component size on linked devices Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 063/395] bpf: Restrict CO-RE poisoning to relocatable instructions Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 064/395] libbpf: Reject truncated ldimm64 CO-RE relocations Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 065/395] ipv4: fib: fix data-race and stale genid check around nh->nh_saddr Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 066/395] netfilter: flowtable: publish HW_DEAD after worker is done Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 067/395] netfilter: nfnetlink_queue: hold nfnl mutex in event notifier Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 068/395] netfilter: nft_synproxy: use the family-aware checksum helper Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 069/395] ipvs: revalidate ihl before icmp_send Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 070/395] netfilter: ctnetlink: fix suspicious RCU usage in expect_iter_name Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 071/395] arm64: io: Reject non-user protection in ioremap_prot() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 072/395] ocfs2: make ocfs2_calc_xattr_init() return void Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 073/395] drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 074/395] drm/nouveau/clk: dont clobber reclock status when restoring volt/fan Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 075/395] drm/nouveau/disp: dont reject HDMI config on cards without SCDC Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 076/395] net/sched: act_ct: dont WARN on benign flow_offload_alloc() failure Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 077/395] net: gue: reject invalid REMCSUM offsets Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 078/395] net: ethernet: mtk_eth_soc: unregister net_devices in case of probe failure Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 079/395] ip6_gre: Call ip6erspan_tunnel_unlink_md() in ip6erspan_changelink() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 080/395] eth: fbnic: Handle maximum standalone channels Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 081/395] eth: fbnic: reset num_napi when the napi vectors are freed Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 082/395] eth: fbnic: Set AW_FLUSH_MODE alongside AW_FLUSH when flushing the mailbox Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 083/395] eth: fbnic: Reuse RX mailbox pages Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 084/395] eth fbnic: Add debugfs hooks for firmware mailbox Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 085/395] eth: fbnic: Handle FW mailbox completions flagged with an error Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 086/395] sctp: avoid livelock while updating retransmit path Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 087/395] bpf: Bound ownership depth through local kptrs and graph roots Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 088/395] net: usb: catc: bound the RX packet length in catc_rx_done() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 089/395] bpf: Check params size before reading reserved fields Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 090/395] net/sched: sch_hfsc: bound the classify inner-filter walk with a drift budget Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 091/395] drm/virtio: fix object leak when drm_gem_handle_create() fails Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 092/395] drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 093/395] drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl() Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 094/395] drm/virtio: release the GEM object on virtio_gpu_vram_create() errors Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 095/395] Revert "drm/virtio: Allow importing prime buffers when 3D is enabled" Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 096/395] drm/virtio: sync shmem backing on guest-bound transfers Greg Kroah-Hartman
2026-09-30 15:25 ` [PATCH 6.18 097/395] drm/bridge: samsung-dsim: fix TE GPIO lifetime for host attach Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 098/395] ovpn: preserve IPv6 scope id for netlink peer endpoints Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 099/395] ovpn: skip UDP source validation for unspecified addresses Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 100/395] ovpn: track UDP socket route key for peer dst cache Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 101/395] ovpn: validate peer state before caching UDP dst Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 102/395] ovpn: replace bind when learning local endpoint Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 103/395] ovpn: replace bind when clearing stale local source Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 104/395] ovpn: always unhash old VPN addresses before rehashing Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 105/395] ovpn: reject duplicate peer VPN addresses Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 106/395] ovpn: reject multipeer peers without " Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 107/395] ovpn: reject invalid peer " Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 108/395] Bluetooth: bnep: fix out-of-bounds reads on short RX/TX frames and control fallthrough Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 109/395] Bluetooth: btintel_pcie: validate device-supplied DMA indices Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 110/395] Bluetooth: RFCOMM: Reject short EA=0 frames in rfcomm_recv_frame() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 111/395] octeontx2-af: Fix memory scaling limitation in SR-IOV mode Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 112/395] ipv6: Prevent rt6_insert_exception() for dying fib6_info Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 113/395] dpll: use exact lookup for reference sync pin id Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 114/395] net: usb: sr9700: include receive overhead in the length check Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 115/395] ipv6: Fix dst leak for uncached routes Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 116/395] udp: relocate a connected socket in the 4-tuple hash table on re-connect Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 117/395] udp: remove a disconnected socket from the 4-tuple hash table Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 118/395] tg3: clean up PHYLIB resources on probe failure Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 119/395] drm/i915/psr: Clear stale sel fetch enable bits on sel fetch disable Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 120/395] s390/debug: Do not register views for failed static debug areas Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 121/395] s390/debug: Fix NULL pointer dereference in debug_info_copy() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 122/395] net: spacemit: clear TX descriptor on fragment mapping failure Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 123/395] net: ethernet: ti: netcp: fix pm_runtime usage counter leak on error Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 124/395] genetlink: report the real command id for dump-only ops in policy dumps Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 125/395] net: pcs: xpcs: fix clock reference leak on xpcs_init_clks failure Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 126/395] thermal: gov_step_wise: Fix stale mitigation vote with non-zero lower bounds Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 127/395] bpf: Fix bounds check for skb-backed dynptrs Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 128/395] bpf: Fix bpf_sock context code generation Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 129/395] bpf, sockmap: Reject max_entries > INT_MAX in sock_map_alloc Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 130/395] net/mlx5: Bridge, dont fail switchdev events of sibling eswitch ports Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 131/395] net/mlx5: Bridge, dont fail unlink of untracked/unsupported peer ports Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 132/395] sctp: hold asoc or transport before mod_timer() in timer handlers Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 133/395] net: stmmac: selftests: Support running selftests on DSA conduits Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 134/395] net: stmmac: selftests: Check the dev->features for S-TAG offload testing Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 135/395] net: stmmac: selftests: Capture all packets for vlan checks Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 136/395] net: stmmac: dwmac4: Use the correct bufzise when the len is exactly 8K Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 137/395] net: stmmac: selftests: Account for alignment shift on dwmac1000 for Jumbo test Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 138/395] eth: fbnic: Avoid rounding zero ring sizes Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 139/395] net/sched: fix potential stack infoleak in em_text_dump() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 140/395] bpf: Reject dev-bound-only programs on other devices Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 141/395] nfc: nfcmrvl: validate helper command length before pull Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 142/395] nfc: st21nfca: validate received frame size Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 143/395] nfc: llcp: Fix list corruption / refcount desync in nfc_llcp_recv_dm() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 144/395] selftests: nci: Correct pthread_create return value check Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 145/395] nfc: llcp: Fix race condition in accept_queue lifecycle Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 146/395] selftests: nci: Fix uninitialized family ID on missing attribute Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 147/395] selftests/nci: Fix out-of-bounds store on thread join Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 148/395] nfc: virtual_ncidev: Add missing ioctl compat handler Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 149/395] nfc: llcp: fix sdreq TLV list leak on parse/alloc/send failure Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 150/395] nfc: st21nfca: validate ISO15693 inventory length Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 151/395] nfc: llcp: fix -ENOMEM on connect with zero-length service name Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 152/395] nfc: llcp: fix WKS SAP hijacking via prefix match in nfc_llcp_wks_sap() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 153/395] nfc: llcp: fix slab-out-of-bounds reads when logging service names Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 154/395] nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid() Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 155/395] net/sched: act_gate: budget the per-entry list in get_fill_size Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 156/395] net: bcmgenet: stop Tx NAPI before disabling the queues Greg Kroah-Hartman
2026-09-30 15:26 ` [PATCH 6.18 157/395] veth: manage XDP program pointers during channel resize Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 158/395] net: skbuff: fix pull-bound underflow in skb_checksum_setup_ipv6() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 159/395] vrf: Stop corrupting skb->csum when capturing CHECKSUM_COMPLETE packets Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 160/395] bpf: Fix immediate JMP JEQ/JNE on MIPS32 Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 161/395] bpf: Fix BSWAP 32 and 16 on MIPS64 Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 162/395] tg3: use random MAC address when tg3_get_device_address fails Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 163/395] net: stmmac: clear stale buf->page after recycling on skb build failure Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 164/395] net: bcmgenet: fix 64-bit RTNL stats reading in ethtool on 32-bit systems Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 165/395] net: bcmgenet: initialize u64 stats seq counter for all queues Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 166/395] net: bcmgenet: do not skip WoL power up on GENET V1 Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 167/395] net: bcmgenet: validate Ethernet address in bcmgenet_set_mac_addr Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 168/395] net: bcmgenet: mask DMA_TIMEOUT_MASK when reading DMA_RING0_TIMEOUT Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 169/395] ip_gre: Reject enabling collect metadata through changelink Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 170/395] vxlan: use one headroom snapshot for neighbour replies Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 171/395] net: xps: reject an out of range traffic class Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 172/395] drm/imagination: clamp freelist reconstruction requests Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 173/395] bonding: crypto offload enabled, non-offload slave failover, rekey failed Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 174/395] macsec: initialize SecY before registering the netdevice Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 175/395] net: dsa: mt7530: fix NULL dereference on unbind of MT7531 and MT7621 Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 176/395] net: dsa: mt7530: leave the MDIO IRQ mappings to regmap-irq Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 177/395] tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 178/395] net: phylink: record the PHY only once bringup cannot fail Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 179/395] nfp: hold IPsec RX state under the XArray lock Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 180/395] net/smc: fix UAF on lgr list traversal in smcr_port_err() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 181/395] tipc: Fix a data race on mon->peer_cnt in mon_timeout() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 182/395] net: ethernet: stmmac: dwmac-rk: fix bulk clock leak when the PHY clock fails Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 183/395] gve: Consolidate and persist ethtool ring changes Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 184/395] gve: Use extack to log xdp config verification errors Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 185/395] gve: Allow ethtool to configure rx_buf_len Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 186/395] gve: Advertise NETIF_F_GRO_HW instead of NETIF_F_LRO Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 187/395] gve: Enable hw-gro by default if device supported Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 188/395] gve: add support for UDP GSO for DQO format Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 189/395] gve: DQO: fix header length used by gve_can_send_tso() for UDP GSO Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 190/395] gve: fix TX drop when GSO MSS is too small for hw Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 191/395] gve: DQO: reject TSO packets with an out of range MSS Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 192/395] llc: fix skb UAF and leaks on llc_mac_hdr_init() failure Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 193/395] bridge: check llc_mac_hdr_init() return value in br_send_bpdu() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 194/395] net/sched: sch_teql: fix shadowed err in __teql_resolve() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 195/395] vlan: ensure sufficient headroom in vlan_dev_hard_header() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 196/395] autofs: fix sbi->pipe file reference leak in autofs_kill_sb() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 197/395] perf/x86/intel: Ensure KVM guest PEBS path doesnt set unwanted PERF_GLOBAL_CTRL bits Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 198/395] perf/x86/intel: Dont write PEBS_ENABLED on host<=>guest xfers if CPU has PEBS isolation, to fix stuck PEBS_ENABLED Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 199/395] perf/x86/intel: Dont pointlessly context switch DS_AREA (and PEBS config) if PEBS is unused Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 200/395] perf/x86/intel: Make @data a mandatory param for intel_guest_get_msrs() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 201/395] perf/core: Fix a refcount leak in attach_perf_ctx_data() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 202/395] sched/core: Account PSI IRQ time to the execution context, not the scheduling context Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 203/395] mptcp: return sk_wait_data() errors from recvmsg() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 204/395] rculist: add list_splice_rcu() for private lists Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 205/395] netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 206/395] x86/mce: Fix hardware debug register corruption on task migration Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 207/395] x86/PCI: Disable enhanced atomics on AMD NBIO 7.7 and 7.11 Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 208/395] virtio_net: copy zerocopy frags in start_xmit without NAPI Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 209/395] tipc: reject invalid and unexpected GRP_ACK_MSG to prevent bc_ackers underflow Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 210/395] tcp: prevent collapsing skbs across boundary in rtx queue Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 211/395] sctp: discard the rest of the packet on a stale-cookie error Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 212/395] af_packet: fix integer overflow in prb_calc_retire_blk_tmo() Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 213/395] arm64/boot: Disable trapping of PMZR_EL0 writes to EL2 Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 214/395] arm64: errata: match the target implementation CPUs own MIDR Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 215/395] ata: libata-scsi: bound the ATA passthru sense descriptor writes Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 216/395] bna: prevent IOC timer rearm during teardown Greg Kroah-Hartman
2026-09-30 15:27 ` [PATCH 6.18 217/395] bpf: fs/xattr: dont assume the inode is locked in path_unlink/path_rmdir Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 218/395] crypto: s390/hmac - Generate intermediate CV for API partial block handling Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 219/395] cgroup/pids: Restore pids.events notifications in local mode Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 220/395] fou: reject omitted FOU_ATTR_IPPROTO on FOU_ENCAP_DIRECT Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 221/395] fs/ntfs3: use d_instantiate_new() in ntfs_create_inode() and murder syzbots "WARNING in do_new_mount" saga Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 222/395] writeback: bound cleanup_offline_cgwb() rescans by rotating scanned inodes Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 223/395] workqueue: Fix NULL current_pwq deref in flush dependency check Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 224/395] writeback: report a Tasks-RCU quiescent state per cgwb drain pass Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 225/395] fsl/fman: Fix clk reference leak in read_dts_node() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 226/395] ipe: fix use-after-free when auditing a newly loaded policy Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 227/395] ipe: protect the dm-verity root hash with RCU Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 228/395] ipv6: do not let ipv6_find_hdr() return an offset past the packet end Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 229/395] ipv6: sr: enforce exact attribute length for SEG6_ATTR_DST Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 230/395] gpio: arizona: Fix runtime PM leak in arizona_gpio_direction_out() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 231/395] gpio: cdev: fix kernel stack leak to user-space in error path Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 232/395] gpio: zynq: fix runtime PM leak on request " Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 233/395] llc: reserve device headroom for allocated frames Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 234/395] mctp: route: iterate socket tag list in mctp_lookup_prealloc_tag() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 235/395] rds: ib: Clear the sg list when mapping an MR fails Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 236/395] drm/imagination: Propagate map failures correctly from pvr_mmu_map_sgl() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 237/395] drm/imagination: Fix page count for page table for map() interface Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 238/395] drm/i915: fix incorrect RCU teardown order Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 239/395] drm/i915/dp_mst: Fix configuring FEC for a disconnected stream Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 240/395] drm/i915/dp_mst: Fix configuring TUs " Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 241/395] drm/amd/display: Fix dc stream excess put in dm_update_crtc_state() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 242/395] drm/amd/display: Bump frame warning limit for clang builds of dml Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 243/395] drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 244/395] drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 245/395] drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 246/395] drm/nouveau/uvmm: fix UAF in nouveau_uvmm_sm when BO is in TTM_PL_SYSTEM Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 247/395] drm/nouveau: fix autosuspend cleanup during teardown Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 248/395] drm/nouveau: Fix bridge reference leak in nv1a_ram_new() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 249/395] drm/nouveau: fix double-free in nvif_vmm_dtor Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 250/395] drm/nouveau: Fix gem reference leak in validate_init() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 251/395] drm/nouveau: Fix runtime PM leak in nouveau_connector_detect() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 252/395] drm/nouveau: RCU-free the scheduler-containing nouveau_sched Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 253/395] drm/nouveau: dont bump pin count on failed re-pin in nouveau_bo_pin_locked() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 254/395] drm/xe/vm: nuke PTs only after unlinking contested VMAs Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 255/395] drm/xe: harden adjust_idledly() against divide-by-zero and overflow Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 256/395] drm/xe: Limit sg segment size to PAGE_SIZE on Xen PV Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 257/395] drm/xe: Keep walking on SVM eviction failure Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 258/395] drm/virtio: fix memory leak of fence event on execbuffer failure Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 259/395] drm/virtio: fix NULL pointer dereference on fence allocation failure Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 260/395] gpio: tps65219: Fix GPIO input value reads Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 261/395] gpio: tps65219: Use the variant-specific direction callback Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 262/395] gpio: tps65219: Fix TPS65214 GPIO direction programming Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 263/395] mm/hugetlb: preserve mremap address delta when skipping page tables Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 264/395] mm/damon/vaddr: avoid hw-driven pte updates during damon_hugetlb_mkold() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 265/395] PCI: of_property: Omit bus properties without a subordinate bus Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 266/395] packet: use ubuf_info completion for TX_RING packets Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 267/395] HID: alps: fix use-after-free on input2 registration failure Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 268/395] HID: quirks: add ALWAYS_POLL quirk for SDINNOVATION gaming keyboard Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 269/395] HID: wacom: fix OOB read in wacom_wac_pen_serial_enforce() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 270/395] net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get() Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 271/395] net/mlx5e: advertise MACsec offload only when supported Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 272/395] net/mlx5e: fix swapped IPv6 IPsec policy masks Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 273/395] net/sched: reject IDR error pointers when deleting actions Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 274/395] net: airoha: npu: cancel wdt_work after releasing the WDT IRQ Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 275/395] net: arp: terminate device name before lookup Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 276/395] net: atl1: fix soft lockup on out-of-range cmb_tpd_next_to_clean read Greg Kroah-Hartman
2026-09-30 15:28 ` [PATCH 6.18 277/395] net: hisilicon: hns_dsaf_mac: fix mdio device leak in hns_mac_register_phy() Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 278/395] net: openvswitch: conntrack: avoid modifying shared unconfirmed ct entry Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 279/395] net: openvswitch: conntrack: remove add_helper dead code Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 280/395] net: openvswitch: conntrack: fix helper UAF due to extensions realloc Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 281/395] net: atl1c: fix soft lockup on out-of-range tpd_cons read Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 282/395] net: atl1e: fix soft lockup on out-of-range hw_next_to_clean read Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 283/395] net: bridge: mdb: restart port group walk after deletion Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 284/395] net: ena: fix PHC cleanup on probe failure Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 285/395] net: ena: fix MMIO read buffer leak " Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 286/395] net: phy: micrel: Advance register data pointer in write loop Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 287/395] net: txgbe: fix FDIR filter restore for VF rules Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 288/395] net: usb: cdc_mbim: add MeiG Smart SRM821 to ZLP whitelist Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 289/395] net: usb: lan78xx: Fix URB reference leak in lan78xx_submit_deferred_urbs() Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 290/395] netfilter: ip6t_rpfilter: reject routes without inet6_dev Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 291/395] netfilter: ip6t_rt: fix zero-address non-strict match out-of-bounds read Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 292/395] netfilter: nf_tables: skip expired catchall elements on insert and delete Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 293/395] nfc: fix use-after-free in nfc_get_local_general_bytes Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 294/395] nfc: llcp: drop truncated I/RR/RNR PDUs in nfc_llcp_recv_hdlc() Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 295/395] nfc: port100: reject frames whose declared length exceeds the received data Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 296/395] nfc: trf7970a: power down on startup RX gain failure Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 297/395] scsi: libiscsi_tcp: Check the data direction of a Data-In PDU Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 298/395] parisc: Increase kernel stack size to 32kb Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 299/395] perf/core: Fix NULL pmu_ctx passed to pmu->sched_task() Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 300/395] perf/core: Run sched_task() for PMUs with only CPU-wide events Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 301/395] pinctrl: single: free the IRQ on domain creation failure Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 302/395] pinctrl: sunxi: keep a shadow copy of the data register output latches Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 303/395] s390/cio: Fix NULL pointer dereference in ccw_device_get_util_str() Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 304/395] s390/cmf: Fix virtual vs physical address confusion Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 305/395] s390/pci: Fix leak of struct pci_dev reference in zpci_report_status() Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 306/395] s390/pci: Fix missing device lock " Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 307/395] s390/pci: Report SCLP status on error events when no pdev is associated Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 308/395] s390/pci: Dont report recovery success on skipped recovery Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 309/395] s390/vfio-ap: fix KVM GISC and page leak when queue removed from host config Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 310/395] KVM: Ensure memory attributes xarray nodes are accounted to the callers memcg Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 311/395] KVM: Dont treat reserved xarray entries as having memory attributes Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 312/395] KVM: SEV: Free have_run_cpus during VM destruction even if VM is no longer SEV Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 313/395] KVM: SEV: Do cache maintenance on the source VM during intra-host migration Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 314/395] KVM: arm64: Fix AArch32 DBGBXVR<n> handling Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 315/395] KVM: arm64: Fix spurious warning for benign stage 2 teardown race Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 316/395] KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, " Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 317/395] KVM: arm64: Transfer the hyp stack pages out of the host stage-2 Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 318/395] RISC-V: KVM: Synchronize hrtimer callback during teardown Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 319/395] RISC-V: KVM: Propagate interrupted G-stage faults Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 320/395] RISC-V: KVM: Fix HSM hart status error propagation Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 321/395] Bluetooth: hci_conn: fix CIS hold ownership on reuse Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 322/395] Bluetooth: hci_sock: validate event length before filtering Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 323/395] Bluetooth: hci_sock: reject out-of-range OCF values Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 324/395] Bluetooth: ISO: balance the parent hold in hci_bind_bis() Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 325/395] Bluetooth: ISO: release unused CIS holds after channel attach Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 326/395] Bluetooth: L2CAP: validate frame length before control and FCS access Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 327/395] Bluetooth: mgmt: fix race in read_unconf_index_list() Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 328/395] Bluetooth: RFCOMM: fix NULL dereference of dlc->session in RFCOMM_CONNINFO Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 329/395] smb: client: fix create context out-of-bounds reads Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 330/395] smb: client: clean up failed cached directory opens Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 331/395] smb: client: preserve create-context parsing errors Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 332/395] smb: client: validate POSIX create context length Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 333/395] xfs: dont assert when XFS_SCRUB_TYPE_HEALTHY scans return corruption Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 334/395] xfs: fix attr fork block count checks in xrep_inode_blockcounts Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 335/395] xfs: release orphanage dir inode if chown fails Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 336/395] xfs: use correct jiffies comparison function in xchk_maybe_relax Greg Kroah-Hartman
2026-09-30 15:29 ` [PATCH 6.18 337/395] xfs: check padding field in xfs_ioc_commit_range Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 338/395] xfs: dont call xfs_exchange_range_finish for a dry run Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 339/395] xfs: use the correct reservations for rtrmap/refcount recovery Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 340/395] xfs: check di_forkoff correctly in scrub Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 341/395] xfs: fix rtgroup repair estimations Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 342/395] xfs: fix wild memcpy access when formatting ondisk rtrefcount btree roots Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 343/395] xfs: call xfs_dquot_set_prealloc_limits if we installed default rtb limits Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 344/395] xfs: dont let hidden_space go negative in xfs_metafile_resv_init Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 345/395] xfs: drop dquot flush lock when we cant find a buffer to flush Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 346/395] xfs: fix blockgc group quota scanning when usrquota isnt enforced Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 347/395] xfs: fix cursor and pointer handling when recovering iunlink buckets Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 348/395] net: tls: fix silent data drop under pipe back-pressure Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 349/395] cgroup/cpuset: Move up prstate_housekeeping_conflict() helper Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 350/395] cgroup/cpuset: Ensure domain isolated CPUs stay in root or isolated partition Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 351/395] cgroup/cpuset: Return PERR_NOCPUS in remote_partition_enable() on subpartitions_cpus conflict Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 352/395] vlan: require the MAC header to be present in __vlan_insert_inner_tag() Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 353/395] i2c: qcom-geni: Fix hardcoded clock index in SE_GENI_CLK_SEL Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 354/395] drm/i915/psr: Disable Panel Replay on Dell XPS 14 DA14260 as a quirk Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 355/395] drm/i915/psr: Fixes for Dell XPS DA14260 quirk Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 356/395] drm/i915/psr: Disable PSR2 on Xiaomi Book Pro 14 2026 as a quirk Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 357/395] drm/i915/quirks: Limit eDP rate to HBR2 on HP Pavilion Plus 14-ew1 Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 358/395] drm/amdgpu: Fix acpi device leak in amdgpu_acpi_enumerate_xcc() Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 359/395] drm/client: Remove holds_console_lock parameter from suspend/resume Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 360/395] drm/client: Pass force parameter to client restore Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 361/395] drm/client: fix restore of partially initialized client Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 362/395] mm/rmap: allocate anon_vma_chain objects unlocked when possible Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 363/395] mm/rmap: fix missing barrier between anon_vma init and vma->anon_vma publish Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 364/395] mm/hugetlb: create hstate_is_gigantic_no_runtime helper Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 365/395] mm/hugetlb: do not dissolve gigantic pages without runtime support Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 366/395] super: make iterate_supers_type() deletion-safe Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 367/395] PCI: Fix BAR resize for devices on a root bus Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 368/395] HID: hid-alps: Use pm_ptr instead of #ifdef CONFIG_PM Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 369/395] HID: alps: unregister DualPoint Stick input device on remove Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 370/395] net: macb: fix dma_alloc_coherent() leak on macb_alloc() error paths Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 371/395] net: ipconfig: Remove outdated comment and indent code block Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 372/395] net: ipconfig: bound DHCP option construction Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 373/395] perf/x86/intel: Update event constraints and cache_extra_regsfor ADL Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 374/395] perf/x86/intel: Fix GRT PEBS load/store direction for latency events, to fix sample classification Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 375/395] perf/x86/intel: Update event constraints and cache_extra_regsfor LNL Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 376/395] perf/x86/intel: Remove incorrect LionCove PEBS data-source constraints Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 377/395] x86/sev: Move the internal header Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 378/395] x86/sev: Add internal header guards Greg Kroah-Hartman
2026-09-30 15:30 ` Greg Kroah-Hartman [this message]
2026-09-30 15:30 ` [PATCH 6.18 380/395] x86/sev: Remove redundant ghcbs_initialized checks around __sev_{get,put}_ghcb() Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 381/395] x86/sev: Make vTPM SVSM calls preemption-safe Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 382/395] net/sched: act_ct: fix helper UAF due to extensions realloc Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 383/395] net/sched: act_ct: avoid modifying shared unconfirmed ct entry Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 384/395] RISC-V: KVM: Fix null pointer dereference in kvm_riscv_aia_imsic_rw_attr() Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 385/395] RISC-V: KVM: Serialize IMSIC attributes with vCPU migration Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 386/395] Revert "rust: net: phy: fix off-by-one bit positions in device status accessors" Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 387/395] rust: net: phy: fix off-by-one bit positions in device status accessors Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 388/395] mm/damon/core: fix unconditionally skip last region Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 389/395] hfsplus: avoid double unload_nls() on mount failure Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 390/395] sched_ext: Derive SCX_RQ_IN_WAKEUP from the core enqueue flags Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 391/395] rose: keep the route needed for routing loop detection Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 392/395] rose: guard rose_transmit_link() against a NULL neighbour Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 393/395] rose: use timer_shutdown_sync() for t0timer teardown Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 394/395] rose: dont warn on stray CALL_ACCEPTED/CLEAR_CONFIRMATION in state 3 Greg Kroah-Hartman
2026-09-30 15:30 ` [PATCH 6.18 395/395] bpf: Reject key-less BTF for hash maps Greg Kroah-Hartman
2026-09-30 21:13 ` [PATCH 6.18 000/395] 6.18.55-rc1 review Florian Fainelli
2026-10-01  1:10 ` Peter Schneider
2026-10-01  9:18 ` Pavel Machek
2026-10-01 10:00 ` Ron Economos
2026-10-01 13:11 ` Miguel Ojeda
2026-10-01 16:44 ` Brett A C Sheffield
2026-10-01 20:34 ` Wentao Guan
2026-10-02  1:45 ` Barry K. Nathan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930152348.919824678@linuxfoundation.org \
    --to=gregkh@linuxfoundation.org \
    --cc=bp@alien8.de \
    --cc=patches@lists.linux.dev \
    --cc=sashal@kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=thomas.lendacky@amd.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox